Combining ISO 42001 With ISO 27001 and ISO 9001 Audits

Many organisations hold multiple management system certifications. ISO 27001 is the information security management system standard, and ISO 9001 is the quality management system standard. If your organisation is certified for both information security and quality, you can choose to audit ISO 42001 separately or to integrate it with your existing certification audits.
Integration has practical benefits. Auditors from different standards look for similar control principles. ISO 27001 auditors examine information security risks and controls. ISO 9001 auditors examine quality risks and controls. ISO 42001 auditors examine AI risks and controls. However, there are overlapping concerns. For example, all three standards require documented procedures, staff training, incident management and management review. By integrating your audits, you can present evidence once and have auditors from all three standards examine it together.
Integrating audits requires that your certification body has auditors qualified for multiple standards. Not all bodies audit all three standards, and not all auditors hold qualifications in multiple standards. When you contact a certification body about ISO 42001 certification, ask whether they can integrate with existing ISO 27001 or ISO 9001 audits.
Scoping Across Multiple Standards
When you plan integrated audits, scopes must be clear about which systems and processes fall under each standard. An AI system might be subject to ISO 27001 (if it processes personal data), ISO 42001 (if it is an AI system) and ISO 9001 (if it is part of your product or service delivery). The auditor must understand which controls apply to each system under which standard.
For example, when assessing an AI system that processes personal data, an ISO 27001 auditor will examine access controls, encryption and incident response procedures. An ISO 42001 auditor will examine risk assessment, system monitoring and human oversight. An ISO 9001 auditor (if your audit includes quality) will examine whether the system meets your defined quality requirements. These are different audit questions applied to the same system.
Clarifying scopes upfront prevents confusion during the audit. If your organisation develops products (subject to ISO 9001), uses information security practices (subject to ISO 27001) and deploys AI systems (subject to ISO 42001), the auditors can tailor their focus rather than duplicating work.
Audit Scheduling and Efficiency
Integrated audits can occur as a single combined audit or as three separate audits scheduled closely together. A combined audit is more efficient but requires finding auditors qualified in all three standards. Three audits scheduled back-to-back or with some overlap are more common. The key is coordinating the schedule so that you do not host separate audit teams weeks or months apart.
When audits are combined or closely scheduled, prepare a central location where all auditors can access evidence. Organise evidence by system and process rather than by standard. For example, create a folder for each AI system that contains all evidence (security controls, AI management, quality procedures). This allows auditors from different standards to find relevant evidence without your staff having to retrieve documents multiple times.
Some organisations maintain unified risk registers and control matrices that map controls to multiple standards. A control might be listed as “Incident escalation procedure” and noted as addressing clauses in all three standards. This unified view helps auditors understand your integrated governance approach rather than seeing three separate, isolated systems.
Benefits and Challenges of Integration
Integrated audits offer several practical benefits. First, they reduce audit costs by consolidating travel, auditor time and administrative overhead. A single audit visit covering all three standards costs less than three separate visits. Second, they reduce burden on staff by scheduling interviews and site access once rather than three times. Staff time is valuable, and consolidating audits respects that.
Third, integrated audits create an opportunity for more coherent governance. When auditors from different disciplines examine the same systems and procedures together, they can identify inconsistencies or gaps that single-standard auditors might miss. For example, an ISO 27001 auditor and an ISO 42001 auditor examining the same incident response procedure together might identify that security controls and AI-specific escalation are not properly coordinated.
However, integration also presents challenges. Finding auditors qualified in all three standards limits your certification body options. The timeline is more complex because all three audits must stay aligned. If one standard requires Stage 1 closure before Stage 2 begins, but another does not, the schedules can conflict. Some certification bodies offer less flexibility in accommodating integration requests, so clarify integration expectations when you obtain quotations.
A practical approach is to integrate core elements (documentation review, management interviews) while allowing flexibility in the detailed evidence sampling. This hybrid approach balances efficiency with the distinct requirements of each standard. Discuss this flexibility with your certification body before committing to an integrated audit.
