ISO27K

ISO 42001 vs ISO 27001: what differs

The two standards share a spine and diverge on subject. ISO 27001 protects your information with 93 Annex A controls. ISO 42001 governs your AI systems with 38, and adds one requirement that has no ISO 27001 counterpart at all: the AI system impact assessment.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

If you already hold ISO 27001, adding ISO 42001 is roughly a third of the work the first certification was, and an integrated audit of both costs fewer audit days than two separate ones. If you hold neither, do ISO 27001 first: most of it sits underneath the AI controls anyway, and it is the certificate buyers already recognise. The genuinely new work in ISO 42001 is clause 6.1.4, the AI system impact assessment, which asks about harm to people outside your organization and has nothing equivalent in ISO 27001.

93 and 38 Annex A controls in ISO 27001 and ISO 42001

25 Mandatory clause requirements in ISO 27001, clauses 4 to 10

1 Clause requirement in ISO 42001 with no ISO 27001 counterpart

What is different, in one table

ISO/IEC 27001:2022 and ISO/IEC 42001:2023 compared
 ISO/IEC 27001:2022ISO/IEC 42001:2023
What it managesInformation securityAI systems and how they are governed
Who is being protectedThe organization and its informationAlso the individuals and groups the AI system affects
Management system clausesClauses 4 to 10, 25 mandatory requirementsClauses 4 to 10, same harmonised structure
Annex A93 controls in four themes38 controls under nine headings, A.2 to A.10
Other annexesNone. Guidance lives in ISO 27002Annex B implementation guidance, Annex C objectives and risk sources, Annex D sector use
Risk activityInformation security risk assessment and treatmentAI risk assessment and treatment, plus a separate impact assessment
Selection documentStatement of ApplicabilityStatement of Applicability, same mechanism, different annex
Role questionNot asked. You are the organizationAsked per system. Developer, tuner, embedder or deployer changes what applies
Audit cycleStage 1, stage 2, two surveillances, recertification at three yearsIdentical
Accredited bodies in CanadaMany. SCC and foreign accreditations both acceptedFew. The domestic pool is small enough to affect scheduling
Buyer recognition in 2026Universal in enterprise procurementEarly. Buyers are still learning what to ask for

Clause by clause: where they actually diverge

Both standards use the harmonised structure ISO applies across management system standards, so clauses 4 to 10 carry the same names and the same shape. That is why an organization with a working ISMS integrates rather than rebuilds. The differences are narrower than the shared spine suggests, and they are all in the same place: what the risk work is about, and who counts as affected.

What each clause asks for in each standard
ClauseISO 27001What ISO 42001 changes
4, ContextInterested parties, issues, ISMS scopeAdds your role for each AI system, which is the input everything downstream depends on
5, LeadershipPolicy, roles, accountabilityAn AI policy, and accountability that has to reach a named person for a system in production
6.1.2, Risk assessmentRisks to confidentiality, integrity, availabilityRisks arising from the AI system, drawn against the risk sources listed in Annex C
6.1.3, Risk treatmentCompare against 93 Annex A controls, produce a Statement of ApplicabilitySame mechanism, compared against the 38 controls in its own Annex A
6.1.4No counterpartThe AI system impact assessment. Consequences for individuals and groups, not for you
7, SupportCompetence, awareness, documented informationSame, with competence read as understanding the systems rather than the security controls
8, OperationRun the risk process, control changesAdds operational impact assessment and life cycle controls that reach into how models are built
9, PerformanceMonitoring, internal audit, management reviewSame three requirements, and they can be run once across both systems
10, ImprovementNonconformity, corrective action, continual improvementIdentical in substance

The one requirement with no counterpart

Clause 6.1.4 is the reason ISO 42001 is not just ISO 27001 with different controls. An information security risk assessment asks what could happen to your information. An AI system impact assessment asks what could happen to the person on the other end of the output, and it asks it whether or not that person is your customer. A credit model that quietly declines a demographic has caused no security incident and no loss to the organization, and it is exactly the harm clause 6.1.4 exists to surface. This is also the deliverable most first-time projects underestimate, so it is worth reading what actually goes in one before scoping the work.

