ISO 27001 And ISO 42001 – What’s the difference?

Brace yourself folks… Threre’s a whole host of ‘AI Experts’ coming to town, and they’re all waving ‘ISO 42001’ certificates at you!! 😂.  We’ll come back to that in a minute, but first let’s address the ‘New kid on the block’ directly and state for the record… 

Right now, organisations aren’t asking “what is ISO 42001?” They’re asking:

👉 “How can we demonstrate to Clients that we’re in control of AI?” 

That’s where ISO 42001 comes in. Published in 2023, it sets out how organisations should manage AI. Everything from internal tools like chatbots through to fully commercial AI-driven products and services. But in practice, it’s less about AI itself, and more about governance, risk, and accountability.

From ISO 27001 to ISO 42001 – familiar, but not the same

Most of the organisations we work with already have ISO 27001 in place.

That helps because ISO 42001 has clearly been built on the same management system foundation (‘Annex SL’)

  • Clauses 4–10 follow the same structure
  • The “Plan-Do-Check-Act” mindset is identical
  • Governance, risk assessment, and continual improvement all carry across

So yes, if you’ve implemented ISO 27001, you’re not starting from scratch.

ISO 27001 Risk Meeting

But here’s the key point:

 👉 An AI Management System (AIMS) is not just an extension of an ISMS.

 Where ISO 27001 focuses on protecting information (confidentiality, integrity, availability), ISO 42001 introduces:

  • Ethical considerations
  • Bias and fairness
  • Transparency and explainability
  • Human oversight of automated decisions

These are not things most ISMS implementations are designed to handle.

The good, the bad, and the reality of ISO 42001

From an implementation perspective, the standard is a solid first version. It gives organisations:

  • A structured way to think about AI risk
  • A governance framework that leadership can engage with
  • Enough flexibility to apply it across very different use cases

But let’s be honest, most organisations aren’t doing this for the love of governance!

👉 They’re doing it for certification.

 

ISO 27001 Incident Response

And that’s where things get messy.

The biggest challenge right now: interpretation

Unlike ISO 27001, which has had years to mature, ISO 42001 is still finding its feet. 

What we’re seeing on the ground:

  • Certification bodies are still learning and charging a FORTUNE! 
  • Auditors are interpreting requirements differently(!)
  • There’s no consistent view on areas like ethics, fairness, or accountability (discuss these terms in YOUR team and see the various thoughts)

 All of this creates friction.

 So here’s the pragmatic advice we give clients:

 👉 If the standard is unclear, take a position and justify it.

 You are not being assessed on perfection (there’s no such thing) You are being assessed on whether:

  • You’ve understood the requirements (Clauses 4–10)
  • You’ve applied them consistently
  • You can demonstrate control and improvement

That’s it, and in many cases the organisation understands its AI risks better than the auditor does (or ever can).

ISO 27001 and ISO 42001

Where to focus (if you actually want to get certified)

Too many teams get distracted by theory.

If your goal is certification, the priority is simple:

👉 Master Clauses 4–10 – That’s where certification is won or lost:

We often tell clients:

👉 “If you read anything daily, read Clauses 4–10. Not blog posts, not opinions.”

Because that’s what you’ll be audited against.

Training and the “AI driven ISO 42001 bandwagon”

As you’d expect, there’s been an explosion of ISO 42001 training:

  • Lead implementer courses
  • Lead auditor courses
  • AI governance certifications 

The challenge?

Many are being delivered by people with limited real-world experience of either AI or the standard. There are very few AI experts around, and I’m sure if they are experts, they’re working at SpaceX or Google, not running a training course from their bedroom in Hounslow! 😂 (I could be wrong, so please correct me if you are!)

But none of this is entirely surprising – it’s a new space. So it does mean you need to be selective.

ISO 27001 Explanation

The same applies to consultants:

👉 There are a lot of people repackaging ISO 27001 knowledge and calling it AI expertise. Some of that translates. A lot of it doesn’t.

Practical implementation insight

When we implement ISO 42001 alongside ISO 27001, the organisations that succeed do three things well…

1. They integrate, not duplicate

They don’t build a separate AI silo. They extend existing governance structures where it makes sense. If you already have a Management System (like ISO9001 or ISO 27001) then build an Integrated Management System to maximise on your efforts.

2. They focus on use cases

They identify where AI is actually being used:

  • Internal productivity tools
  • Customer-facing systems
  • Decision-making processes

Then they assess risk in context, not in theory. 

3. They accept ambiguity

Keep this in mind; There is no “perfect” implementation right now and progress beats precision. 

ISO27001 and FCA relationships

Final thought

ISO 42001 is not about controlling AI. 

It’s about:

  • Understanding how AI is being used
  • Managing the risks it introduces
  • Demonstrating that management is in control

If you already have ISO 27001, you’ve got a head start but don’t assume it’s just more of the same.

👉 This is where information security meets ethics, accountability, and real-world decision-making. And that’s a different conversation.

If you’re considering ISO 42001, my advice is that you first get comfortable with ISO 27001.  Over time your clients will start to ask about ISO 42001, but it’s more likely they’ll want to see you’ve got the foundations in place first.

So get comfortable with ISO 27001and then look at this ‘New kid on the block’!

If you want to discuss further, get in touch and I’ll be happy to help.

 

ISO 27001 Compliance

 More questions?

We are ISO 27001 Consultants who provide ‘Compliance without Complexity’® and we know we can help you… we even wrote a book about it. For more information on how to implement ISO 27001, written by ISO 27001 consultants like us, you like to consider buying our book, “The Real Easy Guide to ISO27001” which is available on Amazon. 

If you’d like to talk through any of the points above, please get in touch.

Whether it’s to discuss if ISO 27001 is right for you or to help understand what ISO 42001 could mean for your organisation or to see how both standards fit into your AI and cyber strategy.