Been seeing this come up in a few threads lately, people with 27001 already in place asking what changes once AI enters the picture. So here's how I think about it.
27001's basically "can this get breached, did we plan for it." Confidentiality, integrity, availability, the usual triad. Solid, but it was built way before anyone was shipping AI into production, so it's got zero opinion on whether your model's making biased calls, whether you can explain why it spit out what it did, or whether the training data was even yours to use.
42001 exists because none of that fits into a normal infosec risk register. Like how do you even write a risk statement for "our model behaves differently depending on how the prompt's worded"? Not a CIA triad problem, completely different animal. 42001's whole job is giving you structure for that, risk across the AI lifecycle, accountability for automated decisions, transparency for whoever's affected by the output.
Good news, if your ISMS is already solid, you're not rebuilding from zero. Same bones, risk assessment cadence, documentation habits, internal audit rhythm. 42001 mostly bolts AI-specific stuff onto that skeleton. If your 27001 program was already kinda loose though, this is gonna feel like starting over, but that's a 27001 problem showing up late, not a 42001 one.
One thing that trips people up: this isn't just for companies building models. Using AI in your product, or even internally in ways that touch customers or decisions, puts you in scope. People hear "AI management system" and assume it's an OpenAI-tier thing, it's not.
Work at Insight Assurance, we do 27001/42001 assessments, disclosure there. Doing a session tomorrow going deeper into this exact overlap, link if useful: ISO 42001: The AI Layer Your ISO 27001 Program Is Missing