Guide · Standards

ISO 27001 vs ISO 42001: what's the difference?

The short version: ISO 27001 is about protecting information; ISO 42001 is about governing artificial intelligence. They're separate standards with separate scopes, but they're built on the same management-system skeleton — so if you already run one, most of the machinery for the other is already familiar. Here's what each covers, where they meet, and when you need which.

ISO 27001 in one paragraph

ISO/IEC 27001 is the international standard for an information security management system (ISMS). It's about keeping information confidential, available and intact — through risk assessment, a set of security controls, and the processes to keep them running. It's mature, widely recognised, and increasingly a procurement requirement: customers ask for it before they trust you with their data. If your question is "can we be trusted to handle information securely?", that's 27001.

ISO 42001 in one paragraph

ISO/IEC 42001 is the first international standard for an AI management system (AIMS), published in December 2023. It's about governing how an organisation develops, deploys or uses artificial intelligence responsibly — managing risks specific to AI such as bias, transparency, human oversight, data quality and unintended outcomes. If your question is "can we show we use AI responsibly and under control?", that's 42001.

Side by side

Where they overlap

This is the part that saves you work. Both standards are written to the same ISO "harmonised structure" — the same numbered clauses for context, leadership, planning, support, operation, performance evaluation and improvement. In practice that means they share the same core machinery:

If you already operate an ISMS, you don't rebuild all of that for AI — you extend it. The risk process, the audit programme, the management review and the improvement loop can serve both, with AI-specific risks and controls layered on top. Run separately, the two standards duplicate a lot of effort; run as one integrated management system, they share it.

Do you need both? Not necessarily. Choose 27001 if handling information securely is the trust question your customers ask. Add 42001 if you build, deploy or rely on AI and need to show it's governed. Many organisations start with 27001 and adopt 42001 as their AI use grows — and because the two share a backbone, the second is far less work than the first.

Which should you start with?

For most organisations the honest answer is 27001 first, for one reason: demand. Information security certification is already a common condition of doing business, so it usually pays back fastest. ISO 42001 then becomes the natural next step once AI is genuinely part of how you operate — and the moment to move early rather than late is when AI starts touching customer data or decisions, because that's when the governance questions arrive.

How Kavorly runs both

Kavorly is built to run ISO management systems as living systems rather than annual document exercises, and it treats the shared backbone as shared: one risk register, one audit programme, one management review cycle, with the controls for 27001, 42001 and other standards layered on the same foundation. For the information-security side it also reads your Microsoft 365 estate to collect much of the audit evidence automatically — so running a second or third standard adds far less overhead than starting from scratch each time.

See how Kavorly runs ISO 42001 →


This guide is a general introduction, not certification advice or a substitute for the standards themselves. For the authoritative requirements, refer to the published text of ISO/IEC 27001 and ISO/IEC 42001 or speak to a certification body.

Next step

Run one standard, or several, on one platform.

Check your readiness free, or see how much evidence Kavorly can pull from your own Microsoft 365.