Already have ISO 27001? Here is how much of ISO 42001 you already hold
Most companies look at the ISO 42001 documentation list and see eleven new documents. If you already run an information security management system, that is not what you are looking at.
The short answer
Both standards follow the harmonised structure that ISO applies across its management system standards. The clauses line up. Scope is still clause 4.3, policy is still 5.2, objectives are still 6.2, internal audit is still 9.2. What changes is the subject matter, not the shape.
What extends, and what is genuinely new
| ISO 42001 document | If you hold ISO 27001 |
|---|---|
| AIMS scope statement | Extends your ISMS scope. Same structure, widened to name which AI systems and business units are covered. |
| AI policy | Sits alongside your information security policy. Same approval and communication route you already run. |
| AI objectives | Extends your existing objectives framework. You already know how to write and measure these. |
| Roles and responsibilities | Extends your existing accountability model. Usually the same people, with AI added to their remit. |
| Risk assessment methodology | Extends your ISMS risk method. The method is familiar, the risk categories are not. |
| Risk treatment plan | Same format, new entries. |
| Statement of Applicability | You have written one before. This one covers ISO 42001 Annex A instead. |
| Internal audit programme | Extends the programme you already run. Add AI to the scope and the schedule. |
| AI system inventory | Mostly new. Your asset register may list some AI tools, but rarely with the detail needed, and almost never covering tools individual staff adopted themselves. |
| AI impact assessment process | Genuinely new. This is the real gap. See below. |
| Operational procedures for AI | Partly new. Human oversight of AI output has no direct equivalent in an ISMS. |
The one that catches ISO 27001 holders out
An ISMS risk assessment is oriented around the organisation: confidentiality, integrity and availability of your information. An AI impact assessment is oriented around the people your AI affects. Whether a decision is fair, whether someone can contest it, whether the system performs differently for different groups.
Teams who are fluent in security risk often fill this in with security thinking and produce something that reads well and misses the point entirely. If you take one thing from this page, take that.
Where human oversight differs from access control
Your ISMS is full of controls that decide who may do what. AI operational procedures need something your ISMS does not contain: a defined point where a person checks whether the output is actually right before it is relied on.
That is not access control and it is not change management. It is a new kind of control, and it is the one that actually prevents an AI mistake from becoming an incident.
What this means in practice
An organisation starting from nothing is writing eleven documents. An organisation with a working ISMS is extending seven, writing two from scratch, and adding a genuinely new kind of control to a third.
That is a materially different piece of work, and it is worth knowing before you decide it is too big to start.
See exactly where you stand
The check asks which certifications you hold and tells you which documents extend what you already have. Three minutes, result on screen.
Start the check