EU AI ActISO 42001StandardsCertification

ISO/IEC 42001 vs the EU AI Act: what each one covers

Published July 28, 2026 · 8 min read

Certification is not compliance. ISO/IEC 42001 builds the management system your organisation uses to govern AI; the EU AI Act imposes product-level legal duties on specific AI systems, by role and by risk tier. An AI management system makes those duties cheaper and faster to discharge. It never discharges them.

What ISO/IEC 42001 actually is

ISO/IEC 42001:2023, formally Information technology — Artificial intelligence — Management system, is the first international management system standard for AI. It sits in the same family as ISO 9001 and ISO/IEC 27001: a Plan-Do-Check-Act structure, requirement clauses covering context, leadership, planning, support, operation, performance evaluation and improvement, plus an Annex A control set of 38 controls grouped from A.2 to A.10 that you select, justify or exclude against your own AI risks and impacts. It is voluntary. It is also certifiable: an accredited certification body audits you against a declared scope, issues a certificate, and returns on a surveillance cycle. What the certificate attests is that your governance process exists and works. It says nothing about any particular model, product or deployment.

What the EU AI Act actually is

Regulation (EU) 2024/1689 is binding law with direct effect in all 27 Member States. There is no opting in and no scope statement you get to write yourself. Obligations attach to a roleprovider, deployer, importer or distributor — and to a risk tier assessed per system. Enforcement runs through national market surveillance authorities, and Article 99 sets the ceiling: up to 35 million euros or 7 % of total worldwide annual turnover for prohibited practices, up to 15 million euros or 3 % for most other operator breaches, and up to 7.5 million euros or 1 % for supplying incorrect information. For SMEs and start-ups each of those caps applies at the lower of the two figures rather than the higher.

Side by side: the six dimensions that settle the question

  • Legal status. ISO/IEC 42001 is a voluntary standard you may adopt. The AI Act is a regulation you must obey. No authority will ever ask to see your certificate; every authority can ask to see your AI Act evidence.
  • Unit of analysis. The certificate covers an organisation, within a scope you define. The Act attaches obligations to each AI system individually — one company can simultaneously operate a prohibited system, several Annex III high-risk systems, and a long tail of minimal-risk tools, each with a different duty set.
  • Who checks. An accredited certification body you contract and pay, on a fixed audit cycle. Versus a market surveillance authority that arrives unannounced, plus a notified body where third-party conformity assessment is required.
  • Geographic scope. ISO/IEC 42001 is international and jurisdiction-neutral; it carries the same weight in Lyon and in Lima, which is to say no legal weight anywhere. The AI Act is territorial: it reaches providers placing systems on the Union market regardless of where they are established, and deployers whose output is used in the Union.
  • Evidence produced. An AI management system yields policies, a risk register, internal audit reports, management review minutes and a certificate. The Act demands Annex IV technical documentation, automatically generated logs, an EU declaration of conformity, CE marking and a database registration. These are different artefacts, not different formats of the same artefact.
  • What failure costs. A 42001 non-conformity triggers corrective action and, at worst, suspension or withdrawal of the certificate. An AI Act breach can trigger orders to bring the system into conformity, restriction, withdrawal or recall from the market, and administrative fines at the levels above.

Where ISO 42001 genuinely helps

The strongest overlap is Article 17, which requires every provider of a high-risk AI system to put in place a documented quality management system. Article 17(1) enumerates thirteen aspects, from (a) to (m), and an organisation already running a 42001 AI management system has the organisational spine for several of them: systems and procedures for data management (f), record-keeping of all relevant documentation (k), resource management (l), and an accountability framework setting out the responsibilities of management and staff (m). You will still rewrite the procedures to speak the Act’s language, but you rewrite rather than invent.

  • Article 17 quality management system. The clause structure, document control and management review cadence transfer almost directly. What does not transfer is the regulatory-compliance strategy in point (a) — that has to be written against the AI Act specifically.
  • Article 9 risk management. Article 9 requires a continuous, iterative risk management process running across the whole lifecycle. A 42001 AI risk assessment and AI system impact assessment already give you the cadence, the register and the owner; you are re-pointing an existing engine, not building one.
  • Article 10 data governance. Annex A controls on data provenance, data quality and data preparation produce exactly the kind of artefacts the Act’s training, validation and testing data requirements expect to see.
  • Roles, competence and AI literacy. The competence and awareness clauses map onto the AI literacy obligation, which has applied since 2 February 2025 and is not deferred by anything.
  • Documentation discipline. Version control, change control, retention schedules. Half the pain of Annex IV is that nobody wrote down what the system does while it was being built; an AI management system forces that habit early.
  • Supplier and third-party controls. Useful when you integrate someone else’s model and need to establish, on the record, whether you are a provider or a deployer of the resulting system.

