ISO management systems

Do you need ISO/IEC 42001 if you already hold ISO/IEC 27001?

ISO/IEC 27001 gives an organisation an information security management system. It does not, by itself, show that the organisation identifies and governs the broader risks, impacts and accountability questions created by AI. ISO/IEC 42001 is separate because it covers the organisational management of AI systems, including responsible use, transparency, human oversight and AI-specific risk and opportunity. An organisation may reuse much of its existing management-system machinery, but it still has to do the AI-specific work.

Decision test

Consider ISO/IEC 42001 implementation, and whether certification is commercially useful, when one or more of these is true:

  • AI is part of a product or customer service;
  • AI influences consequential decisions about people, safety, access, eligibility or finance;
  • the organisation builds, fine-tunes, integrates or provides AI systems;
  • buyers, tenders, regulators, investors or the board ask for demonstrable AI governance;
  • the AI inventory is growing faster than existing risk and supplier processes can govern it; or
  • the organisation needs consistent evidence of human oversight, testing, monitoring and accountability.

A separate ISO/IEC 42001 certificate may not be the first step when AI use is narrow and low consequence, there is no external requirement, or the organisation has not yet identified the AI systems in scope. In that case, an AI inventory and risk-based gap assessment are more useful than choosing a certificate date.

What ISO/IEC 27001 already gives you

A mature ISMS can provide reusable processes for organisational context, leadership, risk governance, competence, controlled documents, supplier oversight, incident handling, internal audit, management review, corrective action and continual improvement. Reuse should be tested, not assumed. A process that works for information-security incidents may need new triggers, owners and evidence for AI behaviour, impact or model drift.

What ISO/IEC 42001 adds

The AIMS has to address the organisation's role in relation to each AI system and the risks and opportunities created by developing, providing or using it. That work commonly includes:

  • a maintained AI-system inventory;
  • intended use and reasonably foreseeable misuse;
  • AI-specific risk and impact assessment;
  • data, model and supplier provenance;
  • transparency and information for affected parties;
  • human oversight and decision authority;
  • performance, change and drift monitoring;
  • AI incident and escalation criteria; and
  • evidence that governance operates through the AI lifecycle.

ISO/IEC 27001 can support those controls, but it does not make them exist automatically.

Can the systems be integrated?

Yes. The standards use a compatible management-system structure, so one governance system can often hold shared processes while preserving the requirements and evidence specific to each standard. Integration can reduce duplicate policy, audit and review activity. The certification body still has to scope each standard and confirm audit duration from the actual organisation, sites, headcount, complexity and degree of integration.

Australian context

Australia's National AI Centre now frames responsible AI adoption through six essential practices and provides implementation guidance for organisations with complex or higher-risk AI use. ISO/IEC 42001 can give those activities a management-system structure with owners, records, audit, management review and improvement. Neither framework automatically proves compliance with every Australian law or sector rule.

A practical sequence

  1. Inventory AI systems in use and development.
  2. Record the organisation's role for each system: developer, provider, integrator or user.
  3. Identify consequential use cases and affected stakeholders.
  4. Map reusable ISMS processes and evidence.
  5. Record the AI-specific gaps.
  6. Decide whether implementation alone or third-party certification matches the external requirement.
  7. Ask a certification body to scope audit time and the certification cycle from the real boundary.

Common questions

Does ISO/IEC 27001 certification cover AI security?

It can include information-security risks associated with AI systems when those risks sit inside the certified ISMS scope. It does not certify conformity with ISO/IEC 42001 or cover every AI governance and impact requirement.

Must an organisation hold ISO/IEC 27001 before ISO/IEC 42001?

No. ISO/IEC 42001 can operate as its own management system. An existing ISMS can reduce duplication where its processes are mature and genuinely shared.

Does using ChatGPT or Microsoft Copilot mean we need ISO/IEC 42001 certification?

Not automatically. The decision should follow the role, scale, consequence, stakeholder expectations and contractual or regulatory drivers. The systems still belong in an AI inventory and risk process.

Can both standards be audited together?

Potentially. An integrated audit depends on the scopes, management-system integration and the certification body's application review. Do not assume a fixed time or fee reduction before that review.

Sources