Every team that already holds ISO 27001 asks the same question first: how much of this carries over?
The answer you will usually get is “most of it.” Both standards share ISO’s harmonized management-system structure, so the reasoning goes, your ISMS gets you most of the way and the AIMS is a short extension.
The first half of that is true and the second half is doing a great deal of work.
What carries over is the management system: the internal audit programme, management review, corrective action, competence and awareness, control of documented information, your supplier process. That is genuinely valuable, and it is why an ISO 27001 program is the right place to start.
What does not carry over is the evidence, because the two standards are asking about different objects. An ISMS is largely a set of claims about systems, access and configuration. An AIMS is largely a set of claims about models, data and decisions — and decisions do not have an API.
This blog is about what that difference means when you evaluate ISO 42001 compliance software, because it changes which questions are worth asking in a demo.
ISO/IEC 42001:2023 is the international management system standard for artificial intelligence. It sets out how an organization establishes, runs, and continually improves an AI Management System (AIMS): the policies, controls, and evidence that govern how it develops, provides, and uses AI. It applies to any organization that builds or uses AI systems, and it is certifiable through an accredited certification body.
ISO 42001 compliance software is the tooling that operationalizes that management system. It maps AI controls to the standard’s requirements, collects the supporting evidence from the systems you already connect, flags gaps, and keeps the program audit-ready between audits rather than in the weeks before one. In an enterprise program it runs alongside ISO 27001 and ISO 27701 on a shared control set, so work already done for one standard supports the next.
ISO 42001 vs ISO 27001: what actually carries over
The management system carries over
Both standards use ISO’s harmonized structure for clauses 4 through 10 — context, leadership, planning, support, operation, performance evaluation, improvement. If you run an ISMS, you already operate that machinery, and it does not need rebuilding.
They are not identical, though, and the differences are the interesting part. Some requirements are AI-specific; others apply a shared discipline to AI:
- Clause 6.1.4 and clause 8.4 — AI system impact assessment. A distinct requirement from risk assessment, performed at planned intervals or when significant changes are proposed, with documented results retained.
- Clause 6.3 — Planning of changes. ISO/IEC 27001:2022 also includes clause 6.3; the shared requirement is to plan changes to the management system.
Both involve human judgment. Impact assessments require documented results and scheduled reviews as well as attention to significant proposed changes.
{{ banner-image }}
The control set does not
ISO publishes no mapping between ISO 42001’s Annex A and ISO 27001’s Annex A. The only official statement on running them together is Annex D of ISO 42001, which is informative — guidance on integrated use, not a crosswalk. The two control sets share almost no control-level text.
That is not an oversight. They are cataloguing different things. ISO 27001:2022’s Annex A holds 93 controls across organizational, people, physical and technological themes. ISO 42001’s Annex A holds 38 controls across nine categories covering AI policy, internal organization, resources for AI systems, impact assessment, the AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party relationships.
Annex B of ISO 42001 is normative, not informative. It carries implementation guidance for the Annex A controls as a requirement of the standard, where ISO 27001 keeps its equivalent guidance in a separate, non-binding standard. If a platform or a consultant tells you Annex B is optional reading, that is a useful signal about how carefully they have read.
The number nobody quotes
For the audit budget, there is a specific rule from the accreditation system.
IAF MD 11:2023 governs how certification bodies calculate audit time for integrated management system audits. Time is calculated for each standard, summed, and then adjusted — and the mandatory document states that where the adjustment results in a reduction, it “shall not exceed 20% from the starting point.”
The cap applies to the combined audit duration where MD 11 governs the integrated audit. It does not measure how much ISO 27001 evidence or implementation work an AIMS can reuse.
Budget the certification audit separately from the internal work of extending your ISMS.
Why the evidence doesn’t transfer
The objects are different, and the difference shows up in what an auditor can sample.
