ISO/IEC 42001:2023 is the management system standard for artificial intelligence, and it is early: over the 365 days to 11 August 2026 it appears in 18 EU tender notices on TED against 3,408 for ISO 27001. Certify if a customer is asking. If you already hold ISO 27001 the second standard is less work, because clauses 4 to 10 are shared and what you add is 38 Annex A controls, the AI system impact assessment in clause 6.1.4, and the AI-specific records. If you hold nothing yet, start with the standard your customers are actually asking for.

Whether it is early, measured rather than guessed

It is early, and it is worth saying so plainly. TED is the EU's own procurement portal and its search API is public, so this is checkable rather than asserted. Over the 365 days to 11 August 2026:

Standard Tender notices
ISO 27001 3,408
SOC 2 104
ISO 42001 18

Eighteen. Nobody is currently losing public tenders for want of ISO 42001. If your reason for certifying is that a customer is asking, that is a real reason. If it is that procurement demands it, the data does not support that yet.

What the number does not capture: private procurement, and the direction of travel around the EU AI Act. Being early on AI governance is a strategic position rather than a response to demand, and it is reasonable to take it deliberately.

What it asks for

Clauses 4 to 10 are the Harmonized Structure, the same skeleton as ISO 27001: context, leadership, planning, support, operation, performance evaluation, improvement. If you hold 27001, you have most of that already and the records count towards both.

Annex A is where they separate. ISO 42001's Annex A has 38 controls covering AI policy, roles, the AI system life cycle, data governance, information for interested parties, and use of AI systems.

The clause with no ISO 27001 counterpart at all is 6.1.4, the AI system impact assessment. Where 27001 asks what could go wrong for the organisation, 42001 asks what the system does to the people it touches, and to society. That is a different question and it is the reason a 42001 audit is not a 27001 audit with extra controls.

If you already hold ISO 27001

The second standard is less work than the first, because the management system underneath is shared. What you are adding is the Annex A control set, the impact assessments, and the AI-specific records. Our clause-by-clause coverage for 42001 states what is held and what is not.

If you hold nothing yet

Start with the standard your customers are actually asking for. On the numbers above, for most companies that is still ISO 27001.