Institutions deploying AI all ask the same question: do we start from scratch, or can we attach AI governance to the information security management system already in place? The answer is more favourable than most expect — provided you understand where the two standards overlap and where they genuinely diverge.
Two standards, two objects
The ISO/IEC 27000 family governs information security. It runs to some forty documents, but only one is certifiable: ISO/IEC 27001, which sets the requirements for an information security management system. The others — 27002 for security controls, 27005 for risk assessment, 27701 for privacy — are guidance orbiting around it.
ISO/IEC 42001, published in December 2023, is the world’s first AI management system standard. It addresses any organisation that develops, provides or uses AI-based systems, in any sector.
The key point: these are not competing standards. One protects information; the other governs how AI is designed, deployed and monitored.
The shared backbone: the harmonised structure
This is where the savings sit. Both standards follow the same skeleton — the harmonised structure, formerly Annex SL — also used by ISO 9001 and ISO 14001. Their requirements live in clauses 4 to 10 and run on the same Plan-Do-Check-Act cycle.
| Clause | Subject | Reusable across standards |
|---|---|---|
| 4 — Context of the organisation | Scope, interested parties | Largely |
| 5 — Leadership | Policy, roles, responsibilities | Largely |
| 6 — Planning | Risks, opportunities, objectives | Partly: the nature of the risks differs |
| 7 — Support | Competence, awareness, documentation | Largely |
| 8 — Operation | Operational implementation | Little: each standard’s specific core |
| 9 — Evaluation | Internal audit, management review | Largely |
| 10 — Improvement | Non-conformities, corrective action | Largely |
In practice, an organisation already certified to 27001 has the documentary governance, the internal audit machinery and the management review. What remains to be built is clause 8 and the AI-specific controls.
What 42001 adds that 27001 does not cover
This is the question that determines the real workload. ISO/IEC 42001 introduces requirements information security does not address:
- AI system impact assessment on individuals and groups, the subject of a dedicated standard, ISO/IEC 42005:2025.
- Bias management, on training data as much as on model outputs.
- Data traceability: provenance, lawfulness of use, quality, life cycle.
- Transparency towards affected people, and documentation of automated decisions.
- Human oversight at sensitive stages of the life cycle.
None of these has an equivalent in Annex A of 27001. Conversely, 42001 does not replace information security: a well-governed model hosted on poorly protected infrastructure remains a risk.
2026: certification becomes genuinely accredited
This is the year’s real change, and it went largely unnoticed. Until recently, 42001 certificates were issued without a settled accreditation framework for certification bodies. ISO/IEC 42006:2025 fixes that: it sets the requirements applying to bodies that audit and certify an AI management system, complementing ISO/IEC 17021-1, with precise rules on auditor competence and audit time calculation.
Accreditation bodies followed. In the United States, ANAB makes it a mandatory criteria document for any 42001 accreditation. In the United Kingdom, UKAS granted BSI, in January 2026, the first accreditation issued under ISO/IEC 42006.
The practical consequence: a 42001 certificate issued today under accreditation does not carry the same evidential weight as one issued in 2024. If you require this certification from a supplier, the question is no longer “are you certified” but “by which body, and under what accreditation”.
What a 42001 certificate does not prove
A misunderstanding is circulating, and it will cost those who settle into it. ISO/IEC 42001 is not a harmonised standard under the EU AI Act. Certification therefore creates no presumption of conformity with the regulation.
Harmonised standards are being developed at CEN-CENELEC, including draft prEN 18286 on AI management systems. Until they are published in the Official Journal of the European Union, no voluntary certification removes the need to demonstrate compliance on your own terms.
That does not make the exercise pointless — quite the opposite. A 42001 certificate is solid evidence of a systematic approach to AI risk, and most of the work will be reusable the day harmonised standards appear. But it is no substitute for regulatory analysis.
What this changes for you
- Start from what exists rather than from a new project. If you are 27001 certified, attach the AI management system to the existing arrangement: scope, leadership, internal audit and management review all carry over. Concentrate the effort on clause 8 and the AI-specific controls.
- Rewrite your supplier requirements. Ask for the certification body’s name and its accreditation, not merely for the existence of a certificate. Since ISO/IEC 42006:2025, the distinction is verifiable.
- Never present certification as EU AI Act compliance. Internally and in tender responses, the accurate wording is “documented systematic approach”, not “compliant with the EU AI Act”.
Bringing information security and AI governance together is less a matter of standards than of organisation — which is precisely the ground our consulting work in organisation and continuous improvement covers.
Sources
- ISO/IEC 42001:2023 — Artificial intelligence management systems — International Organization for Standardization
- ISO/IEC 42006:2025 — Requirements for bodies providing audit and certification of AIMS — International Organization for Standardization
- ISO/IEC 27001:2022 — Information security management systems — International Organization for Standardization
- Understanding the standardisation of the AI Act — European Commission
- ISO/IEC 42001 Artificial Intelligence Management Systems — certification body accreditation — ANAB

Leave a Reply