swap_horizFree crosswalk tool
ISO 27001 to ISO 42001
Where the information security controls of ISO/IEC 27001:2022 meet the AI management controls of ISO/IEC 42001:2023. Useful when you already hold ISO 27001 and are adding AI governance on top.
39 of the 93 ISO 27001 controls (42%) have at least one ISO 42001 counterpart, giving 107 control-to-control relationships across 36 distinct ISO 42001 controls. Coverage is deliberately partial: ISO 42001 governs AI specifically, so most ISO 27001 controls have no counterpart and are shown as such.
These relationships are generated from the Control Stack catalogue and reviewed for topic fidelity, then labelled with how the two controls relate rather than asserted as equivalent. Where no counterpart exists, the row says so plainly instead of stretching for a match. Some rows are read from the other framework’s own mappings, so the wording of those summaries leads with that side.
Control Stack is a free Australian reference covering 1,423 cyber security controls: all 1,143 ASD ISM controls, 149 Essential Eight controls across all four maturity levels, all 93 ISO/IEC 27001:2022 Annex A controls and all 38 ISO/IEC 42001:2023 Annex A controls. Every one of them is cross-mapped between the four frameworks and readable in full without an account.
Reviewed 16 September 2026 · Maps ISO/IEC 27001:2022 Annex A to ISO/IEC 42001:2023 Annex A
ISO 27001 to ISO 42001
| ISO 27001 control | Group | ISO 42001 counterparts |
|---|---|---|
| Annex A 5.1 Policies for information security | Organisational controls |
|
| Annex A 5.2 Defining Information Security Roles and Responsibilities | Organisational controls |
|
| Annex A 5.3 Segregation of Duties | Organisational controls |
|
| Annex A 5.4 Management responsibilities for information security | Organisational controls |
|
| Annex A 5.5 Establish and Maintain Contact with Authorities | Organisational controls |
|
| Annex A 5.6 Contact with special interest groups | Organisational controls | No direct ISO 42001 equivalent |
| Annex A 5.7 Threat Intelligence Collection and Analysis | Organisational controls |
|
| Annex A 5.8 Information security in project management | Organisational controls |
|
| Annex A 5.9 Inventory management of information and associated assets | Organisational controls |
|
| Annex A 5.10 Acceptable Use Policies for Information and Assets | Organisational controls |
|
| Annex A 5.11 Return of Organisation's Assets upon Departure | Organisational controls | No direct ISO 42001 equivalent |
| Annex A 5.12 Information Classification Policy and Practices | Organisational controls |
|
| Annex A 5.13 Labelling of Information | Organisational controls |
|
| Annex A 5.14 Information Transfer Policies and Procedures | Organisational controls |
|
| Annex A 5.15 Access Control Policies and Procedures | Organisational controls | No direct ISO 42001 equivalent |
| Annex A 5.16 Identity life cycle management | Organisational controls | No direct ISO 42001 equivalent |
| Annex A 5.17 Management of Authentication Information | Organisational controls | No direct ISO 42001 equivalent |
| Annex A 5.18 Managing Access Rights to Information Assets | Organisational controls | No direct ISO 42001 equivalent |
| Annex A 5.19 Managing Information Security in Supplier Relationships | Organisational controls |
|
| Annex A 5.20 Integrating security clauses in supplier agreements | Organisational controls |
|
| Annex A 5.21 Managing Information Security in the ICT Supply Chain | Organisational controls |
|
| Annex A 5.22 Monitoring and Managing Supplier Services | Organisational controls |
|
| Annex A 5.23 Cloud Service Security Management | Organisational controls |
|
| Annex A 5.24 Information security incident management planning and preparation | Organisational controls |
|
| Annex A 5.25 Assessment and decision on information security events | Organisational controls | No direct ISO 42001 equivalent |
| Annex A 5.26 Response to Information Security Incidents | Organisational controls | No direct ISO 42001 equivalent |
| Annex A 5.27 Learning from information security incidents | Organisational controls | No direct ISO 42001 equivalent |
| Annex A 5.28 Procedures for Collecting and Preserving Evidence | Organisational controls |
|
| Annex A 5.29 Maintain information security during disruptions | Organisational controls | No direct ISO 42001 equivalent |
| Annex A 5.30 ICT Readiness for Business Continuity | Organisational controls | No direct ISO 42001 equivalent |
| Annex A 5.31 Compliance with Information Security Legal Requirements | Organisational controls |
|
| Annex A 5.32 Intellectual Property Rights Protection | Organisational controls | No direct ISO 42001 equivalent |
| Annex A 5.33 Protection of Records | Organisational controls |
|
| Annex A 5.34 Privacy and Protection of Personally Identifiable Information | Organisational controls |
|
| Annex A 5.35 Independent review of information security | Organisational controls |
|
| Annex A 5.36 Review compliance with information security policies | Organisational controls |
|
| Annex A 5.37 Documented Operating Procedures for Information Processing | Organisational controls |
|
| Annex A 6.1 Personnel Background Verification | People controls | No direct ISO 42001 equivalent |
| Annex A 6.2 Terms and conditions of employment for security | People controls | No direct ISO 42001 equivalent |
| Annex A 6.3 Information security awareness, education and training program | People controls |
|
| Annex A 6.4 Disciplinary Process for Information Security Violations | People controls | No direct ISO 42001 equivalent |
| Annex A 6.5 Responsibilities after employment termination or role change | People controls | No direct ISO 42001 equivalent |
| Annex A 6.6 Confidentiality and Non-disclosure Agreements | People controls | No direct ISO 42001 equivalent |
| Annex A 6.7 Remote Working Security Measures | People controls | No direct ISO 42001 equivalent |
| Annex A 6.8 Mechanisms for Reporting Security Events | People controls |
|
| Annex A 7.1 Physical Security Perimeters | Physical controls | No direct ISO 42001 equivalent |
| Annex A 7.2 Physical access controls for secure areas | Physical controls | No direct ISO 42001 equivalent |
| Annex A 7.3 Physical Security for Offices and Facilities | Physical controls | No direct ISO 42001 equivalent |
| Annex A 7.4 Continuous monitoring of physical access to premises | Physical controls | No direct ISO 42001 equivalent |
| Annex A 7.5 Protecting against physical and environmental threats | Physical controls | No direct ISO 42001 equivalent |