By our reading of the 38 Annex A controls, roughly two thirds produce evidence that exists only because a person made a decision and recorded it — the AI policy and its ownership, impact assessments, documentation of intended and unintended uses, data acquisition and provenance rationale, human oversight arrangements, what you tell interested parties, how you handle third-party model providers. Only a small handful describe system state that a connector could pull directly.
ISO 27001 is not a purely technical standard either. Its 37 organizational and 14 physical controls are policies, agreements, registers and procedures. But its 34 technological controls, plus the access and identity controls among the organizational ones, give it roughly 40 controls — about 43% — that produce genuine configuration telemetry. That is something like five times ISO 42001’s share.
The gap narrows if your engineering org is mature. A model registry, evaluation pipelines, data lineage tooling and drift monitoring can machine-generate the artifacts sitting behind another chunk of the AI life cycle and data categories. If you have that stack, more of your AIMS evidence can be produced automatically than this page implies.
Even then, the automated output is an input to a documented judgment, not the evidence itself. An auditor sampling data provenance wants the licensing, consent and legality rationale for a corpus. A lineage graph is a useful exhibit attached to that rationale. It is not a substitute for it.
So the honest framing is narrower than “ISO 42001 cannot be automated,” and more useful. The automatable fraction is roughly a third at its most generous and well under that on a strict reading — and the remainder is not a backlog that a future connector clears. It is the substance of the standard.
The comparison table
DimensionISO 27001 (ISMS)ISO 42001 (AIMS)What it governsAn information security management system: protecting information and treating information security risk.An AI management system: the responsible development, provision, and use of AI, including AI risk and oversight across the AI lifecycle.Management-system structureHarmonized structure, clauses 4–10, with mandatory clauses that cannot be excluded when you claim conformity.The same harmonized backbone, including planning of changes (6.3), plus AI system impact assessment (6.1.4 and 8.4).Annex A93 controls across four themes.38 controls across nine categories. No official mapping exists between the two sets.Implementation guidanceISO 27002, a separate standard, not binding.Annex B, normative — part of the standard.How risk is framedAssessment and treatment of information security risks.AI risk and opportunity, plus a distinct impact assessment requirement covering effects on individuals and society.What the evidence looks likeMajority documentation, with roughly 43% of Annex A producing configuration telemetry.Overwhelmingly documented judgment. A small fraction describes pullable system state.What carries over—The management system: internal audit, management review, corrective action, competence, documented information, supplier process.Audit-time reduction—Capped at 20% for integrated audits under IAF MD 11:2023.CertificationCertifiable through an accredited body; software supports readiness, it does not issue the certificate.The same. Compliance is what you operate; certification is what the body attests.
A program that already runs ISO 27001 is not building an AIMS from zero. It is also not most of the way there. It is bringing a working management system to a new set of obligations whose evidence it has never had to produce.
What ISO 42001 compliance software does
An AI management system adds AI-specific responsibilities to governance work your program may already perform: defined scope, policy ownership, risk decisions, operating records and review. The shared management-system structure makes the ISO 27001 program a useful foundation, but does not make its evidence sufficient for every AI obligation. ISO 42001 compliance software should let your team see which work can be reused and which obligations remain specific to AI — and, given everything above, should be candid about which of those obligations it can help produce and which it can only help you keep.
Start with collection. Anecdotes pulls evidence from the systems where it already lives, on a recurring schedule, typically weekly, with on-demand collection when a review needs it. It pulls full datasets, including the records behind a pass or a failure, and normalizes them into one queryable, structured format. That full population is what a technical AI control needs behind it: not a screenshot of a setting from the morning someone looked, but the records the setting produced, each with its own timestamp.
That handles the smaller share of the standard. The larger share — the assessments, the rationale, the oversight arrangements — is produced by people, and what software does there is different in kind. It gives a decision a durable home: an owner, a date, the reasoning as written, the controls it satisfies, and the systems it refers to. It notices when the thing the decision was about has changed. It makes the decision retrievable in the same place, and in the same shape, as the machine-collected evidence sitting next to it.
