Skip to content
One clause, three standards: ISO 27001, ISO 27701 and ISO 42001 compared clause by clause

One clause, three standards: ISO 27001, ISO 27701 and ISO 42001 side by side

Marius van Aswegen
Marius van Aswegen

ISO 27001, ISO 27701 and ISO 42001 look like three separate projects. They are not. All three are built on the same harmonised structure, so the same clause asks a similar question in each, with a different lens: information, personal data or artificial intelligence.

Every Monday on our LinkedIn page we take one clause and set the three standards side by side. This article collects the series in one place and grows as it goes, from Clause 4 to Clause 10. Read together, the standards show where one piece of work can serve all three, which is the heart of what we call the Triangle of Control.

Clause 4: Context of the organisation

The shared question: what exactly are we managing, and for whom?

ISO 27001 wants your internal and external issues, your interested parties and their requirements, and a written ISMS scope that states what is excluded and why.

ISO 27701 adds a decision everything else depends on: are you a PII controller, a processor, or both? Many SMEs are both at once, yet their documents only describe one.

ISO 42001 asks what role you play with AI. Do you develop it, provide it to others, or use someone else's model? Your obligations follow from that answer.

What we see at audit: a scope written to impress a buyer rather than describe reality. Auditors read the scope first, and a clever one invites hard questions for three years.

Clause 5: Leadership

The shared question: who is carrying this?

In all three standards, top management sets the policy, provides the resources, assigns the roles and is seen to care about the outcome.

ISO 27001 wants an information security policy that leadership has actually read, security objectives that sit beside the commercial ones, and named owners with real authority rather than extra workload.

ISO 27701 asks the same of privacy, with a clear route from the privacy function to the top table.

ISO 42001 wants an AI policy that says what you will and will not do with AI, and someone senior accountable for keeping to it.

What good looks like: a policy short enough for the managing director to explain in a lift, objectives that appear in the board pack, and a management review that happens between audits, not the week before one.

Clause 6: Planning

The shared question: what could go wrong, what could go right, and what will we do about it?

The skeleton is the same in all three: a risk assessment you can repeat, a treatment plan that follows from it, objectives you can measure, and changes that are planned rather than stumbled into. What changes is the lens.

ISO 27001 looks at risks to the confidentiality, integrity and availability of information, and ends in a Statement of Applicability against the 93 Annex A controls.

ISO 27701 looks at risk to the people whose personal data you hold, not only to the business. The 2025 edition gives privacy its own risk assessment, its own treatment and its own Statement of Applicability.

ISO 42001 adds a step the others do not have: an AI system impact assessment, which considers what your AI could do to individuals and to society, alongside the usual risk to the organisation.

What we see at audit: a risk register built once for certification and never opened again. A useful test: pick any risk you rated high last year and ask what changed because of it.

Coming next

Clause 7, Support (competence, awareness, communication and documented information), follows next Monday, then Operation, Performance evaluation and Improvement through to the end of October. We will add each clause here as it is published.

Why read them together?

Because building the three as one integrated system means one risk process, one internal audit programme and one management review, rather than three competing sets of meetings and records. It costs less to run and tells one clear story to every customer and auditor who asks.

Cybercontrols holds ISO 27001 and ISO 42001 certification ourselves, so every question in this series is one we have answered for our own business first. If you are weighing up one, two or all three standards, talk to us or email hello@cybercontrols.io.

Share this post