ISO/IEC 27001 is one of the world's most established management standards, with 48,671 valid certificates recorded in the 2023 ISO Survey even in a year when China's data was absent. ISO/IEC 42001, published in 2023, is its newest sibling, built for artificial intelligence. The two share the same skeleton but govern very different things: ISO 27001 protects information, while ISO 42001 governs AI. If you already work with one, the other will feel familiar in shape and unfamiliar in substance. The AI Governance Certification Institute (AIGCI) put this comparison together so you can see exactly where they align, where they differ, and whether you need one or both.

ISO 42001 and ISO 27001 share the same management-system structure, but ISO 27001 manages information security while ISO 42001 manages artificial intelligence, each with its own set of Annex A controls.

If you already know ISO 27001, start here

Most people meet ISO 42001 after ISO 27001, so it helps to anchor the new standard to the one you know. ISO 27001 runs an information security management system, or ISMS, focused on the confidentiality, integrity, and availability of information. ISO 42001 runs an AI management system, or AIMS, focused on governing AI responsibly across its lifecycle. Both are certifiable, both are risk-based, and both use the same Plan, Do, Check, Act rhythm. The reason 42001 feels familiar is deliberate: it was built on the same ISO Harmonized Structure (formerly Annex SL) that 27001 uses, so Clauses 4 to 10 line up almost one to one. What changes is what you are managing, and therefore the controls you apply.

How ISO 42001 and ISO 27001 compare, point by point

Here is the full side-by-side. Notice that the structure column is nearly identical, while purpose, controls, and focus diverge sharply.

Dimension

ISO/IEC 27001

ISO/IEC 42001

Manages

An information security management system (ISMS)

An AI management system (AIMS)

Purpose

Protect the confidentiality, integrity, and availability of information

Govern AI responsibly across its lifecycle

Latest version

ISO/IEC 27001:2022

ISO/IEC 42001:2023

Annex A controls

93 controls

38 controls

Control grouping

4 themes: organizational, people, physical, technological

9 control objectives (A.2 to A.10)

Core structure

ISO Harmonized Structure, Clauses 4 to 10, PDCA

Same structure, Clauses 4 to 10, PDCA

Signature risks

Breaches, data loss, unauthorised access

Bias, opacity, unsafe or unaccountable AI

Certifiable

Yes, three-year accredited cycle

Yes, three-year accredited cycle

Shared structure, different focus, in one view

The overlap is real but bounded. Both standards share the management-system machinery; each adds a control set for the risks it exists to address.

Figure 1. ISO 42001 and ISO 27001 share a management-system structure but apply different controls to different risks.

Where the two standards genuinely differ

The clearest way to see the difference is by the risks each is built to manage. ISO 27001 is about protecting information: its 93 controls span organizational, people, physical, and technological measures, and bodies such as the EU Agency for Cybersecurity frame that discipline. ISO 42001 is about governing AI, and its 38 controls address concerns that security frameworks were never designed to cover: bias and fairness, transparency and explainability, human oversight, and the governance of data used to train and test models. The NIST AI Risk Management Framework makes the same point, that AI risk extends well beyond security into fairness and accountability, and the EU AI Act regulates AI on exactly those grounds. In short, 27001 keeps information safe; 42001 keeps AI trustworthy.

Do you need both, and which one comes first

Because AI systems run on data, the two standards complement each other rather than compete. A practical way to choose: if your priority is protecting information, ISO 27001 is the foundation; if you build, buy, or deploy AI, ISO 42001 governs the risks 27001 does not touch. Many organizations hold both, and the good news is that the shared structure makes that far less work than two separate systems. If you already run 27001, you can extend it: our guide on how to integrate them shows how to run one combined management system, and moving from 27001 to 42001 walks through the transition step by step. If ISO 42001 is new to you, start with the overview of the ISO 42001 standard first.

To summarise: ISO 42001 and ISO 27001 sit on the same management-system foundation, so they integrate cleanly, but they solve different problems. ISO 27001 secures your information with 93 controls; ISO 42001 governs your AI with 38. Choose 27001 for security, 42001 for AI, and both when your AI depends on data you also need to protect.

Frequently asked questions

Is ISO 42001 replacing ISO 27001?

No. They govern different things. ISO 27001 manages information security and ISO 42001 manages AI. ISO 42001 does not replace or include 27001; it sits alongside it and addresses risks that security controls do not cover.

Can I get both certifications together?

Yes, and it is efficient to do so. Because both use the same ISO Harmonized Structure, an organization can run a single integrated management system and be audited against both standards, sharing leadership, risk, and improvement processes.

Which has more controls, ISO 27001 or ISO 42001?

ISO 27001:2022 has 93 Annex A controls across four themes. ISO 42001 has 38 controls across nine objectives. The difference reflects their scope: 27001 covers broad information security, while 42001 targets AI-specific governance.

If I already have ISO 27001, is ISO 42001 easier?

Usually, yes. The management-system clauses are shared, so the structure, leadership, and risk approach carry over. The new work is the AI-specific content: impact assessment, transparency, human oversight, and AI data governance.

Do I need ISO 27001 before ISO 42001?

No. ISO 27001 is not a prerequisite for ISO 42001. However, since AI relies on data, many organizations find that having strong information security in place makes AI governance more straightforward.

Build AI governance on a foundation you may already have

If your background is information security, you are closer to AI governance than you might think. AIGCI's ISO 42001 training for security professionals builds directly on the management-system thinking you already use for 27001, so the step across is a short one. To see how the institute structures its programme, read more about the institute.