Skip to main content
ISO Certification Myths That Cost You MonthsAudit Process
5 min readFor Compliance Managers

ISO Certification Myths That Cost You Months

Many myths about ISO/IEC 27001 and ISO/IEC 42001 persist, often leading compliance teams to duplicate work, delay certification, and waste resources on unnecessary steps. These myths arise from advice inherited from consultants or those unfamiliar with the standards. Here's what really happens when you pursue these certifications.

Myth 1: You need perfect documentation before you start

Reality: Certification bodies audit operating controls, not impressive binders.

The mandatory documentation for ISO/IEC 27001 and ISO/IEC 42001 is less extensive than most teams assume: scope statement, information security policy (or AI management system policy), risk assessment methodology, risk treatment plan, Statement of Applicability, objectives, internal audit program, and management review records. Everything else supports evidence that your controls are operational.

An incident log showing resolved events proves your incident management process works. An empty log formatted neatly proves nothing. Stage 2 auditors sample records over time to test control operation, not documentation aesthetics.

Where teams lose months: writing elaborate policies for controls not yet operational. Every unearned claim in a policy becomes a nonconformity at Stage 2. If a control isn't running, provide a dated implementation plan. Auditors accept that. They don't accept a policy claiming "we do X" when evidence shows otherwise.

Myth 2: ISO 42001 and ISO/IEC 27001 are separate projects

Reality: Both standards share the ISO High Level Structure, allowing one integrated management system to satisfy both.

Organizations that run ISO/IEC 42001 and ISO/IEC 27001 sequentially pay twice for the management system: two scope statements, two risk methodologies, two internal audit programs, two management reviews, two corrective action logs. Running them as a single integrated system reduces costs significantly, same clause structure (4 through 10), same documentation requirements, same audit cycle.

The Annex A controls differ, but the management system is identical. One scope statement defines both your information security and AI system boundaries. One risk assessment methodology handles both information security and AI-specific risks. One internal audit schedule covers both sets of controls.

Where teams lose budget: treating AI governance and information security as separate compliance tracks. If both certifications are on your roadmap, design one system that satisfies both standards from the start.

Myth 3: You can't use existing SOC 2 evidence

Reality: The control overlap between SOC 2 and ISO/IEC 27001 is substantial, and mapping existing evidence is far cheaper than generating new evidence.

If you're already SOC 2 Type II certified, you're operating access reviews, change management, vendor risk assessments, incident response, and business continuity controls. These controls satisfy ISO/IEC 27001 Annex A requirements, the evidence format changes, but the control operation doesn't.

Your SOC 2 access review logs become evidence for ISO/IEC 27001 control 5.18 (access rights). Your vendor security assessments satisfy control 5.19 (information security in supplier relationships). Your penetration test reports map to control 8.8 (technical vulnerability management).

Where teams waste time: starting ISO/IEC 27001 implementation as if SOC 2 never happened. Bring your existing evidence to the gap assessment. The delta you need to close is smaller than you think.

Myth 4: Gap assessments are optional if you're already "pretty secure"

Reality: The gap between "we're pretty secure" and "we satisfy clause 8.2 requirements" is where most nonconformities live.

A gap assessment isn't a maturity score, it's a clause-by-clause, control-by-control map of what the standard requires versus what you currently operate. The output is a prioritized remediation order and a list of the specific evidence each control needs.

Common gaps include missing AI system impact assessments, undocumented human oversight, missing supplier AI due diligence, objectives written as aspirations rather than measurable targets, and incomplete asset registers.

Where teams lose certification dates: assuming readiness, skipping the gap assessment, and discovering mandatory requirements during Stage 1 that delay Stage 2. A gap assessment that costs $49 or $59 and takes an hour is the cheapest insurance you'll buy in the certification process.

Myth 5: Implementation means "get everything perfect, then call the auditor"

Reality: Implementation means accumulating operating history, evidence that controls run over time, not that they're documented beautifully.

Stage 2 auditors sample records over a period. Two to three months of a control genuinely operating beats a perfect binder assembled the week before audit. If your access review process runs quarterly, the auditor needs to see at least one completed cycle.

Instrumentation matters more than perfection. If access reviews, training completions, change approvals, and supplier assessments generate records automatically, evidence collection stops being a scramble. The log proving the control ran should be a byproduct of running the control.

Where teams burn weeks: treating implementation as a documentation phase instead of an operations phase. The standard requires evidence of operation. Run the controls, log the events, and let the records accumulate. Then book Stage 1.

What to do instead

Start with clarity on scope and sequencing. A 20-minute readiness discussion answers two questions: what's actually in scope, and which standard goes first. Come ready with three answers: what triggered this (customer requirement, funding diligence, board ask), whether you build AI or buy AI or both, and your real deadline.

Run the gap assessment before you implement. A clause-by-clause status table with required evidence per control is the implementation plan. Skipping it doesn't save time, it just moves the discovery of mandatory requirements to a Stage 1 finding.

Reuse what you already have. Your SOC 2 evidence, your existing policies, your asset inventory, bring it. Mapping existing evidence is faster than starting from zero.

Build one system if both standards are on your roadmap. ISO/IEC 42001 and ISO/IEC 27001 share the same management system structure. One scope, one risk methodology, one audit program, one management review. The second certification should cost a fraction of the first.

Book the certification body early. Scheduling, not readiness, is the most common reason certification dates slip. Get on the calendar while you're still implementing, and complete your internal audit and management review before Stage 1.

Certification isn't the reward for perfect security. It's evidence that your management system operates as documented. Run the controls, log the results, and let the records prove it.

You Might Also Like