Awakening Security

Request the PDF

Enter your email and we will send you a code; your request is then recorded at once, and once I have reviewed it a link to download your copy reaches your email.

By continuing, your email and progress are kept in your account. Privacy

* The file is for your own reading; sharing follows the terms of use, and commercial use is not permitted.

Reading progress
0 of 34 sections read
5 / 34

Chapter 3

03The Standards Map: From 27001 to 42001

2 min read5 of 34Read it in the book · page 22

“A standard does not create security, but it turns security into a habit that can be measured.”

Leaders face dozens of standards, frameworks and laws, all promising security and compliance. The practical question is: where do I start, and how do I avoid building parallel systems that exhaust the team? This chapter draws the map the book follows: two core standards, companion standards, and frameworks and legislation that intersect with them.

The standards map: from information security to AI governanceThe standards map: from information security to AI governance
The standards map: from information security to AI governance
Text in this figure

ISO 27001:2022 · Information security management · ISO 42001:2023 · AI management system · Companion standards · 27002 · Control guidance · 27701 · Privacy · 23894 · AI risk · 42005 · Impact assessment · Intersecting frameworks and laws · NIST CSF · Cybersecurity · SOC 2 · Trust reports · NIST AI RMF · AI risk · EU AI Act · EU law · GDPR · PDPL · Data protection · A harmonized structure makes integrating both standards possible · Figure 4

ISO 27001: The Information Security Management System

ISO/IEC 27001 is the international standard for establishing, implementing, maintaining and continually improving an information security management system (ISMS). It does not impose particular tools; it requires a systematic approach: understand your context, assess your risks, choose your controls, measure your performance, and improve.

Its current 2022 edition arranges its reference controls in four themes (93 controls). It can be applied to any organisation: a creative agency, a software company, or a freelancer who wants to prove their seriousness to clients.

ISO 42001: The AI Management System

ISO/IEC 42001 was published in December 2023 as the first international standard for an AI management system (AIMS). It answers a question 27001 was not designed for: how do we develop, provide and use AI responsibly? It adds to the security questions those of impact on people, fairness, transparency, human oversight and the model life cycle.

Why They Fit Together

The two standards share the harmonized structure for management systems (formerly known as Annex SL): the same Clauses 4 to 10 in the same order. So the policy, leadership, risk register, internal audit and management review are built once and serve both. And AI systems are, in the end, information systems that depend on data, so there is no trustworthy AI without information security.

ISO 27001:2022ISO 42001:2023
Central questionIs our information protected?Is our AI responsible?
Risk focusConfidentiality, integrity, availabilityAlso impact on individuals and society
Reference controls93 controls in 4 themes38 controls in 9 domains
Special assessmentRisk assessmentRisk assessment + system impact assessment

Companion Standards and Intersecting Frameworks

  • ISO 27002: Detailed guidance for implementing each control in 27001.
  • ISO 27701: An extension for privacy information management on top of the ISMS.
  • ISO 23894 and 42005: Guidance on AI risk management and AI system impact assessment.
  • NIST CSF and SOC 2: Frameworks many clients require, especially in the US market, with controls that overlap 27001.
  • Legislation: Data protection laws such as the EU GDPR and the UAE and Saudi PDPL, and the EU AI Act.

2026 Update

The transition period for ISO 27001:2013 certificates ended on 31 October 2025, so every valid certificate today is on the 2022 edition. A 2024 amendment added a requirement to consider climate change among context issues. And in 2025, ISO 42005 on impact assessment and ISO 42006 on requirements for 42001 certification bodies were published.

Start with one solid system, then add to it; do not build two parallel systems.

Lessons Learned

  1. 1ISO 27001 protects information, ISO 42001 governs AI, and the shared structure unites them.
  2. 2Standards do not impose tools but a systematic, risk-based approach.
  3. 3Companion standards and other frameworks are mapped onto the system, not built beside it.
  4. 4Certification on the 2022 edition is the only one recognised today.

Tip: use ← → to move between sections.