Skip to main content
Should You Adopt ISO 42001 Alongside ISO/IEC 27001?Risk Assessment & Treatment
5 min readFor Compliance Managers

Should You Adopt ISO 42001 Alongside ISO/IEC 27001?

The SearchLeak vulnerability in Microsoft 365 Copilot (CVE-2026-42824) highlighted a gap in how organizations govern AI systems. ISO/IEC 27001 controls could have limited the damage, but they don't address the upstream question: should your AI assistant have been configured that way in the first place? That's the decision you're facing now.

The Decision You're Facing

You're implementing or maintaining ISO/IEC 27001 certification. Your organization is deploying AI assistants that access corporate data across Microsoft 365, Salesforce, GitHub, or similar platforms. You need to decide: do you extend your existing ISMS to cover AI-specific risks, or do you implement ISO 42001 as a parallel management system?

This isn't a theoretical exercise. SearchLeak worked because Copilot inherited user permissions across multiple systems and could be tricked through prompt injection. Your auditor will ask how you're governing AI retrieval scope. Your answer determines which path you take.

Key Factors That Affect Your Choice

Scope of AI deployment. If you're running a single AI assistant with read-only access to a limited dataset, ISO/IEC 27001 Annex A controls may suffice. If you're deploying agentic AI that executes actions across identity providers, ticketing systems, and cloud platforms, you need governance decisions that sit upstream of Technological Controls.

Regulatory pressure. Some jurisdictions are beginning to expect AI-specific governance documentation. If you operate in highly regulated sectors or handle sensitive personal data under GDPR, you'll need to demonstrate that you assessed AI impact before deployment, not just that you configured access controls afterward.

Delegation and autonomy. ISO/IEC 27001 assumes humans make decisions and systems enforce them. AI agents receive delegated credentials and service identities that let them perform actions users can't perform directly. If your AI systems coordinate work across applications without human approval for each step, your risk profile has changed.

Audit readiness. Your certification body evaluates your ISMS against ISO/IEC 27001 requirements. If your AI systems introduce risks that don't map cleanly to Annex A controls, you'll face questions during surveillance audits. Having a documented framework for AI governance decisions makes those conversations shorter.

Path A: Extend Your Existing ISO/IEC 27001 ISMS

Choose this path when your AI deployment is limited in scope and your existing controls adequately address the risks.

When this works: You're using AI assistants primarily for information retrieval. The systems don't have delegated write access or the ability to execute multi-step workflows. Your data classification scheme (Annex A.8.2) already identifies what information AI systems shouldn't access. Your access control policy (Annex A.9) explicitly addresses non-human identities.

What you'll need to do: Update your risk register to include AI-specific threat scenarios like prompt injection and unintended data aggregation. Extend your logging and monitoring (Annex A.12.4) to capture AI retrieval patterns. Document AI system permissions in your asset inventory. Ensure your supplier relationship controls (ISO/IEC 27036) cover AI service providers.

The limitation: ISO/IEC 27001 tells you to implement access controls and monitor for anomalies. It doesn't give you a framework for deciding whether your AI assistant should be able to reason across Outlook, SharePoint, and Salesforce in the first place. You'll be making those governance decisions without formal guidance.

Practical implementation: Treat AI assistants as high-privilege service accounts in your identity governance process. Define explicit retrieval scopes that are narrower than user permissions. Don't assume everything needs to be discoverable. Segment sensitive data sources so that even if an AI system is tricked, it can't reach regulated content.

Path B: Implement ISO 42001 Alongside ISO/IEC 27001

Choose this path when your AI systems have broad access, execute autonomous actions, or when you need to demonstrate AI-specific governance to regulators or customers.

When this works: You're deploying agentic AI that coordinates work across multiple business applications. Your AI systems receive delegated authority to perform actions without human approval for each step. You operate in a jurisdiction where regulators expect documented AI impact assessments. Your customers are asking how you govern AI risk.

What you'll need to do: Conduct impact assessments before AI deployment that evaluate unintended model behavior and prompt manipulation risks. Establish human oversight mechanisms for high-risk AI decisions. Document how you determine what AI systems are allowed to do, not just what controls you apply after deployment. Create policies for AI-specific risks including data aggregation across systems.

The integration point: ISO 42001 sits upstream of ISO/IEC 27001. It addresses governance decisions about AI system design and deployment. ISO/IEC 27001 provides the Technological Controls and audit evidence for those decisions. Your ISMS documentation references your AI management system for scope and risk treatment decisions.

Practical implementation: Your ISO 42001 impact assessment determines that an AI assistant shouldn't aggregate data across certain applications. Your ISO/IEC 27001 access controls enforce that decision. Your Annex A.12.4 monitoring detects when retrieval patterns deviate from approved scope. Your ISO 42001 oversight mechanism triggers review.

The overhead: You're maintaining two management systems with separate documentation requirements. You'll need competence in both standards. Your internal audit program covers both frameworks. Budget for this if you're a small team.

Path C: Adopt ISO 42001 Controls Without Certification

Choose this path when you need AI governance structure but don't require third-party attestation.

When this works: You recognize that ISO/IEC 27001 alone doesn't address AI-specific risks, but you don't have regulatory or customer requirements for ISO 42001 certification. You want the governance framework without the audit overhead.

What you'll implement: Use ISO 42001 as a reference architecture for your AI governance policies. Conduct impact assessments using the standard's methodology. Document human oversight mechanisms and AI-specific risk treatments. Reference ISO 42001 controls in your ISO/IEC 27001 risk register without pursuing separate certification.

The tradeoff: You get governance structure without certification costs. You can't claim ISO 42001 certification to customers or regulators. If compliance expectations shift, you may need to pursue formal certification later.

Summary Matrix

Factor Extend ISO/IEC 27001 Only Add ISO 42001 Certification Adopt ISO 42001 Controls
AI scope Limited retrieval, read-only Autonomous agents, delegated authority Moderate complexity
Regulatory pressure Low High or customer-driven Moderate
Governance documentation Risk register entries Formal impact assessments, oversight mechanisms Policy framework
Audit overhead Existing ISMS surveillance Separate certification body engagement Internal review only
Best for Single AI assistant, narrow scope Multi-application agents, regulated sectors Mid-stage AI adoption

SearchLeak demonstrated that AI assistants inherit user permissions and can be tricked into exfiltrating data through prompt injection. ISO/IEC 27001 Annex A.9 would have limited what Copilot could reach. Annex A.12.4 would have made the exfiltration visible. Annex A.8.2 would have kept regulated content from crossing boundaries. But none of those controls tell you whether Copilot should have been indexing emails, MFA codes, and SharePoint files in the first place.

That's the decision ISO 42001 helps you make. Choose your path based on how much autonomy your AI systems have and how much governance documentation your stakeholders expect.

You Might Also Like