Your existing ISO 27001 or SOC 2 program is a head start, not a substitute
If you hold ISO/IEC 27001 or a SOC 2 report, you already have habits auditors recognise: risk processes, supplier reviews, change control, internal audit. ISO 42001 reuses a lot of that. It doesn't reuse the questions.
ISO 42001 follows the same management-system clause structure as ISO 27001, so the two integrate cleanly. SOC 2 is different: it's a CPA attestation on controls against the AICPA Trust Services Criteria, not a management system, so the reuse happens at control level. Neither one asks for AI impact assessment, model lifecycle governance or AI-specific transparency.
You already haveISO 42001 adds
Risk managementInformation security risk assessment
→
AI risk and impactAI risk assessment with its own criteria, plus a separate AI system impact assessment covering effects on individuals, groups and society
Asset inventorySystems, data stores, endpoints
→
AI system inventoryEach AI system with its purpose, models, data, suppliers, owner and your role
Supplier managementSecurity questionnaires, SOC 2 reports collected
→
AI supply chainGovernance of model, data and AI-tool suppliers, with responsibilities allocated between you and them
Change managementCode and infrastructure change control
→
AI lifecycle changesModel versions, provider swaps, prompt and retrieval changes assessed as potentially material
Secure SDLCSecure coding, testing, release gates
→
Responsible developmentVerification and validation against AI acceptance criteria, and technical documentation of the AI system
Data classificationSensitivity labels, handling rules
→
Data for AIProvenance, quality and preparation of training, fine-tuning and retrieval data
Incident managementSecurity incidents and breaches
→
AI incidentsHarmful or wrong outputs and unintended agent actions, even when no data was breached
Trust centreSecurity documentation for customers
→
Information for interested partiesIntended use, limitations and a way to report AI concerns
An integrated programme works well: one scoping exercise, shared evidence where controls genuinely overlap, one internal audit cycle. Relabelling ISMS documents as AIMS documents doesn't. Auditors read the content.