ISO/IEC 42001 and ISO/IEC 27001 share the same management-system shape, so a certified ISMS gives you a real head start: context, leadership, risk treatment, documented information, internal audit, management review and corrective action all carry over. What does not carry over is the object being managed. Your ISMS protects information. An AI management system governs systems that produce decisions. And neither certificate gives you a presumption of conformity under the EU AI Act.
If your organisation holds ISO/IEC 27001 and employs roughly 250 to 5,000 people in the Netherlands or Flanders, this is for you: the IT manager, IT director, informatiemanager or security officer who owns it. You already have the certificate, you already have an audit calendar with a lead auditor's name on it, and someone in the business has now been told that AI needs a certificate of its own. The question is how much of the machinery you already pay for can be reused, and what the certificate actually answers when a customer asks.
What does ISO 42001 ask for that ISO 27001 does not?
ISO/IEC 42001:2023 is edition 1, published in December 2023, and it is still the only edition. ISO describes its scope as requirements and guidance for organisations that develop, provide or use AI systems, which is broader than most readers assume: running somebody else's model puts you inside the scope.
The real gap between the two standards is the definition of risk. ISO/IEC 27001:2022 assesses risk to the confidentiality, integrity and availability of information, judged from the organisation's point of view. ISO/IEC 42001 asks you to assess the impact of an AI system on individuals and on groups of people, including people who are not your customers and who never agreed to anything. Your existing risk method computes euros and downtime. It does not compute a wrong decision taken about a person. That is a new instrument, not a new tab in the same spreadsheet.
Annex A of ISO/IEC 42001 carries 38 controls across nine areas, selected through a Statement of Applicability in exactly the way your 27001 practitioners already work. Six of those areas have no direct counterpart in your ISMS:
- An AI impact assessment, pointed outward at affected people rather than inward at the organisation.
- The AI system life cycle as a controlled process with named gates, not a project that ends at go-live.
- Data provenance and quality, for training data and for the inputs arriving at run time.
- Information provided to interested parties: a disclosure duty, not a security control.
- The use of AI, a deployer-side control set that exists because the standard also covers buyers.
- Third-party relationships expressed in model behaviour and accountability, where 27001's supplier clauses stop at data handling.
Which parts of your ISMS transfer, clause by clause?
Both standards use the ISO harmonised structure, so clauses 4 to 10 line up one to one. That is why the honest answer to "how much can we reuse" is "most of the machinery and almost none of the content". Read clause by clause:
- Clause 4, context and scope. Transfers as a process. Rewrite the boundary, because an AIMS scope is drawn around AI systems and the processes that build or run them, and that rarely matches your ISMS scope statement.
- Clause 5, leadership and policy. Transfers. You need an AI policy as its own document; if you already wrote one for the AI Act literacy duty, treat it as the starting draft, not the finished one.
- Clause 6, risk and opportunity. The procedure transfers, the criteria do not. Keep the method and add an impact scale expressed in affected people and wrong outcomes.
- The Statement of Applicability. The mechanic transfers exactly: 38 Annex A controls instead of 27001's 93, and the same obligation to justify every exclusion in writing.

- Clause 7, competence and documented information. Transfers, with one real cost. Your internal auditors and risk owners need AI competence they do not currently have, and so do the certification body's auditors.
- Clause 8, operation. Least reuse of all. Life-cycle gates, impact assessments and data-provenance records are new artefacts, not renamed old ones.
- Clauses 9 and 10, internal audit, management review, nonconformity and corrective action. Transfer almost unchanged. Same calendar, same forms, new evidence.
- Supplier control is where the two diverge most sharply. 27001 asks whether your supplier protects your data. 42001 asks whether you know what the model does, who may change it, and who answers when the answer is wrong.
Two consequences for planning. First, the integrated audit that Dutch certification bodies already sell for 27001 and 9001 works here too, and it is the least expensive route: one scope, one calendar, one management review, two certificates. Second, the reuse is highest in exactly the clauses your auditor spends the least time on, so do not read "most of the clauses transfer" as "most of the work is done".
Does ISO 42001 certification make you AI Act compliant?
No, and the reason is procedural rather than technical. Article 40 of the AI Act attaches a presumption of conformity to harmonised standards whose references have been published in the Official Journal of the EU, and to nothing else. The Commission says it plainly on its own standardisation page: applying standards remains voluntary, and it is the Official Journal reference that provides legal certainty.
