ISO 27001 is not dead: Why ISO 42001 is an ‘add-on’, not a replacement for ISO 27001.
“ISO 27001 is dead because AI is moving so fast. We need ISO 42001 to replace it.”
If you’ve spent more than five minutes on LinkedIn lately, you may have seen this claim already.
It sounds dramatic and perhaps even sounds plausible… It also happens to be completely wrong! So let’s clear this up once and for all, without any technical fluff or hyperbole.
ISO 27001 vs ISO 42001: Two Standards, Two Different Jobs
The idea that ISO 27001 and ISO 42001 compete with each other is one of the biggest myths doing the rounds right now. They are not rivals and they are not interchangeable. And one does not replace the other.
Keep this in mind – they solve different problems.. ISO 27001 is the international standard for information security management. It focuses on keeping data confidential, accurate, and available. ISO 42001 is the world’s first AI management system standard and it focuses on governing how artificial intelligence is used, including fairness, transparency, accountability, and ethical control.
To put it simply:
ISO 27001 = Is data and our systems secure?
ISO 42001 = Are we using AI responsibly?
I believe you need both, especially if your organisation uses AI in any meaningful way.
WHY ISO 27001 IS MORE IMPORTANT THAN EVER IN AN AI WORLD
Far from being “dead”, I firmly believe ISO 27001 is becoming MORE critical as AI adoption accelerates. Why? Because AI systems are;
- Data-hungry
- Cloud-based
- Model-driven
- Highly interconnected
- Dependent on third-party platforms and APIs, and
- Poorly implemented with very little training around their use
All of this makes them high-value targets for cyber attacks and data misuse. So it’s worth remembering that ISO 27001 remains the foundation for:
- Protecting training and operational data
- Securing technology (including Cloud)
- Controlling access to systems and services (including AI-enabled services)
- Managing supplier and cloud risk
- Maintaining availability and resilience
- Developing and designing systems with security and privacy principles
- Training, education and awareness for people using informational assets (including AI)
Many so-called “AI risks” are actually classic information security failures such as data poisoning, IP theft, unauthorised access and insecure development.
ISO 27001 provides the control discipline to manage all of these risks consistently and defensibly. But if this is the case, then why do we need a new standard? Great question – glad you asked.
WHAT IS ISO 42001 AND WHY IT EXISTS
ISO 42001 is the world’s first formal AI Management System (AIMS) standard and it gives organisations a structured way to:
- Govern AI responsibly
- Manage AI risks across the full lifecycle
- Embed ethical, legal, and operational controls
- Demonstrate accountability and due diligence
- Produce audit-ready evidence that AI is being managed effectively
If you’re familiar with standards like ISO 27001, ISO 9001, ISO 22301 or any other ISO standard that has been released since 2012, you’ll see that it follows the same management system structure. That makes ISO 42001 immediately recognisable and adoptable for organisations already certified to ISO 27001.
All of this makes it easier to align with, and integreate with other standards. Something which Consultants Like Us are experts at.
THE EU AI ACT: WHY BOTH ISO 27001 AND ISO 42001 MATTER
Have you heard of the EU Artificial Intelligence Act? If not, and you’re developing AI tools or using AI, then it’s something you need to take a closer look at. It’s the world’s first binding legal framework for AI governance and is designed to ensure that AI systems are;
- Safe
- Trustworthy
- Transparent
- Accountable
- Respectful of fundamental rights
As you can imagine there is a lot to the legislation to learn and understand, but it is important to note that it takes a risk-based approach to AI. This means the higher the potential harm of an AI system, the more regulation applies.
And yes, even UK organisations are affected if they use AI systems in the EU or sell AI-enabled services into the EU. This is a similar situation to the much misunderstood General Data Protection Regulation (GDPR) where people think it doesn’t apply because of BREXIT (It bares repeating – BREXIT won’t affect it!!)
Just keep in mind that this is not just an IT issue. – It is a board-level risk and compliance issue. But why is the EU AI Act a business risk? And not a technical issue to be dealt with by IT.
Financial Exposure
Firstly, fines of up to €35 million, or 7% of global annual turnover can be levelled at any business that breaches the requirements of the regulation. That puts it firmly in GDPR territory!
Reputational damage and loss of trust
AI misuse, bias, or lack of transparency can destroy customer trust fast! Keep in mind that suppliers and clients are asking deeper questions about the use of AI. They are increasingly knowledgable interested parties who are no longer satisfied with a copy of your AI policy.
They are asking:
- How are you using AI?
- How have you developed the AI?
- How are you training it?
