loader from loading.io

#247 How do ISO 27001 Information Security and ISO 42001 AI Management compare?

The ISO Show

Release Date: 04/01/2026

#256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond show art #256 BedX – Supporting Businesses Looking To Tender For Universal Bedfordshire and Beyond

The ISO Show

There has been a lot of buzz around the upcoming Universal Project currently in development in Bedfordshire. It’s estimated to generate around £50 billion in economic benefit, along with the creation of 20,000 jobs during its construction, and a further 8,000 jobs once it’s operational. It’s undoubtedly brought a lot of eyes towards the smallest county in the UK, and with it a lot of opportunity for local businesses to get involved with not only the main theme park itself, but the surrounding projects that aim to make Bedford and beyond a thriving tourist destination. For those...

info_outline
#255 AI Due Diligence - Information Security Checks Before You Integrate AI show art #255 AI Due Diligence - Information Security Checks Before You Integrate AI

The ISO Show

AI can be fantastic for relieving a lot of administrative burdens, allowing individuals to focus on more complex tasks that need a human touch. However, many are all too quick to install and integrate, which can lead to crucial vetting processes being skipped. So many applications have also integrated various AI features, and while you may have vetted the software before these were available, those new AI features still need scrutiny before widespread use within the business. In this episode, we dive into why there is a need for a more cautious approach to implementing AI and share some...

info_outline
#254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill show art #254 Driving ISO Implementation – Meet the Consultant: Emma Coxhill

The ISO Show

The path towards becoming an ISO consultant is often a meandering one. It’s not often a career that many aspire to, yet despite that, there are still thousands of ISO professionals worldwide. We’re continuing with our mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.   In this episode we introduce Emma Coxhill, an isologist® at Blackmores, to share their recent journey into the world of ISO consultancy and how they’ve found their first...

info_outline
#253 Building The Case For Health & Safety Regulations & Standards show art #253 Building The Case For Health & Safety Regulations & Standards

The ISO Show

Everyone who goes to work should have the right to go home after work. This is a sentiment that wasn’t necessarily formally recognised until the 1970’s here in the UK.   Health & Safety often gets mocked for overly cautious or seemingly onerous tasks to meet certain regulations and Standards today, however these are in place for a reason. They save lives, plain and simple. In this episode, Ian Battersby makes the case for Health & Safety regulations, including why they were introduced, events that sparked the conversation for workplace safety and the impact regulations have...

info_outline
#252 Wavenet’s On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards show art #252 Wavenet’s On-going Commitment to Best Practice – Successfully Maintaining Seven ISO Standards

The ISO Show

Anyone that has undergone the ambitious task of Implementing an ISO Standard will know how much work goes into creating and maintaining a single ISO certification. Now imagine juggling seven ISO certifications! There’s a key difference between those that simply collect badges and those that see the value each ISO certification can bring, as every Standard has their own requirements and guidance to tackle specific areas of quality, risk and sustainability. When implemented well, they create a solid well-rounded framework that can drive unparalleled continual improvement. In this episode...

info_outline
#251 Driving The Demand For GHG Emissions - How Davies Group Tackled Carbon Verification show art #251 Driving The Demand For GHG Emissions - How Davies Group Tackled Carbon Verification

The ISO Show

Carbon verification is quickly becoming a necessary step for many businesses, whether due to regulatory compliance, market demand or as part of a voluntary scheme. The drivers for this demand are varied, as is the approach many take for their path towards carbon verification. This can look very different depending on the industry you operate in and can be difficult to tackle for more service based industries, such as today’s guest, Davies Group, who are a service provider for the insurance industry. In this episode Mel is joined by Gillie Fairbrother, Global Responsible Business Officer...

info_outline
#250 Driving ISO Implementation – Meet the Consultant: Steve Mason show art #250 Driving ISO Implementation – Meet the Consultant: Steve Mason

The ISO Show

How often have you heard someone say they aspire to be an ISO consultant? Likely not at all! That’s not surprising as it’s quite a niche world to find yourself in, yet despite that, there are still thousands of ISO professionals worldwide. We’re continuing with our mini-series where we introduce members of our team, to explore how they fell into the world of ISO and discuss the common challenges they face while helping clients achieve ISO certification.   In this episode we introduce Steve Mason, a Principle isologist® at Blackmores, to share the journey of how he went from...

info_outline
#249 How To Meet Documentation Requirements Within ISO show art #249 How To Meet Documentation Requirements Within ISO

