Tel +852 5382 0328 info@safeharbour.hk WhatsApp 繁體中文
Safe Harbour Consultants · Hong Kong & Macau Get a Quote
AI governance

ISO 42001 or ISO 27001 — which comes first?

Most organisations should do 27001 first, because it carries the controls that 42001 assumes exist. The exception is a firm whose client is asking specifically about AI.

The short answer

If the pressure is a security questionnaire, do 27001. If the pressure is an AI questionnaire, do the AI governance work first and add 27001 later only if the client base demands it.

What this means for you

The two share control areas — access, supplier management, incident handling, competence — so the second one is materially cheaper than the first.

If you do both

Run one integrated management system with one document set and one internal audit cycle, rather than two parallel programmes.

Delaying the decision does not remove the question — it only leaves you answering the next questionnaire with a promise instead of a certificate. Decide by what the next tender or questionnaire will actually ask for.

Start with the standard the market is already asking for.

Sources
ISO/IEC 42001:2023 — iso.org
ISO/IEC 27001:2022 — iso.org