One system, four standards: integrating 42001 with 27001, 27701, and 9001
Lesson 5 of 5 in Certification, Audit, and Integrated Management Systems: ISO/IEC 42006.
Almost no organisation adopts 42001 on a green field. The realistic scenario is a company that already runs ISO/IEC 27001 for information security, perhaps ISO/IEC 27701 for privacy and ISO 9001 for quality — and now needs AI governance without hiring a second bureaucracy. The design answer is the integrated management system (IMS): one management framework satisfying several standards at once.
Integration is possible because of the Harmonized Structure (Annex SL) you met earlier: 42001, 27001, 27701, and 9001 all share the same ten-clause skeleton — context, leadership, planning, support, operation, performance evaluation, improvement. That shared skeleton means the machinery can be genuinely single: one document-control procedure, one competence and training process, one internal audit programme covering all standards, one management review with sectioned inputs, one corrective-action workflow. What stays distinct is the domain content flowing through that machinery: security risks and controls for 27001, privacy processing for 27701, product/service quality for 9001, and AI risks, impact assessments, and Annex A AI controls for 42001.
| Harmonized Structure element | ISO/IEC 27001 (security) | ISO/IEC 27701 (privacy) | ISO 9001 (quality) | ISO/IEC 42001 (AI) — what is new |
|---|---|---|---|---|
Clause 4 — context & scope | Interested parties, ISMS scope | Adds PII controller/processor role determination | Interested parties, QMS scope | Adds AI role determination (provider / developer / user per 22989) as an explicit requirement shaping everything downstream |
Clause 6 — planning & risk | InfoSec risk assessment; SoA against Annex A (93 controls) | Privacy risk layered on the ISMS assessment | Risks & opportunities (no SoA mechanism) | AI risk assessment plus the 6.1.4 AI system impact assessment — the affected-party lens no other MSS requires; own SoA against 42001 Annex A (38 controls) |
Clause 7 — support & documentation | Shared machinery: competence, awareness, documented information | Shared machinery | Shared machinery | Same machinery — AI competence (data science literacy for governors, governance literacy for engineers) is the new content |
Clause 8 — operation | Operate risk treatment; control changes | Operate privacy controls (Annexes A/B of 27701) | Operational planning; production & service control | Operate AI risk treatment and perform impact assessments at planned intervals / on significant change (8.4) |
Clauses 9–10 — check & improve | Internal audit, management review, corrective action | Folded into ISMS audit/review | Internal audit, management review, corrective action | Identical machinery — one integrated audit programme and management review can cover all four, with AI-specific inputs (drift incidents, impact-assessment outcomes) |
Control catalogue | Annex A: 93 security controls (via 27002) | Annexes A/B: PIMS controls for controllers/processors | No control annex — clause requirements only | Annex A: 38 AI controls in 9 groupings, with Annex B implementation guidance — overlapping 27001 on logging, suppliers, and documentation, unique on impact assessment, responsible use, and lifecycle |
Where the overlaps pay. Logging (27001 A.8.15 territory meets 42001 A.6.2.8), supplier management (27001’s supplier controls meet 42001 A.10), documentation control, incident-style processes — one process can carry both standards’ requirements if it is written to cover both evidence sets. Combining risk methodologies is trickier but doable: a single enterprise risk method with security, privacy, and AI lenses, feeding one integrated SoA (with columns per standard) or two aligned SoAs. Both patterns pass audits; what fails is two contradictory risk scales run by teams that do not talk.
Where naive integration fails. The AI impact assessment has no 27001 analogue — its lens is harm to others (individuals, groups, societies), not risk to the organisation. Teams that bolt AI onto the ISMS routinely produce ‘impact assessments’ that are security risk assessments with the labels changed. Auditors trained under 42006 are specifically primed to catch that.
Combined audits are the operational payoff: one CB, one audit week, one team (with the AI competence 42006 demands) covering 27001 + 42001 together. Shared clauses get audited once; standard-specific content gets its own sessions. Typical savings run 20–30% of audit days versus separate engagements — and, more valuably, one coherent findings list instead of two overlapping ones.
Tool: AIMS Builder & Audit — Build the thing auditors will sample: draft an AIMS scope and a Statement of Applicability for a fictional organisation, then stress-test your justifications the way a Stage 2 auditor would.
Key terms: integrated management system, Harmonized Structure (Annex SL), combined audit, Statement of Applicability, ISO/IEC 27701
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.