How to Integrate ISO/IEC 27001 and ISO/IEC 42001?

Integrate ISO/IEC 27001 and ISO/IEC 42001

Why Integration Makes Sense?

Organizations already certified to ISO/IEC 27001 are well positioned to extend their existing Information Security Management System into a combined ISMS and AIMS, significantly reducing the duplication of documentation, governance processes and audit effort.

The case for integration is practical and commercial. An organization that runs ISO/IEC 27001 and ISO/IEC 42001 as separate, siloed management systems incurs duplicated policy documentation, separate internal audit programs, duplicate management reviews and two sets of risk registers covering overlapping subject matter.

Integration eliminates this duplication while preserving the AI-specific governance requirements that ISO/IEC 42001 introduces. For organizations already using AI systems, integration is not just efficient, it is strategically coherent: AI governance and information security governance address overlapping risks and the same underlying infrastructure.

Tip: For ISO/IEC 27001-certified organizations using AI, map existing ISMS documentation to ISO/IEC 42001 requirements to identify integration gaps efficiently early.


Common Governance Processes

These requirements are substantively identical across both standards and can be fully unified in a single integrated management system.

The Annex SL structure ensures that Clauses 4 through 10 of both standards follow the same framework. A single context of the organization analysis, a single set of interested party requirements and a single leadership commitment structure can satisfy both standards simultaneously. Objectives can be defined and monitored in a single framework covering both information security and AI governance targets.

Competence and awareness requirements can be addressed through a unified training and awareness program that covers both ISMS and AIMS roles. Management review can be conducted as a single meeting covering both standards, with a combined agenda and combined output records.

Writer's view: Integrate ISO/IEC 42001 requirements into existing ISMS governance documents to align AI and information security controls within one coherent policy.


Combined Risk Management Approach

The integration point is the risk assessment methodology: a single documented approach that covers information security risks and AI-specific risks within a unified risk treatment framework.

Key points for combined risk management:

  • Unified risk assessment methodology documented in a single procedure

  • Single risk register covering information security and AI governance risks

  • AI-specific risk dimensions added as defined categories within the unified register

  • AI system impact assessments maintained as separate standalone documents linked to risk register entries

  • Single risk treatment plan covering both ISMS and AIMS risk treatment decisions

Final Remark: Extend your ISO/IEC 27001 risk assessment to include AI-specific risks like bias, model drift, data provenance and misuse potential.


Shared Policies and Internal Audits

A single information security and AI governance policy, supported by topic-specific sub-policies, satisfies both standards and presents a more coherent governance framework to auditors, customers and regulators.

A unified policy structure for an integrated ISMS and AIMS should cover information security governance, AI governance principles, ethical AI use, data governance for both security and AI purposes, human oversight obligations and supply chain security and AI supplier management. Internal audit programs can be combined into a single annual program that audits both ISMS and AIMS requirements in coordinated visits, using auditors who hold competence in both standards.

Combined internal audit programs reduce staff time required for audit preparation and interviews, provide a more holistic view of integrated governance performance and generate a single set of findings that can be addressed in a unified corrective action process.

Tip: Brief internal auditors on ISO/IEC 42001 and expand ISMS audit scope to AI governance using one combined audit checklist.


Separate AI-Specific Controls

ISO/IEC 27001's 93 Annex A information security controls and ISO/IEC 42001's 38 Annex A AI governance controls address distinct subject matter and must each be assessed independently against their own applicability criteria.

ISO/IEC 42001's Annex A controls cover subject matter that has no equivalent in ISO/IEC 27001, including AI system impact assessment, data governance for AI training and validation, model lifecycle management, transparency and explainability requirements, human oversight mechanisms and AI system-specific third-party and customer relationship controls.

These controls cannot be satisfied by reference to ISO/IEC 27001 Annex A controls and require dedicated implementation, documentation and evidence of operational effectiveness. Both Statements of Applicability must be maintained separately, with applicability and exclusion justifications specific to each standard's control set.

Maintain separate SoAs for ISO/IEC 27001 and ISO/IEC 42001, cross-referencing overlapping controls without substituting information security controls for AI-specific requirements.


Supplier and Third-Party AI Governance

Many organizations deploy third-party AI tools, including large language models, AI-powered analytics platforms, automated decision-making systems and AI-enabled SaaS products, without subjecting them to the same governance rigor applied to internally developed AI systems.

ISO/IEC 42001 requires that externally sourced AI systems are assessed for their AI-specific risks, transparency characteristics, data governance practices and alignment with the organization's AI policy before deployment, and monitored on an ongoing basis for model drift, bias and performance degradation.

The integration point with ISO/IEC 27001 is the supplier management process: a single supplier evaluation procedure can be extended to cover both information security requirements and AI governance requirements for AI system suppliers.

Writer's view: Review approved AI suppliers and ensure evaluations cover transparency, data provenance, bias risks, governance controls, monitoring, and human oversight capabilities.