Where it does not help at all

The decisive point: a 42001 certificate confers no presumption of conformity. Under Article 40, that presumption arises only for systems conforming to harmonised standards whose references have been published in the Official Journal of the European Union under Regulation (EU) No 1025/2012. ISO/IEC 42001 has not been through that route and was never drafted for it. The track that matters is CEN-CENELEC JTC 21, and the relevant deliverable is prEN 18286, a quality management system standard written explicitly for EU AI Act regulatory purposes. Until a reference appears in the Official Journal, nobody holds a presumption of anything — and an auditor’s certificate is not a substitute.

  • Annex IV technical documentation. A per-system dossier covering architecture, data, performance metrics, risk controls and post-market monitoring. Nothing in an AI management system produces it. See the Annex IV breakdown.
  • Risk classification. Deciding whether a system is prohibited, high-risk, limited-risk or minimal-risk is a legal analysis against Article 5, Article 6 and Annex III. A certificate does not perform it.
  • Conformity assessment, declaration of conformity and CE marking. A distinct regulatory procedure, sometimes involving a notified body. See how conformity assessment works.
  • Article 49 registration. High-risk systems must be registered in the EU database before being placed on the market or put into service. No ISO process touches this.
  • Fundamental rights impact assessment. Article 27 obliges deployers that are public bodies or private entities providing public services, plus deployers of the Annex III point 5(b) and 5(c) systems, to run a FRIA before deployment. It is a deployer duty with its own method.
  • Serious incident reporting. Article 73 requires providers to report serious incidents to the market surveillance authority — no later than 15 days as a rule, 10 days where a death is involved, and 2 days in the case of a widespread infringement. That clock is regulatory, not contractual.

And the NIST AI RMF?

The NIST AI Risk Management Framework 1.0, released in January 2023 and extended by a Generative AI Profile in July 2024, organises AI risk work around four functions: Govern, Map, Measure and Manage. It is voluntary, US-origin, and — unlike ISO/IEC 42001 — not a certifiable scheme: no accredited body issues an AI RMF certificate, so there is no artefact to show a customer or an auditor. Its value is vocabulary and structure. Its legal effect in the European Union is nil. Treat it as a reference text you borrow from, not as a compliance deliverable you produce.

Practical sequencing for an SME with a high-risk system

  1. Classify every system first. Establish your role and the risk tier for each system before spending anything else. It is fast, it costs nothing, and it determines the entire downstream workload. Start with the Risk Checker.
  2. Clear what is already in force. The prohibited practices and the AI literacy obligation have applied since 2 February 2025; obligations on general-purpose AI models have applied since 2 August 2025. These are live today, not on a horizon.
  3. Work backwards from your actual date. Stand-alone Annex III high-risk systems apply from 2 December 2027; high-risk AI embedded in products covered by Annex I sectoral legislation applies from 2 August 2028. Both dates come from the Digital Omnibus on AI, which entered into force on 27 July 2026 — the previously circulated August 2026 and August 2027 dates are superseded.
  4. Build the Article 17 quality management system around your real systems. Scope it to the products you actually place on the market, not to a certificate boundary drawn for audit convenience.
  5. Write Annex IV documentation as you build, per system. Retrofitting a technical file onto a shipped system is the single most expensive mistake in this space. Use the SME compliance checklist to sequence the rest.
  6. Pursue 42001 certification last, and only if it buys you something. If enterprise customers or public tenders demand it, go for it — reusing evidence you have already produced. Inverting this order means paying for an audit that leaves your legal exposure untouched. Be honest with yourself: for most SMEs the Act’s deadlines, not the certificate, set the priority.

The two instruments are complementary, and the sales pitch that conflates them is the problem, not the standard. ISO/IEC 42001 is a governance accelerator and a procurement asset; the AI Act is the binding obligation. If you do not yet know which tier your systems fall into, run the Risk Checker first, then look at how EU AI Act compliance software can carry the per-system evidence your AI management system was never designed to produce. This article is general information about regulatory requirements and is not legal advice; assess your own systems with qualified counsel.

Related guides