Integrating ISO 27001 and ISO 42001: One ISMS and AIMS Governance System
Implement ISO 27001 and ISO 42001 together: shared processes, distinct specialist logic, scope, risks, audits and management review.
ISO 27001 and ISO 42001 can be designed as an integrated management system because both use recurring elements such as context, leadership, objectives, documented information, internal audit, management review and improvement. Specialist logic must remain distinct: information-security risks and AI impacts require their own criteria, expertise and evidence.
What can be shared
| Shared process | Integrated approach |
|---|---|
| Context and interested parties | One coordinated register with security- and AI-specific requirements |
| Document control | Common approval, versioning, retention and access protection |
| Competence | One training process with role-specific modules |
| Suppliers | One due-diligence workflow with security and AI-governance questions |
| Internal audit | One programme with competent criteria for each standard |
| Management review | One meeting with separate performance and risk blocks |
| Corrective action | One workflow for causes, actions, owners and effectiveness checks |
What should remain distinct
- ISMS and AIMS scope must each be explicit
- Information-security risk and AI-impact criteria should not be collapsed
- The security SoA and AI-specific control selection need their own traceability
- Security evidence and AI-lifecycle evidence have different technical content
- Privacy, NIS2 and EU AI Act duties need separate mappings
A practical integrated programme
- Inventory existing management processes and maturity
- Define scopes, interfaces and shared governance
- Design shared processes once
- Add specialist risk and control processes
- Connect the AI inventory with information assets
- Plan a combined audit programme and management review
- Coordinate certification strategy with independent bodies
The real benefit
The benefit is less about a promised percentage saving and more about consistent decisions and reduced duplicate maintenance. A supplier, nonconformity or training need follows one workflow while specialist requirements remain visible.
Integration is particularly useful when a functioning ISMS already exists. An immature system should not be overloaded with additional standards before ownership, routines and evidence are stable.
How Sternberg Consulting supports you
We structure AI inventory, risks, roles, evidence and internal review into a pragmatic AIMS. Learn more about ISO 42001 consulting and ISO 27001 consulting.
Frequently asked questions
Do we need two certificates?
If both standards are certified, conformity to each is confirmed. Audit planning and processes may still be integrated.
Can the ISMS risk register be reused for AI?
The platform can be shared, but criteria and impact perspectives must be extended for AI.
Which standard should come first?
It depends on customer, risk and regulatory pressure. Where security governance already exists, ISO 27001 is often a stable foundation.