If your organization is starting to explore AI governance, you've probably run into both of these standards in the same sentence: ISO/IEC 27001 and ISO/IEC 42001. They sound similar, they're issued by the same body, and both result in a certifiable management system — but they govern fundamentally different risks. Understanding the difference matters, because getting it wrong usually means an organization implements one when it actually needed both.

ISO/IEC 27001: Managing Information Security Risk

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It has been the global benchmark for information security governance since 2005, most recently updated in 2022. At its core, ISO 27001 answers one question: how does your organization identify, treat, and continuously manage the risk of a confidentiality, integrity, or availability failure across its information assets?

An ISO 27001 implementation typically covers access control, asset management, cryptography, physical security, supplier risk, incident response, and business continuity — all built around a risk register and an Annex A control set. It says nothing specific about Artificial Intelligence (AI); it was written for information security in general.

ISO/IEC 42001: Managing Artificial Intelligence (AI) Risk

ISO/IEC 42001, published in December 2023, is the first international standard for an Artificial Intelligence Management System (AIMS). It was written specifically because AI systems introduce risks that a traditional ISMS was never designed to catch — model bias, explainability, data provenance, human oversight, and the unpredictable behavior of systems that learn and change over time.

Where ISO 27001 asks "is this data protected?", ISO 42001 asks a broader set of questions: "was this AI system trained on data we had the right to use? Can we explain why it made a given decision? Do we have a human in the loop where it matters? What happens when the model drifts?" It's a governance framework for the full AI lifecycle — from design and data sourcing through deployment and monitoring.

In Short

ISO 27001 protects your information. ISO 42001 governs your AI. One is about keeping data safe; the other is about making sure your AI systems are safe, fair, transparent, and accountable.

Do You Need Both?

In practice, yes — increasingly so. Most organizations deploying generative AI or machine learning models are already handling sensitive data through those systems, which means the two standards overlap and reinforce each other rather than compete. A typical sequencing looks like this:

  • If you handle sensitive data but haven't deployed AI at scale yet — start with ISO 27001. It's the foundational layer almost every other framework, including ISO 42001, assumes is already in place.
  • If you're already ISO 27001 certified and now deploying generative AI, Copilot, or ML models in production — ISO 42001 is the natural next step, and much of your existing risk management process, documentation discipline, and internal audit cadence can be extended rather than rebuilt.
  • If you're building or selling AI products — customers and regulators are increasingly asking for ISO 42001 evidence specifically, the same way they ask for ISO 27001 today.
"Many organizations implement both standards together to build a complete governance foundation for the AI era."

What This Looks Like for Malaysian Organizations

Malaysia doesn't yet mandate ISO 42001 certification, but regulators, procurement teams, and enterprise customers are starting to ask for it — particularly in banking, healthcare, and government-linked sectors where AI decisioning has real consequences. Getting ahead of that expectation, rather than reacting to it, is usually far cheaper and less disruptive.

Frequently Asked Questions

Can I get ISO 42001 certified without ISO 27001?

Yes, technically ISO 42001 can be implemented as a standalone management system. In practice, most organizations find it far more efficient to build it on top of an existing ISO 27001 ISMS, since the two frameworks share governance structures like risk registers, internal audit processes, and management review cycles.

How long does ISO 42001 implementation take?

It varies by organizational complexity, but a fintech-scale implementation is often achievable in 4–8 months with dedicated internal ownership and external audit support, similar to the ISO 27001 timelines many organizations are already familiar with.

Who audits ISO 42001 in Malaysia?

ISO 42001 certification requires a Lead Auditor qualified specifically against the standard. Tillandran Achuthan holds ISO/IEC 42001 Lead Auditor certification from the Global Association for Quality Management (GAQM) and supports organizations across Malaysia through implementation and audit readiness.

TA
Tillandran Achuthan ISO/IEC 27001 & 42001 Lead Auditor, ESG Lead Implementer, and HRDCorp-accredited Artificial Intelligence (AI) trainer based in Kuala Lumpur, Malaysia.

Need this implemented, not just explained?

Tillandran advises organizations across Malaysia on Artificial Intelligence (AI) governance, ISO 27001 & 42001 implementation, cybersecurity, and ESG reporting — book a consultation to discuss your specific situation.