AI Governance Gap Check

Already have ISO 27001? Here is how much of ISO 42001 you already hold

Most companies look at the ISO 42001 documentation list and see eleven new documents. If you already run an information security management system, that is not what you are looking at.

The short answer

ISO 42001 uses the same management system structure as ISO 27001, so seven of its expected documents extend ones your ISMS already maintains rather than starting from nothing.

Both standards follow the harmonised structure that ISO applies across its management system standards. The clauses line up. Scope is still clause 4.3, policy is still 5.2, objectives are still 6.2, internal audit is still 9.2. What changes is the subject matter, not the shape.

What extends, and what is genuinely new

ISO 42001 documentIf you hold ISO 27001
AIMS scope statementExtends your ISMS scope. Same structure, widened to name which AI systems and business units are covered.
AI policySits alongside your information security policy. Same approval and communication route you already run.
AI objectivesExtends your existing objectives framework. You already know how to write and measure these.
Roles and responsibilitiesExtends your existing accountability model. Usually the same people, with AI added to their remit.
Risk assessment methodologyExtends your ISMS risk method. The method is familiar, the risk categories are not.
Risk treatment planSame format, new entries.
Statement of ApplicabilityYou have written one before. This one covers ISO 42001 Annex A instead.
Internal audit programmeExtends the programme you already run. Add AI to the scope and the schedule.
AI system inventoryMostly new. Your asset register may list some AI tools, but rarely with the detail needed, and almost never covering tools individual staff adopted themselves.
AI impact assessment processGenuinely new. This is the real gap. See below.
Operational procedures for AIPartly new. Human oversight of AI output has no direct equivalent in an ISMS.

The one that catches ISO 27001 holders out

Information security risk asks what it costs you if something goes wrong. AI impact assessment asks what it costs the person on the other side. Those are different questions.

An ISMS risk assessment is oriented around the organisation: confidentiality, integrity and availability of your information. An AI impact assessment is oriented around the people your AI affects. Whether a decision is fair, whether someone can contest it, whether the system performs differently for different groups.

Teams who are fluent in security risk often fill this in with security thinking and produce something that reads well and misses the point entirely. If you take one thing from this page, take that.

Where human oversight differs from access control

Your ISMS is full of controls that decide who may do what. AI operational procedures need something your ISMS does not contain: a defined point where a person checks whether the output is actually right before it is relied on.

That is not access control and it is not change management. It is a new kind of control, and it is the one that actually prevents an AI mistake from becoming an incident.

What this means in practice

An organisation starting from nothing is writing eleven documents. An organisation with a working ISMS is extending seven, writing two from scratch, and adding a genuinely new kind of control to a third.

That is a materially different piece of work, and it is worth knowing before you decide it is too big to start.

See exactly where you stand

The check asks which certifications you hold and tells you which documents extend what you already have. Three minutes, result on screen.

Start the check