| Annex A 7.6 Security Measures for Working in Secure Areas | Physical controls | No direct ISO 42001 equivalent |
| Annex A 7.7 Clear desk and clear screen policies | Physical controls | No direct ISO 42001 equivalent |
| Annex A 7.8 Equipment Siting and Protection | Physical controls | No direct ISO 42001 equivalent |
| Annex A 7.9 Security of Off-Site Assets | Physical controls | No direct ISO 42001 equivalent |
| Annex A 7.10 Secure Management of Storage Media | Physical controls |
|
| Annex A 7.11 Protection from Utility Failures | Physical controls | No direct ISO 42001 equivalent |
| Annex A 7.12 Secure Cabling for Power and Data | Physical controls | No direct ISO 42001 equivalent |
| Annex A 7.13 Proper Maintenance of Equipment | Physical controls | No direct ISO 42001 equivalent |
| Annex A 7.14 Secure disposal or re-use of equipment | Physical controls | No direct ISO 42001 equivalent |
| Annex A 8.1 Protection of User Endpoint Devices | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.2 Management of Privileged Access Rights | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.3 Restrict access to information and assets | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.4 Access management for source code and tools | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.5 Secure authentication technologies and procedures | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.6 Capacity Management for Resource Use | Technological controls |
|
| Annex A 8.7 Protection against malware | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.8 Management of Technical Vulnerabilities | Technological controls |
|
| Annex A 8.9 Configuration Management for Secure IT Systems | Technological controls |
|
| Annex A 8.10 Secure deletion of information when no longer needed | Technological controls |
|
| Annex A 8.11 Data Masking for Sensitive Information | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.12 Data Leakage Prevention Measures | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.13 Backup and Recovery Procedures for Data | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.14 Redundancy of Information Processing Facilities | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.15 Logging of Activities and Events | Technological controls |
|
| Annex A 8.16 Monitoring Networks and Systems for Anomalous Behaviour | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.17 Clock synchronisation for information systems | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.18 Use of Privileged Utility Programs | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.19 Secure Software Installation Procedures | Technological controls |
|
| Annex A 8.20 Network and Network Devices Security | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.21 Security of Network Services | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.22 Network Segregation for Security | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.23 Web Filtering to Reduce Malicious Website Exposure | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.24 Effective Use of Cryptography and Key Management | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.25 Secure Development Lifecycle | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.26 Defining Security Requirements for Applications | Technological controls |
|
| Annex A 8.27 Secure system architecture and engineering principles | Technological controls |
|
| Annex A 8.28 Secure Coding Practices in Software Development | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.29 Security testing in development and acceptance | Technological controls |
|
| Annex A 8.30 Management of Outsourced System Development | Technological controls |
|
| Annex A 8.31 Separation of Development, Test, and Production Environments | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.32 Change management procedures for information systems | Technological controls |
|
| Annex A 8.33 Test Information Selection and Protection | Technological controls | No direct ISO 42001 equivalent |
| Annex A 8.34 Protection of information systems during audits | Technological controls | No direct ISO 42001 equivalent |
How to use this mapping
Read it in whichever direction you are being assessed. If ISO 27001 is your primary framework, use the table to find the ISO 42001 controls that cover the same ground, so evidence you already hold can be reused instead of rebuilt. If ISO 42001 is what you are being held to, work back from the counterpart column to see which ISO 27001 controls contribute. A mapping means the two controls address related risk, not that satisfying one satisfies the other, so always read the relationship label before relying on it.
Frequently asked questions
Why do most ISO 27001 controls have no ISO 42001 counterpart?
Because the two standards cover different subjects. ISO/IEC 27001:2022 manages information security across the whole organisation, while ISO/IEC 42001:2023 manages artificial intelligence, with 38 Annex A controls concentrated on AI impact assessment, data provenance, the AI system life cycle and transparency. Only the parts of ISO 27001 that touch those areas have a counterpart, so a blank row is the expected result rather than a gap in the data.
Can I reuse my ISO 27001 management system for ISO 42001?
Largely, yes. Both standards share the harmonised clause structure, so the internal audit program, management review, document control, corrective action process and much of the supplier and incident work can be extended rather than rebuilt. The scopes, risk assessments, Statements of Applicability and certificates stay separate, and each standard is audited on its own terms.
What does ISO 42001 add that ISO 27001 does not have?
The AI system impact assessment is the clearest difference. ISO 27001 assesses risk to the organisation, while ISO 42001 also requires you to assess consequences for individuals, groups and societies across the AI system life cycle. It also adds requirements on data provenance and quality, documentation for users of an AI system, and responsible use of third-party AI.
Is this mapping official?
No. ISO does not publish a control-level crosswalk between these two standards. This mapping is produced by Control Stack from the control text of both and reviewed for topic fidelity, and it is the thinnest of the crosswalks on this site because ISO 42001 is the newest and least mapped framework in the catalogue. Read the relationship label on each pairing before relying on it.