ISO 27001 to ISO 42001: Control Mapping and Expansion Guide
Gabriela Silk
·
9 minute read
Organizations with an existing ISO/IEC 27001 program already have a head start on ISO/IEC 42001. If an Information Security Management System (ISMS) certified to ISO/IEC 27001 is already in place, a meaningful share of the groundwork for ISO/IEC 42001 is already done.
The standards diverge in their primary focus, but when understood correctly can be leveraged to build off of ISO 27001. ISO/IEC 27001 protects information, establishing an information security management system for managing risks to the confidentiality, integrity, and availability of information. ISO/IEC 42001 governs how AI systems are designed, deployed, monitored, and retired responsibly, and that introduces additional categories of risk and impact: fairness, explainability, human oversight, model drift, and the downstream effect of automated decisions on real people.
Contents
- ISO 27001 to ISO 42001: Core Similarities
- Key Differences Between ISO 27001 and ISO 42001
- Steps to Expand Your Program
- ISO 27001 to ISO 42001: Clause Mapping (Clauses 4 Through 10)
- Reusable ISO 27001 Elements for ISO 42001
- ISO 42001 Capabilities That May Require New or Expanded Processes
- Conclusion
ISO 27001 to ISO 42001: Core Similarities
ISO 27001 and ISO 42001 share a common management system architecture. This alignment allows organizations to reuse governance processes instead of standing up a second, parallel system just for AI.
Shared Management System Structure
ISO 27001 and ISO 42001 follow ISO's harmonized management system structure. In both standards, Clauses 4 through 10 address the same broad management-system areas: organizational context, leadership, planning, support, operation, performance evaluation, and improvement.
Because the framework is the same, an organization with a mature ISO 27001 program already has working procedures for:
-
Defining organizational scope
-
Identifying interested parties
-
Establishing management responsibilities
-
Conducting management reviews
-
Performing internal audits
-
Managing documented information
-
Corrective action and continual improvement
Risk-Based Management
ISO 27001 uses a risk-based approach to identify, assess, and treat information security risks and determine the controls needed to protect information. ISO 42001 applies a similar risk-based management approach to AI, addressing AI-related risks and opportunities and requiring organizations to consider impacts arising from the development, provision, or use of AI systems. These can include issues involving reliability, fairness, transparency, explainability, safety, human oversight, and impacts on individuals and society.
Documentation Requirements
Implementing either standard runs on many (but not all) of the same category of documented information: policies, objectives, risk assessments, internal audit records, risk treatment plans, management review records, corrective actions, and competency records. For organizations with an established ISO 27001 program, updating these documents to account for AI is a far more efficient path than creating a second, separate set from scratch.
Governance and Leadership
Both standards depend on executive leadership to drive standards. Leaders demonstrate that commitment by:
-
Establishing governance objectives
-
Allocating resources
-
Assigning responsibilities
-
Supporting continual improvement
-
Reviewing management system performance
Organizations may be able to extend existing governance structures to cover AI rather than creating an entirely separate governance body. In an integrated approach, AI-related risks, objectives, responsibilities, and performance can be incorporated into existing processes.
Internal Audits and Certification
Internal audits, effectiveness reviews, nonconformity handling, are required under both standards. Third-party certification audits may also be pursued by organizations to demonstrate conformity, though this is not required by ISO management-system standards. Organizations that already run a mature ISO 27001 audit program tend to find ISO 42001 certification more familiar since the audit activities, evidence collection methods, and management review cadence transfer directly.
Key Differences Between ISO 27001 and ISO 42001
While the management system architecture is the same in both ISO 27001 and ISO 42001, the latter introduces governance requirements that extend traditional cybersecurity.
Primary Governance Objective
The clearest difference between the two standards is the management system objective.
ISO 27001 establishes requirements for managing information-security risks, with confidentiality, integrity, and availability at its core. ISO/IEC 42001 establishes requirements for managing AI responsibility across an organization's development, provision, and use of AI systems, including associated risks, opportunities, and impacts.
