Skip to content
arrow_back

swap_horizFree crosswalk tool

ISO 27001 to ISO 42001

Where the information security controls of ISO/IEC 27001:2022 meet the AI management controls of ISO/IEC 42001:2023. Useful when you already hold ISO 27001 and are adding AI governance on top.

39 of the 93 ISO 27001 controls (42%) have at least one ISO 42001 counterpart, giving 107 control-to-control relationships across 36 distinct ISO 42001 controls. Coverage is deliberately partial: ISO 42001 governs AI specifically, so most ISO 27001 controls have no counterpart and are shown as such.

These relationships are generated from the Control Stack catalogue and reviewed for topic fidelity, then labelled with how the two controls relate rather than asserted as equivalent. Where no counterpart exists, the row says so plainly instead of stretching for a match. Some rows are read from the other framework’s own mappings, so the wording of those summaries leads with that side.

Control Stack is a free Australian reference covering 1,423 cyber security controls: all 1,143 ASD ISM controls, 149 Essential Eight controls across all four maturity levels, all 93 ISO/IEC 27001:2022 Annex A controls and all 38 ISO/IEC 42001:2023 Annex A controls. Every one of them is cross-mapped between the four frameworks and readable in full without an account.

Reviewed 16 September 2026 · Maps ISO/IEC 27001:2022 Annex A to ISO/IEC 42001:2023 Annex A

