ComplianceISO 27001AI companies
ISO 27001 · AI Companies

ISO 27001 and ISO 42001 for AI Companies

The Short Answer

ISO 27001 comes first. It answers the security half of every AI vendor review — access, logging, incidents, suppliers — and it is what buyers can verify today. ISO 42001, the AI management system standard, extends the same machinery, and is added once buyers start asking for it.

The questions AI companies get that other vendors do not

AI vendors receive the standard security review plus a second set of questions procurement is still developing.

The first set is predictable: access control, logging, incident response, supplier management, all answered by the same ISO 27001 machinery. The second set covers the provenance of training data and whether customer data enters it; which people and which systems can call, modify or extract the models, given that pipelines, agents and integrations hold model access; and, for agentic products, what the system did in a specific case and why.

Buyer question Where it lands
“Who can access customer data?” Standard ISO 27001 — access control, evidenced through your ISMS
“How do you handle security incidents?” Standard ISO 27001 — incident management with records
“Does customer data train your models?” AI-specific, answered by ISO 27001 mechanics: classification and documented data flows
“Who and what can reach the model?” AI-specific, and still access control, with models, weights and pipelines on the asset list
“What did the AI do, and why?” New — an audit trail of model and agent actions, which a standard stack does not produce by default

Most AI questions are security questions applied to a wider asset list. Training data handling is classification plus data flow documentation. Model access is access control. Only the final row requires a control family that does not already exist: evidencing AI behaviour takes security built for the AI systems themselves, logging and monitoring the models and agents rather than the servers they run on. That question has its own page — how do you prove what an AI system did — and the full picture of what regulators, auditors and customers ask AI vendors is in our AI governance guide.

ISO 27001 first, ISO 42001 when buyers ask

ISO 42001 is the AI management system standard. The sequence that works is ISO 27001 first, for three reasons.

It is what procurement can verify today. Every security review this year contains an ISO 27001-shaped section, and certification answers it outright. ISO 42001 sections remain the exception, and an ISO 27001 base is the position to answer them from.

It carries most of the load. As the table shows, most AI questions resolve into information security controls a certified ISMS already operates.

ISO 42001 builds on the same machinery. A management system standard requires scope, risk assessment, internal audit and management review. Built once for ISO 27001, the AI management layer is an extension. Built for 42001 first, the same machinery is constructed without the certificate buyers are currently asking for.

The resulting sequence: certify ISO 27001 with AI assets — models, weights, training data, pipelines — explicitly in scope; start producing the AI audit trail immediately, because behaviour history cannot be reconstructed retrospectively; and add ISO 42001 once buyers ask, on top of a running system.

Most AI companies are also startups, and ISO 27001 for Australian SaaS startups applies with more weight: the small scope remains an advantage, and the post-audit ownership problem is more acute, because the asset list is less familiar and the reviewers are more cautious. Cost mechanics are unchanged — what ISO 27001 costs in Australia has the market breakdown.

AI vendors fail the ordinary section, not the exotic one

Deferring certification until the AI standards settle costs deals in the meantime, because the reviews are running now. AI vendors are already fielding every question in the table above, and the failures are concentrated in the conventional controls: no access logging on model endpoints, no supplier assessment covering model providers, no incident process that contemplates the product acting incorrectly on its own.

The AI review is mostly the security review, and the security review is standardised, certifiable and available today. Once the evidence trail exists, the unsettled part carries less risk, because a system that records what the AI did can answer questions that have not been written yet.

How Secure60 handles this

Secure60 delivers the certification and operates the security behind it. For an AI company that covers the ISMS through to certification, the security operations an auditor samples, and the AI layer — monitoring the models and agents themselves, so the behaviour question has evidence behind it. We run AI in our own security operations and hold ISO 27001:2022 certification, so we have answered these questionnaires from both sides. Commercials are scoped on a readiness call.

Frequently Asked Questions

Do we need ISO 42001 before ISO 27001?

No. ISO 27001 comes first. It answers the security half of every AI vendor review today, and its management-system machinery is the base ISO 42001 extends. Add 42001 once buyers start asking for it.

What is ISO 42001?

The AI management system standard. Where ISO 27001 governs information security, ISO 42001 governs how AI systems are managed. It is the standard buyers name once their AI questions outgrow the security review.

Are our models and training data in scope for ISO 27001?

They should be. They are information assets, and scoping them out invites the questions hardest to answer without preparation. Access control, classification and supplier assessments extend to them directly.

How do we answer what an AI system did, and why?

With an audit trail of model and agent actions, retained the way security logs are retained. A standard stack does not produce this by default — see how you prove what an AI system did.

Can AI agents help run the security side itself?

Yes, and that is how we run our own operations. See can AI agents run security operations for what they do and where humans stay in the loop.

What does certification cost for an AI company?

The market components match those for any company of the same size — see what ISO 27001 costs in Australia. The AI-specific work is scoping and evidence design rather than additional invoices.

Corporate Certification With Governed AI Adoption

A readiness call scopes ISO 27001 for the organisation and maps the AI-specific questions buyers ask next.

30 days, every feature switched on. No credit card.