ISO 27001 vs ISO 42001: What AI companies actually need
By Joe Zhou ยท
Every week, I get the same question from founders and CTOs: "We're building AI. Do we need ISO 27001 or ISO 42001?"
Most consultants answer: "Both!"
And technically, they're right. But when you're staring down a $150K compliance bill and a board asking why certification is taking six months, "both" isn't helpful advice.
The real answer depends on three things: what you're building, who you're selling to, and where you're selling. Let me break it down.
The quick distinction
ISO 27001 is about information security: protecting data from breaches, ensuring confidentiality, integrity, and availability. It's been around since 2005 and is table stakes for enterprise sales.
ISO 42001 is the new kid, published in December 2023. It's specifically about AI governance: how you develop, deploy, and manage AI systems responsibly. Think bias testing, explainability, human oversight, and lifecycle management.
Here's the thing: ISO 42001 doesn't replace ISO 27001. They cover different ground. The question isn't which one. It's which one first, and whether you need both now.
Scenario 1: you're building SaaS with AI features
Example: A CRM that uses AI for lead scoring, or a marketing platform with AI-generated content suggestions.
What you need:
ISO 27001 is mandatory. Your customers require this. It protects their data. Without it, you won't pass procurement.
ISO 42001 is increasingly required. While not legally mandated, major enterprise buyers are adding ISO 42001 to vendor requirements. Microsoft's SSPA program now includes ISO 42001 requirements. For AI-enabled SaaS targeting enterprise markets, plan for ISO 42001 as part of your 12-18 month roadmap.
Important distinction: For minimal-risk AI use cases like content recommendations and marketing lead scoring, ISO 42001 helps with differentiation. However, if your AI touches credit scoring or financial assessments, that's classified as high-risk under EU AI Act Annex III. Different story entirely.
My recommendation: Start with ISO 27001. Budget 4-6 months and $35-50K. Build ISO 42001 into your roadmap for months 12-18, sooner if you're seeing it in RFPs.
Scenario 2: you're building AI for healthcare
Example: AI analyzing medical images, clinical decision support, patient risk stratification.
What you need:
ISO 27001 is mandatory. Protects patient data. Hospital procurement won't talk to you without it.
ISO 42001 is strongly recommended. You're building high-risk AI. Clinical decision support is explicitly listed in EU AI Act Annex III as high-risk. Medical directors and procurement teams are increasingly asking about AI governance frameworks.
ISO 13485 is mandatory for medical devices. If you're Class IIb or III, this is non-negotiable.
A note on TGA: The TGA regulates AI medical devices through its standard medical device framework, requiring registration on the Australian Register of Therapeutic Goods (ARTG). While ISO 42001 isn't explicitly required by TGA, demonstrating robust AI governance frameworks helps satisfy their evidence requirements for safety and performance.
My recommendation: Plan for all three. Budget $120-150K total and 9-12 months. The good news: there's significant overlap between standards, so a combined approach saves time and money versus doing them sequentially.
Scenario 3: you're building AI for energy or utilities
Example: AI for grid optimisation, predictive maintenance, demand forecasting.
What you need:
ISO 27001 is mandatory. Critical infrastructure means heightened security requirements. Utilities won't engage without it.
ISO 42001 is effectively mandatory for EU markets. Energy AI for grid management falls under critical infrastructure in EU AI Act Annex III, classifying it as high-risk. Even for Australian-only operations, demonstrating AI governance opens doors and de-risks procurement decisions.
My recommendation: Lead with ISO 27001, but build your ISO 42001 roadmap now. Energy sector procurement cycles are long. Having both certifications when you enter the tender process beats scrambling to add them later.
Scenario 4: you're using third-party AI tools
Example: A consultancy using ChatGPT for report drafting, or a healthcare org using AI transcription.
What you need:
ISO 27001 depends on your situation. If you're handling sensitive data (patient records, financial information), yes. For general business use, it's optional but increasingly expected.
ISO 42001 is not needed yet. You're using AI, not building it. Your vendor (OpenAI, Microsoft, Google) should have their own governance. Focus on vendor risk assessment instead.
My recommendation: Get ISO 27001 if you're handling sensitive data. Build a solid vendor due diligence framework for your AI tools. Save ISO 42001 budget for when you start building your own AI capabilities.