ISO 27001 to ISO 42001

ISO 27001 controlGroupISO 42001 counterparts
Annex A 5.1
Policies for information security
Organisational controls
  • Annex A 2.2Depends on
    AI Policy
  • Annex A 2.3Partially overlaps
    Alignment with Other Organisational Policies
  • Annex A 2.4Partially overlaps
    Review the AI Policy at Planned Intervals to Keep It Effective
  • Annex A 5.3Depends on
    Document and Retain AI Impact Assessment Results
  • Annex A 6.1.2Depends on
    Objectives for Responsible Development of AI Systems
  • Annex A 6.2.2Depends on
    AI System Requirements and Specification
  • Annex A 9.2Depends on
    Define and Document Processes for Responsible Use of AI Systems
  • Annex A 9.3Depends on
    Objectives for Responsible Use of AI System
  • Annex A 10.3Depends on
    Manage Suppliers to Support Responsible AI Use
  • Annex A 10.4Depends on
    Consider Customer Expectations and Needs When Using AI
Annex A 5.2
Defining Information Security Roles and Responsibilities
Organisational controls
  • Annex A 3.2Partially overlaps
    Define and Allocate AI Roles and Responsibilities
  • Annex A 4.6Partially overlaps
    Document the People and Skills Running Your AI System
  • Annex A 10.2Partially overlaps
    Allocating Responsibilities
  • Annex A 10.4Partially overlaps
    Consider Customer Expectations and Needs When Using AI
Annex A 5.3
Segregation of Duties
Organisational controls
  • Annex A 3.2Depends on
    Define and Allocate AI Roles and Responsibilities
Annex A 5.4
Management responsibilities for information security
Organisational controls
  • Annex A 2.2Depends on
    AI Policy
  • Annex A 2.3Depends on
    Alignment with Other Organisational Policies
  • Annex A 9.2Depends on
    Define and Document Processes for Responsible Use of AI Systems
Annex A 5.5
Establish and Maintain Contact with Authorities
Organisational controls
  • Annex A 5.5Depends on
    Assess and Document AI Societal Impacts Across the Life Cycle
  • Annex A 8.4Depends on
    Document a Plan for Communicating Incidents to AI System Users
  • Annex A 8.5Depends on
    Determine and Document AI Reporting Obligations to Interested Parties
Annex A 5.6
Contact with special interest groups
Organisational controlsNo direct ISO 42001 equivalent
Annex A 5.7
Threat Intelligence Collection and Analysis
Organisational controls
  • Annex A 6.2.6Depends on
    Defining and Documenting Ongoing AI System Operation Requirements
Annex A 5.8
Information security in project management
Organisational controls
  • Annex A 3.2Depends on
    Define and Allocate AI Roles and Responsibilities
  • Annex A 5.5Depends on
    Assess and Document AI Societal Impacts Across the Life Cycle
  • Annex A 6.2.2Partially overlaps
    AI System Requirements and Specification
  • Annex A 10.4Depends on
    Consider Customer Expectations and Needs When Using AI
Annex A 5.9
Inventory management of information and associated assets
Organisational controls
  • Annex A 4.3Partially overlaps
    Document the Data Resources Used by Your AI System
  • Annex A 4.4Partially overlaps
    Document the Tooling Resources Used for AI Systems
Annex A 5.10
Acceptable Use Policies for Information and Assets
Organisational controls
  • Annex A 2.3Partially overlaps
    Alignment with Other Organisational Policies
  • Annex A 7.2Depends on
    Data for Development and Enhancement of AI System
  • Annex A 9.2Partially overlaps
    Define and Document Processes for Responsible Use of AI Systems
  • Annex A 9.4Depends on
    Intended Use of the AI System
  • Annex A 10.3Partially overlaps
    Manage Suppliers to Support Responsible AI Use
Annex A 5.11
Return of Organisation's Assets upon Departure
Organisational controlsNo direct ISO 42001 equivalent
Annex A 5.12
Information Classification Policy and Practices
Organisational controls
  • Annex A 2.3Partially overlaps
    Alignment with Other Organisational Policies
  • Annex A 4.3Depends on
    Document the Data Resources Used by Your AI System
  • Annex A 7.2Depends on
    Data for Development and Enhancement of AI System
  • Annex A 7.3Depends on
    Acquisition and Selection of Data
  • Annex A 7.6Depends on
    Data Preparation
  • Annex A 8.5Depends on
    Determine and Document AI Reporting Obligations to Interested Parties
  • Annex A 10.3Depends on
    Manage Suppliers to Support Responsible AI Use
Annex A 5.13
Labelling of Information
Organisational controls
  • Annex A 4.3Depends on
    Document the Data Resources Used by Your AI System
  • Annex A 7.3Depends on
    Acquisition and Selection of Data
Annex A 5.14
Information Transfer Policies and Procedures
Organisational controls
  • Annex A 6.2.7Depends on
    Provide AI System Technical Documentation to Interested Parties
  • Annex A 9.4Partially overlaps
    Intended Use of the AI System
  • Annex A 10.3Depends on
    Manage Suppliers to Support Responsible AI Use
Annex A 5.15
Access Control Policies and Procedures
Organisational controlsNo direct ISO 42001 equivalent
Annex A 5.16
Identity life cycle management
Organisational controlsNo direct ISO 42001 equivalent
Annex A 5.17
Management of Authentication Information
Organisational controlsNo direct ISO 42001 equivalent
Annex A 5.18
Managing Access Rights to Information Assets
Organisational controlsNo direct ISO 42001 equivalent
Annex A 5.19
Managing Information Security in Supplier Relationships
Organisational controls
  • Annex A 7.3Depends on
    Acquisition and Selection of Data
  • Annex A 10.2Depends on
    Allocating Responsibilities
  • Annex A 10.3Partially overlaps
    Manage Suppliers to Support Responsible AI Use
