ComplianceISO 27001AI companies
ISO 27001 · AI companies

ISO 27001 for AI companies (and where ISO 42001 fits)

The short answer

Get ISO 27001 first. It answers the security half of every AI vendor review — access, logging, incidents, suppliers — and it’s what buyers can verify today. ISO 42001, the AI management system standard, is its AI sibling: add it when your buyers start asking, on top of the management system you already run.

The questions AI companies get that other vendors don’t

Sell software and you get the standard security review. Sell AI and you get the standard review plus a second one that procurement is still learning how to run.

The first set you can predict: access control, logging, incident response, supplier management — the same questions every vendor gets, answered by the same ISO 27001 machinery. The second set is newer and sharper. Where did your training data come from, and does customer data ever enter it? Who — and what — can call, modify or extract your models, given that pipelines, agents and integrations hold model access too? And the one that decides deals for agentic products: what did the system do in this specific case, and why?

Buyer question Where it lands
“Who can access customer data?” Standard ISO 27001 — access control, evidenced through your ISMS
“How do you handle security incidents?” Standard ISO 27001 — incident management with records
“Does customer data train your models?” AI-specific, but answered by ISO 27001 mechanics: classification and documented data flows
“Who and what can reach the model?” AI-specific, but still access control — with models, weights and pipelines on the asset list
“What did the AI do, and why?” Genuinely new — an audit trail of model and agent actions, which nothing in a standard stack produces by default

Read the table closely and the pattern shows: most AI questions are security questions wearing new clothes. Training data handling is classification plus data flow documentation. Model access is access control with a wider asset list. Only the last row needs something you don’t already have a control family for — evidencing AI behaviour takes security built for the AI systems themselves, logging and monitoring the models and agents rather than just the servers they run on. The behaviour question is big enough to have its own page: how do you prove what an AI system actually did. The full picture of what regulators, auditors and customers now ask AI vendors is in our AI governance guide.

ISO 27001 first, ISO 42001 when buyers ask

ISO 42001 is the AI management system standard — ISO 27001’s AI sibling. If you’re an AI company, someone on your board has already asked about it. The practical sequence is still ISO 27001 first, for three reasons.

It’s what procurement can verify today. Every security review you’ll face this year has an ISO 27001-shaped section, and certification answers it outright. ISO 42001 sections are still the exception, and an ISO 27001 base is the credible position to answer from when they appear.

It carries most of the load. As the table above shows, the bulk of the AI questions resolve into information security controls a certified ISMS already operates.

ISO 42001 builds on the same machinery. A management system standard means scope, risk assessment, internal audit, management review. Build that once for ISO 27001 and adding the AI management layer later is an extension. Chase 42001 first and you build the same machinery anyway — without the certificate buyers are actually asking for.

So: certify ISO 27001 with your AI assets — models, weights, training data, pipelines — explicitly in scope. Start producing the AI audit trail now, because behaviour history can’t be retrofitted. Add ISO 42001 when your buyers start asking, on top of a system that’s already running.

Most AI companies are also startups, and everything in ISO 27001 for Australian SaaS startups applies here with the volume turned up: the small scope is still your advantage, and the post-audit ownership problem is worse, because your asset list is stranger and your reviewers are more nervous. Cost mechanics don’t change — what ISO 27001 actually costs in Australia has the market breakdown.

What most people get wrong

Waiting. “We’ll wait until the AI standards settle” feels prudent and costs deals now, because the reviews aren’t waiting. AI vendors are already fielding every question in the table above — and the ones failing aren’t failing the exotic AI section. They’re failing the ordinary one: no access logging on model endpoints, no supplier assessment covering their model providers, no incident process that contemplates the product doing something wrong on its own.

The correction: the AI review is mostly the security review, and the security review is available now — standardised, certifiable, verifiable. Do the settled part. The genuinely unsettled part matters less once the evidence trail exists, because a system that records what your AI did can answer questions that haven’t been written yet.

How Secure60 handles this

Tools hand you a to-do list. We do the list — and run the security behind it. For an AI company the list has an extra column: the ISMS through to certification, the security operations an auditor samples, and the AI layer most providers can’t offer — monitoring the models and agents themselves, so the behaviour question has evidence behind it. We run AI in our own security operations and hold ISO 27001:2022 ourselves, which means we’ve answered these questionnaires from both sides of the table. Commercials are scoped on a readiness call.

Frequently asked questions

Do we need ISO 42001 before ISO 27001?

No — do ISO 27001 first. It answers the security half of every AI vendor review today, and its management-system machinery is the base ISO 42001 extends. Add 42001 when your buyers start asking for it.

What is ISO 42001?

The AI management system standard — ISO 27001’s AI sibling. Where ISO 27001 governs information security, ISO 42001 governs how you manage AI systems. It’s the standard buyers name when their AI questions outgrow the security review.

Are our models and training data in scope for ISO 27001?

They should be — they’re information assets like any other, and scoping them out invites exactly the questions you can least afford to fumble. Access control, classification and supplier assessments all extend to them naturally.

How do we answer 'what did your AI system do and why'?

With an audit trail of model and agent actions, kept the way you keep security logs. Nothing in a standard stack produces this by default — see how you prove what an AI system actually did.

Can AI agents help run the security side itself?

Yes — that’s how we run our own operations. See can AI agents run security operations for what they genuinely do and where humans stay in the loop.

What does certification cost for an AI company?

The market components are the same as for any company your size — see what ISO 27001 actually costs in Australia. The AI-specific work is mostly scoping and evidence design, not extra invoices.

Certify the company, govern the AI

Book a readiness call — we'll scope ISO 27001 for your team and map the AI-specific questions your buyers will ask next.

Book a readiness call Run a pilot