The role question, which ISO 27001 never asks

ISO 27001 has one subject: you. ISO 42001 asks, per system, whether you developed the model, tuned somebody else's, embedded a third party's through an API, or simply deployed one as a user. The answer changes which Annex A controls are applicable and it changes them differently for each system in your inventory, which is why the inventory is the first deliverable rather than the policy. A company running four AI systems can genuinely hold four different roles and be assessed against four different subsets.

Annex A: 93 controls against 38

The two annexes are not versions of each other and no control maps one-to-one. What they share is a handful of subjects seen from different angles. The table below is the honest overlap, and it is smaller than vendor mapping spreadsheets suggest.

Where the two annexes touch, and where they do not
SubjectISO 27001 Annex AISO 42001 Annex ADoes the ISO 27001 evidence carry?
Supplier and third-party managementSupplier and cloud service controls in A.5Third parties and customers, A.10Mostly. Add what the model provider does with your data and on what terms
Logging and monitoringA.8 logging and monitoringEvent logging under the life cycle group, A.6Partly. Model inputs, outputs and version are new fields, not new pipelines
Change managementA.8 change managementLife cycle controls, A.6Partly. A model retrain is a change your existing process probably does not catch
DataClassification, retention, maskingFive controls in A.7 on acquisition, quality, provenance and preparationBarely. Provenance and lawful basis for training are new questions
Impact on peopleNothingA.5, and clause 6.1.4 behind itNo. This is the new work
Communication to usersNothing equivalentA.8, what you tell people about the systemNo
Access control, cryptography, physical securityExtensiveAssumed rather than restatedFully, and this is why doing ISO 27001 first is cheaper

Read the last row carefully, because it is the argument for order. ISO 42001 does not restate access control, encryption or physical security. It assumes a competent information security posture underneath and audits the AI-specific layer on top. Certifying to ISO 42001 with nothing underneath is possible, and you will find yourself building most of Annex A of ISO 27001 to satisfy an auditor asking how the training data is protected, without getting the ISO 27001 certificate at the end of it.

What does an integrated audit of both cost?

Ask for it by name. A certification body that holds accreditation for both standards can run one integrated audit covering both management systems, and the day count is lower than two separate audits because the clause 4 to 10 evidence is examined once. The saving lands in audit days, which is the number to negotiate on, and it is typically in the range of ten to twenty per cent of the combined days rather than the half that people hope for. The AI-specific technical work still has to be audited separately, because it is separate work.

Certification body cost, separate against integrated, Canadian bands in CAD
RouteInitial audit, CADEach surveillance year, CADWhat you give up
ISO 27001 alone$15,000 to $40,000$5,000 to $16,000Nothing. Start here if choosing
ISO 42001 alone$15,000 to $45,000$5,000 to $15,000A smaller pool of accredited bodies and less buyer recognition
Both, two bodies, two audits$30,000 to $85,000$10,000 to $31,000Two audit calendars, two sets of findings, two management review cycles
Both, one body, integrated$25,000 to $72,000$8,000 to $26,000Body choice. Fewer bodies hold both accreditations
Three-year cycle, integrated, certification body only$41,000 to $124,000 Excludes consulting, internal audit and testing

These are certification body figures only. The consulting and internal figures behave differently: a second standard on an existing management system is dominated by the new technical work rather than by the paperwork, so budget $30,000 to $90,000 CAD for a first ISO 42001 readiness engagement from a standing start and roughly half that when a certified ISMS already exists. The cost calculator runs the ISO 27001 half against your own numbers, and the ISO 42001 certification page takes the audit process apart line by line.

The integration mistake that costs the most

Running two parallel management systems. Two risk registers, two internal audit programs, two management reviews, two document sets, two sets of objectives. It is the default outcome when the AI project is owned by a different team from the ISMS, and it doubles the ongoing cost permanently rather than once. One system with AI-specific criteria added to the risk method, one internal audit program with AI in its scope, and one management review with an AI section on the agenda is the arrangement an auditor expects and the only one that stays affordable at year three.

Which one should you do first?

