One Backbone, Three Certificates: Integrating ISO 27001, 27701 and 42001 into a Single Management System
ISO 27001 · ISO 42001 · ISO 27701 · Integrated Management System · Harmonized Structure · ISMS · AIMS · PIMS · Certification
A familiar scene in maturing GRC programmes: the ISMS team is preparing for the ISO 27001 surveillance audit, the privacy office is building a PIMS for ISO 27701, and a newly formed AI governance group is scoping ISO 42001 — each with its own scope document, risk methodology, internal audit plan, and management review. Three programmes, three document sets, one exhausted leadership team asked to approve essentially the same policy three times under different names. It is redundant by design accident, and the standards themselves offer the fix.
The Harmonized Structure is the whole trick. ISO 27001:2022, ISO 27701, and ISO/IEC 42001:2023 are all built on the same Annex SL skeleton: Clause 4 context and scope, Clause 5 leadership and policy, Clause 6 risk-based planning, Clause 7 support and competence, Clause 8 operation, Clause 9 audit and management review, Clause 10 improvement. The clause numbers and their requirements align deliberately, which means the management-system machinery — the part that consumes most of the maintenance effort — can be built once and shared. One integrated scope statement covering information security, privacy, and AI. One top-level policy family under a single leadership commitment. One risk management process with three risk lenses. One internal audit programme sampling all three domains. One management review with a three-part agenda instead of three meetings.
What stays domain-specific. Integration does not mean flattening. Each standard contributes its own control universe and one signature artefact. ISO 27001 brings the 93 Annex A controls and the Statement of Applicability. ISO 27701 extends the ISMS with PII-controller and PII-processor controls and forces role clarity GDPR also demands. ISO 42001 adds the 38 AIMS controls plus the deliverable neither sibling has: the AI System Impact Assessment, evaluating consequences for individuals and society, alongside an AI system register. The integrated system therefore has a shared trunk (clauses 4–10) and three branches (control sets, specialised assessments) — and the branches genuinely interlock: ISO 42001's data-governance controls lean on 27001's A.8 technological controls; an AI system processing personal data triggers 27701's PII controls; supplier controls (27001 A.5.19–5.22) extend naturally into AI-provider due diligence (42001 A.10.3).
The unified risk picture is where integration pays hardest. Run separately, the three programmes assess the same asset three times and miss the compound risks. Consider an AI-powered HR screening tool: it is an information asset (security risk: model and data exfiltration), a processing activity (privacy risk: lawful basis, profiling), and an AI system (bias, explainability, human oversight). One integrated risk assessment sees the whole object; three siloed ones each see a third and file it under a different owner. The same convergence maps outward to regulation — the EU AI Act, GDPR, and NIS2 land on the same systems too, and an integrated management system gives you one evidence base to answer all of them.
The audit economics seal the case. Certification bodies routinely offer combined audits for HLS-aligned standards: one Stage 1/Stage 2 cycle, shared clause-level evidence, domain-specific sampling for the control branches, and materially fewer audit days than three separate cycles — with 27701 in particular audited as an extension of the 27001 certificate rather than standing alone. Internally the saving is larger still: one document-control regime, one corrective-action log, one competence matrix, one annual calendar.
A realistic sequence. Almost nobody should start all three at once. The proven path: establish or refresh ISO 27001 as the backbone, since both other standards assume its security foundation. Then extend rather than rebuild — add 27701 if personal data processing is core to the business, or 42001 first if AI is the bigger exposure, folding each into the existing clause machinery: same risk method with a new lens, same audit programme with new criteria, same management review with a longer agenda. Resist the organisational temptation to let privacy or AI governance spin up parallel bureaucracies; give them seats in the existing system instead.
The strategic point runs deeper than efficiency. Security, privacy, and AI trustworthiness are not three subjects — they are three facets of the same question a customer, regulator, or board is asking: can this organisation be trusted with data and the systems that act on it? An integrated management system is simply that answer with an architecture — and three certificates hanging off one well-run backbone will always beat three programmes competing for the same calendar.