AI Impact Assessments
Where ISO 27001 evaluates the possibility of data compromise, service unavailability, and system manipulation, ISO 42001 asks a wider set of questions:
-
Whether a model could produce discriminatory outcomes
-
How an automated decision affects the person on the other end of it
-
Whether model output is sufficient for its intended use
-
Whether appropriate mechanisms for human oversight, review, or intervention are needed
-
Whether adequate human oversight exists
-
What unintended effects the system could have on society more broadly
Expanded Control Objectives
ISO 27001:2022 Annex A contains 93 reference controls grouped into four themes: 37 organizational, 8 people, 14 physical, and 34 technological controls. ISO 42001 contains its own Annex A reference-control set, with 38 controls organized under nine control objectives covering AI policy, organizational responsibilities, resources, AI system impact assessment, AI system lifecycle activities, data, information for interested parties, use of AI systems, and third-party and customer relationships.
ISO 42001 adds to that framework rather than replacing it. 38 AI management controls across nine control objectives in its own Annex A, covering areas such as:
-
Policies related to AI
-
Internal organization
-
Resources for AI systems
-
Assessing impacts of AI systems
-
AI system lifecycle
-
Data for AI systems
-
Information for interested parties
-
Use of AI systems
-
Third-party and customer relationships
Lifecycle Governance
ISO 27001 manages information-security risks across information, technology, people, processes, and supporting assets. ISO 42001 adds governance requirements specifically tailored to AI systems and includes Annex A controls addressing the AI system lifecycle. Depending on an organization's role and the AI systems in scope, lifecycle governance can include activities such as:
-
Planning and design
-
Data acquisition and preparation
-
Development
-
Verification and validation
-
Deployment
-
Operation and monitoring
-
Change management
-
Retirement
External Stakeholder Considerations
ISO 42001 puts more weight on how AI governance is perceived by the people and groups outside the organization who are affected by it, including customers, end users, regulators, business partners, and society at large.
ISO 42001 treats trustworthiness as something to demonstrate to the people who interact with an organization's AI systems, not just track internally.
Steps to Expand Your Program
For organizations that already operate an effective ISO 27001-aligned ISMS, extending existing management-system processes can provide an efficient starting point for implementing ISO 42001.
Run a Gap Analysis
Start by comparing existing ISO 27001 governance processes against ISO 42001's requirements. The gaps that show up most often include:
-
AI governance policies
-
AI lifecycle documentation
-
AI impact assessment processes
-
Human oversight requirements
-
Model validation procedures
-
AI monitoring metrics
-
Transparency requirements
Integrate Frameworks
Integrating an AIMS with an existing ISMS may include:
-
Expanding risk-management processes to address AI-related risks and opportunities
-
Adding AI system impact assessment processes
-
Incorporating relevant AIMS requirements into internal audit and management review programs
-
Establishing AI-specific objectives, responsibilities, and performance measures
-
Extending supplier and third-party governance to AI systems and services
-
Coordinating document control, corrective action, competence, and continual-improvement processes across both management systems
Prepare for Certification
Once AI-specific governance processes are in place, internal audits should verify conformity with ISO 42001.
Readiness work includes reviewing documented information, validating AI risk assessments, confirming that leadership involvement is real and evidenced, and making sure operational evidence, not just policy language, backs up every claim.
ISO 27001 to ISO 42001: Clause Mapping (Clauses 4 Through 10)
ISO/IEC 27001 and ISO 42001 share ISO's harmonized management system structure, commonly referred to as Annex SL. This structure is used across many ISO management system standards and provides the same clause framework from Clauses 4 through 10: organizational context, leadership, planning, support, operation, performance evaluation, and improvement.
This structural alignment allows organizations to integrate the two management systems more effectively and reuse established processes such as risk management, documented information, internal audits, management reviews, corrective action, and continual improvement. However, it does not mean the requirements or their implementation are identical .
The following clause-by-clause comparison highlights where organizations can reuse existing ISMS processes and where ISO 42001 introduces new AI-specific governance requirements.


Clause 4: Context of the Organization
Clause 4 lays the foundation for both management systems, requiring organizations to understand the internal and external factors shaping their operations, identify interested parties and what they expect, define the scope of the management system, and establish the management system itself.