The Commission asked CEN and CENELEC for deliverables in ten areas, from risk management through to conformity assessment, and that work sits in the joint technical committee JTC 21. The first deliverable is finished: EN 18286:2026, "Artificial intelligence. Quality management system for EU AI Act regulatory purposes", published in July 2026 and written for the quality management system that Article 17 requires of providers of high-risk AI systems. It exists as a bespoke European standard rather than an adoption of ISO/IEC 42001 because the Commission found 42001's goals and definitions not aligned with the AI Act's quality-management requirement. ISO/IEC 42001 was separately adopted in Europe as EN ISO/IEC 42001:2026 in March 2026, and a European adoption is not a citation in the Official Journal.
This point has been made before us, and made well. lawandtechnology.eu set it out in July 2026: until the harmonised standards are cited, no certificate stands in for AI Act conformity. We agree and we are not claiming the observation. What that piece does not do, because it is not written for you, is say what it means for a Dutch IT organisation that buys AI rather than builds it.
Here is that part. Article 17 is a provider obligation. If your organisation licenses a model or a product, configures it, and puts it in front of staff or customers, you are a deployer, and the standard closest to citation is one you will never be audited against. Your own exposure sits elsewhere: the AI literacy duty, the deployer duties for any high-risk system you operate, the transparency obligations, and the dates, which the Digital Omnibus moved. If you have not classified your own systems yet, start there, because the answer changes which of these paragraphs applies to you.
Does the Dutch accreditation layer change what a certificate is worth?
It does, and this is the part a Dutch security officer can act on tomorrow. Certification against 42001 is performed under ISO/IEC 17021-1, and since 7 July 2025 there is an AI-specific supplement: ISO/IEC 42006:2025, edition 1, 31 pages, which sets additional requirements for the bodies that audit and certify an AI management system, including competence criteria for each audit role. It does not replace 17021-1; it adds to it.
The dates do not line up, and that is the useful detail. The Raad voor Accreditatie issued the first Dutch ISO 42001 accreditations to BSI and DNV in early January 2025 and announced them on 27 January 2025, six months before 42006 was published. In Flanders the equivalent body is BELAC, and the same questions apply. Accreditation bodies have since turned 42006 into operational criteria and more certifiers have come through. So two certificates carrying the same standard number can have materially different things standing behind them, depending on who accredited the certifier and when. There is no official count to sanity-check against either: ISO's own Survey does not yet track 42001, so every market figure you read is assembled from press releases.
What should you ask a supplier who shows you an ISO 42001 certificate?
Treat it the way you treat a 27001 certificate, which means reading the scope before the logo. Five questions, in this order:
- Which legal entity, and what does the scope statement say? A certificate covers a defined scope, not a company. If the AI product you are buying is not inside it, the certificate is about something else.
- Which of the 38 Annex A controls were excluded, and on what justification? Ask for the Statement of Applicability itself, not a summary. The exclusions are the interesting reading.
- Which accreditation body, and is it assessing against 42006? An unaccredited certificate is not worthless, but it is a different claim, and certifiers accredited earliest were assessed under earlier arrangements.
- What does the certificate say about the model you will actually be using? Usually nothing, because the foundation model is a third party to your supplier too, and 42001 asks them to manage that relationship rather than guarantee the model.
- What can change in production without an RFC? A certificate never answers this, your change process depends on it, and the same blind spot shows up in shadow AI.
So do you actually need it?
Three answers, and which one is yours depends on why you are being asked. If you sell services or software with AI in them into professional procurement, certification is becoming the gate, and the cost of not holding it arrives as lost tenders rather than as a fine. If you are a deployer with a certified ISMS and no external demand, extend the ISMS scope, run the 42001 clauses as conformance without certifying, and buy the certificate the first time a customer asks for it in writing; you get most of the governance benefit without a second surveillance cycle. And if you genuinely are a provider of a high-risk system, 42001 is a useful management frame but it is not the document a conformity assessment will ask for. Watch EN 18286 and the Official Journal.
One thing worth saying plainly, since we are an AI supplier writing about supplier assurance. We do not run your ISMS, your audit or your certification project, and we are not your ICT partner. What we can be held to is the layer an AIMS needs evidence from: the evaluation set, the data contracts, the model and prompt registry, and the record of who changed what and when. Keep those on your side of the line and your AI management system has something real to audit. If you want that layer built alongside the IT organisation you already have, that is the work we do.
A consultant tells you where AI pays off; Crux Digits also builds it. A fixed price per step, one named expert, from Utrecht.
AI consultancy in the Netherlands →


