# How to Integrate ISO/IEC 27001 and ISO/IEC 42001?
Author: Pacific Certifications
Author URL: https://blog.pacificcert.com/author/pacific-certifications/
Published: 2026-08-10
Meta Title: How to Integrate ISO 27001 & ISO 42001? (ISMS & AI)
Meta Description: Learn how to integrate ISO/IEC 27001 and ISO/IEC 42001 into a unified management system in 4 simple phases. Streamline your ISMS and AI governance.
Tags: ISO/IEC 42001:2023, ISO/IEC 27001:2022, ISMS and AI
Tag URLs: ISO/IEC 42001:2023 (https://blog.pacificcert.com/tag/isoiec-420012023/), ISO/IEC 27001:2022 (https://blog.pacificcert.com/tag/isoiec-270012022/), ISMS and AI (https://blog.pacificcert.com/tag/isms-and-ai/)
URL: https://blog.pacificcert.com/integrate-iso-iec-27001-and-iso-iec-42001-isms-ai/

![Integrate ISO/IEC 27001 and ISO/IEC 42001](https://prod.superblogcdn.com/site_cuid_cljse4miw184303tp9kqsuho9k/images/how-to-integrate-iso-iec-27001-and-iso-iec-42001-1786352641288-compressed.webp)

## **Why Integration Makes Sense?**

Organizations already certified to ISO/IEC 27001 are well positioned to extend their existing **Information Security Management System** into a combined ISMS and AIMS, significantly reducing the duplication of documentation, governance processes and audit effort.

The case for integration is practical and commercial. An organization that runs ISO/IEC 27001 and ISO/IEC 42001 as separate, siloed management systems incurs duplicated policy documentation, separate internal audit programs, duplicate management reviews and two sets of risk registers covering overlapping subject matter.

Integration **eliminates this duplication** while preserving the AI-specific governance requirements that ISO/IEC 42001 introduces. For organizations already using AI systems, integration is not just efficient, it is strategically coherent: AI governance and information security governance address overlapping risks and the same underlying infrastructure.

> **Tip:** For ISO/IEC 27001-certified organizations using AI, map existing ISMS documentation to ISO/IEC 42001 requirements to identify integration gaps efficiently early.

Assess ISO 27001 And ISO 42001 Integration Readiness

* * *

## **Common Governance Processes**

These requirements are substantively identical across both standards and can be fully unified in a single integrated management system.

The **Annex SL structure** ensures that Clauses 4 through 10 of both standards follow the same framework. A single context of the organization analysis, a single set of interested party requirements and a single leadership commitment structure can satisfy both standards simultaneously. Objectives can be defined and monitored in a single framework covering both information security and AI governance targets.

Competence and awareness requirements can be addressed through a unified training and awareness program that covers both **ISMS** and **AIMS** roles. Management review can be conducted as a single meeting covering both standards, with a combined agenda and combined output records.

> **Writer's view:** Integrate ISO/IEC 42001 requirements into existing ISMS governance documents to align AI and information security controls within one coherent policy.

* * *

## **Combined Risk Management Approach**

The integration point is the risk assessment methodology: a single documented approach that covers information security risks and AI-specific risks within a unified risk treatment framework.

Key points for combined risk management:

- Unified risk assessment methodology documented in a single procedure

- Single risk register covering information security and AI governance risks

- AI-specific risk dimensions added as defined categories within the unified register

- AI system impact assessments maintained as separate standalone documents linked to risk register entries

- Single risk treatment plan covering both ISMS and AIMS risk treatment decisions


> **Final Remark:** Extend your ISO/IEC 27001 risk assessment to include AI-specific risks like bias, model drift, data provenance and misuse potential.

Combine ISO 27001 And ISO 42001 Risk Management

* * *

## **Shared Policies and Internal Audits**

A single information security and AI governance policy, supported by topic-specific sub-policies, satisfies both standards and presents a more **coherent governance framework** to auditors, customers and regulators.

