The Overlap Between the HITRUST AI Security Assessment and ISO 42001
Artificial Intelligence | HITRUST | ISO 42001
Published: May 14, 2025
Schellman's Danny Manimbo and Senior Associate within the AI practice, Jerrad Bartczak, discuss what you need to know about the overlap between HITRUST AI Security Assessment and ISO 42001 and how to map the two frameworks.
What is the HITRUST AI Security Assessment?
The HITRUST AI Security Assessment is a way for organizations to certify their AI systems through up to 44 additional requirements that can be added to an existing r2, i1, or e1 assessments. To begin, organizations simply select the AI assessment option during scoping and purchase an additional report credit.
How is it Scoped?
Scoping is tailored to each organization through a short AI-focused questionnaire to determine the following:
1. What type of AI model is in use?
- Rule-based model
- Non-generative machine learning model
- Generative AI model
3. Is the model proprietary/confidential to the organization or based on an open-source model?
Based on the responses, the assessment dynamically adjusts the number requirements to be added on, ranging from 27 to 44.
Scoring and Certification
The score is made up of an average of all of the AI requirements across all of the domains. Here are the passing thresholds:
-
i1 or e1: 83%
- r2: 62%
This structure makes the AI assessment more holistic and focused specifically on AI-related risk areas.
The Difference Between AI Security vs. AI Risk Management Assessment
It’s important not to confuse the AI Security Assessment with HITRUST’s AI Risk Management Assessment. The latter is a non-certifying, standalone evaluation comprising a flat set of 51 requirements. It offers a solid baseline report of an organization’s AI risk posture but does not lead to formal certification.
In contrast, the AI Security Assessment must be bundled with a core HITRUST assessment and results in a certifiable outcome—an important distinction for organizations seeking formal validation of their AI practices.
Alignment with ISO 42001
HITRUST and ISO 42001, the new international AI management system standard, share common ground. Of the 44 HITRUST AI requirements, there are 12 that are directly mapped to ISO 42001 controls, signaling meaningful overlap. While not a one-to-one match, this alignment provides a helpful foundation for organizations aiming to adopt both frameworks.
Final Thoughts
The HITRUST AI Security Assessment is a flexible, scalable solution for organizations wanting to demonstrate control over their AI systems. Whether used as a stepping stone toward broader AI governance or in conjunction with ISO 42001, it’s a practical and credible way to stay compliant in an AI-driven world.
Want to dive deeper into HITRUST and ISO 42001 alignment and mapping? Check out the full blog post for further mapping details or reach out to the Schellman team for additional guidance and we'll get back to you shortly.
About Jerrad Bartczak
Jerrad Bartczak is a Senior Associate – AI within the AI Practice at Schellman, based in New York. He specializes in AI assessments including ISO 42001 and HITRUST + AI, while staying current on worldwide AI compliance and governance developments. He also possesses in-depth compliance knowledge cultivated through years of experience conducting HITRUST, SOC 1, SOC 2, DEA EPCS and HIPAA audits. Jerrad maintains CISSP, CISA, CCSFP, CCSK and Security+ certifications.