What is genuinely shared
Both standards use identical clause skeletons, so a single integrated system carries: one document control regime, one competence and awareness program, one internal audit function and schedule, one management review covering both scopes, one corrective action process, and one supplier management framework with security and AI lenses. Risk management integrates naturally too: the ISMS risk process extends to AI risks, with the AI impact assessment added as the genuinely new discipline.
What ISO 42001 adds on top of an ISMS
- AI system inventory and roles (developer, provider, user per system), the anchor of everything else.
- Impact assessment looking outward at individuals, groups, and society, which no 27001 process performs.
- Lifecycle controls for AI development and operation: data provenance and quality, evaluation before deployment, human oversight, monitoring for drift and misuse, retirement.
- Transparency and responsible-use controls toward users and affected parties.
- An AI-specific SoA against ISO 42001's Annex A, parallel to your 27001 SoA.
Sequencing advice from the audit chair
Hold 27001, adding 42001: the standard path and the fast one; extend the existing system, expect 30 to 50 percent incremental effort, and schedule the 42001 Stage 2 adjacent to a 27001 surveillance visit. Starting with neither: if your customers ask about both security and AI (the common case for AI SaaS), build one integrated system from day one and certify both in a coordinated cycle; it is barely more work than 27001 alone done properly. 42001 first, alone: rare but legitimate for pure AI governance pressure; the management machinery you build becomes your 27001 head start later.
The failure mode to avoid
Two systems, two owners, two vocabularies, and two sets of meetings about the same models and the same suppliers. Every duplicated artifact eventually contradicts its twin, and auditors read contradictions as system failure because that is what they are. One system, one risk register with two lenses, one review cadence: that architecture is cheaper to run, easier to audit, and vastly easier to sell.