Suppose a mid-sized organisation that spent the better part of two years getting its Information Security Management System into shape. Policies were rewritten, risk registers updated, staff trained, and eventually, ISO/IEC 27001 certification was awarded. It was a genuine milestone, and for a while, information security felt like a settled matter.
Then AI started creeping into daily work. Customer service began leaning on chatbots. HR started using AI tools to screen CVs. Developers were experimenting with AI-assisted coding. None of this necessarily put information at risk in the way ISO/IEC 27001 was built to address, but it raised a different set of questions. Can anyone explain how the AI reached a particular decision? Who is accountable when an AI-generated output turns out to be wrong? Is anyone actually monitoring how these tools are used across the business? Increasingly, customers and regulators are asking the same things.
This is where it becomes clear that protecting information and governing AI are related, but not identical, challenges.
Why ISO/IEC 27001 Alone Is No Longer Enough
ISO/IEC 27001 does an excellent job of protecting the confidentiality, integrity and availability of information. That hasn’t changed, and organisations shouldn’t treat it as outdated. But AI systems introduce risks that sit outside what an ISMS was ever designed to catch. A model can be biased in ways that have nothing to do with a data breach. It can behave like a black box, making decisions no one can fully explain. It can be trained on poor quality data, used without any real oversight, or raise ethical questions that a security control was never built to answer. ISO/IEC 27001 remains essential. It simply wasn’t written with AI governance in mind.
How ISO/IEC 42001 Builds on Your Existing ISMS
The good news for organisations already certified to ISO/IEC 27001 is that most of the groundwork is already in place. Risk management processes, internal audits, management reviews, continual improvement cycles, documented procedures, leadership buy in all of it transfers across. ISO/IEC 42001 isn’t asking teams to start from zero or compete with what they’ve already built.
What it adds is a structured way to govern AI specifically: how systems are developed and deployed responsibly, how they’re managed across their lifecycle, how transparency is maintained, where human oversight sits, and how AI-related risks get assessed rather than assumed. Rather than a rival standard, it’s better understood as the next layer on a foundation that’s already been laid. Many of the habits an ISO/IEC 27001 certified organisation already has documenting decisions, reviewing risk regularly, assigning clear ownership are exactly the habits ISO/IEC 42001 asks for, just pointed at a new kind of risk.
What Certification Demonstrates
It’s tempting to think of certification as a list of controls to tick off, but the real value is what it signals. ISO/IEC 42001 certification shows that an organisation manages AI deliberately rather than reactively, that governance decisions are documented rather than informal, and that there’s a structure in place to catch problems before they become serious ones.
That matters more each year, because stakeholders are no longer satisfied with a verbal assurance that “we take AI seriously.” Customers, regulators and business partners increasingly want to see evidence of responsible practice, not just hear about it. Certification, backed by independent assessment, gives them something concrete to point to. It also tends to make internal conversations easier, when governance is documented, teams spend less time debating who owns what and more time actually managing risk.
Is Your Organisation Ready?
Rather than a checklist, it’s worth sitting with a few honest questions. Does anyone in the business have a clear picture of where AI is actually being used, beyond the obvious tools? Have the risks tied to those use cases been properly assessed, or just assumed to be low? Is there a named person responsible for AI oversight, or does it fall into a gap between IT, legal and operations? For decisions that genuinely matter hiring, credit, safety is there a human actually reviewing the outcome? And is any of this written down anywhere, or does it live mostly in people’s heads?
If several of those questions are hard to answer, that’s not a failure. It’s simply a sign of where the next stage of work lies.
AI adoption isn’t slowing down, and most organisations are further along than their formal governance suggests. Many already have a strong information security foundation through ISO/IEC 27001. The next step is making sure AI is governed with the same discipline not through good intentions alone, but through a structured management system that can be reviewed, audited and improved over time. ISO/IEC 42001 gives organisations a way to demonstrate that commitment clearly, rather than simply asserting it.
“As AI adoption continues, independent certification offers a way to confirm that governance practices aren’t just written down, but consistently applied in practice. Working with an experienced, accredited certification body gives organisations a credible way to demonstrate their commitment to responsible AI to customers, partners and regulators alike.”