Do we need ISO 42001 if we already hold ISO 27001?
Yes, if you build or deploy AI systems and want certified assurance over them. ISO 42001 shares ISO 27001's management-system structure, so your existing clauses 4 to 10 — context, leadership, planning, internal audit, management review — largely carry across. What does not carry across is the subject matter: 27001 governs information security, 42001 governs the AI system lifecycle, including impact assessment, data quality, human oversight and model transparency.
The practical read is that holding 27001 makes 42001 substantially cheaper rather than unnecessary. You are extending a management system you already run, not standing up a second one.
The gap that surprises most teams is not technical. It is that AI impact assessment asks about effects on individuals and society, which is a different question from the asset-and-threat framing an information security team is fluent in.
Sources
- ISO/IEC 42001:2023 — Annex A and management system clauses
- ISO/IEC 27001:2022 — harmonised structure
Drafted with the tools on this site, then checked against the sources above by a practitioner before publishing. Reviewed 2026-08-07. Found something wrong? It should be corrected — this page is only worth as much as its accuracy.