Guide 10 min read

ISO 42001 on Top of ISO 27001: The Real Extra Work

J

September 28, 2026

The Question Every ISO 27001 Client Asks Me First

Every conversation I have with an ISO 27001-certified client about ISO 42001 starts the same way. Not "what is an AI management system" — they've read the LinkedIn posts. Not "do we need this" — a customer or a regulator has already told them they might. What they actually want to know is narrower and more useful: how much of what we already built for our ISMS carries over, and how much is genuinely new work?

That's a fair question, and it has a real answer. It's not "a little" and it's not "almost all of it." It's somewhere in between, and where you land depends on how seriously your ISO 27001 program was actually run versus how much of it exists mainly in a binder for the auditor.

Why This Question Is Suddenly Urgent

ISO/IEC 42001:2023 is the first certifiable management system standard built specifically for organizations that develop, provide, or use AI systems. It was published in December 2023, making it young compared to ISO 27001's two decades of history.

Procurement teams that used to ask "are you ISO 27001 certified" are starting to ask "are you ISO 42001 certified" in the same breath. That shift shows up most in regulated industries and in any vendor relationship where the customer is using your product to make decisions about people.

If you're the compliance lead who already carries ISO 27001, you're the natural owner of this question inside your organization, whether you asked for that role or not.

How Much Structural Overlap Actually Exists

Here's the part that surprises people in a good way. ISO/IEC 42001:2023 and ISO/IEC 27001:2022 both use the Annex SL harmonized structure that ISO applies across its management system standards, which means clauses 4 through 10 carry the same titles and roughly the same numbering in both. Context of the organization, leadership, planning, support, operation, performance evaluation, improvement — if you've written this once, you're not starting from a blank page the second time.

That's not a marketing simplification. It's the actual clause architecture, and it's the reason organizations with a mature ISMS move through the management-system half of ISO 42001 faster than organizations building an AI governance program from zero.

Where the two standards diverge is Annex A, and the divergence is bigger than most people expect.

Element ISO/IEC 27001:2022 ISO/IEC 42001:2023
Core clauses 4–10, Annex SL structure 4–10, same Annex SL structure
Annex A controls 93 controls 38 controls
Annex A themes 4 (organizational, people, physical, technological) 9 (A.2 policies through A.10 third-party relationships)
Scope object Information assets AI systems across their lifecycle
Unique clause requirement Risk assessment and treatment (6.1.2, 6.1.3) Adds AI system impact assessment (6.1.4)
Certifiable Yes, accredited third-party certification Yes, accredited third-party certification
Published 2022 (current revision) 2023

The control counts tell you where the real work sits. ISO 27001's Annex A is broad and mature: 93 controls covering access management, cryptography, physical security, supplier relationships, and more. ISO 42001's Annex A is narrower but oriented around questions ISO 27001 was never built to ask: is this AI system's impact on people, groups, and society being assessed, is the training data documented and fit for purpose, is a human able to intervene when the system behaves unexpectedly. A few of the 38 AI-specific controls — Annex A's internal-organization requirements (A.3) and resourcing requirements (A.4) — have a direct ISO 27001 cousin. The rest, including the data governance (A.7) and third-party (A.10) controls covered below, are new territory even for a mature security program.

What's Genuinely New, Not Just Relabeled

I've seen consultants tell clients that ISO 42001 is "basically ISO 27001 for AI," and that framing does people a disservice, because it sets them up to underbudget the work. Three things in ISO 42001 have no real ISO 27001 equivalent, and they're the three that eat the most implementation hours:

AI system impact assessment. Clause 6.1.4 requires you to formally assess the impact of each AI system on individuals, groups, and society, not just on your organization's information assets. ISO 27001's risk register was built to protect confidentiality, integrity, and availability of data. ISO 42001 asks you to also think about fairness, transparency, and the downstream effect of a wrong output on a real person. That's a different kind of risk assessment, and most ISMS teams don't have a template for it sitting in a drawer.

Data governance across the AI lifecycle. Annex A's data-for-AI-systems controls (A.7) push into provenance, quality, and appropriateness of training and test data in a way that goes well beyond ISO 27001's data classification and handling controls. You're not just protecting the data. You're documenting where it came from and whether it's fit to train the system you're building.

Third-party AI component management. If you build on a foundation model, a third-party API, or an open-source model you didn't train yourself, Annex A's third-party controls (A.10) require you to manage and document that dependency in a way ISO 27001's supplier-relationship controls don't quite reach. Most organizations I work with underestimate how much of their AI system is actually somebody else's model wearing their branding, and that gap shows up immediately during gap assessment.

How Much Extra Work, Realistically

In my experience running gap assessments for organizations moving from ISO 27001 into ISO 42001, the honest range is three to five months for the add-on implementation, compared to eight to twelve months for a green-field AI management system built with no existing ISMS to lean on. That's not a guarantee, it's a pattern I've seen hold across clients whose ISO 27001 programs were genuinely operational rather than certificate-only.

