+91 98804 42758

ISO 27001 to ISO 42001

You built the management system once. Annex SL means you do not build it again — you extend it to AI, and add the one requirement ISO 27001 has no equivalent for.

Updated August 2026 9 min read Information Security

Why You Are Further Along Than You Think

ISO 27001 and ISO 42001 both use the Annex SL harmonized structure. That is not a technicality — it means clauses 4 through 10, the entire management system scaffolding, is common to both standards. Context, leadership, planning, support, operation, performance evaluation, improvement.

If you hold ISO 27001, you have already built and been audited on all of it. You have a working internal audit programme, a management review that actually happens, a documented risk methodology, and document control that survived a Stage 2.

What you are adding is AI-specific content on top of a system that already exists. That is a materially different project from building a management system from nothing, and it is why organizations with an ISMS reach ISO 42001 far faster.

What Transfers

ElementTransfers?What changes
Clauses 4–10LargelyExtend scope statement to cover AI systems
Internal audit programmeYesAdd AI scope to the audit plan
Management reviewYesAdd AI performance and impact inputs
Risk methodologyYesReused, but impact assessment is additional
Competence and awarenessYesExtend training to AI-specific roles
Document controlYesNo change
Supplier managementLargelyExtend to AI providers and model vendors
Incident managementLargelyAdd AI-specific incident types

The pattern: everything that makes a management system a management system carries over. See ISO 27001 Annex A controls for what you already have.

What Is Genuinely New

Three things, and one of them has no ISO 27001 equivalent at all.

The AI impact assessment

This is the new one. ISO 42001 requires assessing the consequences of your AI systems for individuals, groups and society — not just risk to the organization.

The distinction matters and it takes teams a while to internalise. Your ISO 27001 risk assessment asks what could harm the business. An AI impact assessment asks what the system could do to the people it affects: who is subject to its decisions, what happens when it is wrong, whether outcomes could be unfair or biased, what human oversight exists, and how someone contests a result.

It is also the part that most resembles what regulators want, which is why it carries value beyond the certificate.

AI system life cycle controls

Annex A area A.6 covers objectives, design, verification and validation, deployment, operation and monitoring of AI systems. If you build models, this is substantial work. If you consume vendor APIs, it is lighter but not absent — you still own intended purpose, monitoring and human oversight.

Data for AI systems

Area A.7 covers acquisition, quality, provenance and preparation of data used in AI. Organizations that never tracked where training data came from find this the hardest area to retrofit, and it is not something that can be assembled quickly under audit pressure.

One Management System, Two Certificates

The efficient structure is a single integrated management system covering both scopes, not two parallel systems that happen to share a company.

What integration gives you: one set of clause 4–10 documentation, one internal audit programme covering both scopes, one management review, one document control system, and — where your certification body is accredited for both — a combined audit that shares the management system clauses and reduces total audit days against two separate visits.

It also aligns the surveillance schedule, so ongoing upkeep is one annual cycle rather than two that drift apart.

What stays separate: two Statements of Applicability, two scope statements, and two certificates. The standards remain distinct even when the system is one.

What the Extension Costs

Starting pointTypical timelineRelative effort
ISO 27001 certified3–6 monthsExtension — lowest
ISO 27001 in progress4–8 monthsRun them together
Neither6–12 monthsBuilding both — highest

Market ranges for ISO 42001 run $3,000–$15,000 for readiness, $10,000–$50,000 for implementation, and $7,000–$20,000 for the certification audit. An ISO 27001-certified organization extending its system sits near the bottom of those; the ranges reflect an average that includes companies building from nothing. Full breakdown in ISO 42001 certification cost.

Those are market ranges, not Avantcert prices — ISO 42001 is scoped per engagement because AI estates vary far more than headcounts do.

Get a Scoped Extension Quote

Tell us your current ISO 27001 scope and what AI systems you run. Scoped estimate within 24 hours.

If You Hold Neither

Do them together rather than sequentially. Building the management system once and certifying two scopes against it is meaningfully cheaper than an ISO 27001 project followed a year later by an ISO 42001 project that rebuilds half of it.

If you must choose one first, ISO 27001 is usually the right starting point: it is the certificate more customers currently ask for, it is the lower-cost programme, and it creates the scaffolding ISO 42001 then extends. An Avantcert ISO 27001 engagement starts at $4,000 for a 5–50 employee company.

The exception is an organization whose product is AI and whose buyers are already asking about governance. There, ISO 42001 is the certificate that unblocks deals, and ISO 27001 follows.

FAQs

Can I extend my ISO 27001 certification to ISO 42001?

You cannot extend the certificate itself — they are separate standards with separate certificates. What you extend is the management system underneath. Because both use the Annex SL structure, clauses 4 to 10 are largely shared, so you are adding AI-specific scope and controls to a system that already exists rather than building a second one.

What transfers from ISO 27001 to ISO 42001?

The management system clauses 4 to 10, your internal audit programme, the management review cadence, the documented risk methodology, competence and awareness processes, document control, and much of supplier management. What does not transfer is the AI-specific content: impact assessments, AI system life cycle controls, and AI data provenance requirements.

What is the AI impact assessment and why is it new?

ISO 42001 requires assessing the consequences of AI systems for individuals, groups and society — not only risk to the organization. ISO 27001 has no equivalent. A conventional risk assessment asks what could harm the business; an AI impact assessment asks what the system could do to the people it affects, and it is the requirement that most resembles what regulators are asking for.

Can ISO 27001 and ISO 42001 be audited together?

Yes, where your certification body is accredited for both. A combined audit shares the management system clauses across the two scopes and reduces total audit days compared with two separate visits. It also aligns your surveillance schedule, so upkeep happens once a year rather than twice.

How long does adding ISO 42001 to ISO 27001 take?

Typically three to six months for an organization already certified to ISO 27001, against six to twelve when starting with no management system. The variable is AI estate rather than headcount: the AI system inventory and the impact assessments are the work, and both scale with how many models you run and whether you built them.

Related Reading

See ISO 42001 certification services, the 38 Annex A controls, ISO 27001 consulting, or how ISO 42001 relates to the EU AI Act.

Official references: ISO/IEC 27001, ISO/IEC 42001:2023.

You built the system once

Extend it to AI rather than starting again.

Ready to get certified?

Join 3,000+ organizations that trust Avantcert. Get a free, scoped quote today.