A unified policy structure for an integrated ISMS and AIMS should cover information security governance, AI governance principles, ethical AI use, data governance for both security and AI purposes, human oversight obligations and supply chain security and AI supplier management. Internal audit programs can be combined into a single annual program that audits both ISMS and AIMS requirements in coordinated visits, using auditors who hold competence in both standards.

Combined internal audit programs **reduce staff time** required for audit preparation and interviews, provide a more holistic view of integrated governance performance and generate a single set of findings that can be addressed in a unified corrective action process.

> **Tip:** Brief internal auditors on ISO/IEC 42001 and expand ISMS audit scope to AI governance using one combined audit checklist.

* * *

## **Separate AI-Specific Controls**

ISO/IEC 27001's 93 Annex A information security controls and ISO/IEC 42001's 38 Annex A **AI governance controls** address distinct subject matter and must each be assessed independently against their own applicability criteria.

ISO/IEC 42001's Annex A controls cover subject matter that has no equivalent in ISO/IEC 27001, including AI system impact assessment, data governance for AI training and validation, model lifecycle management, transparency and explainability requirements, human oversight mechanisms and AI system-specific third-party and customer relationship controls.

These controls cannot be satisfied by reference to **ISO/IEC 27001 Annex A controls** and require dedicated implementation, documentation and evidence of operational effectiveness. Both Statements of Applicability must be maintained separately, with applicability and exclusion justifications specific to each standard's control set.

> Maintain separate SoAs for ISO/IEC 27001 and ISO/IEC 42001, cross-referencing overlapping controls without substituting information security controls for AI-specific requirements.

Review ISO 27001 And ISO 42001 SoA Separation

* * *

## **Supplier and Third-Party AI Governance**

Many organizations deploy third-party AI tools, including large language models, AI-powered analytics platforms, automated decision-making systems and AI-enabled SaaS products, without subjecting them to the same governance rigor applied to **internally developed AI systems**.

ISO/IEC 42001 requires that externally sourced AI systems are assessed for their AI-specific risks, transparency characteristics, data governance practices and alignment with the organization's AI policy before deployment, and monitored on an ongoing basis for model drift, bias and performance degradation.

The integration point with ISO/IEC 27001 is the **supplier management process**: a single supplier evaluation procedure can be extended to cover both information security requirements and AI governance requirements for AI system suppliers.

> **Writer's view:** Review approved AI suppliers and ensure evaluations cover transparency, data provenance, bias risks, governance controls, monitoring, and human oversight capabilities.

* * *

## **Integration Roadmap**

### **Phase 1: Gap Analysis (2 to 4 weeks)**

Map existing ISO/IEC 27001 ISMS documentation against ISO/IEC 42001 requirements clause by clause. Inventory all AI systems in scope and identify gaps in AI governance, risk assessment, data governance and Annex A control coverage.

### **Phase 2: Documentation and Process Updates (6 to 10 weeks)**

Extend existing governance documents to cover ISO/IEC 42001 requirements. Develop AI-specific documentation including the AI policy, AI system inventory, impact assessment procedures, data governance controls and AI-specific Statement of Applicability.

### **Phase 3: Training and Internal Audit (4 to 6 weeks)**

Train relevant staff and internal auditors on ISO/IEC 42001 requirements. Conduct a combined internal audit covering both standards and resolve all identified nonconformities.

### **Phase 4: Combined Certification Audit (4 to 6 weeks)**

Submit to a combined Stage 1 and Stage 2 certification audit with Pacific Certifications covering both ISO/IEC 27001 and ISO/IEC 42001, resulting in the issuance of both certificates upon successful completion.

> **Tip:** For ISO/IEC 27001-certified organizations, integration typically takes 4–6 months; appoint a project lead early and follow milestone-based planning throughout implementation.