From there, requirements do the connecting. Anecdotes cross-maps at the requirement level, the expected evidence behind each control, so one piece of evidence can answer the same requirement wherever it appears, across the frameworks a program runs, from ISO 27001 to ISO 42001. Every framework, ISO 42001 included, sits on that same architecture, whether it comes from the library or from a control listing you bring in. Your team configures the analysis rules that read each evidence record and mark it as a gap or a warning, and that reading is recomputed every time new evidence is collected or a rule changes. The platform moves a control to “In Progress” on its own; your team is the one that flags a “Gap” and marks a control “Ready for Audit.” You can see the other frameworks a program maps in the framework library.
Recurring collection and analysis make audit readiness easier to inspect between reviews. Each evidence record keeps the source data and collection context, so the team can examine completeness and accuracy rather than accept a status badge alone. An auditor still evaluates whether that evidence supports the requirement and the conclusion. The software helps keep the record available; it does not turn every collected artifact into proof that the AIMS is effective.
The AIMS lifecycle, and where the work lives
ISO 42001 defines a management system, which means it runs as a cycle, not a project with an end date. These are the stages the standard asks for, and the places where continuous evidence changes the work instead of only recording it.
Policy. The standard requires an AI policy. Policy Guardian reads a policy document, extracts the statements meant to be enforced, links each one to the relevant controls and evidence from your connected systems, and shows whether a monitoring rule already exists or should be added. The policy stops being a document filed once and becomes something you can see in the data.
Leadership and planning. ISO 42001 asks you to manage the risks and opportunities of AI. Anecdotes keeps AI risks in their own register, with their own required fields, next to the security risk register rather than mixed into it, and rolls both into one view. Link a risk to the controls meant to reduce it and you see how a change in a control’s effectiveness moves the risk level; a proposed new level waits for a person to approve it before it applies.
Impact assessment. Clauses 6.1.4 and 8.4 make this its own requirement, separate from risk assessment, with assessments at planned intervals or when significant changes are proposed. This is the requirement with no ISO 27001 equivalent and the one most likely to be underscoped by a team extending an existing ISMS. ISO/IEC 42005:2025, published in May 2025, is the companion guidance for how to conduct and document one — worth reading, and worth noting that it is guidance, not a certifiable standard. Every item it describes is a documented human judgment.
Support and operation. This is where the collected evidence lives. Controls map to ISO 42001 requirements, and the evidence behind them is collected from connected systems on a recurring schedule and mapped once at the requirement level, so it counts wherever that requirement appears.
Performance evaluation. The standard requires internal audit and management review. Both read from live control statuses and from evidence records that carry their own completeness and accuracy attributes, so the review examines the same data an external auditor would, not a report assembled for the occasion.
Improvement. With the relevant playbooks configured, a flagged gap can open a finding, and a finding can trigger a task with an owner. The next collection gives the team evidence to check whether the fix held. The cycle closes where it started, with the evidence, and begins again on the next schedule.
Evaluate this workflow against actual AI-governance work. The table below is a demonstration checklist: it identifies what your team should be able to trace and which decisions remain with people.
AIMS workWhat to trace in the demonstrationHuman decision to preserveAI-system scope and ownershipHow the systems and organizational activities in scope connect to their controls, owners and supporting records.Your team defines the AIMS boundary and keeps its record of AI resources accurate.AI risk and impact assessmentHow a risk record connects to the controls and evidence chosen to address it, and how the assessment record is retained and re-opened on change.Risk and impact judgments, treatment choices and residual-risk acceptance belong to accountable owners.Policy and implementationHow a stated requirement connects to a configured analysis rule or another valid evidence source.A person confirms the interpretation, coverage and exceptions; a document alone does not establish implementation.Changes and reviewHow new evidence changes a result and how a finding reaches its owner with traceable follow-up.Owners judge the impact of changes and verify that corrective action is effective.Internal and external auditHow a reviewer receives the selected evidence with its scope and collection context.Auditors evaluate the management system; the certification body issues the certificate.