Annex A 5.20
Integrating security clauses in supplier agreements
Organisational controls
  • Annex A 10.2Depends on
    Allocating Responsibilities
  • Annex A 10.3Partially overlaps
    Manage Suppliers to Support Responsible AI Use
Annex A 5.21
Managing Information Security in the ICT Supply Chain
Organisational controls
  • Annex A 7.3Depends on
    Acquisition and Selection of Data
  • Annex A 10.3Partially overlaps
    Manage Suppliers to Support Responsible AI Use
Annex A 5.22
Monitoring and Managing Supplier Services
Organisational controls
  • Annex A 4.3Depends on
    Document the Data Resources Used by Your AI System
  • Annex A 10.3Depends on
    Manage Suppliers to Support Responsible AI Use
Annex A 5.23
Cloud Service Security Management
Organisational controls
  • Annex A 6.2.2Partially overlaps
    AI System Requirements and Specification
Annex A 5.24
Information security incident management planning and preparation
Organisational controls
  • Annex A 3.2Partially overlaps
    Define and Allocate AI Roles and Responsibilities
  • Annex A 3.3Depends on
    Process for Reporting Concerns About AI Systems
  • Annex A 6.1.3Partially overlaps
    Processes for Responsible AI System Design and Development
  • Annex A 8.4Broader than
    Document a Plan for Communicating Incidents to AI System Users
Annex A 5.25
Assessment and decision on information security events
Organisational controlsNo direct ISO 42001 equivalent
Annex A 5.26
Response to Information Security Incidents
Organisational controlsNo direct ISO 42001 equivalent
Annex A 5.27
Learning from information security incidents
Organisational controlsNo direct ISO 42001 equivalent
Annex A 5.28
Procedures for Collecting and Preserving Evidence
Organisational controls
Annex A 5.29
Maintain information security during disruptions
Organisational controlsNo direct ISO 42001 equivalent
Annex A 5.30
ICT Readiness for Business Continuity
Organisational controlsNo direct ISO 42001 equivalent
Annex A 5.31
Compliance with Information Security Legal Requirements
Organisational controls
  • Annex A 2.3Depends on
    Alignment with Other Organisational Policies
  • Annex A 5.2Depends on
    AI System Impact Assessment Process
  • Annex A 5.5Depends on
    Assess and Document AI Societal Impacts Across the Life Cycle
  • Annex A 6.2.2Depends on
    AI System Requirements and Specification
  • Annex A 8.5Partially overlaps
    Determine and Document AI Reporting Obligations to Interested Parties
  • Annex A 10.3Partially overlaps
    Manage Suppliers to Support Responsible AI Use
  • Annex A 10.4Depends on
    Consider Customer Expectations and Needs When Using AI
Annex A 5.32
Intellectual Property Rights Protection
Organisational controlsNo direct ISO 42001 equivalent
Annex A 5.33
Protection of Records
Organisational controls
  • Annex A 4.3Depends on
    Document the Data Resources Used by Your AI System
  • Annex A 5.3Partially overlaps
    Document and Retain AI Impact Assessment Results
  • Annex A 6.2.7Depends on
    Provide AI System Technical Documentation to Interested Parties
  • Annex A 7.5Depends on
    Data Provenance
Annex A 5.34
Privacy and Protection of Personally Identifiable Information
Organisational controls
  • Annex A 4.3Partially overlaps
    Document the Data Resources Used by Your AI System
  • Annex A 5.2Partially overlaps
    AI System Impact Assessment Process
  • Annex A 5.4Partially overlaps
    Assess and Document AI Impacts on Individuals and Groups
  • Annex A 8.5Partially overlaps
    Determine and Document AI Reporting Obligations to Interested Parties
  • Annex A 10.3Partially overlaps
    Manage Suppliers to Support Responsible AI Use
  • Annex A 10.4Partially overlaps
    Consider Customer Expectations and Needs When Using AI
Annex A 5.35
Independent review of information security
Organisational controls
  • Annex A 2.4Depends on
    Review the AI Policy at Planned Intervals to Keep It Effective
Annex A 5.36
Review compliance with information security policies
Organisational controls
  • Annex A 2.2Depends on
    AI Policy
  • Annex A 2.3Depends on
    Alignment with Other Organisational Policies
  • Annex A 2.4Partially overlaps
    Review the AI Policy at Planned Intervals to Keep It Effective
  • Annex A 9.3Depends on
    Objectives for Responsible Use of AI System
  • Annex A 10.3Depends on
    Manage Suppliers to Support Responsible AI Use
Annex A 5.37
Documented Operating Procedures for Information Processing
Organisational controls
  • Annex A 4.4Depends on
    Document the Tooling Resources Used for AI Systems
  • Annex A 7.2Depends on
    Data for Development and Enhancement of AI System
  • Annex A 7.6Depends on
    Data Preparation
  • Annex A 9.2Depends on
    Define and Document Processes for Responsible Use of AI Systems
Annex A 6.1
Personnel Background Verification
People controlsNo direct ISO 42001 equivalent
Annex A 6.2
Terms and conditions of employment for security
People controlsNo direct ISO 42001 equivalent
Annex A 6.3
Information security awareness, education and training program
People controls
  • Annex A 4.6Depends on
    Document the People and Skills Running Your AI System
  • Annex A 8.2Partially overlaps
    Provide Users the Information They Need to Use the AI System
Annex A 6.4
Disciplinary Process for Information Security Violations
People controlsNo direct ISO 42001 equivalent
Annex A 6.5
Responsibilities after employment termination or role change
People controlsNo direct ISO 42001 equivalent
Annex A 6.6
Confidentiality and Non-disclosure Agreements
People controlsNo direct ISO 42001 equivalent
Annex A 6.7