Integration Roadmap

Phase 1: Gap Analysis (2 to 4 weeks)

Map existing ISO/IEC 27001 ISMS documentation against ISO/IEC 42001 requirements clause by clause. Inventory all AI systems in scope and identify gaps in AI governance, risk assessment, data governance and Annex A control coverage.

Phase 2: Documentation and Process Updates (6 to 10 weeks)

Extend existing governance documents to cover ISO/IEC 42001 requirements. Develop AI-specific documentation including the AI policy, AI system inventory, impact assessment procedures, data governance controls and AI-specific Statement of Applicability.

Phase 3: Training and Internal Audit (4 to 6 weeks)

Train relevant staff and internal auditors on ISO/IEC 42001 requirements. Conduct a combined internal audit covering both standards and resolve all identified nonconformities.

Phase 4: Combined Certification Audit (4 to 6 weeks)

Submit to a combined Stage 1 and Stage 2 certification audit with Pacific Certifications covering both ISO/IEC 27001 and ISO/IEC 42001, resulting in the issuance of both certificates upon successful completion.

Tip: For ISO/IEC 27001-certified organizations, integration typically takes 4–6 months; appoint a project lead early and follow milestone-based planning throughout implementation.


Author's Views

The structural compatibility of the two standards means that the efficiency gains from integration are real and substantial. The key discipline required is maintaining the separation between the AI-specific Annex A control set and the information security control set: these are distinct bodies of requirements addressing distinct risks, and the temptation to satisfy AI governance requirements by reference to information security controls should be firmly resisted.

Organizations that integrate both standards within a single management system, maintain separate and rigorously completed Statements of Applicability, and conduct combined internal audits with auditors competent in both standards will be in the strongest possible position for certification, regulatory scrutiny and stakeholder confidence.


How Pacific Certifications Can Help?

Accredited by ABIS, Pacific Certifications conducts impartial, evidence-based audits in full conformance with ISO/IEC 17021. Services include:

  • Combined ISO/IEC 27001 and ISO/IEC 42001 certification audits in coordinated, efficient audit visits

  • Initial ISO/IEC 42001 certification for organizations already certified to ISO/IEC 27001

  • Integrated management system audits covering ISO/IEC 27001, ISO/IEC 42001 and ISO 9001

  • Stage 1 and Stage 2 audit execution and certificate issuance

  • Annual surveillance and triennial recertification audits for both standards


Contact Us

To get started with your Integration of ISO/IEC 27001 and ISO/IEC 42001, ISO certification program or initiate your audit, contact us at support@pacificcert.com or +91-8595603096.

For training programs, contact us at trainings@pacificcert.com.

Apply for Integrated ISO 27001 and ISO 42001 Certification
Strengthen information security and AI governance together by aligning ISMS controls, AI risk management and responsible AI practices through an integrated certification approach.

Also read: ISO/IEC 23894 and ISO 42001 responsible AI framework

Pacific Certifications
Integrate ISO/IEC 27001 and ISO/IEC 42001

Frequently Asked Questions

Can ISO/IEC 27001 and ISO/IEC 42001 be certified together in a single audit?
Yes. Because both standards share the Annex SL High Level Structure, Pacific Certifications can conduct combined Stage 1 and Stage 2 audits covering both standards in coordinated visits.
Do organizations need to be ISO/IEC 27001 certified before pursuing ISO/IEC 42001?
No. ISO/IEC 42001 can be implemented and certified as a standalone standard. However, organizations already certified to ISO/IEC 27001 have a significant head start: the governance framework, risk management processes, documented information controls and internal audit program required by ISO/IEC 42001 are largely already in place and need extension rather than creation from scratch.
Can the same internal auditor audit both ISO/IEC 27001 and ISO/IEC 42001?
Yes, provided the auditor holds demonstrated competence in both standards. Internal auditors should receive specific training on ISO/IEC 42001 AI governance requirements, particularly AI system impact assessment, data governance controls and human oversight mechanisms, before auditing AIMS processes.
Are the Statements of Applicability for ISO/IEC 27001 and ISO/IEC 42001 combined or separate?
They must be maintained as separate documents. ISO/IEC 27001 requires a Statement of Applicability covering its 93 Annex A information security controls, while ISO/IEC 42001 requires a separate Statement of Applicability covering its 38 Annex A AI governance controls.
What is the most efficient starting point for integrating ISO/IEC 42001 into an existing ISO/IEC 27001 ISMS?
The most efficient starting point is a structured gap analysis that maps existing ISMS documentation against ISO/IEC 42001 clause requirements, combined with an AI system inventory.
Pacific Certifications

Pacific Certifications

Looking for ISO Certification? Get in touch now!

Pacific Certifications

Pacific Certifications is an independent, internationally recognized certification body providing third-party audit and certification services for management system standards such as ISO 9001, ISO 14001, ISO/IEC 27001, ISO 45001, and other ISO standards. We also provide product certification services and training and personnel certification programs designed to support organizational and professional competence.