What to actually evaluate in a demo
If most of the standard is documented judgment, “how much can you automate?” is the wrong opening question. It sorts vendors by how confidently they will overstate. Five better ones:
1. Can a decision be a first-class evidence record? Not an attachment, not a note on a control. A record with an owner, a date, the reasoning as written, the requirements it answers, and a link to the systems it refers to — retrievable and reviewable the same way a collected artifact is. If judgment can only live as an uploaded PDF, two thirds of your AIMS lives outside the platform.
2. When the subject of a decision changes, does the record know? Clause 8.4 calls for impact assessments at planned intervals or when significant changes are proposed. Ask what happens when a connected system changes materially — whether anything reaches the owner of the assessment that referenced it, or whether the link between the change and the decision only exists in someone’s memory.
3. Can you see which requirements rest on judgment and which rest on telemetry? That split is the honest state of your program. It tells you where a stale record is a configuration problem you can fix with a schedule, and where it is a person who needs to revisit a decision. Most platforms show you a status. Ask to see the substrate.
4. Does the machine-collectable slice stay current without anyone chasing it? The point of automating the smaller share is not the smaller share. It is that your people stop spending their weeks on it and spend them on the assessments, which is the work only they can do.
5. Does reuse preserve scope? Requirement-level mapping should show you exactly where an ISO 27001 artifact answers an ISO 42001 requirement and where it does not. A mapping records a relationship. It does not declare either requirement satisfied, and a platform that blurs that will produce a confident dashboard and a difficult stage 2.
Bring an AI system or use case, its owner, a risk decision and the supporting source systems. Follow that evidence through collection, mapping, review and corrective action. You should leave knowing what is supported in your environment, what needs configuration and what your team still needs to do.
Buyer questions about ISO 42001 compliance software
What is ISO 42001 compliance software?
ISO 42001 compliance software operationalizes an AI Management System: it maps AI controls to the requirements of ISO/IEC 42001, collects the supporting evidence from the systems you already connect, flags gaps, and keeps the program audit-ready instead of rebuilding evidence before each audit. In an enterprise program it usually runs alongside ISO 27001 and ISO 27701 on a shared control set, so evidence gathered for one framework can support the requirements it shares with another.
How much of ISO 27001 carries over to ISO 42001?
The management system carries over: internal audit programme, management review, corrective action, competence and awareness, control of documented information, supplier process. Both standards use ISO’s harmonized structure for clauses 4 through 10, so that machinery does not get rebuilt.
The control set does not. ISO publishes no mapping between the two Annex As, and the sets share almost no control-level text. IAF MD 11:2023 caps reductions to combined audit duration at 20% from the summed starting point; this does not quantify the implementation work you can reuse.
Treat your ISMS as the foundation, not as most of the building.
Can ISO 42001 evidence be collected automatically?
Some of it. ISO 42001’s Annex A is dominated by evidence that exists because a person made a decision and recorded it — impact assessments, intended-use documentation, data acquisition and provenance rationale, oversight arrangements. A small share describes system state a connector can pull directly, and organizations with mature model registries, evaluation pipelines and data lineage tooling can machine-generate the artifacts behind more of the life cycle and data controls than most.
Even there, the automated artifact is an input to a documented judgment rather than the judgment itself. Any vendor promising to automate ISO 42001 evidence collection outright is describing a different standard. What good software does is keep the collectable share current on its own, and give the rest a durable, traceable home.
What is the difference between ISO 42001 and ISO 27001?
ISO 27001 governs an information security management system: protecting information. ISO/IEC 42001 governs an AI management system: the responsible development, provision, and use of AI, including AI risk and oversight across the AI lifecycle. They share the harmonized management-system structure, which is why an existing ISO 27001 program is a strong foundation rather than a separate build. ISO 42001 adds AI system impact assessment (clauses 6.1.4 and 8.4). Planning of changes (clause 6.3) is shared with ISO 27001:2022.
How much does ISO 42001 certification cost?
