Where Information Security Meets AI Governance: The Case for Combined ISO/IEC 27001 and ISO/IEC 42001 Audits

Consilium Labs graphic illustrating ISO/IEC 27001 and ISO/IEC 42001 audits, showing the intersection of information security, AI governance, ISMS, AIMS, and coordinated certification.

Artificial intelligence has made the boundary between information security and AI governance increasingly difficult to treat as two separate management concerns. An AI system may rely on confidential customer data, cloud infrastructure, APIs, identity controls, third-party models, logging, monitoring, and incident processes. At the same time, that same system may create additional questions about intended use, human involvement, data quality, model behavior, impact, transparency, and accountability.

That convergence is creating a stronger case for organizations to consider combined ISO/IEC 27001 and ISO/IEC 42001 audits.

ISO/IEC 27001 establishes requirements for an Information Security Management System, or ISMS, focused on managing risks to the confidentiality, integrity, and availability of information. ISO/IEC 42001 establishes requirements for an Artificial Intelligence Management System, or AIMS, addressing the responsible development, provision, and use of AI systems. ISO also presents the two standards together within an AI and information security management package, reflecting the practical relationship between these governance domains in modern organizations (International Organization for Standardization [ISO], 2022, 2023).

The standards remain distinct. But where AI systems depend on the same people, data, infrastructure, suppliers, risk processes, and management oversight already governed through an ISMS, a coordinated certification audit can examine those relationships within a common operational context while preserving the applicable requirements of each standard.

Why 2026 Is Changing the AI Governance Conversation

The regulatory and standards environment around artificial intelligence is becoming more concrete.

In the European Union, AI Act transparency requirements began applying on August 2, 2026. The European Commission and national authorities also began exercising enforcement powers on that date for provisions already applicable, while additional requirements for certain high-risk systems follow later implementation phases (European Commission, 2026).

For organizations operating AI systems, the implications extend beyond policy statements. Traceability, documentation, disclosure, system oversight, and evidence increasingly form part of the governance environment surrounding AI.

At the same time, NIST states that the AI Risk Management Framework 1.0 is being revised, and in April 2026 it released a concept note for a profile focused on trustworthy AI in critical infrastructure. NIST’s Generative AI Profile also approaches AI risk across the lifecycle rather than as a single technical event (National Institute of Standards and Technology [NIST], 2024, 2026).

The direction is significant. Cybersecurity, information governance, AI risk, supplier oversight, and management accountability are increasingly operating as interconnected evidence domains rather than isolated governance exercises.

For organizations already operating an ISMS, this raises a practical question:

Why evaluate information security and AI governance through completely disconnected audit cycles when significant parts of the management environment genuinely intersect?

What a Combined ISO/IEC 27001 and ISO/IEC 42001 Audit Actually Means

A combined audit does not merge ISO/IEC 27001 and ISO/IEC 42001.

Each standard retains its own requirements, applicable scope, audit criteria, evidence expectations, findings, and conformity determination. Coordinating the audits does not create a new hybrid ISO standard.

Instead, a coordinated approach recognizes areas where the organization operates integrated management processes and allows those processes to be evaluated coherently while preserving the integrity of the criteria applicable to each standard.

The International Accreditation Forum’s mandatory document for audits of integrated management systems requires audit planning to consider the organization’s level of management-system integration while ensuring that applicable requirements from each management-system standard are adequately covered by competent auditors (International Accreditation Forum [IAF], 2023).

Where ISO/IEC 27001 and ISO/IEC 42001 are audited together, the extent to which integrated-audit principles apply therefore depends on how far the organization has actually integrated its management systems.

Integration can influence how an audit is organized.

It does not remove requirements from either standard.

That distinction is central to how Consilium Labs approaches coordinated ISO/IEC 27001 and ISO/IEC 42001 certification audits. The objective is not to make the standards appear interchangeable. It is to evaluate genuine operational intersections without weakening the independent evaluation of either management system.

Where the ISMS and AIMS Intersect

ISO/IEC 27001 and ISO/IEC 42001 are both management-system standards. Organizations will therefore encounter familiar governance disciplines across both environments.

