Confused about AI?

Here’s how ISO 27001 and ISO 42001 Fit together.

ISO 27001-FAQ

ISO 27001 & ISO 42001 A marriage made in heaven?

Artificial Intelligence (AI) has crept into our lives faster than any of us expected. 

It’s not that long ago when people had never heard of ‘ChatGPT’ or the term ‘AI’. And this has happened in the workplace faster than most organisations anticipated too.

Sometimes it’s obvious when Microsoft or Google release new versions of Copilot, Gemini or ChatGPT. These AI tools are sometimes baked into business software meaning that you have little choice in their use.Sometimes it’s even less visible, as suppliers use AI behind the scenes, or staff begin experimenting quietly to “get things done quicker”.

And that’s usually where the questions start.

  • Should we be allowed to use this?
  • Is this secure?
  • Who’s responsible if something goes wrong?
  • What could go wrong?
  • And how do we explain this to customers, auditors, or regulators?

If you already work with ISO 27001, you may be wondering where ISO 42001 fits into all of this, and whether it’s something you need to worry about now.

All great questions. So let’s talk it through in plain English.

Information Security ISO 27001

ISO 27001: Securing Information (Including AI Data)

ISO 27001 has always been about one core thing: Managing information risk in a sensible, structured way.  ISO 27001 is a ‘risk based management system’. When Information Security became a ‘thing’ (yes, I was there at the birth of Security), it was said that Information Security should be comenerate to the size and complexity of the organisation.

In plain English, this means security needs to fit YOU. Not ther other way around.

But how do you go about considering risk? Well, again to keep things simple we should use the ‘CIA Triad’ of information security, where CIA means;

  • Protecting the Confidentiality of data
  • Ensuring the Integrity, and the Availability of data.

In short, security is about understanding risks, not just installing controls. It’s about showing that security is thoughtfully considered and managed, not simply focused on arbitrary controls.

“But what about AI?” I hear you cry! That’s a great question. When AI entered the picture, ISO 27001 didn’t suddenly become irrelevant. In fact, it plays a critical role in underpinning AI systems.  Why?

Because AI systems;

  • rely on data and inputs
  • process information
  • produce outputs
  • integrate with existing systems
  • are used by humans (in most cases)

All of that falls squarely within ISO 27001’s world. So if you’re using AI tools, ISO 27001 helps answer questions like:

  • Is the data going into AI protected?
  • Are access controls in place?
  • Are suppliers managed properly?
  • Do we understand information risks?
  • Is the use of AI covered in a policy (e.g. Acceptable Use Policy)?

Keep in mind that AI needs data to exist – No data. No AI.

Now you know why ISO 27001 is needed, let’s take a look at the new kid on the block.

ISO 27001 Super Heroes

ISO 42001: Governing How AI Is Used

In 2022, the world got very excited about ChatGPT, and in 2023, the Security community got very excited about ISO/IEC 42001:2023.  The new international AI management system standard is the first of its kind in the world, so it’s pretty special.

However, keep this in mind; It’s not about coding models, and it doesn’t expect you to become an AI expert. 

ISO 42001 is about governance, and focuses on:

  • how AI is selected and approved
  • how risks and unintended consequences are considered
  • who is accountable for AI decisions
  • how AI use is monitored, reviewed, and improved
  • how organisations demonstrate responsible use

In other words, ISO 42001 is concerned with behaviour, decisions, and oversight, not just technical controls.

Where ISO 27001 asks: “Is the information managed to ensure confentially, integrity and availablity?”

ISO 42001 asks: “Is the intended purposes of AI effective, fair and transparent?”

Anyone who is familiar with the EU AI Act, will recognise these words and these core principles and expectations.

ISO 27001 implementation benefits

Can ISO27001 and ISO 42001 Fit Together (Without Duplication)?

The simple answer is yes. ISO 42001 is not a replacement for ISO 27001, in the same way that ISO 22301 (Business Continuity Management System) is not a replacement for ISO 27001 either (even though it talks about Business Continuity). It’s also not a shiny add-on for the sake of it either.

A simple way to think about it is this:

  • ISO 27001 protects information. Information that AI might rely on
  • ISO 42001 governs how AI uses that information

The good thing is that if you already have ISO 27001 in place:

  • risk management concepts are familiar
  • management reviews aren’t new
  • policies, roles, and responsibilities already exist
  • supplier controls are already part of the conversation

That means ISO 42001 often feels like a natural extension, not a brand-new world. However it is important to repeat that ISO 42001 is a whole standard of its own and is NOT an extension to ISO 27001, even though it might feel like it!  Got it? Good.

Do You Need ISO 42001 Yet?

I guess this is the most important question of all, and the answer isn’t always “yes”.. In our experience, ISO 42001 starts to make sense when:

  • AI influences decisions that affect people, customers, or outcomes
  • customers or partners start asking about your governance and control of AI
  • leadership wants confidence they could explain their AI use if challenged
  • AI use is growing faster than informal rules can handle
  • Your competitors start implementing (and shouting about) ISO 42001

If AI use is minimal, experimental, or tightly constrained, certification may be premature. However, some light-touch governance is still a sensible step to take.  This can include:

  • Setting clear boundaries
  • Defining an AI policy
  • Gainign visibility of how AI is being used

This is the first. not certification.

Will ISO 42001 make me compliant to the EU AI Act?

In a word, no. In a longer word … Nooooooooo.

In the same way that having ISO 27001 does not make you compliant with the General Data Protection Regulation (GDPR), ISO 42001 cannot make you compliant with the EU AI Act.

Standards like ISO 27001 and ISO 42001 help you put in place controls and processes that demonstrate compliance (with the law), but they don’t prevent you from ever having a breach or security incident.

Think of it this way: The EU AI Act is like the recipe for a cake. It tells you exactly what must go into the cake for it to be legal to serve.

ISO 42001 is a professional kitchen setup, with clean surfaces, trained staff, good processes for everyone to follow.

A great kitchen makes it more likely you’ll bake the cake properly… but it doesn’t replace the recipe, and it doesn’t guarantee the cake is legal to sell! (Is anyone else feeling hungry?)

Why this matters more than people think

Most organisations don’t get into trouble because they intended to misuse AI. People get excited about these new technologies, and rightly so.

AI offers us incredible opportunities (and terrifying risks, but that’s for another blog).

The virtual explosion of AI is similar in look and feel to the months when the World Wide Web became popular.  Of course when the “dot.com bubble” burst, it hurt a lot of people financially, and perhaps that will happen in the AI-Bubble. But whatever happens, AI is here to stay so we need to ensure we’re using it responsibily.

ISO 42001 exists to ensure we use AI in an effective, fair and transparent way for it’s intended purpose.

I don’t know about you,  but I like the sound of that, and when it sits alongside ISO 27001, it creates a much more complete and compelling story:

  • secure information
  • governed AI use
  • defensible decisions
  • confidence under scrutiny
ISO 27001 Recovery Point Objective

What next? ISO 42001 is a step forward, not a leap

If you’re already ISO 27001 certified (or working towards it), the question isn’t:  “Do we need ISO 42001 immediately?”

It’s: “Do we understand how AI is being used and could we explain it if we had to?”

If the answer you get feels uncomfortable, that’s usually a sign to start the conversation.

Don’t panic. Seek clarity.

Of course if you’d like to talk through what ISO 42001 could mean for your organisation or whether it even applies yet, that’s exactly the sort of discussion we have every day.

👉 Book a free, no-pressure conversation and we’ll help you work it out calmly and proportionately.

 More questions?

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you like to consider buying our book, “The Real Easy Guide to ISO27001” which is available on Amazon.