The ISO Show

Most ISO Standards are designed with implementation flexibility in mind. They set the framework without specifying an exact method to meet requirements, giving businesses the freedom to implement them how they see fit. One of the key requirements you can’t escape, however, is documentation. This is more than a list of key documents you must have in place, it encompasses how you develop, control and store documented information. In this episode, Ian Battersby dispels common myths around documentation in ISO, explains what the requirements actually mean in practice and how you address each...

info_outline
#248 How To Address Risk Management Within ISO show art #248 How To Address Risk Management Within ISO

The ISO Show

Most ISO Standards take what’s known as a ‘risk-based approach’, which focuses on proactively identifying and mitigating potential risks while capitalising on opportunities. The methods for managing risk can be very varied, and many make the mistake of treating it as a separate task rather than as an integrated part of your existing processes. In this episode, Ian Battersby explains what risk management means in regard to ISO management, what this looks like in practice and breaks down different methods you can utilise for effective risk management. You’ll learn ...

info_outline
#247 How do ISO 27001 Information Security and ISO 42001 AI Management compare? show art #247 How do ISO 27001 Information Security and ISO 42001 AI Management compare?

The ISO Show

Information is increasingly becoming the number one priority for businesses. With so many of us reliant on tech to stay in operation, there is an inevitable increase in data breaches and incidents year-on-year. The addition of new AI driven technology has added a new layer of complexity to the information security landscape, regarding both the new risks using the technology brings as well as falling prey to more complex AI led scams.   Thankfully ISO Standards are here to help, with ISO 27001 tackling general information security and ISO 42001 for effective AI Management. But how do...

info_outline
 
More Episodes

Information is increasingly becoming the number one priority for businesses. With so many of us reliant on tech to stay in operation, there is an inevitable increase in data breaches and incidents year-on-year.

The addition of new AI driven technology has added a new layer of complexity to the information security landscape, regarding both the new risks using the technology brings as well as falling prey to more complex AI led scams.  

Thankfully ISO Standards are here to help, with ISO 27001 tackling general information security and ISO 42001 for effective AI Management. But how do these two compare, and is there merit in implementing both?

In this episode, Ian Battersby is joined by Bas Von Hertom, Cyber Security Specialist at TUV Nord, to discuss what ISO 27001 and ISO 42001 are, the main differences between the Standards and how they can complement each other when integrated.  

You’ll learn

·      Who is Bas Von Hertom?

·      Who are TUV Nord?

·      What are ISO 27001 and ISO 42001?

·      How does ISO 42001 support regulatory frameworks such as the EU AI Act?

·      How do ISO 27001 and ISO 42001 differ in managing information security risks?

·      Other key differences between ISO 27001 and ISO 42001

·      How much more work is involved for Implementing ISO 42001 if you already have ISO 27001 in place?

·      Can ISO 27001 and ISO 42001 be integrated?

·      What organisations should be implementing both Standards?

·      How are Certification Bodies quoting for ISO 27001 and ISO 42001?

·      Bas’s advice to leadership teams looking to build a case for full certification

 

Resources

·      TUV Nord

·      Isologyhub

 

In this episode, we talk about:

[02:05] Episode Summary – Ian is joined by Bas Von Hertom, Cyber Security Specialist at TUV Nord, to explore the differences between ISO 27001 and ISO 42001 and the benefits of integrating both Standards.

[02:30] Who is Bas Von Hertom? Bas is the Cyber Security Specialist at TUV Nord. He is a lead auditor for Standards including ISO 27001, ISO 42001, TISAX and standards specifically for industrial automation.

Bas had once stated around 5 years ago that he would never pursue a career in auditing, but once he came into contact with TUV Nord he decided to give it a go. Before joining TUV, he was a very hands-on systems administrator and many of those skills transferred well into auditing.

[04:45] Who are TUV Nord? TUV Nord are a UKAS accredited Certification Body. They also offer services for testing and inspection.

TUV have worked with a large range of sectors, from manufacturing and energy to IT, healthcare and even space.

[06:25] What are ISO 27001 and ISO 42001? ISO 27001 is the Standard for Information Security Management, with compliant management systems being called an ISMS. It provides structure for identifying, assessing, and managing risks related to the information security while also ensuring availability and resilience on the information security.

ISO 42001 AI Management is a much more recent Standard, being published in December of 2024. It focuses on ethical and effective AI management, with a system that applies to relevant products in addition to the wider business.

[07:30] How does ISO 42001 support regulatory frameworks such as the EU AI Act? The EU AI Act sets out legal obligations that organisations offering AI products must comply with, however it only defines the rules rather than providing any implementation guidance.

