Chapter 28
28The Integrated System and a Case Study
“One system governing information and AI together is stronger than two systems competing for the team’s time.”
We have reached the full picture. ISO 27001 and ISO 42001 share the harmonized structure for management systems, so Clauses 4 to 10 are the same in their titles and order. This enables an integrated management system (IMS) that is built once and serves both standards, with what is specific to each added on top.


Text in this figure
Information security · 93 controls · CIA triad · Business continuity · AI governance · 38 controls · Impact assessment · Model life cycle · Clauses 4–10 · Policy, leadership · Risk register · Internal audit · Management review · Improvement · ISO 27001 · ISO 42001 · The shared space is built once and serves both standards · Figure 35
What Is Built Once?
- Context and scope: A single study covering security and AI, and the interested parties of both.
- Leadership and policies: One top-level policy, from which the security policy and the AI policy branch.
- Risk register: One register with a column identifying the standard, as in the appendix template.
- Documentation, competence and awareness: One documentation system and one training programme with modules for both standards.
- Audit and management review: A joint audit programme and a single management review.
- Improvement: One log of nonconformities and corrective actions.
And What Stays Specific?
For 27001: its ninety-three controls and their Statement of Applicability, and its focus on confidentiality, integrity and availability. For 42001: its thirty-eight controls, the system impact assessment, the AI system register, and the ethical questions of fairness, transparency and human oversight.
Case Study: Implementing ISO 27001 in a Creative Agency
The company
A medium-sized creative agency specialising in digital marketing and brand design, serving clients from start-ups to multinationals.
The challenges
- Protecting client data: A large volume of sensitive data: marketing plans, customer lists and financial information.
- Securing intellectual property: Its creative concepts, designs and proprietary methodologies were valuable assets in need of protection.
- Managing a distributed workforce: A large number of remote workers and freelancers made access control and data security difficult.
- Client expectations: Growing demands to demonstrate a commitment to information security.
The solution
The agency decided to build an information security management system based on ISO 27001:2022, through the following steps:
- Management buy-in: A clear business case highlighting improved security, enhanced client trust and competitive advantage.
- Defining the scope: All processes and assets involved in delivering the agency’s services.
- Risk assessment: A comprehensive assessment of the main risks to information assets, then analysis of their likelihood and impact.
- Treatment plan: A set of controls including access control, encryption and staff training.
- Implementing controls: Over several months, through a mix of technical changes such as a new access control system and procedural ones such as a new clean desk policy.
- Internal audit: Regular audits to ensure effective implementation and identify areas for improvement.
- Certification: Success in a formal audit by an accredited certification body.
The results
- Improved security: A significant improvement in security posture and a drop in the number of incidents.
- Client trust: Demonstrating its commitment to information security helped build trust and win new business.
- Competitive advantage: Certification became a key differentiator in the market.
- Operational efficiency: Streamlined processes and better overall efficiency.
The next step: from 27001 to the integrated system
Two years later, the agency began building chat assistants for its clients and using generative tools in every campaign, and a major client asked it to demonstrate AI governance. It did not start from scratch: it extended the context and scope to cover AI systems, added an AI policy and appointed a committee for it, created a register of its systems, carried out impact assessments for public-facing assistants, added AI risks to the same register, and merged the audits into one programme.
The figures here illustrate a pattern of results: the extension took less than half the effort of the first certification.
Awakening security begins with protecting information, matures with governing AI, and is complete when the two become one system.
Lessons Learned
- 1The harmonized structure enables an integrated system for both standards.
- 2Context, policy, risks and audit are built once.
- 3Each standard keeps its controls, and 42001 adds impact assessment and the system register.
- 427001 certification shortcuts half the way to 42001.
Tip: use ← → to move between sections.

