CertAI
ISO 27001 + ISO 42001: why companies selling AI to enterprises will need both
D

Domenico Ruggiano

updated on

AI Governance

ISO 27001 + ISO 42001: why companies selling AI to enterprises will need both

There is a precise moment when an AI startup discovers what selling to large companies really means: when the first vendor questionnaire lands. Dozens of pages on information security, data handling, business continuity. And, increasingly often, a new section: how do you govern your artificial intelligence systems?

Until yesterday there was one expected answer: ISO/IEC 27001. Today a second one is emerging: ISO/IEC 42001. And for anyone developing or embedding AI in their products, the real question is no longer "which of the two" but "in which order".

In short
Enterprise procurement uses standards as a filter: without structured evidence, the deal stalls in security review.
ISO/IEC 27001 covers information security; ISO/IEC 42001 covers responsible AI management. For AI vendors, questionnaires are starting to ask for both.
The two standards share the same structure: roughly half of the controls are reusable. If you hold ISO 27001, you are already halfway to ISO 42001.
With the AI Act in its operational phase, ISO 42001 is also the most solid way to demonstrate the AI governance the regulation demands.

#The invisible filter of enterprise procurement

Large companies don't evaluate vendors on the product alone: they evaluate the risk that vendor introduces. The mechanism is standardised (vendor questionnaire, security review, certification requests) and works as a binary filter: those with structured evidence pass; those answering "we're working on it" end up at the back of the queue, or out.

For years this filter had a single name: ISO 27001. For a company handling enterprise customer data, it is effectively the entry ticket.

With the explosion of AI, though, the scope of the questions has widened. How do you manage model risks? How do you control bias and model drift over time? Who oversees automated decisions? What data do you train on? ISO 27001, on its own, does not answer these questions.

#Two standards, two different questions


ISO/IEC 27001

ISO/IEC 42001

Question it answers

"Are your data and systems secure?"

"Is your AI developed and used responsibly?"

Scope

Information security (confidentiality, integrity, availability)

AI management system: risks, transparency, human oversight

Typical controls

Access, encryption, incident response, suppliers, continuity

Impact assessment, bias, training data quality, model monitoring, responsible use

Who asks for it

Any enterprise customer

Enterprise customers of AI vendors, growing fast

Since

2005 (rev. 2022)

2023: the world's first certifiable AI management standard

ISO/IEC 42001 is the first standard that makes AI governance certifiable: it defines a management system (AIMS, AI Management System) with requirements on risk assessment, impact assessments, human oversight and continuous monitoring of AI systems. We cover it in detail in a dedicated article (see our ISO/IEC 42001 guide).

#The good news: the standards are built to work together

Anyone fearing they'll have to start over can breathe. ISO 42001 follows the same harmonised structure as every ISO management system (the same as 27001, 9001, 14001): context, leadership, planning, support, operation, performance evaluation, improvement. Identical chapters, identical logic.

In practice, this means:

  • policies, roles, document management, internal audits and management review are shared: a single governance framework supports both standards;
  • controls on access, supplier management, incident response and change management satisfy requirements of both;
  • field experience shows that roughly 50% of the work done for ISO 27001 is reusable for ISO 42001. The remaining 50% is genuinely AI-specific: bias assessment, model drift monitoring, impact assessments, training data quality.

Starting from ISO 42001 without an information security foundation, by contrast, is harder: an AI system feeds on data, and protecting that data is a prerequisite, not an option.

#The right sequence for an AI startup

  1. ISO 27001 first. It's what customers ask for today, in every industry. It unlocks enterprise deals now and builds the management framework everything else rests on. (see the CertAI service for ISO 27001)
  2. Then the extension to ISO 42001. With the management system in place, extending to AI controls is an incremental project, not a second mountain to climb. And it arrives just as questionnaires start asking for it.
  3. Meanwhile, cover your AI Act obligations. Transparency and AI literacy are already binding; high-risk obligations arrive between late 2027 and 2028 (see our AI Act deadlines guide). An AIMS aligned with ISO 42001 is the most natural way to produce the evidence the regulation requires.

The competitive advantage lies in timing: today ISO 42001 is still a differentiator, and presenting it in a vendor questionnaire sets you apart. In a couple of years it will be, like ISO 27001, simply expected.

#The cost of not having them

The maths is quick: an enterprise sales cycle stuck in security review is often worth tens of thousands of euros in ARR. A poorly answered questionnaire stretches the cycle by months. And building compliance under pressure, with a deal hanging, always costs more than building it methodically.

Compliance is not a documentation project: it is a management system to be designed, adopted and maintained. But with the right approach, with AI generating and maintaining the documentation, the timeline is measured in weeks, not years.

#How CertAI helps

CertAI takes companies to ISO/IEC 27001 and ISO/IEC 42001 compliance with a guided path: initial gap analysis, documentation generated and tailored by our AI systems, continuous controls and monitoring, and preparation for the certification audit with independent third-party bodies.

Want to unlock enterprise deals without hiring a compliance team? CertAI takes you to ISO 27001 and ISO 42001 compliance.

Book a demo

Last updated: July 2026.