Chapter 3
03The Standards Map: From 27001 to 42001
“A standard does not create security, but it turns security into a habit that can be measured.”
Leaders face dozens of standards, frameworks and laws, all promising security and compliance. The practical question is: where do I start, and how do I avoid building parallel systems that exhaust the team? This chapter draws the map the book follows: two core standards, companion standards, and frameworks and legislation that intersect with them.


Text in this figure
ISO 27001:2022 · Information security management · ISO 42001:2023 · AI management system · Companion standards · 27002 · Control guidance · 27701 · Privacy · 23894 · AI risk · 42005 · Impact assessment · Intersecting frameworks and laws · NIST CSF · Cybersecurity · SOC 2 · Trust reports · NIST AI RMF · AI risk · EU AI Act · EU law · GDPR · PDPL · Data protection · A harmonized structure makes integrating both standards possible · Figure 4
ISO 27001: The Information Security Management System
ISO/IEC 27001 is the international standard for establishing, implementing, maintaining and continually improving an information security management system (ISMS). It does not impose particular tools; it requires a systematic approach: understand your context, assess your risks, choose your controls, measure your performance, and improve.
Its current 2022 edition arranges its reference controls in four themes (93 controls). It can be applied to any organisation: a creative agency, a software company, or a freelancer who wants to prove their seriousness to clients.
ISO 42001: The AI Management System
ISO/IEC 42001 was published in December 2023 as the first international standard for an AI management system (AIMS). It answers a question 27001 was not designed for: how do we develop, provide and use AI responsibly? It adds to the security questions those of impact on people, fairness, transparency, human oversight and the model life cycle.
Why They Fit Together
The two standards share the harmonized structure for management systems (formerly known as Annex SL): the same Clauses 4 to 10 in the same order. So the policy, leadership, risk register, internal audit and management review are built once and serve both. And AI systems are, in the end, information systems that depend on data, so there is no trustworthy AI without information security.
| ISO 27001:2022 | ISO 42001:2023 | |
|---|---|---|
| Central question | Is our information protected? | Is our AI responsible? |
| Risk focus | Confidentiality, integrity, availability | Also impact on individuals and society |
| Reference controls | 93 controls in 4 themes | 38 controls in 9 domains |
| Special assessment | Risk assessment | Risk assessment + system impact assessment |
Companion Standards and Intersecting Frameworks
- ISO 27002: Detailed guidance for implementing each control in 27001.
- ISO 27701: An extension for privacy information management on top of the ISMS.
- ISO 23894 and 42005: Guidance on AI risk management and AI system impact assessment.
- NIST CSF and SOC 2: Frameworks many clients require, especially in the US market, with controls that overlap 27001.
- Legislation: Data protection laws such as the EU GDPR and the UAE and Saudi PDPL, and the EU AI Act.
2026 Update
The transition period for ISO 27001:2013 certificates ended on 31 October 2025, so every valid certificate today is on the 2022 edition. A 2024 amendment added a requirement to consider climate change among context issues. And in 2025, ISO 42005 on impact assessment and ISO 42006 on requirements for 42001 certification bodies were published.
Start with one solid system, then add to it; do not build two parallel systems.
Lessons Learned
- 1ISO 27001 protects information, ISO 42001 governs AI, and the shared structure unites them.
- 2Standards do not impose tools but a systematic, risk-based approach.
- 3Companion standards and other frameworks are mapped onto the system, not built beside it.
- 4Certification on the 2022 edition is the only one recognised today.
Tip: use ← → to move between sections.