Plan Combined ISO 27001 And ISO 42001 Certification Audit

* * *

## **Author's Views**

The structural compatibility of the two standards means that the efficiency gains from integration are real and substantial. The key discipline required is maintaining the separation between the AI-specific Annex A control set and the information security control set: these are distinct bodies of requirements addressing distinct risks, and the temptation to satisfy AI governance requirements by reference to information security controls should be firmly resisted.

Organizations that integrate both standards within a single management system, maintain separate and rigorously completed Statements of Applicability, and conduct combined internal audits with auditors competent in both standards will be in the strongest possible position for certification, regulatory scrutiny and stakeholder confidence.

* * *

## **How Pacific Certifications Can Help?**

Accredited by [ABIS](https://abisonline.org/), Pacific Certifications conducts impartial, evidence-based audits in full conformance with ISO/IEC 17021. Services include:

- Combined ISO/IEC 27001 and ISO/IEC 42001 certification audits in coordinated, efficient audit visits

- Initial ISO/IEC 42001 certification for organizations already certified to ISO/IEC 27001

- Integrated management system audits covering ISO/IEC 27001, ISO/IEC 42001 and ISO 9001

- Stage 1 and Stage 2 audit execution and certificate issuance

- Annual surveillance and triennial recertification audits for both standards


* * *

## **Contact Us**

To get started with your Integration of ISO/IEC 27001 and ISO/IEC 42001, ISO certification program or initiate your audit, contact us at [**support@pacificcert.com**](mailto:support@pacificcert.com) or +91-8595603096.

For training programs, contact us at [**trainings@pacificcert.com**](mailto:trainings@pacificcert.com).

Apply for Integrated ISO 27001 and ISO 42001 Certification

Strengthen information security and AI governance together by aligning ISMS controls, AI risk management and responsible AI practices through an integrated certification approach.

[Apply for ISO 27001 and ISO 42001 Certification](https://pacificcert.com/contact-us/)

Also read: [ISO/IEC 23894 and ISO 42001 responsible AI framework](https://blog.pacificcert.com/iso-iec-23894-iso-42001-responsible-ai-guide/)

![Pacific Certifications](https://prod.superblogcdn.com/site_cuid_cljse4miw184303tp9kqsuho9k/images/pacific-certifications-1786097587280-compressed.png)Integrate ISO/IEC 27001 and ISO/IEC 42001
## FAQs
Q: Can ISO/IEC 27001 and ISO/IEC 42001 be certified together in a single audit?
A: Yes. Because both standards share the Annex SL High Level Structure, Pacific Certifications can conduct combined Stage 1 and Stage 2 audits covering both standards in coordinated visits.

Q: Do organizations need to be ISO/IEC 27001 certified before pursuing ISO/IEC 42001?
A: No. ISO/IEC 42001 can be implemented and certified as a standalone standard. However, organizations already certified to ISO/IEC 27001 have a significant head start: the governance framework, risk management processes, documented information controls and internal audit program required by ISO/IEC 42001 are largely already in place and need extension rather than creation from scratch.

Q: Can the same internal auditor audit both ISO/IEC 27001 and ISO/IEC 42001?
A: Yes, provided the auditor holds demonstrated competence in both standards. Internal auditors should receive specific training on ISO/IEC 42001 AI governance requirements, particularly AI system impact assessment, data governance controls and human oversight mechanisms, before auditing AIMS processes.

Q: Are the Statements of Applicability for ISO/IEC 27001 and ISO/IEC 42001 combined or separate?
A: They must be maintained as separate documents. ISO/IEC 27001 requires a Statement of Applicability covering its 93 Annex A information security controls, while ISO/IEC 42001 requires a separate Statement of Applicability covering its 38 Annex A AI governance controls.

Q: What is the most efficient starting point for integrating ISO/IEC 42001 into an existing ISO/IEC 27001 ISMS?
A: The most efficient starting point is a structured gap analysis that maps existing ISMS documentation against ISO/IEC 42001 clause requirements, combined with an AI system inventory.




---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

