Already certified to ISO 9001, 13485 or 27001

Adding AI to an Annex SL system

ISO 42001 for
ISO 9001 Certified Companies

If you already run an ISO 9001, ISO 13485 or ISO 27001 system, most of ISO 42001 is already in place. This page shows what carries over clause by clause, what is genuinely new, and how to add it as one system rather than two.

"Keep it Simple. Keep it Real."

Clauses 4–10
Shared structure
Annex A
The new part
One system
Not two
Jared Clark, ISO 9001 and ISO 42001 consultant

What Carries Over

The same seven clauses, applied to AI

ISO 42001 uses the harmonized structure every modern ISO management standard uses. If you hold ISO 9001, 13485 or 27001, you already have clauses 4 through 10. The table shows what you reuse and what each clause adds for AI.

ClauseWhat you already haveWhat ISO 42001 adds
4. ContextIssues, interested parties, scopeYour role with AI (developer, provider, user) and the AI systems in scope
5. LeadershipPolicy, roles, commitmentAn AI policy with objectives and a named owner for AI governance
6. PlanningRisk-based thinking, objectivesAI risk assessment, AI risk treatment, AI system impact assessment (6.1.4), and the Statement of Applicability
7. SupportCompetence, awareness, document controlAI awareness for everyone who uses it, and records for AI systems and AI-generated content
8. OperationProcess control, change control, suppliersRunning the impact assessments, controlling AI system changes, and the Annex A controls you selected
9. Performance evaluationMonitoring, internal audit, management reviewMeasures for AI systems, an internal audit that covers Annex A, and AI on the management review agenda
10. ImprovementNonconformity, corrective actionThe same CAPA process, now fed by AI incidents and impact-assessment findings

The clause-level detail, with the evidence an auditor asks for at each one, is in ISO 42001 clause by clause.

What Is New

Six things your current system will not have

This is the real size of the project for a company that already holds a certificate.

The AI system inventory

Every AI system you develop or use, with an owner, a purpose, the data it sees and the decisions it touches. Vendor features count. This is usually the first document an auditor asks for and the one nobody has.

The AI policy and objectives

A short policy leadership actually signed, with objectives that can be measured. Your quality policy does not cover this, and a paragraph about "responsible AI" on the website does not count.

AI impact assessments

For each system that affects people, products or decisions: who could be harmed, how, and what you do about it. Your risk register has the method; this is a new object in it.

The Statement of Applicability

Which Annex A controls apply, which do not, and why. ISO 27001 holders know this document; ISO 9001 holders will be writing their first one. See the SoA explained.

Supplier AI terms

What your contracts say about AI a supplier runs on your data or inside your process. Your supplier qualification process already exists; the questions on the questionnaire do not.

Human oversight evidence

Not a sentence in a procedure but a record: who reviews AI output before it becomes a decision or a document, and proof that they did. This is where most systems are thinnest.

Integrate, Do Not Duplicate

Run one management system, not two

The most expensive mistake we see companies make with a second standard is building a second system: a separate manual, a separate document register, a separate internal audit calendar and a separate management review, each maintained by a different person. It doubles the upkeep and it makes the auditor's job harder, because the same requirement now has two answers.

The better way is to extend what you have. Add AI to the scope statement. Put the AI policy beside the quality policy. Add the AI system inventory and the impact assessments to the existing risk process. Extend the supplier questionnaire, the training matrix and the internal audit checklist. Put AI on the management review agenda. Then ask your certification body whether it is accredited for ISO 42001 under ISO/IEC 42006 and whether it can audit both standards in one visit. Many can; some cannot yet, and it is worth knowing before you plan the audit.

The one place we recommend a genuinely new process rather than an extension is human oversight of AI-generated content. Existing review and approval steps were designed for documents people wrote slowly. They need to be re-stated for documents a tool can produce instantly, or the review step quietly disappears. We wrote about why that matters most for regulated manufacturers in AI governance and quality management.

A realistic plan for a certified company

  1. Gap assessment against ISO 42001, marking what carries over from your current certificate. Two to three weeks.
  2. AI system inventory, AI policy, impact assessments and the Statement of Applicability. One to three months depending on how much AI you use.
  3. Extend suppliers, training, records and internal audit. Usually one to two months, mostly your team's time.
  4. Internal audit and management review covering the new content, then the certification audit. Book the body early; auditor availability is the long pole.

Most certified companies land at the short end of the four-to-twelve-month range.

What it costs

Our gap assessment is a fixed $9,750 and tells you the rest of the number. Implementation support is scoped from the gap report. Certification body fees for an extension to an existing certificate are usually lower than for a new one, because the audit days are fewer; ask the body for a quote that covers both standards.

The line items and three worked budgets are in what ISO 42001 costs. If your base is ISO 27001 rather than ISO 9001, read from ISO 27001 to ISO 42001 as well.

Frequently asked questions

Can ISO 42001 be integrated into our ISO 9001 system instead of run separately?

Yes, and it should be. Both follow the Annex SL structure, so one manual, one document control process, one internal audit program and one management review can cover both. The AI-specific content sits inside the system you already have. Ask your certification body whether it is accredited for ISO 42001 and can audit both together; not every body is yet.

How much shorter is the project when we already hold ISO 9001?

Typically at the short end of the four-to-twelve-month range. Clauses 4 through 10 mostly exist already; the work is the AI system inventory, AI risk and impact assessments, the Statement of Applicability, the Annex A controls that apply, and evidence of human oversight.

Does an ISO 27001 system carry over more than ISO 9001?

In some places. ISO 27001 already has a Statement of Applicability and a risk-treatment habit, which ISO 42001 borrows directly. ISO 9001 carries over more on process control, supplier management and records. Either is a strong base; ISO 13485 adds design controls and risk management that map well onto AI systems you build.

What is genuinely new in ISO 42001 that our system will not have?

An inventory of AI systems, an AI policy with objectives, AI risk assessment and AI system impact assessments, the Statement of Applicability, controls on AI from suppliers, and documented human oversight of AI decisions. Everything else is an extension of a process you already run.

See how much of ISO 42001 you already have

Book a free 30-minute call. Tell us which standard you hold and which AI tools you use, and we will tell you roughly how much of the work is already done and what the rest would take.

Or email us at [email protected]