ISO 27001 is the standard for an information security management system, and for companies considering certification of AI governance it is important for a practical reason: both standards share the same management system structure. Anyone who has information security in place has already resolved the organisation's context, policy, risk management, objectives, internal audit, management review and document control – that is, the framework that forms a substantial part of the requirements. What needs to be added is what is specific to artificial intelligence: a register of the systems used, assessment of impacts on affected persons, management of data and its quality, transparency towards users, and human oversight. Certification can be run as an integrated system with a single audit, which reduces both costs and administration.
See also: ISO/IEC 42001, AI management system, Internal audit and management review.