An ISMS establishes requirements around organizational context, leadership, responsibilities, information-security risk, operational processes, monitoring, internal audit, management review, and continual improvement.

An AIMS similarly addresses organizational context, leadership responsibilities, AI risks and impacts, operational processes, performance evaluation, management review, and governance associated with the responsible development, provision, or use of AI systems.

The relationship becomes particularly visible when an AI system processes protected or sensitive information.

Consider a generative AI capability embedded within an enterprise SaaS platform.

The ISMS may govern access privileges, cloud infrastructure, security logging, supplier relationships, incident processes, and protection of customer information.

The AIMS introduces another set of questions. What is the intended use of the AI system? Which AI-specific risks and impacts have been considered? What data considerations apply? Where is human involvement required? How are third-party AI dependencies governed? What records demonstrate how significant AI-related decisions are managed?

The same AI-enabled service can therefore operate inside two legitimate governance domains.

A coordinated audit can examine those connections directly rather than treating the AI environment as though it exists separately from the information-security controls surrounding it.

Why a Combined Audit Can Provide a More Coherent Evidence Picture

The strongest case for a combined audit is not administrative convenience.

It is evidence coherence.

Organizations frequently use the same risk committees, supplier processes, management-review structures, document controls, change records, executive oversight mechanisms, and internal audit functions across more than one management system.

When information security and AI governance intersect operationally, the underlying evidence may also intersect.

A coordinated audit allows auditors to examine those relationships across both domains while maintaining distinct conclusions against the applicable requirements of each standard.

Consider a third-party AI provider.

Under ISO/IEC 27001, that provider may appear within supplier-security records, information-security risk processes, access arrangements, contractual requirements, or incident-management activities.

Under ISO/IEC 42001, the same provider relationship may need to be considered in relation to AI-system dependencies, intended use, data considerations, monitoring, accountability, lifecycle processes, and other applicable AIMS requirements.

One relationship. Different criteria. Distinct evidence questions.

Evaluating those relationships within a coordinated audit structure can provide a more coherent view of how information-security management and AI governance operate across the organization.

Industry Use Cases

SaaS: Generative AI Inside an Enterprise Platform

A B2B SaaS provider introduces generative AI into a platform that processes confidential customer information.

Its ISO/IEC 27001 environment may already govern authentication, privileged access, cloud resources, security monitoring, incident records, software processes, and third-party providers.

The AIMS adds another governance layer.

Who approved the AI use case? What information may be submitted to the AI system? What AI-specific risks and impacts have been considered? Where is human oversight relevant? How are model-provider changes addressed? What evidence demonstrates monitoring and accountability?

A coordinated ISO/IEC 27001 and ISO/IEC 42001 audit allows information-security and AI-governance evidence to be examined within the same operational context while maintaining findings against the applicable requirements of each standard.

Financial Services: AI in Risk, Surveillance, and Customer Processes

Financial organizations increasingly use AI across customer communications, fraud detection, surveillance, investment processes, operational analytics, and other business functions.

FINRA has documented multiple AI applications within securities firms while emphasizing that organizations remain responsible for evaluating the regulatory implications and risks associated with their use of AI (Financial Industry Regulatory Authority [FINRA], n.d.).

For a financial institution, ISO/IEC 27001 may address protection of transaction data, privileged access, supplier security, monitoring, and incident processes.

ISO/IEC 42001 can introduce additional criteria relevant to AI-system responsibilities, impacts, human involvement, monitoring, lifecycle governance, and applicable records.

A coordinated engagement enables auditors to examine how those governance structures operate across both domains without treating information security and AI management as equivalent disciplines.

Healthcare Technology: AI-Enabled Clinical Systems

Artificial intelligence is becoming increasingly embedded in healthcare technology.

The U.S. Food and Drug Administration maintains a public list of AI-enabled medical devices authorized for marketing in the United States. In August 2026, the agency also sought public input on regulatory considerations for generative-AI-enabled medical devices, including risk assessment and post-market monitoring (U.S. Food and Drug Administration [FDA], 2026a, 2026b).

For a healthcare technology organization, the ISMS may govern sensitive information, access, infrastructure, logging, supplier relationships, and security incidents.