The decision tree
Here's how to think through it:
Start here: do you build AI or use AI?
If you build AI: Is it high-risk? (Healthcare, finance, safety-critical, critical infrastructure, EU AI Act Annex III categories)
If yes: ISO 27001 + ISO 42001 + any domain-specific standards (ISO 13485 for medical, etc.)
If no: ISO 27001 now. ISO 42001 within 12-18 months as enterprise procurement increasingly requires it.
If you use AI (vendor tools): Do you handle sensitive data?
If yes: ISO 27001 + vendor risk assessment framework
If no: Vendor risk assessment framework. Consider ISO 27001 for general credibility.
The 2026 factor: EU AI Act and ISO 42001
The EU AI Act took effect August 2, 2025. If you're selling to European customers or have European users, this matters.
Here's what you need to know: ISO 42001 is not a harmonised standard under the EU AI Act. It won't automatically prove compliance. However, there's approximately 40-50% overlap between ISO 42001 and EU AI Act requirements.
What ISO 42001 does give you:
A structured framework addressing roughly half of EU AI Act requirements. Evidence of AI governance capability for procurement teams. A foundation to build EU AI Act compliance on top of.
What it doesn't give you:
Automatic EU AI Act compliance. A substitute for the Act's specific technical documentation requirements. Exemption from conformity assessments for high-risk systems.
Australian companies exporting to Europe: start your ISO 42001 journey now, but understand it's one piece of your EU AI Act compliance strategy, not the whole puzzle.
What this looks like by company stage
Pre-seed / Seed: Focus on product-market fit. Get ISO 27001 only if it's blocking your first enterprise customer. Document your AI development practices. You'll thank yourself later.
Series A: ISO 27001 is now mandatory. Enterprise sales are blocked without it. Add ISO 42001 if you're building high-risk AI or seeing it in RFPs. Start building compliance into your engineering culture, not bolting it on.
Series B+: Should already have ISO 27001. Add ISO 42001 for competitive differentiation. It's increasingly showing up in enterprise procurement requirements. Consider SOC 2 Type II for US customers. Your compliance posture is now a board-level conversation.
Realistic cost breakdown
Let me be direct about what this actually costs:
| Certification | Timeline | Investment (USD) |
|---|---|---|
| ISO 27001 alone | 4-6 months | $35-50K |
| ISO 42001 alone | 4-6 months | $40-60K |
| Combined package | 6-9 months | $70-90K |
These estimates assume medium-sized organisations using external consultants. Costs vary significantly based on existing security maturity, scope, and vendor selection.
The combined approach saves 20-30% versus doing them separately. That's because there's genuine overlap: risk management frameworks, documentation practices, audit processes, and management review structures are shared across standards. Organisations with existing ISO 27001 can often achieve ISO 42001 certification 30-40% faster.
The three mistakes I see constantly
"We'll just do ISO 42001 and skip 27001."
No. ISO 27001 is foundational. It covers the security controls that ISO 42001 assumes you already have. Every enterprise procurement team asks for 27001 first. Skipping it is like building a house without a foundation.
"We'll do both simultaneously from scratch."
This is technically possible but operationally brutal. You're building two management systems, writing double the documentation, and running parallel audit prep. Unless you have dedicated compliance staff, sequence them. Get 27001 stable, then layer 42001 on top.
"We don't need the certificate, just compliance."
I hear this from companies trying to save money. Here's the problem: customers want the certificate. Not a letter saying you're "aligned with" or "working towards" the standard. The certificate. It's third-party validation that you've actually done the work. Self-attestation doesn't cut it in enterprise sales.
The bottom line
Most AI companies need ISO 27001 first, ISO 42001 second. But "second" increasingly means within 12-18 months, not "someday."
The exceptions: if you're building AI for healthcare, finance, critical infrastructure, or any EU AI Act high-risk category, you need both from the start.
Don't let compliance become a blocker. The companies winning enterprise AI deals in 2025 and 2026 are the ones who treated compliance as a competitive advantage, not a checkbox.
Not sure which certification your company needs?
Joe has helped 20+ AI companies navigate this decision. Happy to spend 30 minutes working through your specific situation.