ISO/IEC 27001 is one of the world's most established management standards, with 48,671 valid certificates recorded in the 2023 ISO Survey even in a year when China's data was absent. ISO/IEC 42001, published in 2023, is its newest sibling, built for artificial intelligence. The two share the same skeleton but govern very different things: ISO 27001 protects information, while ISO 42001 governs AI. If you already work with one, the other will feel familiar in shape and unfamiliar in substance. The AI Governance Certification Institute (AIGCI) put this comparison together so you can see exactly where they align, where they differ, and whether you need one or both.
ISO 42001 and ISO 27001 share the same management-system structure, but ISO 27001 manages information security while ISO 42001 manages artificial intelligence, each with its own set of Annex A controls.
If you already know ISO 27001, start here
Most people meet ISO 42001 after ISO 27001, so it helps to anchor the new standard to the one you know. ISO 27001 runs an information security management system, or ISMS, focused on the confidentiality, integrity, and availability of information. ISO 42001 runs an AI management system, or AIMS, focused on governing AI responsibly across its lifecycle. Both are certifiable, both are risk-based, and both use the same Plan, Do, Check, Act rhythm. The reason 42001 feels familiar is deliberate: it was built on the same ISO Harmonized Structure (formerly Annex SL) that 27001 uses, so Clauses 4 to 10 line up almost one to one. What changes is what you are managing, and therefore the controls you apply.
How ISO 42001 and ISO 27001 compare, point by point
Here is the full side-by-side. Notice that the structure column is nearly identical, while purpose, controls, and focus diverge sharply.
|
Dimension |
ISO/IEC 27001 |
ISO/IEC 42001 |
|---|---|---|
|
Manages |
An information security management system (ISMS) |
An AI management system (AIMS) |
|
Purpose |
Protect the confidentiality, integrity, and availability of information |
Govern AI responsibly across its lifecycle |
|
Latest version |
ISO/IEC 27001:2022 |
ISO/IEC 42001:2023 |
|
Annex A controls |
93 controls |
38 controls |
|
Control grouping |
4 themes: organizational, people, physical, technological |
9 control objectives (A.2 to A.10) |
|
Core structure |
ISO Harmonized Structure, Clauses 4 to 10, PDCA |
Same structure, Clauses 4 to 10, PDCA |
|
Signature risks |
Breaches, data loss, unauthorised access |
Bias, opacity, unsafe or unaccountable AI |
|
Certifiable |
Yes, three-year accredited cycle |
Yes, three-year accredited cycle |
Shared structure, different focus, in one view
The overlap is real but bounded. Both standards share the management-system machinery; each adds a control set for the risks it exists to address.

Figure 1. ISO 42001 and ISO 27001 share a management-system structure but apply different controls to different risks.
Where the two standards genuinely differ
The clearest way to see the difference is by the risks each is built to manage. ISO 27001 is about protecting information: its 93 controls span organizational, people, physical, and technological measures, and bodies such as the EU Agency for Cybersecurity frame that discipline. ISO 42001 is about governing AI, and its 38 controls address concerns that security frameworks were never designed to cover: bias and fairness, transparency and explainability, human oversight, and the governance of data used to train and test models. The NIST AI Risk Management Framework makes the same point, that AI risk extends well beyond security into fairness and accountability, and the EU AI Act regulates AI on exactly those grounds. In short, 27001 keeps information safe; 42001 keeps AI trustworthy.
Do you need both, and which one comes first
Because AI systems run on data, the two standards complement each other rather than compete. A practical way to choose: if your priority is protecting information, ISO 27001 is the foundation; if you build, buy, or deploy AI, ISO 42001 governs the risks 27001 does not touch. Many organizations hold both, and the good news is that the shared structure makes that far less work than two separate systems. If you already run 27001, you can extend it: our guide on how to integrate them shows how to run one combined management system, and moving from 27001 to 42001 walks through the transition step by step. If ISO 42001 is new to you, start with the overview of the ISO 42001 standard first.
To summarise: ISO 42001 and ISO 27001 sit on the same management-system foundation, so they integrate cleanly, but they solve different problems. ISO 27001 secures your information with 93 controls; ISO 42001 governs your AI with 38. Choose 27001 for security, 42001 for AI, and both when your AI depends on data you also need to protect.
Frequently asked questions
Is ISO 42001 replacing ISO 27001?
No. They govern different things. ISO 27001 manages information security and ISO 42001 manages AI. ISO 42001 does not replace or include 27001; it sits alongside it and addresses risks that security controls do not cover.
Can I get both certifications together?
Yes, and it is efficient to do so. Because both use the same ISO Harmonized Structure, an organization can run a single integrated management system and be audited against both standards, sharing leadership, risk, and improvement processes.
Which has more controls, ISO 27001 or ISO 42001?
ISO 27001:2022 has 93 Annex A controls across four themes. ISO 42001 has 38 controls across nine objectives. The difference reflects their scope: 27001 covers broad information security, while 42001 targets AI-specific governance.
If I already have ISO 27001, is ISO 42001 easier?
Usually, yes. The management-system clauses are shared, so the structure, leadership, and risk approach carry over. The new work is the AI-specific content: impact assessment, transparency, human oversight, and AI data governance.
Do I need ISO 27001 before ISO 42001?
No. ISO 27001 is not a prerequisite for ISO 42001. However, since AI relies on data, many organizations find that having strong information security in place makes AI governance more straightforward.
Build AI governance on a foundation you may already have
If your background is information security, you are closer to AI governance than you might think. AIGCI's ISO 42001 training for security professionals builds directly on the management-system thinking you already use for 27001, so the step across is a short one. To see how the institute structures its programme, read more about the institute.