top of page
Insights


ISO 27001 vs ISO 42001: Do You Need Both? A Lead Auditor’s Honest Answer
ISO 27001 vs ISO 42001 is a comparison I am asked about constantly. Usually by companies that already hold ISO 27001 or are partway through implementation, and have started using AI in their products or operations. The question is always the same: do we need another standard?
Daniel Sampson
Apr 234 min read


How to Integrate ISO 27001 and ISO 42001 Into a Single Management System
If your organisation already holds ISO 27001 certification and is now developing, deploying, or using AI systems, you are in the strongest possible position to integrate ISO 42001 into your existing management system. Both standards follow the same Annex SL structure. That shared backbone means you are not building a second management system from scratch. You are extending the one you already have.
Daniel Sampson
Apr 74 min read


The Auditor's Mindset: Why the Best ISO 27001 Audits Start with Empathy
If you think a successful ISO 27001 audit is about finding as many minor non-conformities as possible, you are missing the point. Audits should be built around finding conformity, not solely hunting for gaps. The difference between the two approaches defines the ISO 27001 auditor mindset that separates a competent auditor from a truly strategic one.
Daniel Sampson
Mar 264 min read


Internal Audit vs External Audit: What’s the Difference and Why It Matters
In my experience as a Lead Auditor, I’ve seen many organisations approach ISO 27001 risk assessment as a creative writing exercise. They’ll start by building a massive spreadsheet, filling it with ‘low, medium, high’ labels and hope I don't look too closely at the underlying detail.
But in 2026, with cyber threats evolving at machine speed, auditors have had to change their approach to adjust to a much more threatening landscape. What we’re not looking for is a perfect list
Daniel Sampson
Mar 103 min read
bottom of page