Docply Browse kits
ISO 42001

ISO 42001 vs ISO 27001: The Actual Mapping, Not a Percentage

By Alessandro Stella · · 13 min read

Search for the difference between ISO/IEC 42001 and ISO/IEC 27001 and you will be told the overlap is 40%. Or 50 to 60%. Or 60 to 70%. Sometimes that certification is “40% faster” if you already hold 27001.

None of these numbers is sourced. They do not agree with each other. And the most commonly repeated one — that most ISO 27001 Annex A controls “carry directly into” an AI management system — is not just imprecise. It is wrong, in a way that will cost you time if you plan around it.

This article gives the mapping instead of the percentage: what genuinely transfers, what has to be built, and the one structural fact about the two Annex A sets that the percentage claims obscure.

Running both, or planning to? The ISO 27001 Compliance Suite and the ISO 42001 Compliance Suite are built on the same template and the same document architecture, so the shared processes are genuinely shared rather than duplicated. €590 excl. VAT each.

The claim that is wrong

Several published comparisons say that 60–70% of ISO 27001 Annex A controls carry over into ISO 42001, or that the two control sets substantially overlap.

ISO 42001 Annex A is a different control set. Not a subset of ISO 27001’s, not an extension of it, not a re-labelled version. ISO 27001 Annex A has 93 controls organised in four themes. ISO 42001 Annex A has 38 controls organised around AI-specific objectives: AI policy, internal organisation, resources for AI systems, impact assessment, the AI system life cycle, data for AI systems, information for interested parties, responsible use, and third-party relationships.

The two sets were written by different working groups, for different subject matter, with different objectives. There is no control-level correspondence to “carry over”.

What does carry over is the management system layer — clauses 4 to 10. And that is genuine, substantial and worth having. But it is a different claim from the one being made, and the difference matters when you plan: if you budget on the assumption that most of your Annex A work is done, you will discover in week three that all 38 controls need a decision and none of them is answered by your existing Statement of Applicability.

What transfers between ISO 27001 and ISO 42001: the management system layer transfers, the Annex A control sets do not

What genuinely transfers, clause by clause

Both standards use the harmonised structure, so clauses 4 to 10 sit in the same positions. But “same position” is not the same as “same content”. Here is where each stands.

ClauseTransfers?What has to change
4.1 ContextYesAdd AI-specific issues to the same analysis. Both carry the climate determination from the 2024 amendment
4.2 Interested partiesPartlyISO 42001 expects the people affected by the AI system, not only those with requirements of the organisation
4.3 ScopeNoA second boundary: which AI systems are in scope. It rarely equals the ISMS scope
4.4 The system and its processesYesSame requirement, extended process inventory
5.1–5.3 Leadership, policy, rolesPartlyA separate AI policy is expected. New roles: AI system owner, impact assessor
6.1.1 Risks and opportunitiesPartlySame mechanism, different consequence dimension
6.1.2–6.1.3 Risk assessment and treatmentPartlySame process shape, different criteria and a different Annex A to compare against
6.1.4 Impact assessmentNoNo ISO 27001 equivalent at all. The largest single gap
6.2 ObjectivesYesOne register, add AI objectives to it
6.3 Planning of changesYesOne process
7.1 ResourcesPartlyISO 42001 adds data, tooling, computing and human oversight as resource categories
7.2–7.3 Competence and awarenessYesOne matrix, both role sets
7.4 CommunicationPartlyAdds duties toward affected parties, not only interested parties
7.5 Documented informationYesOne master list holding both sets. The cleanest merge of all
8.1 Operational planningYesSame requirement
8.2–8.3 Risk assessment and treatment in operationPartlySame discipline, separate registers
8.4 Impact assessments performedNoFollows 6.1.4
9.1–9.3 Performance, audit, reviewYesOne audit programme, one review with both agendas. The biggest saving in running cost
10.1–10.2 Nonconformity and improvementYesOne register, one process

Count the rows if you want a number. But the number is less useful than knowing which rows, because the ones marked No are concentrated in one place, and it is not where the percentage claims suggest.