The certification-body fee is separate from compliance software. Your internal preparation and operating effort are separate budget items too. The ISO 42001 certification cost guide explains the inputs to a scoped quote; use the workflow above to evaluate how software supports the program.
How long does ISO 42001 implementation take?
Implementation depends on the AIMS scope and what your program already operates. Reusable management-system processes help, but AI risk, impact and oversight work still need their own evidence, and that evidence has to be produced rather than connected. Use the ISO 42001 implementation plan to organize readiness; use a demonstration to check which parts of that work the platform can support.
How does ISO 42001 compliance software help with audit preparation?
It turns audit preparation into a state rather than an event. The software maps controls to ISO/IEC 42001 requirements, collects evidence automatically on a recurring schedule, and flags gaps as they appear, so findings surface between audits instead of during one. The same evidence record serves continuous monitoring and a formal audit request, with no separate audit version to assemble, and it carries the timestamp and raw source data an auditor checks. Your team decides when a control is ready for audit, and the auditor still makes the final judgment.
Can one platform cover ISO 42001, ISO 27001, and ISO 27701 together?
A multi-framework program can reuse evidence where requirements genuinely overlap. Anecdotes provides requirement-level cross-mapping, with scope decisions for what is shared and what stays separate. ISO 27701:2025 is now a standalone privacy management-system standard rather than an extension to ISO 27001; it can still be integrated with ISO 27001 and ISO 42001. Our team describes that integrated way of working in the ISO Trifecta webinar linked below.
Is ISO 42001 certification the same as ISO 42001 compliance?
No. Compliance means operating an AI management system that meets ISO/IEC 42001, and you can run and demonstrate it internally. Certification is the separate step where an accredited, independent body assesses that system and attests to it. Software supports the first: it builds and maintains the evidence that shows the standard is being met. The certificate comes from the body, not the tool, and passing that assessment is a baseline the program keeps clearing, not a one-time result.
Worth knowing if you are choosing a body: ISO/IEC 42006:2025, published July 2025, sets the requirements for organizations auditing and certifying an AIMS, and accredited capacity has been building since. Check the accreditation attached to the certificate you are being offered, for this standard and as of its date.
Why Anecdotes: AI governance becomes real when you operate it
AI governance becomes useful when the program can connect a policy to what actually happens. A policy establishes intent and responsibility. Operating records, evaluation and follow-up show how that intent is put into practice. That is the work to test in a software evaluation: can the team trace a requirement to the evidence, the decision and the action that followed?
This is also why the data foundation matters more here than anywhere else, and in a way that is easy to state backwards. The argument for a trusted data layer usually runs through automation — collect the full population, let the agents reason over it. That argument holds for the technical slice of an AIMS. But the reason it matters for the rest is quieter: a platform that treats a documented judgment as a second-class citizen, an attachment hanging off a control, will hold two thirds of your AI management system as filing rather than as evidence. You find that out at stage 2, when the auditor asks how the assessment was revisited after the model changed.
Anecdotes holds ISO 27001, ISO 27701 and ISO 42001. Its AI-governance commitments describe the posture behind those claims, while the first-hand account of the three certifications explains how the team organized the program. The ISO Trifecta webinar expands on that experience with the CISO and InfoSec Risk and Compliance Manager. It is a real implementation story, not a guarantee of another team’s audit result.
For a program that already runs ISO 27001, begin by identifying the processes and evidence that can support the AIMS. Then add and test the AI-specific obligations. Check whether the platform lets you reuse shared work while keeping differences in scope, evidence and accountability visible.
This is what the agentic GRC platform is for: mature, multi-framework programs that need one trusted, auditor-grade data foundation under every framework they run, ISO 42001 included. Not a checklist tool that stops at pass or fail, and not a workflow engine with AI added on top.
Your ISO 27001 program is the foundation. It is not the first two thirds.
The evidence an AIMS runs on is mostly produced by your people, which means the question worth asking of any platform is not how much it collects, but whether it can hold what they decide — durably, traceably, and next to the data that decision was about.





