Why You Are Further Along Than You Think
ISO 27001 and ISO 42001 both use the Annex SL harmonized structure. That is not a technicality — it means clauses 4 through 10, the entire management system scaffolding, is common to both standards. Context, leadership, planning, support, operation, performance evaluation, improvement.
If you hold ISO 27001, you have already built and been audited on all of it. You have a working internal audit programme, a management review that actually happens, a documented risk methodology, and document control that survived a Stage 2.
What you are adding is AI-specific content on top of a system that already exists. That is a materially different project from building a management system from nothing, and it is why organizations with an ISMS reach ISO 42001 far faster.
What Transfers
| Element | Transfers? | What changes |
|---|---|---|
| Clauses 4–10 | Largely | Extend scope statement to cover AI systems |
| Internal audit programme | Yes | Add AI scope to the audit plan |
| Management review | Yes | Add AI performance and impact inputs |
| Risk methodology | Yes | Reused, but impact assessment is additional |
| Competence and awareness | Yes | Extend training to AI-specific roles |
| Document control | Yes | No change |
| Supplier management | Largely | Extend to AI providers and model vendors |
| Incident management | Largely | Add AI-specific incident types |
The pattern: everything that makes a management system a management system carries over. See ISO 27001 Annex A controls for what you already have.
What Is Genuinely New
Three things, and one of them has no ISO 27001 equivalent at all.
The AI impact assessment
This is the new one. ISO 42001 requires assessing the consequences of your AI systems for individuals, groups and society — not just risk to the organization.
The distinction matters and it takes teams a while to internalise. Your ISO 27001 risk assessment asks what could harm the business. An AI impact assessment asks what the system could do to the people it affects: who is subject to its decisions, what happens when it is wrong, whether outcomes could be unfair or biased, what human oversight exists, and how someone contests a result.
It is also the part that most resembles what regulators want, which is why it carries value beyond the certificate.
AI system life cycle controls
Annex A area A.6 covers objectives, design, verification and validation, deployment, operation and monitoring of AI systems. If you build models, this is substantial work. If you consume vendor APIs, it is lighter but not absent — you still own intended purpose, monitoring and human oversight.
Data for AI systems
Area A.7 covers acquisition, quality, provenance and preparation of data used in AI. Organizations that never tracked where training data came from find this the hardest area to retrofit, and it is not something that can be assembled quickly under audit pressure.
One Management System, Two Certificates
The efficient structure is a single integrated management system covering both scopes, not two parallel systems that happen to share a company.
What integration gives you: one set of clause 4–10 documentation, one internal audit programme covering both scopes, one management review, one document control system, and — where your certification body is accredited for both — a combined audit that shares the management system clauses and reduces total audit days against two separate visits.
It also aligns the surveillance schedule, so ongoing upkeep is one annual cycle rather than two that drift apart.
What stays separate: two Statements of Applicability, two scope statements, and two certificates. The standards remain distinct even when the system is one.
What the Extension Costs
| Starting point | Typical timeline | Relative effort |
|---|---|---|
| ISO 27001 certified | 3–6 months | Extension — lowest |
| ISO 27001 in progress | 4–8 months | Run them together |
| Neither | 6–12 months | Building both — highest |
Market ranges for ISO 42001 run $3,000–$15,000 for readiness, $10,000–$50,000 for implementation, and $7,000–$20,000 for the certification audit. An ISO 27001-certified organization extending its system sits near the bottom of those; the ranges reflect an average that includes companies building from nothing. Full breakdown in ISO 42001 certification cost.
Those are market ranges, not Avantcert prices — ISO 42001 is scoped per engagement because AI estates vary far more than headcounts do.
Get a Scoped Extension Quote
Tell us your current ISO 27001 scope and what AI systems you run. Scoped estimate within 24 hours.
Our form could not load. Email your ISMS scope and AI systems and you'll get the same estimate within 24 hours.
Email your requirements Open the full quote formIf You Hold Neither
Do them together rather than sequentially. Building the management system once and certifying two scopes against it is meaningfully cheaper than an ISO 27001 project followed a year later by an ISO 42001 project that rebuilds half of it.
If you must choose one first, ISO 27001 is usually the right starting point: it is the certificate more customers currently ask for, it is the lower-cost programme, and it creates the scaffolding ISO 42001 then extends. An Avantcert ISO 27001 engagement starts at $4,000 for a 5–50 employee company.
The exception is an organization whose product is AI and whose buyers are already asking about governance. There, ISO 42001 is the certificate that unblocks deals, and ISO 27001 follows.
FAQs
Can I extend my ISO 27001 certification to ISO 42001?
You cannot extend the certificate itself — they are separate standards with separate certificates. What you extend is the management system underneath. Because both use the Annex SL structure, clauses 4 to 10 are largely shared, so you are adding AI-specific scope and controls to a system that already exists rather than building a second one.
What transfers from ISO 27001 to ISO 42001?
The management system clauses 4 to 10, your internal audit programme, the management review cadence, the documented risk methodology, competence and awareness processes, document control, and much of supplier management. What does not transfer is the AI-specific content: impact assessments, AI system life cycle controls, and AI data provenance requirements.
What is the AI impact assessment and why is it new?
ISO 42001 requires assessing the consequences of AI systems for individuals, groups and society — not only risk to the organization. ISO 27001 has no equivalent. A conventional risk assessment asks what could harm the business; an AI impact assessment asks what the system could do to the people it affects, and it is the requirement that most resembles what regulators are asking for.
Can ISO 27001 and ISO 42001 be audited together?
Yes, where your certification body is accredited for both. A combined audit shares the management system clauses across the two scopes and reduces total audit days compared with two separate visits. It also aligns your surveillance schedule, so upkeep happens once a year rather than twice.
How long does adding ISO 42001 to ISO 27001 take?
Typically three to six months for an organization already certified to ISO 27001, against six to twelve when starting with no management system. The variable is AI estate rather than headcount: the AI system inventory and the impact assessments are the work, and both scale with how many models you run and whether you built them.
Related Reading
See ISO 42001 certification services, the 38 Annex A controls, ISO 27001 consulting, or how ISO 42001 relates to the EU AI Act.
Official references: ISO/IEC 27001, ISO/IEC 42001:2023.
You built the system once
Extend it to AI rather than starting again.