Do You Need ISO 42001 If You Already Have SOC 2 (or ISO 27001)?
Already have SOC 2 or ISO 27001? Learn what ISO 42001 adds for AI governance, when buyers ask for it, and when questionnaires are still enough.
You already have SOC 2-or you are mid-audit for it. Maybe you also hold ISO 27001. Then an enterprise RFP asks about 'AI governance,' 'responsible AI,' or ISO 42001. The question is practical: do you need ISO 42001 vs SOC 2 as a second certification, or will your existing security program plus strong questionnaire answers still clear the deal?
This post is for growth-stage AI and SaaS teams facing that call. It explains what each framework is for, where SOC 2 stops short of AI governance, when buyers actually push for ISO 42001 (often voluntarily and unevenly), what you can reuse from work already in Vanta, and how to decide whether to start readiness now or prioritize questionnaire coverage first.
SOC 2, ISO 27001, and ISO 42001 do different jobs
These frameworks are related, but they are not substitutes. Treat them as layers with different jobs.
SOC 2, in plain English
SOC 2 is an attestation report from an independent CPA firm against the AICPA Trust Services Criteria. Security is always in scope; Availability, Processing Integrity, Confidentiality, and Privacy are optional criteria you add based on your product and buyer expectations. A Type 2 report tests whether selected controls operated effectively over a period-not only whether they were designed well. Buyers use SOC 2 to judge whether your organization protects systems and data in a trustworthy way. It is the common security bar for SaaS sales in North America. It is not an AI management standard.
ISO 27001, in plain English
ISO/IEC 27001 is a certifiable information security management system (ISMS). You define scope, run risk assessment and treatment, implement controls (including Annex A controls in the 2022 edition), and maintain the management system through internal audits, management review, and continual improvement. An accredited certification body issues the certificate, typically with a three-year cycle and surveillance audits. ISO 27001 proves you manage information security as a system. It can cover the environment where AI runs, but it was not written to govern AI-specific risks such as model impact, training-data fitness, or AI lifecycle accountability.
ISO 42001, in plain English
ISO/IEC 42001:2023 is the first international standard for an artificial intelligence management system (AIMS). It gives organizations a structured way to develop, deploy, use, and govern AI systems-covering accountability, transparency, ethical use, safety, and privacy-by-design expectations in a management-system format. Like other ISO management standards, it is certifiable through an accredited body. ISO 42001 sits next to-not inside-SOC 2 and ISO 27001. Workstreet describes it as complementary: it addresses AI governance gaps that security frameworks alone do not close.
If you remember one line: SOC 2 attests security/trust controls; ISO 27001 certifies an ISMS; ISO 42001 certifies how you manage AI.
Why SOC 2 is not AI governance
SOC 2 answers: 'Are the security (and related trust) controls we claimed actually in place and operating?'
It does not answer:
- Do we maintain an inventory of AI systems with risk classification?
- Who is accountable for AI policy and oversight at the leadership level?
- Have we run AI impact assessments before new deployments?
- How do we govern training data quality, provenance, and fitness for purpose?
- How do we monitor model behavior, misuse, and AI-specific nonconformities-not only security incidents?
- How do we manage the AI lifecycle from design through monitoring and retirement?
Those topics are the core of an AIMS. You can be SOC 2 Type 2 clean and still lack documented AI governance. That is why ISO 42001 vs SOC 2 is a useful comparison for AI/SaaS vendors: one is necessary security evidence for most enterprise deals; the other is AI-specific management evidence that only some buyers ask for today.
ISO 27001 helps more than SOC 2 on the 'management system' muscle-risk, roles, documented processes, internal audit-but it still does not replace AI-domain controls. Vanta's guidance is explicit on this point: organizations already certified to ISO 27001 can reuse shared management-system structure, then add AI-specific controls for faster readiness. They still need the AI layer.
When buyers ask for ISO 42001-and when they do not
Be honest about market maturity: ISO 42001 is voluntary. There is generally no legal mandate to hold the certificate unless a contract, SLA, or procurement rule requires it. Demand is emerging and uneven. Many deals still close on SOC 2 (or ISO 27001) plus detailed AI/security questionnaire answers, a Trust Center, and clear contractual language on data use and model training.
Situations where ISO 42001 more often appears
Buyers and stakeholders more often raise ISO 42001-or 'formal AI management system' language-when:
- Your product's AI materially affects customer outcomes or decisions (not only assistive drafting with human review).
- You sell into healthcare, public sector, finance, or other high-scrutiny environments where AI risk language shows up in RFPs.
- EU or other regulated buyers ask how you align with AI governance expectations (for example, EU AI Act-related questions). Note: the EU AI Act does not require ISO 42001 by name; organizations often use ISO 42001 as supporting evidence for governance documentation, not as a substitute for regulatory obligations.
- Prospects repeatedly ask for AI inventory, impact assessments, model oversight, or responsible-AI policies-and informal answers are slowing deals.
- Leadership wants third-party validation of AI governance before risk, brand, or liability concerns escalate.
