An organization is evaluating whether to adopt ISO/IEC 42001 as its AI management system standard. A senior manager argues that the organization's existing ISO 27001 certification already covers AI systems. How should the AI risk manager respond?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because ISO 27001 addresses information security management (confidentiality, integrity, availability of information assets) and does not cover AI-specific concerns such as model fairness, bias, explainability, AI-specific governance structures, impact assessments, and AI system transparency. ISO/IEC 42001 is specifically designed for the unique governance challenges of AI systems.
Full explanation below image
Full Explanation
B is correct because ISO 27001 addresses information security management (confidentiality, integrity, availability of information assets) and does not cover AI-specific concerns such as model fairness, bias, explainability, AI-specific governance structures, impact assessments, and AI system transparency. ISO/IEC 42001 is specifically designed for the unique governance challenges of AI systems. The two standards are complementary, not redundant. C is incorrect; ISO/IEC 42001 applies to both developers and deployers of AI. D is incorrect; both standards address different risk domains and should be maintained concurrently.