Trava

Solutions

+

Advisory Solutions

Compliance Readiness

Data Privacy Compliance

Internal Audit

vCISO

AI Risk Management Services

Cybersecurity Risk Assessment Service

Cyber Due Diligence

Documentation Support

Policy & Controls Implementation

Tabletop Exercises

Cybersecurity Solutions

Penetration Testing

Vulnerability Assessment Service

Social Engineering

Red Teaming

Managed Programs

Managed Compliance Program

Managed Pen Test Program

Managed Security Training Program

Managed VM Program

Managed SOC Program

Blog

ISO 42001 vs. ISO 27001: Key Takeaways from Our Webinar with Insight Assurance

Trava and Insight Assurance broke down what ISO 42001 adds to an existing ISO 27001 program. Here's what security and compliance leaders need to know.

Published August 27, 2026

Trava’s Kaitlin Zanoni, Security Advisor, joined Mario Vlieg, Service Lead for ISO at Insight Assurance, for a live session on what ISO 42001 actually requires and how it fits alongside an ISO 27001 program you’ve already built. If you missed it, or want the highlights without the full recording, here’s what came out of the conversation.

The core idea: ISO 42001 and ISO 27001 are built on the same skeleton

The single biggest misconception Mario hears from prospective clients is that ISO standards are primarily about a checklist of controls. They’re not. As he put it during the session:

“There’s a big misconception out there that ISO standards are about controls. Not really: ISO standards are frameworks for governance and management.”

That distinction matters because it explains why ISO 27001 and ISO 42001 pair so naturally. The two standards share nearly identical clause structure from clause 4 through clause 10, the section containing most of the actual requirements. One governs information security; the other governs artificial intelligence. The underlying discipline (set objectives, assess risk, select controls, review and improve) is the same discipline applied to a different subject.

That’s good news if you already run ISO 27001: you’re not starting from zero. It’s not, however, a reason to assume ISO 42001 is a light lift. The overlap between the two standards runs lower than the overlap most teams are used to seeing between SOC 2 and ISO 27001. Mario put SOC 2-to-ISO 27001 technical control overlap at around 70% on the high end; ISO 27001-to-ISO 42001 overlap, by contrast, runs closer to 30-40% at the high end, because ISO 42001 introduces its own risk categories, its own documentation requirements, and at least one control area that ISO 27001 doesn’t touch at all.

Who actually needs ISO 42001

A theme both speakers returned to repeatedly: ISO 42001 isn’t just for companies that build AI products. As Mario explained, the standard applies “organization-wide,” meaning any company that uses AI in any capacity, including internally, falls within its scope. His framing: “The moment you start consuming AI internally makes you eligible for 42001.”

Kaitlin echoed this from her own client work, noting that a lot of organizations who don’t think of themselves as an AI company at all discover, once they take inventory, that they’re using AI vendors, AI features baked into existing tools, or that employees are simply using AI day to day without any formal governance around it. Ignoring that, both speakers agreed, doesn’t make the risk disappear. It just makes it unmanaged.

The most common audit pitfall

If you’re extending an existing ISO 27001 program into ISO 42001, there’s one gap that shows up more than any other. In Mario’s words:

“The most common pitfall has to do with the AI impact assessment, precisely because it is one of the few areas where 42001 differs from 27001. Many organizations that are coming from 27001 basically expand their existing policies to also include 42001 elements, but then they forget one of the more key components, that AI impact assessment. That’s probably where we see the most issues in the audit.”

The AI impact assessment isn’t a formality. It’s meant to drive the rest of your implementation, documenting how your use of AI systems affects your organization, your stakeholders, and the people your AI touches. Skipping it doesn’t just leave a documentation gap; it leaves the actions you take in the rest of your ISO 42001 program without the foundation they’re supposed to be built on.

Where the two standards diverge

Beyond the impact assessment, a handful of areas are specific to ISO 42001 and won’t be covered by an existing ISO 27001 (or SOC 2) program:

No, ISO 27001 isn’t a prerequisite

A direct question from the Q&A worth flagging: does a company need ISO 27001 before pursuing ISO 42001? The answer is no. The two standards can be pursued independently, or audited together as an integrated management system audit if you’re pursuing both. Having ISO 27001 already in place is an advantage, not a requirement.

What the certification timeline actually looks like

For companies weighing whether to start now, Mario offered a realistic range: the full certification process typically runs anywhere from three months on the fast end to eight months or a year on the long end, depending on organizational complexity and readiness. A Stage 1 audit itself takes about two days; Insight Assurance recommends leaving at least three weeks between Stage 1 and Stage 2 to give organizations room to remediate anything flagged.

One useful piece of vendor-vetting advice from the session: be cautious of any certification body that isn’t accredited, or that promises a turnaround measured in days rather than months. That’s a signal worth noticing, not a shortcut worth taking.

A practical starting checklist

Both speakers converged on the same starting sequence, regardless of where an organization is starting from:

One honest note on security questionnaires

Asked directly whether an ISO 42001 certificate makes security questionnaires go away, Mario didn’t oversell it: “I am sorry to be the bearer of bad news, we will never get rid of compliance questionnaires.” But he was equally direct about the upside: the total hours a team spends filling out those questionnaires drops significantly once a real certification is in place, even if some redundant questions persist.

Where Trava fits in

If this conversation raised more questions about where your own organization stands, whether ISO 42001 makes sense for you yet, how it would build on a SOC 2 or ISO 27001 program you already have, or what an AI inventory and risk assessment would actually turn up, that’s exactly the kind of scoping conversation Trava’s compliance advisory team has every day. Talk to Trava about AI governance and ISO 42001 readiness.

For the full context behind these takeaways, including the complete Q&A, watch the full webinar recording.

FAQ

Is ISO 42001 only relevant to companies that build AI products?

No. Both speakers were clear that ISO 42001 applies organization-wide to any company using AI in any capacity, including purely internal use by employees, not just companies developing or selling AI products.

What’s the most common mistake companies make extending ISO 27001 into ISO 42001?

Forgetting the AI impact assessment. It’s one of the few elements ISO 27001 doesn’t already cover, and it’s meant to drive the rest of the ISO 42001 implementation. Skipping it is the most common audit finding cited in the webinar.

Do I need ISO 27001 before I can pursue ISO 42001?

No. The two standards can be pursued independently or audited together as an integrated management system audit. Having ISO 27001 in place already is an advantage but not a requirement.

How much of an existing ISO 27001 or SOC 2 program carries over to ISO 42001?

Less than most teams expect. SOC 2-to-ISO 27001 technical control overlap can run as high as 70%; ISO 27001-to-ISO 42001 overlap typically runs 30–40% at the high end, since ISO 42001 introduces its own risk categories and documentation requirements.