  1. Read what the buyer wrote. If the words are information security, data protection or a security questionnaire, they mean ISO 27001 or SOC 2, and an AI governance certificate answers a different question. If the words are AI governance, model risk or responsible AI, they mean ISO 42001.
  2. If you have neither, start with ISO 27001. It is recognised everywhere, it underpins the AI controls, and it is the cheaper first certificate to defend at a stage 2 audit.
  3. If you hold ISO 27001 and AI is now material to the product, add ISO 42001 at your next surveillance visit. Aligning the two audit calendars from the start is what makes the integrated audit available later. Retrofitting alignment means an off-cycle audit you pay for twice.
  4. If you hold SOC 2 and nothing else, price both. The management system layer you are missing serves both standards, so the second one is much cheaper than the first. The SOC 2 reuse estimator puts a number on how much of the ISO 27001 half you already hold.
  5. If nobody has asked for either, do neither yet. An inventory, a policy and vendor terms answer most of what arrives in the next year. The test for when that stops being enough is the honest version of this decision.

Does the Canadian situation change the answer?

In one way that matters. Both certificates are only worth what the accreditation behind them is worth, and the accreditation position for the two standards is not the same here. ISO 27001 has a deep pool of bodies accredited by the Standards Council of Canada and by UKAS and ANAB, all of which are recognised under the IAF multilateral arrangement, so a Canadian certificate travels to a European buyer without argument. ISO/IEC 42001 accreditation is newer and the domestic pool is small: SCC accreditation for AI management system audits exists in Canada, and the number of bodies holding it is countable. That constrains scheduling more than price, and it makes checking the scope document mandatory rather than prudent. The procedure is the same for both standards and it is set out on the accreditation page.

On the law, the asymmetry runs the other way. ISO 27001 sits alongside PIPEDA, PHIPA and Law 25 without conflict. ISO 42001 runs into Law 25 directly, because the right to be informed about a decision based exclusively on automated processing is in force in Quebec today and applies whether or not you certify anything. If your AI systems make decisions about Quebec residents, that obligation exists this year and no certificate discharges it.

Get both priced properly

Tell us which standards you need and what your AI systems do, and we will match you with Canadian firms and certification bodies that handle both.

Get matched

Common questions

Can ISO 42001 replace ISO 27001?

No. They certify different management systems and a buyer asking for information security assurance will not accept an AI governance certificate. ISO 42001 assumes an information security posture underneath it rather than auditing one, so it is an addition, never a substitute.

How many controls do the two standards have between them?

ISO 27001 Annex A has 93 controls in four themes and ISO 42001 Annex A has 38 under nine headings. Adding them is not useful, because they are different reference sets for different subjects and a control that appears in both is still two separate decisions in two separate Statements of Applicability. Separately from the annexes, both standards carry mandatory clause requirements in clauses 4 to 10, and in ISO 27001 there are 25 of them. A clause requirement is not a control and cannot be excluded.

Can one certification body audit both at once?

Yes, if it holds accreditation for both standards, and you should ask for an integrated audit explicitly rather than assume it. The clause 4 to 10 evidence is examined once instead of twice, which usually takes ten to twenty per cent off the combined day count. Ask for the day count per visit across the whole three-year cycle, not a total, because that is the only number comparable between bodies.

How much cheaper is ISO 42001 if we already have ISO 27001?

Expect roughly a third of the effort of the first certification. The savings are in the management system layer, which already exists: scope, policy, competence, documented information, internal audit, management review, nonconformity. The costs that do not shrink are the AI system inventory, the impact assessments and the data provenance work, because none of those had an ISO 27001 counterpart to reuse.

Do we need a separate Statement of Applicability for each?

Yes. Each standard requires its own, because each records decisions against its own Annex A. Combining them into one document is a common shortcut that produces a file an auditor cannot follow, since the exclusion justifications answer to different clauses. Keep two documents and one review process. The control selector gives you a first pass at the ISO 27001 one.

Which is harder to pass?

ISO 42001, for most organizations, and not for the reason people expect. The controls are fewer and the clauses are familiar. What is hard is that the impact assessment and the data provenance controls ask questions the organization has never had to answer in writing, and there is no established template industry to buy an answer from. ISO 27001 stage 2 findings tend to be about missing records. Early ISO 42001 findings tend to be about missing thinking.