The AIMS may address intended use, AI risks and impacts, data considerations, human involvement, performance monitoring, change records, and lifecycle processes.

A coordinated audit can therefore examine both the information-security environment surrounding the technology and the management-system processes governing the AI capability.

This does not replace sector-specific legal or regulatory obligations. Each applicable requirement remains distinct from management-system certification.

Manufacturing: AI Across the Factory Floor

Manufacturers are increasingly applying AI to predictive maintenance, quality control, demand forecasting, production planning, robotics, and other operational processes.

NIST has identified data quality, cybersecurity, privacy, workforce capability, and legacy-system integration among the challenges organizations may encounter as AI use expands within manufacturing environments (NIST, 2026).

In this context, ISO/IEC 27001 can address information-security risks affecting connected production environments, data, infrastructure, suppliers, and operational technology interfaces within the defined ISMS scope.

ISO/IEC 42001 addresses the organization’s management of AI systems and associated risks, impacts, responsibilities, monitoring, and lifecycle processes within the defined AIMS scope.

For manufacturers moving further into predictive and increasingly autonomous environments, secure infrastructure and accountable AI management may intersect substantially while remaining governed by different audit criteria.

What Consilium Labs Evaluates in a Coordinated Engagement

Consilium Labs conducts independent certification audits against ISO/IEC 27001:2022 and ISO/IEC 42001:2023 in accordance with applicable certification requirements and defined audit scopes.

A coordinated engagement can evaluate organizational context, management-system scope, governance responsibilities, information-security risk, AI-specific risk and impact records, supplier relationships, data governance, monitoring evidence, internal audit activity, management review, lifecycle documentation, and other applicable evidence.

Where evidence legitimately relates to requirements under both management systems, auditors may evaluate that evidence against the applicable criteria of each standard.

Where a requirement applies only to ISO/IEC 27001 or ISO/IEC 42001, it remains subject to the criteria associated with that respective standard.

Findings remain traceable to the applicable standard, and conformity against each standard is evaluated independently.

Consilium Labs’ role remains one of independent third-party certification. The organization retains responsibility for its management systems, controls, governance decisions, risk decisions, and operational processes.

That separation is essential to maintaining the impartiality and credibility of the certification process.

Combined Audits Are Not About Doing Less

A common misunderstanding is that combining ISO/IEC 27001 and ISO/IEC 42001 means reducing the depth of either audit.

That is not the objective.

IAF requirements for audits of integrated management systems make clear that applicable areas and activities associated with each management-system standard must still be adequately addressed by competent auditors (IAF, 2023).

The significance of coordination lies in evaluating legitimate intersections.

Where risk processes, supplier governance, management review, internal audit structures, evidence repositories, or organizational responsibilities genuinely apply across both systems, the same management process or evidence source may be evaluated in relation to requirements from both standards.

Every applicable audit criterion remains subject to evaluation.

Any determination of audit duration remains governed by applicable certification and integrated-audit requirements rather than by a commercial expectation of reduced audit activity.

A coordinated structure can therefore provide greater coherence without converting two standards into one or reducing the integrity of either certification audit.

Frequently Asked Questions

Can ISO/IEC 27001 and ISO/IEC 42001 be audited together?

Yes.

Organizations operating integrated or interconnected management systems may undergo coordinated audits covering more than one management-system standard.

IAF MD 11 establishes requirements relevant to audits of integrated management systems against two or more sets of audit criteria.

Each applicable standard remains subject to its own requirements, scope considerations, evidence, findings, and conformity evaluation.

No.

Coordinating the audits does not merge ISO/IEC 27001 and ISO/IEC 42001 into a new certification standard.

Each standard remains a separate set of certification criteria, and conformity must be established against the applicable requirements of each standard.

Where an organization operates an integrated management system, the audits may be conducted within a coordinated audit program in accordance with applicable certification requirements. Certification documentation must accurately identify the standards and scopes for which conformity has been established.

AI systems frequently depend on information assets, infrastructure, suppliers, access controls, risk processes, monitoring, and management oversight that may already form part of an ISMS.