Here's roughly how that time breaks down:

  • Gap assessment (2-4 weeks). Map your existing ISMS documentation, risk register, and internal audit program against ISO 42001's clauses and Annex A. This step alone tells you whether you're looking at three months or eight.
  • Documentation build (6-10 weeks). Write the AI policy, extend your risk methodology to cover AI-specific impact assessment, document your AI system inventory, and build the data governance records Annex A expects. Your existing context-of-the-organization, leadership commitment, and competence documentation typically needs extension, not a rewrite.
  • Internal audit and management review (3-4 weeks). If your ISO 27001 internal audit program is functioning, you're adding a scope rather than building a new program from scratch.
  • Certification audit, Stage 1 and Stage 2 (4-8 weeks, dependent on your certification body's calendar). Some certification bodies can run this as a scope extension to your existing ISO 27001 audit cycle; others treat it as a fully separate certification.

Cost follows a similar logic. The organizations that spend the least are the ones whose ISO 27001 program was audited and enforced, not just filed away, because the leadership, competence, and internal-audit infrastructure genuinely reduces new documentation. The organizations that spend the most are the ones layering ISO 42001 onto an ISO 27001 certificate that was largely paperwork, because in that case you're not really adding a standard, you're building two management systems at once and only just realizing it.

Can You Combine the Audits?

This is the vendor-facing question underneath the cost question, and the answer depends on your certification body more than on the standards themselves. A growing number of accredited certification bodies now offer ISO 42001 as a scope extension audited alongside your existing ISO 27001 surveillance or recertification audit, which saves you a second Stage 1 and often a second travel or remote-audit fee. Others require a fully independent certification cycle with its own Stage 1 and Stage 2. Ask your current certification body directly whether they hold accreditation for ISO 42001 under ISO/IEC 17021-1 before you assume the combined-audit path is available to you. Not every body has added AI management systems to their scope yet, and switching certification bodies mid-cycle is its own project.

A Practical Roadmap If You're Starting From ISO 27001

  1. Inventory your AI systems first, before touching the standard. You cannot gap-assess against Annex A until you know which systems in your organization actually qualify as AI systems under ISO 42001's definition, including the third-party models you didn't build.
  2. Run the gap assessment against clauses 4-10 and Annex A separately. The clause-level gap will be small if your ISMS is healthy. The Annex A gap is where your real project plan gets built.
  3. Extend your existing risk methodology to include the 6.1.4 impact assessment, rather than building a second, parallel risk process. Two risk registers is a maintenance problem you'll regret at your first surveillance audit.
  4. Talk to your certification body about scope extension before you write a single policy. Their answer changes your timeline and your budget more than anything else on this list.
  5. Reuse your internal audit program and management review cycle. Add AI management system agenda items to the review you already run rather than scheduling a second one.

FAQ

How much does ISO 42001 cost if we already have ISO 27001?

There's no fixed number I can quote honestly, because cost depends on your certification body's fee schedule, the number and complexity of your AI systems, and how healthy your existing ISMS documentation already is. What I can tell you is that the driver of cost is Annex A's 38 AI-specific controls, not the clause-level management system requirements, since those overlap heavily with what you've already built for ISO 27001.

How long does ISO 42001 implementation take as an add-on to an existing ISMS?

Most organizations I've guided through this land between three and five months when their ISO 27001 program is genuinely operational and audited. Without an existing ISMS to build from, budget closer to eight to twelve months instead.

Can we add ISO 42001 to our current ISO 27001 certificate, or is it a separate audit?

That depends on your certification body's accreditation, not on the standards themselves. Many accredited bodies will run ISO 42001 as a scope extension on your existing ISO 27001 surveillance or recertification audit; others require a fully separate Stage 1 and Stage 2 cycle. Ask which path yours offers before you budget for either.

Is NIST AI RMF the same as ISO 42001?

No. NIST's AI Risk Management Framework, published January 2023, is a voluntary framework with four functions (Govern, Map, Measure, Manage) and no certification mechanism. ISO 42001 is a certifiable management system standard audited by accredited third-party certification bodies. A customer asking for NIST alignment and a customer asking for ISO 42001 certification are asking for two different things.

What actually causes a customer to suddenly require ISO 42001 certification?

Most often it's a change in the customer's own vendor risk questionnaire, usually driven by their regulator, their board, or a competitor's certification announcement, rather than any change in your own AI risk profile. Once "ISO 42001 certified: yes/no" becomes a checkbox on enough procurement forms in your industry, the requirement spreads fast.


If you're weighing whether the overlap with your existing ISMS is big enough to make this a quick project or a real one, that's exactly what a structured ISO 42001 gap assessment is built to answer before you commit budget. And if you're still deciding whether your current ISO 27001 program is strong enough to build on, that's worth a straight conversation before the AI management system project starts.

Last updated: 2026-09-28

J

Jared Clark

Principal Consultant, Certify Consulting

Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.