ISO 27001 And ISO 42001 – What’s the difference?
Brace yourself folks… Threre’s a whole host of ‘AI Experts’ coming to town, and they’re all waving ‘ISO 42001’ certificates at you!! 😂. We’ll come back to that in a minute, but first let’s address the ‘New kid on the block’ directly and state for the record…
Right now, organisations aren’t asking “what is ISO 42001?” They’re asking:
👉 “How can we demonstrate to Clients that we’re in control of AI?”
That’s where ISO 42001 comes in. Published in 2023, it sets out how organisations should manage AI. Everything from internal tools like chatbots through to fully commercial AI-driven products and services. But in practice, it’s less about AI itself, and more about governance, risk, and accountability.
From ISO 27001 to ISO 42001 – familiar, but not the same
Most of the organisations we work with already have ISO 27001 in place.
That helps because ISO 42001 has clearly been built on the same management system foundation (‘Annex SL’)
- Clauses 4–10 follow the same structure
- The “Plan-Do-Check-Act” mindset is identical
- Governance, risk assessment, and continual improvement all carry across
So yes, if you’ve implemented ISO 27001, you’re not starting from scratch.
But here’s the key point:
👉 An AI Management System (AIMS) is not just an extension of an ISMS.
Where ISO 27001 focuses on protecting information (confidentiality, integrity, availability), ISO 42001 introduces:
- Ethical considerations
- Bias and fairness
- Transparency and explainability
- Human oversight of automated decisions
These are not things most ISMS implementations are designed to handle.
The good, the bad, and the reality of ISO 42001
From an implementation perspective, the standard is a solid first version. It gives organisations:
- A structured way to think about AI risk
- A governance framework that leadership can engage with
- Enough flexibility to apply it across very different use cases
But let’s be honest, most organisations aren’t doing this for the love of governance!
👉 They’re doing it for certification.
And that’s where things get messy.
The biggest challenge right now: interpretation
Unlike ISO 27001, which has had years to mature, ISO 42001 is still finding its feet.
What we’re seeing on the ground:
- Certification bodies are still learning and charging a FORTUNE!
- Auditors are interpreting requirements differently(!)
- There’s no consistent view on areas like ethics, fairness, or accountability (discuss these terms in YOUR team and see the various thoughts)
All of this creates friction.
So here’s the pragmatic advice we give clients:
👉 If the standard is unclear, take a position and justify it.
You are not being assessed on perfection (there’s no such thing) You are being assessed on whether:
- You’ve understood the requirements (Clauses 4–10)
- You’ve applied them consistently
- You can demonstrate control and improvement
That’s it, and in many cases the organisation understands its AI risks better than the auditor does (or ever can).
Where to focus (if you actually want to get certified)
Too many teams get distracted by theory.
If your goal is certification, the priority is simple:
👉 Master Clauses 4–10 – That’s where certification is won or lost:
We often tell clients:
👉 “If you read anything daily, read Clauses 4–10. Not blog posts, not opinions.”
Because that’s what you’ll be audited against.
Training and the “AI driven ISO 42001 bandwagon”
As you’d expect, there’s been an explosion of ISO 42001 training:
- Lead implementer courses
- Lead auditor courses
- AI governance certifications
The challenge?
Many are being delivered by people with limited real-world experience of either AI or the standard. There are very few AI experts around, and I’m sure if they are experts, they’re working at SpaceX or Google, not running a training course from their bedroom in Hounslow! 😂 (I could be wrong, so please correct me if you are!)
But none of this is entirely surprising – it’s a new space. So it does mean you need to be selective.
The same applies to consultants:
👉 There are a lot of people repackaging ISO 27001 knowledge and calling it AI expertise. Some of that translates. A lot of it doesn’t.
Practical implementation insight
When we implement ISO 42001 alongside ISO 27001, the organisations that succeed do three things well…
1. They integrate, not duplicate
They don’t build a separate AI silo. They extend existing governance structures where it makes sense. If you already have a Management System (like ISO9001 or ISO 27001) then build an Integrated Management System to maximise on your efforts.
2. They focus on use cases
They identify where AI is actually being used:
- Internal productivity tools
- Customer-facing systems
- Decision-making processes
Then they assess risk in context, not in theory.
3. They accept ambiguity
Keep this in mind; There is no “perfect” implementation right now and progress beats precision.
Final thought
ISO 42001 is not about controlling AI.
It’s about:
- Understanding how AI is being used
- Managing the risks it introduces
- Demonstrating that management is in control
If you already have ISO 27001, you’ve got a head start but don’t assume it’s just more of the same.
👉 This is where information security meets ethics, accountability, and real-world decision-making. And that’s a different conversation.
If you’re considering ISO 42001, my advice is that you first get comfortable with ISO 27001. Over time your clients will start to ask about ISO 42001, but it’s more likely they’ll want to see you’ve got the foundations in place first.
So get comfortable with ISO 27001and then look at this ‘New kid on the block’!
If you want to discuss further, get in touch and I’ll be happy to help.
More questions?
We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you like to consider buying our book, “The Real Easy Guide to ISO27001” which is available on Amazon.
If you’d like to talk through any of the points above, please get in touch.
Whether it’s to discuss if ISO 27001 is right for you or to help understand what ISO 42001 could mean for your organisation or to see how both standards fit into your AI and cyber strategy.
