Already have ISO 27001? Here is how much of ISO 42001 you already hold
Most companies look at the ISO 42001 documentation list and see 11 new documents. If you already run an information security management system, that is not what you are looking at.
The short answer
Both standards follow the harmonised structure that ISO applies across its management system standards. The clauses line up. Scope is still clause 4.3, policy is still 5.2, objectives are still 6.2, internal audit is still 9.2. What changes is the subject matter, not the shape.
What extends, and what is genuinely new
| ISO 42001 document | If you hold ISO 27001 |
|---|---|
| AIMS scope statement | Extends your ISMS scope. Same structure, widened to name which AI systems and business units are covered. |
| AI policy | New document. It sits alongside your information security policy and goes through the same approval and communication route you already run, so the process is familiar even though the document is not. |
| AI objectives | Extends your existing objectives framework. You already know how to write and measure these. |
| Roles and responsibilities | Extends your existing accountability model. Usually the same people, with AI added to their remit. |
| Risk assessment methodology | Extends your ISMS risk method. The method is familiar, the risk categories are not. |
| Risk treatment plan | Same format, new entries. |
| Statement of Applicability | You have written one before. This one covers ISO 42001 Annex A instead. |
| Internal audit programme | Extends the programme you already run. Add AI to the scope and the schedule. |
| AI system inventory | Mostly new. Your asset register may list some AI tools, but rarely with the detail needed, and almost never covering tools individual staff adopted themselves. |
| AI impact assessment process | Genuinely new. This is the real gap, and the section after this table is about it. |
| Operational procedures for AI | Partly new. Human oversight of AI output has no direct equivalent in an ISMS. |
The one that catches ISO 27001 holders out
An ISMS risk assessment is oriented around the organisation: confidentiality, integrity and availability of your information. An AI impact assessment is oriented around the people your AI affects. Whether a decision is fair, whether someone can contest it, whether the system performs differently for different groups.
Teams who are fluent in security risk often fill this in with security thinking and produce something that reads well and misses the point entirely. That single swap is the most common way an otherwise strong ISMS produces a weak impact assessment.
Where human oversight differs from access control
Your ISMS is full of controls that decide who may do what. AI operational procedures need something your ISMS does not contain: a defined point where a person checks whether the output is actually right before it is relied on.
Checking AI output is a new kind of control, different from access control and from change management, and it is what stops an AI mistake becoming an incident.
What this means in practice
Extending 7 documents is a materially different piece of work from writing 11, and worth knowing before you decide the job is too big to start.
See exactly where you stand
The check asks which certifications you hold and tells you which documents extend what you already have, in about 3 minutes, with the result on screen.
Start the 3-minute check