Remote Working Security Measures
People controlsNo direct ISO 42001 equivalent
Annex A 6.8
Mechanisms for Reporting Security Events
People controls
  • Annex A 3.3Partially overlaps
    Process for Reporting Concerns About AI Systems
  • Annex A 8.3Partially overlaps
    External Reporting
  • Annex A 8.5Partially overlaps
    Determine and Document AI Reporting Obligations to Interested Parties
Annex A 7.1
Physical Security Perimeters
Physical controlsNo direct ISO 42001 equivalent
Annex A 7.2
Physical access controls for secure areas
Physical controlsNo direct ISO 42001 equivalent
Annex A 7.3
Physical Security for Offices and Facilities
Physical controlsNo direct ISO 42001 equivalent
Annex A 7.4
Continuous monitoring of physical access to premises
Physical controlsNo direct ISO 42001 equivalent
Annex A 7.5
Protecting against physical and environmental threats
Physical controlsNo direct ISO 42001 equivalent
Annex A 7.6
Security Measures for Working in Secure Areas
Physical controlsNo direct ISO 42001 equivalent
Annex A 7.7
Clear desk and clear screen policies
Physical controlsNo direct ISO 42001 equivalent
Annex A 7.8
Equipment Siting and Protection
Physical controlsNo direct ISO 42001 equivalent
Annex A 7.9
Security of Off-Site Assets
Physical controlsNo direct ISO 42001 equivalent
Annex A 7.10
Secure Management of Storage Media
Physical controls
Annex A 7.11
Protection from Utility Failures
Physical controlsNo direct ISO 42001 equivalent
Annex A 7.12
Secure Cabling for Power and Data
Physical controlsNo direct ISO 42001 equivalent
Annex A 7.13
Proper Maintenance of Equipment
Physical controlsNo direct ISO 42001 equivalent
Annex A 7.14
Secure disposal or re-use of equipment
Physical controlsNo direct ISO 42001 equivalent
Annex A 8.1
Protection of User Endpoint Devices
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.2
Management of Privileged Access Rights
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.3
Restrict access to information and assets
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.4
Access management for source code and tools
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.5
Secure authentication technologies and procedures
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.6
Capacity Management for Resource Use
Technological controls
  • Annex A 6.2.6Partially overlaps
    Defining and Documenting Ongoing AI System Operation Requirements
Annex A 8.7
Protection against malware
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.8
Management of Technical Vulnerabilities
Technological controls
Annex A 8.9
Configuration Management for Secure IT Systems
Technological controls
Annex A 8.10
Secure deletion of information when no longer needed
Technological controls
  • Annex A 5.3Partially overlaps
    Document and Retain AI Impact Assessment Results
Annex A 8.11
Data Masking for Sensitive Information
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.12
Data Leakage Prevention Measures
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.13
Backup and Recovery Procedures for Data
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.14
Redundancy of Information Processing Facilities
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.15
Logging of Activities and Events
Technological controls
Annex A 8.16
Monitoring Networks and Systems for Anomalous Behaviour
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.17
Clock synchronisation for information systems
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.18
Use of Privileged Utility Programs
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.19
Secure Software Installation Procedures
Technological controls
  • Annex A 6.2.6Depends on
    Defining and Documenting Ongoing AI System Operation Requirements
Annex A 8.20
Network and Network Devices Security
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.21
Security of Network Services
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.22
Network Segregation for Security
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.23
Web Filtering to Reduce Malicious Website Exposure
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.24
Effective Use of Cryptography and Key Management
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.25
Secure Development Lifecycle
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.26
Defining Security Requirements for Applications
Technological controls
  • Annex A 6.2.2Partially overlaps
    AI System Requirements and Specification
Annex A 8.27
Secure system architecture and engineering principles
Technological controls
  • Annex A 6.2.3Partially overlaps
    Documentation of AI System Design and Development
Annex A 8.28
Secure Coding Practices in Software Development
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.29
Security testing in development and acceptance
Technological controls
  • Annex A 6.2.4Partially overlaps
    AI System Verification and Validation
Annex A 8.30
Management of Outsourced System Development
Technological controls
Annex A 8.31
Separation of Development, Test, and Production Environments
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.32
Change management procedures for information systems
Technological controls
  • Annex A 6.2.6Partially overlaps
    Defining and Documenting Ongoing AI System Operation Requirements
  • Annex A 7.4Depends on
    Quality of Data for AI Systems
Annex A 8.33
Test Information Selection and Protection
Technological controlsNo direct ISO 42001 equivalent
Annex A 8.34
Protection of information systems during audits
Technological controlsNo direct ISO 42001 equivalent

