AI Governance Gap Check

Already have ISO 27001? Here is how much of ISO 42001 you already hold

Most companies look at the ISO 42001 documentation list and see 11 new documents. If you already run an information security management system, that is not what you are looking at.

The short answer

ISO 42001 uses the same management system structure as ISO 27001, so 7 of its expected documents extend ones your ISMS already maintains rather than starting from nothing.

Both standards follow the harmonised structure that ISO applies across its management system standards. The clauses line up. Scope is still clause 4.3, policy is still 5.2, objectives are still 6.2, internal audit is still 9.2. What changes is the subject matter, not the shape.

What extends, and what is genuinely new

Of the 11 documents ISO 42001 expects, 7 extend ones an ISO 27001 system already maintains. The 4 that do not are the AI policy, the AI system inventory, the impact assessment process, and operational procedures for AI.
ISO 42001 documentIf you hold ISO 27001
AIMS scope statementExtends your ISMS scope. Same structure, widened to name which AI systems and business units are covered.
AI policyNew document. It sits alongside your information security policy and goes through the same approval and communication route you already run, so the process is familiar even though the document is not.
AI objectivesExtends your existing objectives framework. You already know how to write and measure these.
Roles and responsibilitiesExtends your existing accountability model. Usually the same people, with AI added to their remit.
Risk assessment methodologyExtends your ISMS risk method. The method is familiar, the risk categories are not.
Risk treatment planSame format, new entries.
Statement of ApplicabilityYou have written one before. This one covers ISO 42001 Annex A instead.
Internal audit programmeExtends the programme you already run. Add AI to the scope and the schedule.
AI system inventoryMostly new. Your asset register may list some AI tools, but rarely with the detail needed, and almost never covering tools individual staff adopted themselves.
AI impact assessment processGenuinely new. This is the real gap, and the section after this table is about it.
Operational procedures for AIPartly new. Human oversight of AI output has no direct equivalent in an ISMS.

The one that catches ISO 27001 holders out

Information security risk asks what it costs you if something goes wrong. AI impact assessment asks what it costs the person on the other side.

An ISMS risk assessment is oriented around the organisation: confidentiality, integrity and availability of your information. An AI impact assessment is oriented around the people your AI affects. Whether a decision is fair, whether someone can contest it, whether the system performs differently for different groups.

Teams who are fluent in security risk often fill this in with security thinking and produce something that reads well and misses the point entirely. That single swap is the most common way an otherwise strong ISMS produces a weak impact assessment.

Where human oversight differs from access control

Your ISMS is full of controls that decide who may do what. AI operational procedures need something your ISMS does not contain: a defined point where a person checks whether the output is actually right before it is relied on.

Checking AI output is a new kind of control, different from access control and from change management, and it is what stops an AI mistake becoming an incident.

What this means in practice

A company starting from nothing writes 11 documents. A company with a working ISO 27001 system extends 7 and writes 4, and one of those 4 needs a kind of control an ISMS does not contain.

Extending 7 documents is a materially different piece of work from writing 11, and worth knowing before you decide the job is too big to start.

See exactly where you stand

The check asks which certifications you hold and tells you which documents extend what you already have, in about 3 minutes, with the result on screen.

Start the 3-minute check