The control layer, objective by objective

The clause table above is the transferable half. This is the other one — the nine control objectives of ISO 42001 Annex A, rated against what an operating ISMS already provides.

ISO 42001 Annex ASubjectFrom ISO 27001
A.2AI policyPartial — a dedicated policy is expected, aligned with the security one
A.3Internal organisation, reporting concernsPartial — the channel must accept reports from outside the organisation
A.4Resources for AI systemsPartial — data, tooling and computing recorded per system
A.5Impact assessmentNothing
A.6AI system life cyclePartial — secure development maps; the stage gates and the responsible-development definition do not
A.7Data for AI systemsPartial — provenance, rights of use and fitness for purpose are absent from an ISMS
A.8Information for interested partiesPartial — technical documentation and user information are new artefacts
A.9Responsible use of AI systemsNothing
A.10Third parties and customersPartial — allocation of responsibility across the value chain

Two of nine have no counterpart. The other seven are partial in a particular way that experienced teams misread: the ISMS has a process in that area, and it answers a different question.

Access control decides who may use a system. It does not decide whether the system should be used for a given task. Both are legitimate controls; only the second is what A.9 asks about. Data classification decides who may see a dataset. It does not decide whether you have the right to train on it. Both matter; only the second is A.7.

That distinction is invisible in a percentage and obvious in an audit.

Four questions the two standards ask differently

Calling the standards complementary is accurate and unhelpful. Here is where the difference actually bites.

On risk. ISO 27001 asks what harm follows if confidentiality, integrity or availability is compromised. ISO 42001 asks what consequences follow for individuals, for groups of individuals and for societies — including when the system works exactly as designed. A recruitment model that ranks candidates consistently and ranks one group lower has suffered no security event: nothing was breached, altered or made unavailable. The ISMS risk process, applied faithfully, returns nothing.

On oversight. An ISMS asks whether access is appropriate and privileged actions are logged. An AI management system asks whether the human reviewing an output can, in practice, contradict it. The measurable version is how many outputs were overridden in the last hundred. If the answer is zero, the oversight is nominal — and nominal oversight is worse than none, because it is relied upon.

On documentation. ISO 27001 asks you to document what you do. ISO 42001 asks you additionally to document what the system does, in terms a non-specialist can act on: intended purpose, limits of valid use, known failure modes. That is a different genre of writing and it usually falls to people who have never had to produce it.

On who you owe something to. An ISMS’s interested parties are those with requirements of you: customers, regulators, staff, owners. An AI management system adds a party with no relationship to you at all — the person affected by an output. They did not buy anything, sign anything or agree to anything, and the standard asks what they are told and who answers when they ask why a decision was made about them.

That last one is the conceptual shift, and no clause mapping conveys it.

The three things that never merge

Some published guidance encourages a “single unified management system” without saying what cannot be unified. Three things.

The two Statements of Applicability. 93 controls against 38, different control sets, different justification logic. A merged list is not accepted by a certification body and signals that the organisation has not understood what a Statement of Applicability is. Two documents, always.

The two risk registers. This looks like the obvious merge and it is the wrong one. The AI risk register carries a consequence dimension the security register does not have: harm to individuals and to societies from a system working as designed. Merge them and you must adopt a common scale, which either dilutes the AI dimension or imports it into security risks where it does not belong. Keep them separate and cross-reference — an AI risk often has a security consequence and the reverse.

The inventories. An AI system is also an information asset, but the two inventories ask different questions. The asset inventory asks about classification, ownership and retention. The AI system inventory asks about intended purpose, the role you hold — provider, deployer, or both — and the status of the impact assessment. Link them with a reference column; do not fold one into the other.

Where the real saving is

Not in the controls. In the running cost of the management system.

Six processes can genuinely be operated once for both standards:

That last group is where the saving compounds. Running two audit programmes and two management reviews costs roughly twice as much every year, forever. Running one costs about the same as one. This is the argument for an integrated system, and it is an operating-cost argument rather than an implementation-cost one — which is why the percentage claims, all of which are about implementation, miss it.