ISO 42001 stretches that foundation beyond information security. It may include AI-specific considerations such as:
-
AI use cases
-
Regulatory expectations
-
Ethical principles
-
Customer expectations regarding trustworthy AI
-
Third-party AI providers
-
Emerging AI legislation
-
Social impacts resulting from AI-enabled decisions
Climate Change Considerations
Both ISO 27001 and ISO 42001 also require organizations to consider climate change within Clauses 4.1 and 4.2. Organizations must determine whether climate change is a relevant issue and recognize that relevant interested parties may have climate-related requirements.
For ISO 42001, this may also affect how AI systems are governed. AI used in areas such as environmental monitoring, energy, transportation, agriculture, infrastructure, or resource optimization may contribute to climate-related objectives or create climate-related impacts that should be considered within the AIMS.
Defining the Organization’s Role in AI
ISO 42001 also requires organizations to determine their role in relation to the AI systems within scope. Depending on its activities, an organization may act as an AI producer, provider, customer, partner, or another relevant role. Defining these roles helps establish which responsibilities apply across the development, provision, deployment, monitoring, and use of AI systems.
Transitioning to ISO 42001 requires reusing existing documentation and expanding it to include AI governance objectives, affected stakeholders and AI system inventories.
Clause 5: Leadership
On paper, leadership requirements barely change between the two standards. Commitment, policy-setting, and resourcing all carry over.
Under ISO 42001, executives now need to:
-
Define organizational AI governance principles
-
Establish accountability for AI decision making
-
Ensure ethical considerations
-
Support transparency and explainability initiatives
-
Promote human oversight where automated decisions are used
-
Monitor AI-related organizational risks
Most organizations can keep their existing governance structure intact here. The work is in broadening committee charters to include ethical oversight and responsible AI performance metrics, not building a parallel governance body.
Clause 6: Planning
Both standards use risk-based planning, but ISO 42001 introduces several AI-specific planning requirements. Clause 6 requires organizations to address AIMS-related risks and opportunities, establish and apply an AI risk-assessment process, define an AI risk-treatment process, determine necessary controls, compare those controls against Annex A, and document applicable controls through a Statement of Applicability.
ISO 42001 also requires an AI system impact-assessment process to evaluate the potential consequences of AI systems for individuals or groups of individuals, or both, and societies. In addition, organizations must establish AI objectives and plan changes to the AIMS.
Depending on the AI system and context, risks and impacts considered through these processes may involve:
-
Bias and fairness
-
Reliability and robustness
-
Data quality and suitability
-
Transparency and explainability
-
Human oversight
-
Safety
-
Misuse
-
Security and privacy
-
Legal and regulatory obligations
-
Effects on individuals, groups, organizations, or society
Clause 6 specifically includes 6.1.2 AI risk assessment, 6.1.3 risk treatment and 6.1.4 AI system impact assessment.
Clause 7: Support
Clause 7 covers the people, training, and documentation an effective management system runs on.
ISO 42001 differs in the expertise it demands. AI governance calls for competencies that sit outside traditional cybersecurity training:
-
AI lifecycle governance
-
Machine learning fundamentals
-
Data governance
-
Responsible AI principles
-
Bias detection techniques
-
Model validation
-
Explainability methods
-
AI risk assessment
-
AI regulatory compliance
-
Human oversight practices
Clause 8: Operation
Clause 8 is where the processes planned under Clause 6 are put into operation. ISO 42001 organizes the clause into four areas: operational planning and control, AI risk assessment, AI risk treatment, and AI system impact assessment.
Under Clause 8.1, the organization plans, implements, and controls the processes needed to meet AIMS requirements and carry out the actions determined during planning. This includes establishing process criteria, controlling planned changes, addressing unintended changes where necessary, and ensuring relevant externally provided processes are controlled.
Clause 8.2 requires the organization to perform AI risk assessments in accordance with its defined risk-assessment process at planned intervals and when significant changes are proposed or occur. Clause 8.3 requires implementation of the AI risk-treatment plan. Clause 8.4 requires AI system impact assessments to be performed using the process established under Clause 6.1.4.