- How are you governing it?
Regulators are explicitly focused on “trustworthy AI” so if you can’t answer the questions above then you already have a gap.
Supply Chain Accountability
This may surprise you but you are responsible not only for AI you build, but also for third-party AI tools, AI embedded in software platforms and AI outputs used in decision-making. Yes, that’s right. That wonderful new marketing tool you just purchased that is ‘AI enabled’, means that you have a new regulation to comply with!
HOW ISO 42001 HELPS YOU COMPLY WITH THE EU AI
Please keep this in mind; No ISO standard can make you ‘compliant’ to any regulation.
This statement is worth repeating; No ISO standard can make you ‘compliant’ to any regulation.
Why is this important? Because they can only provide evidence of compliance, not MAKE you compliant. Think of it like this; Going on a diet does not MAKE you healthy (it’s just evidence that you are acting in a healthy way). Having ISO 42001 (or ISO 27001) does not MAKE you compliant – it’s just evidence that you’re acting in an ethical and secure way.
So how does it help? From a practical business perspective, ISO 42001 delivers three big outcomes.
Structure (because AI is currently chaotic!)
Most organisations don’t know where AI is being used and lack clear leadership and accountability of AI (do YOU know who is responsible for AI in YOUR organisation?)
In many situations there is no consistent risk assessment of the use of AI, which takes us back to the point above. But having ISO 42001 forces you to set accountability, define policies and implement repeatable controls that give you confidence in your control of AI.
Evidence for Regulators and Customers
The EU AI Act requires proof, not good intentions and as all ISO standards require evidence of their effectiveness, ISO 42001 ensures organisations using it create robust policies and procedures. These include;
- Documented risk assessments
- Decision records
- Monitoring and review processes
- Audit-ready documents and records (including management reviews, training etc)
- Audit results
Safe Innovation
Good governance doesn’t slow AI adoption and innovation, rather it removes uncertainty. A little like brakes on a car – they allow you to go faster and be safe! ISO 42001 enables you to scale AI use confidently, while onboarding new tools faster and all the while, avoid reactive compliance firefighting
HOW ISO 27001 AND ISO 42001 WORK TOGETHER
The most effective organisations won’t treat these as separate initiatives, but will see it as a journey. If they already have ISO 27001, then ISO 42001 will be a natural progression. In fact a joined-up way of thinking about this, looks like this:
The General Data Protection Regulation (GDPR) and the UK DPA
Defines legal and regulatory expectations around the way personal data is handled
ISO 27001
Defines how personal data, information and AI systems are developed, secured and protected.
The EU AI Act
Defines legal and regulatory expectations around the use of AI.
ISO 42001
Defines how AI is governed, assessed, monitored, and improved
WHY ISO 27001 IS THE FOUNDATION FOR ISO 42001
For organisations already working with ISO 27001, ISO 42001 is not a reinvention; It’s an extension. Keep in mind that they share:
- Management system structure (Annex SL)
- Risk-based thinking
- Policy-driven controls
- Continuous improvement
- Audit and evidence-led assurance
This allows for shared risk registers, combined internal audits, unified incident management, consistent board reporting and a range of other features.
For Consultants Like Us who are familiar with integrating standards, it is going to be easy enough to bring ISO 42001 into the Integrated Management Systems (IMS) we build. Remember that our watch phrase is; “Compliance without Complextiy”®
Result of all of this is;
- Less compliance fatigue.
- More joined-up governance.
- Better real-world outcomes.
CONCLUSION
From a Consultants Like Us perspective we see ISO 27001 as the foundation and ISO 42001 as the AI overlay, with The EU AI Act as the regulatory driver. Organisations that already take ISO 27001 seriously are far better placed to:
- Adopt AI at pace
- Demonstrate regulatory readiness
- Defend decisions to regulators
- Build trust with customers and partners
Those that don’t will struggle to evidence control (even if their AI intentions are sound) because AI governance is not a future problem. It is not a technology experiment and and it is not optional.
AI is now a trust, regulatory and resilience issue. It is a business risk and a business issue. This is not something that IT can sort out for you.
It needs calm, proportionate thinking. Not hype.
More questions?
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you like to consider buying our book, “The Real Easy Guide to ISO27001” which is available on Amazon.
If you’d like to talk through any of the points above, please get in touch.
Whether it’s to discuss if ISO 27001 is right for you or to help understand what ISO 42001 could mean for your organisation or to see how both standards fit into your AI and cyber strategy.
We’re here to help.
👉 Book a free, no-pressure conversation and we’ll help you work it out calmly and proportionately.