The six management system processes that can be operated once for both standards

Which one first

Neither is a prerequisite for the other. You can certify to ISO 42001 without holding ISO 27001, and some organisations do. But there is a practical reason the order usually runs one way.

ISO 42001 assumes an information security foundation it does not fully define. Access control, encryption, change management, incident handling, supplier security — the AI management system relies on these without specifying them, because they belong to a different standard. An organisation with no security management system will end up building them anyway, under AI labels, less well.

So:

Neither yet, and AI is central to what you do. Run them as one programme rather than sequentially. The shared clauses get built once, and the certification bodies that are accredited for both can audit them in one visit.

ISO 27001 already certified. ISO 42001 is an extension, not a second implementation. The management system layer is done. What remains is the impact assessment process, the AI system life cycle, data provenance and quality, information to affected persons, and 38 control decisions.

ISO 42001 only, no security foundation. Possible, and occasionally right — a small organisation whose only meaningful exposure is a single AI product. But enterprise buyers will ask for ISO 27001 regardless of AI maturity, so this order tends to be temporary.

The certification body question nobody mentions

Accreditation is per standard. A body accredited for ISO 27001 is not thereby accredited for ISO 42001, and in 2026 the pool accredited for 42001 is still considerably smaller.

If you intend combined audits, verify that ISO 42001 sits inside your certification body’s accreditation scope — not that they offer it, that they are accredited for it. Ask for the accreditation certificate and read the scope. It is a two-minute check that occasionally saves a wasted audit cycle.

Frequently asked questions

Do most ISO 27001 controls carry over into ISO 42001? No. The two Annex A sets are different: 93 controls in ISO 27001, 38 in ISO 42001, written for different subject matter with no control-level correspondence. What transfers is the management system layer, clauses 4 to 10.

How much of the documentation can we reuse? Six governing processes can be operated once for both, and their records merge with a column identifying the system. The risk procedures, the two Statements of Applicability and the inventories stay separate. Rather than a percentage, work from the clause table above.

Do we need ISO 27001 before ISO 42001? Not formally. ISO 42001 assumes a security foundation it does not define, so organisations without one usually end up building it. If you hold neither and AI is central to your business, run both as a single programme.

Can we hold one certificate for both? No. Two certificates, from a body accredited for each. The audits can be combined into one visit if the body is accredited for both and has competent auditors for both.

Can the two Statements of Applicability be merged? No. Different control sets and different justification logic. Two documents.

Does ISO 42001 certification help with the EU AI Act? It builds most of the operational machinery the Act’s obligations run on — inventory, impact assessment, technical documentation, information to users, incident channel. It does not discharge the obligations, which are assessed against the Act itself. See what the Digital Omnibus changed for the current deadlines.

Is one harder than the other? ISO 42001 is less prescriptive, which makes it harder to implement well and easier to implement badly. ISO 27001 tells you what to consider; ISO 42001 more often tells you to make a judgement and record it.

Where to go from here

If you take one thing from the comparison, take this: the percentages are answering the wrong question. The useful question is not how much overlaps, it is which parts overlap — because the parts that do are the ones you operate every year, and the parts that do not are concentrated in a place your existing system says nothing about.

The ISO 27001 Compliance Suite and the ISO 42001 Compliance Suite are built on the same template, the same section structure and the same record architecture — one process per procedure, records in separate modules, the registers the standard requires as separate files. Which means the six shared processes are shared in practice, not just in theory. 43 and 39 files, €590 excl. VAT each.

For the ISO 42001 side specifically, the readiness checklist is organised by what produces evidence, what certification involves covers the audit and the accreditation check, the AI impact assessment covers the one requirement with no ISO 27001 equivalent, and how to write the Statement of Applicability covers the document this page already said never merges with its ISO 27001 counterpart. On the security side, which documents ISO 27001 actually requires applies the same distinction between documents and records that both standards make.