The broader AI lifecycle is addressed through the AIMS as a whole and through ISO 42001 Annex A, particularly controls relating to the AI system lifecycle, data, use of AI systems, and third-party relationships. Organizations integrating ISO 42001 with ISO 27001 can therefore reuse operational planning, change-management, supplier-management, documentation, and control-monitoring processes while adding the AI-specific activities required by the AIMS.
Clause 9: Performance Evaluation
Internal audits and management reviews don't change under ISO 42001. Instead, what they measure does.
ISO 42001 adds the monitoring of:
-
AI model performance
-
Prediction accuracy
-
Fairness indicators
-
Bias metrics
-
Explainability effectiveness
-
Human oversight effectiveness
-
Incident trends involving AI
-
Data quality
-
Regulatory developments
-
Stakeholder feedback
-
AI system reliability
An internal audit program built for ISO 27001 can accommodate this by expanding its scope.
Clause 10: Improvement
Both standards handle continual improvement the same way: catch nonconformities, fix them, check whether the fix worked, and keep the records to prove it.
ISO 42001 introduces additional improvement opportunities such as:
-
Refining AI governance policies
-
Improving model monitoring processes
-
Addressing newly identified bias
-
Updating explainability methods
-
Improving training data quality
-
Strengthening human oversight mechanisms
-
Responding to emerging AI regulations
-
Enhancing transparency practices
-
Improving AI lifecycle documentation
Existing corrective action workflows need only minor updates. What changes is the list of issues they need to be able to catch, which now includes AI governance failures, model performance degradation, ethical concerns, and unintended outcomes alongside the security incidents they already track.
Reusable ISO 27001 Elements for ISO 42001
The following ISO 27001 elements can be reused or adapted directly:
-
Policies. Information security, risk management, access control, supplier management, and incident management policies can all be extended to incorporate AI governance. Existing organizational policies can often be extended or supplemented, but the AI policy requirements of ISO 42001 must still be addressed.
-
Core processes. Risk assessment, risk treatment, internal audit, corrective action, management review, change management, and document control processes built for ISO 27001 apply just as well once AI systems are added to their scope.
-
Governance structure. Security committees, risk owners, compliance functions, and executive reporting lines can absorb AI governance accountability without needing a separate structure.
-
Training framework. Existing security awareness and competency programs can be adapted to cover data quality, human oversight, and AI risk training.
-
Documentation templates. Risk registers, statements of applicability, audit schedules, corrective action records, management review templates, and policy structures can all be adapted rather than rebuilt.
*A note for the statement of applicability - The organization's existing Statement of Applicability process and template structure may be reusable, but the ISO 42001 SoA must address the controls determined for the AIMS and comparison against ISO 42001 Annex A rather than ISO 27001's control set.
ISO 42001 Capabilities That May Require New or Expanded Processes
ISO 27001 provides a strong foundation, but orgs implementing ISO 42001 will need to ensure that several AI-specific capabilities are established.
-
AI risk assessment framework. Existing risk methodology needs to be extended to cover AI-specific risks such as bias, reliability, transparency, explainability, and misuse.
-
AI lifecycle process documentation. Build out governance requirements for planning, design, development, testing, deployment, and monitoring of AI systems.
-
AI data governance. Organizations need control over the quality, provenance, relevance, suitability, and management of the data used to develop and operate AI systems.
-
Model monitoring and validation. This means establishing processes for validating AI systems before deployment and monitoring their performance once they're live.
-
Human oversight design. Organizations need to define when and how humans review, intervene in, or override AI system outputs, particularly in cases where the output affects individuals.
-
Transparency and explainability requirements. Appropriate information about how AI systems work needs to be communicated to the stakeholders affected by them.
-
AI impact assessment. An AI system impact assessment procedure needs to be developed to evaluate its effects on individuals, groups, organizations, and society.
Conclusion
Extending an ISMS into an AI management system is a more realistic starting point than building one from nothing, and it tends to produce a more durable AIMS in the long run, one where AI governance is embedded in the same processes that already keep the organization accountable, rather than treated as a separate initiative.
We work with organizations at every stage of that transition: identifying governance gaps, building out AI management processes, and preparing for ISO/IEC 42001 certification.
Learn how you can leverage ISO 27001 and ISO 42001 for your business.