ISO 42001 vs ISO 27001
Same machinery, different subject. If you already hold 27001, most of the management system is built, and the new work is the AI-specific part.
ISO 27001 governs information security and ISO 42001 governs AI. They share the same clause structure, so a 27001 holder has most of the scaffolding already and adds the AI-specific content.
If your organisation already holds ISO 27001, you are the reader this comparison is for. The useful answer is not that 42001 is a whole new mountain, but that it reuses machinery you have running (BSI on ISO 27001 and ISO 42001). This page names the standards and their structure; it does not reproduce either one's text.
What does each standard cover?
ISO/IEC 27001 is the information security management system standard: how you protect the confidentiality, integrity and availability of information. ISO/IEC 42001 is the AI management system standard: how you govern the AI you develop and use, including risks that are specific to AI (ISO/IEC 42001:2023).
They overlap where AI handles information, which is increasingly everywhere, but they answer different questions and neither replaces the other.
What does a 27001 holder already have?
Both standards use the harmonised high-level structure, so Clauses 4 to 10 carry the same shape across them (BSI on ISO 27001 and ISO 42001). An organisation running a working ISO 27001 system already has the leadership, context, planning, support, performance evaluation and improvement machinery that ISO 42001 also asks for.
What that means in practice is that the management-system scaffolding is not the work. The work is the AI-specific content that sits inside it.
What does ISO 42001 add?
The AI-specific parts: understanding the AI systems you run and the roles you hold for them, the impact of AI on the people it affects, the treatment of AI-specific risks, and the operational controls and data governance around AI use. Annex A adds a set of reference controls to consider, named at a high level.
These are additions to a system you may already operate, not a parallel system. The requirements guide sets out where each sits in the clauses.
Can they run as one management system?
Yes, and they are designed to. The shared structure lets the two run as a single management system with common leadership, planning and review, and the AI-specific content layered in, which is the integration BSI describes for organisations adding one to the other (BSI on ISO 27001 and ISO 42001).
If you hold 27001 today, start by mapping your existing management system onto the ISO 42001 clauses and then filling the AI-specific gaps. The readiness check gives you that map, and the gap sheet covers it offline.