How to use this mapping

Read it in whichever direction you are being assessed. If ISO 27001 is your primary framework, use the table to find the ISO 42001 controls that cover the same ground, so evidence you already hold can be reused instead of rebuilt. If ISO 42001 is what you are being held to, work back from the counterpart column to see which ISO 27001 controls contribute. A mapping means the two controls address related risk, not that satisfying one satisfies the other, so always read the relationship label before relying on it.

Frequently asked questions

Why do most ISO 27001 controls have no ISO 42001 counterpart?

Because the two standards cover different subjects. ISO/IEC 27001:2022 manages information security across the whole organisation, while ISO/IEC 42001:2023 manages artificial intelligence, with 38 Annex A controls concentrated on AI impact assessment, data provenance, the AI system life cycle and transparency. Only the parts of ISO 27001 that touch those areas have a counterpart, so a blank row is the expected result rather than a gap in the data.

Can I reuse my ISO 27001 management system for ISO 42001?

Largely, yes. Both standards share the harmonised clause structure, so the internal audit program, management review, document control, corrective action process and much of the supplier and incident work can be extended rather than rebuilt. The scopes, risk assessments, Statements of Applicability and certificates stay separate, and each standard is audited on its own terms.

What does ISO 42001 add that ISO 27001 does not have?

The AI system impact assessment is the clearest difference. ISO 27001 assesses risk to the organisation, while ISO 42001 also requires you to assess consequences for individuals, groups and societies across the AI system life cycle. It also adds requirements on data provenance and quality, documentation for users of an AI system, and responsible use of third-party AI.

Is this mapping official?

No. ISO does not publish a control-level crosswalk between these two standards. This mapping is produced by Control Stack from the control text of both and reviewed for topic fidelity, and it is the thinnest of the crosswalks on this site because ISO 42001 is the newest and least mapped framework in the catalogue. Read the relationship label on each pairing before relying on it.