Skip to main content
Services
Audit & Certification
ISO Gap AnalysisInternal AuditAudit PreparationAfter the AuditClose Nonconformities
Standards
ISO 9001 Quality ManagementISO 9001:2026 TransitionISO 14001 Environmental ManagementISO 45001 Occupational Health & SafetyISO 27001 Information SecurityISO 42001 AI ManagementISO 13485 Medical Devices
Industries & Support
Industry SolutionsMedical DevicesMechanical Engineering & ProductionIT, SaaS & AIManagement System MaintenanceExternal QMRQM Training
Industries
All IndustriesMechanical Engineering & ProductionAutomotive SuppliersLaser Optics, Photonics & SemiconductorsIndustrial Service ProvidersMedical DevicesIT, SaaS & AI
FundingFAQKnowledgeAboutContactSend emailCall now
DE/EN
Free Consultation
ISO 42001, AI & CompliancePublished: 10 July 2026

Integrating ISO 27001 and ISO 42001: One ISMS and AIMS Governance System

Implement ISO 27001 and ISO 42001 together: shared processes, distinct specialist logic, scope, risks, audits and management review.

ISO 27001 and ISO 42001 can be designed as an integrated management system because both use recurring elements such as context, leadership, objectives, documented information, internal audit, management review and improvement. Specialist logic must remain distinct: information-security risks and AI impacts require their own criteria, expertise and evidence.

What can be shared

Table 1: Integrating ISO 27001 and ISO 42001: One ISMS and AIMS Governance System
Shared processIntegrated approach
Context and interested partiesOne coordinated register with security- and AI-specific requirements
Document controlCommon approval, versioning, retention and access protection
CompetenceOne training process with role-specific modules
SuppliersOne due-diligence workflow with security and AI-governance questions
Internal auditOne programme with competent criteria for each standard
Management reviewOne meeting with separate performance and risk blocks
Corrective actionOne workflow for causes, actions, owners and effectiveness checks

What should remain distinct

  • ISMS and AIMS scope must each be explicit
  • Information-security risk and AI-impact criteria should not be collapsed
  • The security SoA and AI-specific control selection need their own traceability
  • Security evidence and AI-lifecycle evidence have different technical content
  • Privacy, NIS2 and EU AI Act duties need separate mappings

A practical integrated programme

  1. Inventory existing management processes and maturity
  2. Define scopes, interfaces and shared governance
  3. Design shared processes once
  4. Add specialist risk and control processes
  5. Connect the AI inventory with information assets
  6. Plan a combined audit programme and management review
  7. Coordinate certification strategy with independent bodies

The real benefit

The benefit is less about a promised percentage saving and more about consistent decisions and reduced duplicate maintenance. A supplier, nonconformity or training need follows one workflow while specialist requirements remain visible.

Integration is particularly useful when a functioning ISMS already exists. An immature system should not be overloaded with additional standards before ownership, routines and evidence are stable.

How Sternberg Consulting supports you

We structure AI inventory, risks, roles, evidence and internal review into a pragmatic AIMS. Learn more about ISO 42001 consulting and ISO 27001 consulting.

Discuss your project

Frequently asked questions

Do we need two certificates?

If both standards are certified, conformity to each is confirmed. Audit planning and processes may still be integrated.

Can the ISMS risk register be reused for AI?

The platform can be shared, but criteria and impact perspectives must be extended for AI.

Which standard should come first?

It depends on customer, risk and regulatory pressure. Where security governance already exists, ISO 27001 is often a stable foundation.

Sources and further guidance

Next step

Let's talk.

Tell me where you stand and what you need.

Within 24 hours you receive a first assessment and a concrete meeting proposal — free and without commitment.

  • Reply within 24 hours
  • Personal assessment of your project
  • Funding eligibility checked on request

By submitting you agree to the processing of your details for answering your enquiry.