
A business that already holds ISO 9001 certification, or is well into building toward it, is often in a better starting position for AI governance than it realises. The instinct when a new standard comes up is to assume it means starting again from a blank page. For a business that already has a working quality management system, that assumption is usually wrong.
The reason is structural, not coincidental. ISO 9001 and ISO/IEC 42001, the AI management system standard, are both built on what’s officially called the Harmonised Structure (previously known as Annex SL), the common framework ISO uses across its management system standards. In practice this means both standards share the same ten-clause skeleton, Context of the Organisation, Leadership, Planning, Support, Operation, Performance Evaluation, and Improvement, using the same core language for the requirements they share (source: ISOCentral’s plain-English guide to Annex SL).
What genuinely carries straight over
Because the two standards share a skeleton, a business that already runs ISO 9001 properly already has working versions of several things ISO 42001 also requires, not identical, but close enough that they’re a starting point rather than a gap:
- A real context and interested parties analysis (Clause 4). The exercise of identifying who your business answers to and what they expect doesn’t need to be reinvented, it needs an AI-specific lens added to it.
- Leadership commitment and a documented policy structure (Clause 5). If your business already has a real quality policy signed off by leadership, not a filed-away document nobody’s read, the discipline of writing and living an AI policy is the same muscle, applied to a new subject.
- A working risk and planning process (Clause 6). A business that already thinks in terms of risks and opportunities, rather than treating risk as an annual paperwork exercise, already has the habit ISO 42001’s AI risk assessment needs. What’s genuinely new is the specific risks to look for, not the discipline of looking.
- An internal audit programme and management review cadence (Clauses 9). According to the same shared-structure research, an integrated internal audit programme can audit against multiple standards at once using a combined checklist, and a single management review meeting can cover both systems rather than running two separate ones.
- A nonconformity and corrective action process (Clause 10). The discipline of raising an issue, investigating its root cause, fixing it, and checking the fix actually worked doesn’t change. What changes is the kind of issue being raised.
What genuinely does not carry over
The shared skeleton covers the management system’s scaffolding, not the specific content that sits inside it. ISO 42001 adds its own Annex A control set, specific to AI, that has no real ISO 9001 equivalent to adapt:
- An AI system inventory. ISO 9001 has never needed a business to maintain a live register of every software system in use. ISO 42001 does, and for most small businesses, building this register honestly is the single biggest and most overdue step, since most have never actually inventoried where AI is already being used across the business.
- Third-party AI vendor risk. ISO 9001’s supplier-quality thinking is about whether a supplier delivers a consistent, conforming product. AI vendor risk is a different question entirely, what happens to the data sent to that vendor’s tool, and what the vendor’s own terms of service actually permit.
- Human oversight of automated decisions. Reviewing whether a human genuinely checked an AI-generated output before it reached a client or informed a decision is a specific, new discipline with no direct quality-management equivalent.
- AI-specific incident types. A biased output, a data exposure through an AI tool, or an unreviewed automated decision are new categories of thing to detect and log, even though the underlying investigate-and-correct process is familiar.
Why this matters practically, not just conceptually
For a business already running ISO 9001, this means the honest way to think about ISO 42001 is not “a second, separate compliance project,” but “the same management system, extended to cover a new area of the business.” One set of procedures, one internal audit programme, one management review agenda covering both, rather than duplicating the entire structure a second time. That’s a genuinely significant practical time saving for a small business, and it’s exactly the kind of efficiency that makes running two standards financially realistic where running them as two unrelated projects would not be.
The businesses that get this wrong tend to make one of two mistakes. Either they treat ISO 42001 as something to bolt on entirely separately, duplicating work that already exists in their quality system, or they assume their existing ISO 9001 system already covers AI governance by default, when the AI-specific controls above genuinely need their own attention. The efficient path sits in the middle: reuse the scaffolding, build the AI-specific content properly.
The bottom line
If your business already has a real, working ISO 9001 system, you are not starting an AI governance project from zero. The context analysis, the leadership commitment, the risk thinking, the audit and review cadence, and the corrective action discipline are already muscles your business has built. What’s actually new is a small, specific set of AI-focused additions, an AI inventory, vendor risk review, and human oversight of automated decisions, layered onto a structure you already understand.
Sources
ISOCentral — What Is Annex SL? A Plain-English Guide for SMEs