Situations where SOC 2 + AI questionnaire is often still enough
For many growth-stage SaaS companies, especially those with assistive AI features and US commercial buyers:
- A current SOC 2 Type 2 (and ISO 27001 if you sell internationally) remains the primary gate.
- Buyers dig into AI via security questionnaires and follow-ups: training-data use, human oversight, logging, sub-processors, customer data used for model improvement, and incident handling.
- A maintained Trust Center and consistent questionnaire answers frequently unblock sales without a separate AI management certificate.
In other words: hearing 'ISO 42001' in one RFP does not mean every buyer requires certification. Treat frequency and deal-blocking behavior as your signal-not a single named standard in a template.
Overlap and reuse: what SOC 2 / ISO 27001 already give you
If you are already on Vanta for SOC 2 or ISO 27001, you are not starting from zero. Management-system and security foundations map into ISO 42001 readiness; AI-domain work is largely net-new.
Evidence and processes you can often reuse
- Governance cadence: risk assessment habits, management review, internal audit discipline, corrective action tracking-especially if you already run ISO 27001.
- Security controls that AI still depends on: access control, change management, encryption, vendor/subservice oversight, incident response, secure development practices, logging and monitoring of underlying systems.
- Policy and people machinery: policy acknowledgment, training workflows, role definitions, evidence collection automation in Vanta.
- Documentation hygiene: versioned policies, system descriptions, control owners, continuous monitoring tests.
Workstreet's ISO 42001 announcement notes that customers who already achieved SOC 2 or ISO 27001 can expand more straightforwardly with Workstreet and Vanta by reusing prior framework work rather than rebuilding compliance infrastructure.
What is typically net-new for ISO 42001
- AI policy and explicit AI accountability structure.
- AI system inventory and risk classification.
- AI impact / risk assessment methods tied to AI use cases.
- AI lifecycle controls (design, data management for AI, deployment, monitoring, change of models).
- Processes for AI-specific issues and continual improvement of the AIMS-not only the ISMS or SOC control set.
- Cross-functional ownership across product, engineering, security, legal, and GTM for human oversight and transparency commitments.
Plan for reuse on the shared management and security layer, and dedicated build-out on AI inventory, impact assessment, and lifecycle governance.
Decision tree: start readiness, hold, or prioritize questionnaires first
Use this sequence. It mirrors how teams already decide between commercial security attestations and sector-specific programs: buyer reality first, then framework expansion.
1. Is AI central to the product you sell into enterprise deals?
- No / lightly assistive with mandatory human review: Keep SOC 2 (and ISO 27001 if relevant) current. Invest in clear AI questionnaire answers and Trust Center materials. Hold formal ISO 42001 unless a named customer requires it.
- Yes - AI drives core functionality or consequential decisions: Continue to step 2.
2. Are EU or other highly regulated buyers already in your pipeline?
- Yes, and they ask for AI governance evidence or Act-aligned documentation: Start ISO 42001 readiness in parallel with strengthening questionnaire packs. Use the AIMS work to produce reusable artifacts (inventory, impact assessments, AI policy) even before the certificate lands.
- No: Continue to step 3. You may still want readiness if US enterprise RFPs repeatedly cite ISO 42001.
3. Are buyers asking for ISO 42001 by name-or only for AI controls in questionnaires?
- By name, repeatedly, or as a deal-blocker: Prioritize gap analysis and a certification roadmap.
- Mostly questionnaire topics: Prioritize accurate, evidence-backed answers (and SOC 2/ISO 27001 maintenance). Build lightweight AI governance docs you can attach. Revisit certification when asks become contractual.
4. Are you already on Vanta?
- Yes: Expanding to ISO 42001 is primarily scoping AI systems, closing AI-specific gaps, and mapping reusable controls-not standing up a new GRC stack. Workstreet supports ISO 42001 compliance with Vanta, including gap analysis, policy development, risk management, implementation support, internal audits, and continuous compliance.
- No: Stabilize your security attestation path first; adding ISO 42001 without a working evidence system usually creates dual busywork.
Practical default for most growth-stage AI/SaaS teams
- Keep SOC 2 Type 2 (and ISO 27001 if your buyers expect it) healthy.
- Treat AI questionnaires and Trust Center content as the near-term sales unlock.
- Start ISO 42001 readiness when AI is product-central and buyer or regulatory pressure is concrete-not because the standard exists.
How Workstreet and Vanta fit
Workstreet now supports ISO 42001 compliance with Vanta. The services path is the same shape teams already use for SOC 2 and ISO 27001 expansion: assess gaps against the AIMS requirements, build AI-specific policies and risk processes, implement controls, run internal audit preparation, then maintain continuous compliance on the platform.
If you are comparing frameworks the way you compared commercial security vs. sector mandates, start with buyer signal. SOC 2 and ISO 27001 remain the security foundation. ISO 42001 is the AI management layer you add when governance questions stop being answerable by questionnaires alone-or when a contract makes certification explicit.
For a deeper services overview, see Workstreet's ISO 42001 framework page. If questionnaires are still the bottleneck, pair any readiness work with a durable questionnaire and Trust Center process so GTM is not waiting on certification timelines.