This is where ISO 42001 can fill the gaps, by providing a framework that will meet these regulatory requirements.

[08:45] How do ISO 27001 and ISO 42001 differ in managing information security risks? Both Standards take a risk-based approach to their subject matter, but the nature of the risks that each address are what differ.

ISO 27001 focuses on risks that relate to the protection of information assets based on confidentiality, integrity and availability of information. It’s also ensures that business objectives are clearly defined and aligned with business strategy.

ISO 42001 on the other hand deals with a broader and more complex set of risks, because it also looks at ethical considerations. This can includes the monitoring and measurement of ethical risks such as AI bias and discrimination. It also looks at societal, legal and reputational risks as one of ISO 42001’s key values is creating trust within the AI space.

[10:10] Other key differences between ISO 27001 and ISO 42001: Besides their subject matter, another key difference is the way objectives are framed and evaluated. In ISO 42001 these objectives have to be aligned with the Annexes within the Standard, which is something not commonly done when implementing ISO 27001.

ISO 42001 also requires an ‘AI Impact Assessment’, which again, aligns with the systems objectives as the results of the AI Impact Assessment will describe the way bias, ethical and societal considerations impact other requirements within ISO 42001.

[11:00] How much more work is involved for Implementing ISO 42001 if you already have ISO 27001 in place? If you already have ISO 27001 in place, you have a strong foundation for ISO 42001. ISO 27001 puts the fundamental base in place, with a governance structure, risk assessment processes, internal audits, corrective actions and methods for continual improvement.

There’s a lot of overlap where the high-level requirements are concerned. However, ISO 42001 also looks at AI products and services, which differs from ISO 27001.  

ISO 42001 may also require additional training for those involved with the management systems and the AI products and services.

[12:15] Can ISO 27001 and ISO 42001 be integrated? Yes, and in fact, Bas highly encourages it!

If you intend to implement both Standards, it’s much more efficient to do so as an integrated management system. They both utilise the Annex SL format, a high-level structure that’s shared with most ISO Standards, so they’re designed to be integrated.

This also saves on duplication of effort where documentation is concerned and also potentially on cost if you require additional support with implementation.

[13:30] What organisations should be implementing both Standards? Both ISO 27001 and ISO 42001 can apply to any business.

Most businesses are now utilising AI in some form, and ISO 42001 can apply to those using it just as much as it does to those developing their own AI tools or selling related services.

However, sectors where ISO 42001 will likely become fundamental include the financial sector, where AI tools for fraud detection are becoming popular. There’s also a growing need for it within the medical field as AI is increasingly used for research and development.

[14:30] How are Certification Bodies quoting for ISO 27001 and ISO 42001? There are a number of variables that Certification Bodies use to work out certification costs, these include size of the organisation and business complexity.

This can be tricky to calculate for ISO 42001 as you need to consider the amount of AI systems used before you can provide a quote. The full requirements for this are described in ISO 42006, which is a guidance Standard.

Most certification bodies will offer a discount for the combined certification to both Standards.

An integrated approach is certainly something that Bas recommends, in addition to ensuring that you keep the same auditor or audit team throughout the implementation. By having one team for both systems, you can complete combined internal audits to save on time and resources.  

[16:20] Bas’s advice to leadership teams looking to build a case for full certification: First of all, don’t wait, just make a start.

A lot of businesses make the mistake of waiting until it’s a common requirement within their market, which can leave you lagging behind the curve. Instead, strive to be one of the early adopters as that will give you a strategic advantage in the market.

This is especially the case if you already have ISO 27001 in place. You already have the foundational knowledge to implement ISO 42001, so just make a start on looking at risks relevant to ISO 42001.

Many businesses opt to implement certain Standard due to the demands of their clients, and ISO 42001 is likely to be added to that list. So it’s better to get a head start!

Bas also recommends finding sources of guidance on ISO 42001 implementation. Whether that’s sourcing training or an external party to advise, it’s good to have other sources of knowledge of you’re not familiar with the Standard or ISO implementation as a whole.

[21:30] Bas’s favourite quote: We don't rise to the level of our expectation, but we fall to the level of the systems that we use.

If you’d like to find out more TUV Nord or are looking for ISO 27001 and ISO 42001 certification, check out their website.

We’d love to hear your views and comments about the ISO Show, here’s how:

     Share the ISO Show on Twitter or Linkedin

     Leave an honest review on iTunes or Soundcloud. Your ratings and reviews really help and we read each one.

Subscribe to keep up-to-date with our latest episodes:

Stitcher | Spotify | YouTube |iTunes | Soundcloud | Mailing List