ISO/IEC 42001 introduces separate AI-management requirements that may intersect with those same organizational processes.

A coordinated audit allows those intersections to be examined within the same operational environment while preserving the criteria applicable to each standard.

No.

ISO/IEC 42001 applies to organizations that develop, provide, or use AI systems, subject to the organization’s context and defined AIMS scope.

That makes the standard relevant beyond model developers. SaaS providers, financial institutions, healthcare organizations, manufacturers, government bodies, professional services organizations, and other enterprises may operate or use AI systems within their business processes.

ISO/IEC 27001 establishes requirements for an Information Security Management System focused on managing risks associated with the confidentiality, integrity, and availability of information.

ISO/IEC 42001 establishes requirements for an Artificial Intelligence Management System addressing organizational governance of AI systems, including applicable AI risks and impacts, responsibilities, lifecycle processes, transparency considerations, monitoring, and accountability.

The standards address different management-system objectives even where operational evidence or governance structures intersect.

No.

Every applicable audit criterion remains subject to evaluation.

Where the same management process or evidence source legitimately relates to requirements under both standards, auditors may evaluate that evidence against the applicable criteria of each management system.

Coordination does not remove evidence requirements, eliminate applicable criteria, or automatically reduce the audit activity necessary to establish conformity.

No.

ISO/IEC 27001 certification establishes conformity with ISO/IEC 27001 within the defined certification scope.

ISO/IEC 42001 contains separate requirements for an Artificial Intelligence Management System.

Where an organization seeks certification against both standards, conformity with each must be established against the applicable criteria.

No.

ISO/IEC 42001 is an AI management-system standard. It does not replace an Information Security Management System or other information-security requirements applicable to the organization.

AI systems may depend heavily on information-security controls, but the governance objectives of ISO/IEC 27001 and ISO/IEC 42001 remain distinct.

Information Security and AI Governance Are Becoming More Interconnected

The next phase of enterprise AI governance will not be defined by AI management in isolation.

AI increasingly operates inside environments already governed by information-security controls, supplier relationships, identity systems, cloud infrastructure, risk processes, and executive oversight.

At the same time, regulatory developments and management-system standards are making AI-specific accountability, transparency, lifecycle monitoring, and evidence more explicit.

ISO/IEC 27001 and ISO/IEC 42001 address different governance questions.

Modern organizations may increasingly need to demonstrate how they address both.

A coordinated certification audit allows the relationship between information-security management and AI governance to be evaluated within a common audit structure while preserving the requirements, evidence, findings, and conformity determinations applicable to each standard.

Consilium Labs conducts coordinated, independent certification audits against ISO/IEC 27001:2022 and ISO/IEC 42001:2023, grounded in defined scope, objective evidence, impartiality, and applicable certification requirements.

Consilium Labs
https://consilium-labs.com

 

References

European Commission. (2026, July 31). Commission starts enforcing AI Act rules and new transparency requirements on 2 August.

Financial Industry Regulatory Authority. (n.d.). AI applications in the securities industry.

International Accreditation Forum. (2023). IAF MD 11: Mandatory document for the application of ISO/IEC 17021-1 for audits of integrated management systems.

International Organization for Standardization. (2022). ISO/IEC 27001:2022: Information security, cybersecurity and privacy protection—Information security management systems—Requirements.

International Organization for Standardization. (2023). ISO/IEC 42001:2023: Information technology—Artificial intelligence—Management system.

National Institute of Standards and Technology. (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1).

National Institute of Standards and Technology. (2026). The rise of artificial intelligence in U.S. manufacturing.

U.S. Food and Drug Administration. (2026a). Artificial intelligence-enabled medical devices.

U.S. Food and Drug Administration. (2026b, August 18). FDA seeks public feedback to inform regulatory approach for generative AI-enabled medical devices.

Related Articles

Let's get in touch

Start your audit now. Achieving cybersecurity audit can be complex. We have made it our mission to simplify the process, giving you access to the professional expertise you need to prepare your company for the future. Get in touch with us today!

Please enable JavaScript in your browser to complete this form.
Please enable JavaScript in your browser to complete this form.