One system, four standards: integrating 42001 with 27001, 27701, and 9001

Lesson 5 of 5 in Certification, Audit, and Integrated Management Systems: ISO/IEC 42006.

Almost no organisation adopts 42001 on a green field. The realistic scenario is a company that already runs ISO/IEC 27001 for information security, perhaps ISO/IEC 27701 for privacy and ISO 9001 for quality — and now needs AI governance without hiring a second bureaucracy. The design answer is the integrated management system (IMS): one management framework satisfying several standards at once.

Integration is possible because of the Harmonized Structure (Annex SL) you met earlier: 42001, 27001, 27701, and 9001 all share the same ten-clause skeleton — context, leadership, planning, support, operation, performance evaluation, improvement. That shared skeleton means the machinery can be genuinely single: one document-control procedure, one competence and training process, one internal audit programme covering all standards, one management review with sectioned inputs, one corrective-action workflow. What stays distinct is the domain content flowing through that machinery: security risks and controls for 27001, privacy processing for 27701, product/service quality for 9001, and AI risks, impact assessments, and Annex A AI controls for 42001.

Where the standards share machinery — and where 42001 adds its own content
Harmonized Structure elementISO/IEC 27001 (security)ISO/IEC 27701 (privacy)ISO 9001 (quality)ISO/IEC 42001 (AI) — what is new

Clause 4 — context & scope

Interested parties, ISMS scope

Adds PII controller/processor role determination

Interested parties, QMS scope

Adds AI role determination (provider / developer / user per 22989) as an explicit requirement shaping everything downstream

Clause 6 — planning & risk

InfoSec risk assessment; SoA against Annex A (93 controls)

Privacy risk layered on the ISMS assessment

Risks & opportunities (no SoA mechanism)

AI risk assessment plus the 6.1.4 AI system impact assessment — the affected-party lens no other MSS requires; own SoA against 42001 Annex A (38 controls)

Clause 7 — support & documentation

Shared machinery: competence, awareness, documented information

Shared machinery

Shared machinery

Same machinery — AI competence (data science literacy for governors, governance literacy for engineers) is the new content

Clause 8 — operation

Operate risk treatment; control changes

Operate privacy controls (Annexes A/B of 27701)

Operational planning; production & service control

Operate AI risk treatment and perform impact assessments at planned intervals / on significant change (8.4)

Clauses 9–10 — check & improve

Internal audit, management review, corrective action

Folded into ISMS audit/review

Internal audit, management review, corrective action

Identical machinery — one integrated audit programme and management review can cover all four, with AI-specific inputs (drift incidents, impact-assessment outcomes)

Control catalogue

Annex A: 93 security controls (via 27002)

Annexes A/B: PIMS controls for controllers/processors

No control annex — clause requirements only

Annex A: 38 AI controls in 9 groupings, with Annex B implementation guidance — overlapping 27001 on logging, suppliers, and documentation, unique on impact assessment, responsible use, and lifecycle

Where the overlaps pay. Logging (27001 A.8.15 territory meets 42001 A.6.2.8), supplier management (27001’s supplier controls meet 42001 A.10), documentation control, incident-style processes — one process can carry both standards’ requirements if it is written to cover both evidence sets. Combining risk methodologies is trickier but doable: a single enterprise risk method with security, privacy, and AI lenses, feeding one integrated SoA (with columns per standard) or two aligned SoAs. Both patterns pass audits; what fails is two contradictory risk scales run by teams that do not talk.

Where naive integration fails. The AI impact assessment has no 27001 analogue — its lens is harm to others (individuals, groups, societies), not risk to the organisation. Teams that bolt AI onto the ISMS routinely produce ‘impact assessments’ that are security risk assessments with the labels changed. Auditors trained under 42006 are specifically primed to catch that.

Combined audits are the operational payoff: one CB, one audit week, one team (with the AI competence 42006 demands) covering 27001 + 42001 together. Shared clauses get audited once; standard-specific content gets its own sessions. Typical savings run 20–30% of audit days versus separate engagements — and, more valuably, one coherent findings list instead of two overlapping ones.

Tool: AIMS Builder & Audit — Build the thing auditors will sample: draft an AIMS scope and a Statement of Applicability for a fictional organisation, then stress-test your justifications the way a Stage 2 auditor would.

Key terms: integrated management system, Harmonized Structure (Annex SL), combined audit, Statement of Applicability, ISO/IEC 27701

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.