AI governance

ISO 42001 vs EU AI Act: management system standard vs AI law

ISO/IEC 42001 is a voluntary, certifiable standard. The EU AI Act is binding law with fines. Here is how they differ, where the work overlaps and why a certificate is not conformity.

Short answer

ISO 42001 vs EU AI Act is a comparison of a voluntary standard and a binding law. ISO/IEC 42001:2023 sets requirements for an AI management system and can be certified. The EU AI Act, Regulation (EU) 2024/1689, sets legal duties by risk class, with fines. Certification supports compliance with the Act but does not prove it.

Key takeaways

  • ISO 42001 is voluntary and certifies an organisation; the EU AI Act is law and regulates each AI system by risk class.
  • ISO 42001 has 38 Annex A controls alongside clauses 4 to 10.
  • An ISO 42001 certificate does not give a presumption of conformity with the Act.
  • High-risk obligations under the Act apply from 2 December 2027, after the 2026 Digital Omnibus.

The short version

ISO/IEC 42001:2023 is a management system standard. It asks an organisation to set an AI policy, assess AI risks and impacts, apply controls across the AI system life cycle, and review how it all performs. An accredited body can certify it. The EU AI Act is a regulation. It applies to anyone who places an AI system on the EU market, puts one into service there or uses one there, and it sets duties by how risky the system is.

ISO 42001EU AI Act
What it isRequirements for an AI management system (AIMS)A law regulating AI systems placed on or used in the EU market
ReferenceISO/IEC 42001:2023Regulation (EU) 2024/1689, amended by the 2026 Digital Omnibus
Binding?VoluntaryMandatory for those in scope
Who it applies toAny organisation that develops, provides or uses AIProviders, deployers, importers and distributors, including those outside the EU
ApproachManagement system: policy, risk, controls, reviewRisk classes, plus rules for general-purpose AI models
StructureClauses 4 to 10, plus 38 Annex A controlsChapters, articles and annexes
How you show itCertificate from an accredited bodyConformity assessment, CE marking and registration for high-risk systems
PenaltiesNone; a certificate can be withdrawnUp to €35 million or 7% of worldwide turnover for prohibited practices
Enforced byCertification bodies, through auditsNational authorities and the EU AI Office

How the EU AI Act sorts AI systems

The Act uses four levels. Some practices are prohibited outright. High-risk systems, such as AI used in recruitment, credit scoring or as a safety component of a regulated product, carry the heaviest duties. Systems that interact with people or generate content have transparency duties. Everything else is minimal risk, with no specific obligations. General-purpose AI models have their own set of rules.

Timeline

EU AI Act: when each part applies

  1. In forceRegulation (EU) 2024/1689
  2. Prohibitions applyProhibited practices and AI literacy
  3. General-purpose AIDuties for providers of general-purpose AI models
  4. Transparency dutiesArticle 50
  5. High-risk obligationsAfter the 2026 Digital Omnibus

How ISO 42001 is built

ISO 42001 follows the same structure as ISO 27001. Clauses 4 to 10 set the management system: context, leadership, planning, support, operation, performance evaluation and improvement. Two requirements are specific to AI: an AI risk assessment and an AI system impact assessment, which looks at the effect on individuals and society. Annex A then lists 38 controls under nine objectives, from AI policies and internal organisation to data for AI systems, information for interested parties, use of AI systems and third-party relationships.

A certificate is not conformity

Under the Act, following a harmonised European standard gives a presumption of conformity with the requirements it covers. ISO/IEC 42001 is not a harmonised standard under the Act, so holding a certificate does not give that presumption. European standards written for this purpose are being developed. What ISO 42001 does give you is the working machinery: named owners, a risk process, records and reviews that an authority or a customer can inspect.

Where ISO 42001 and the EU AI Act overlap

An AI management system supplies most of the working parts the Act expects from providers of high-risk systems. The mapping below shows where work can be reused. It is indicative and does not show legal equivalence.

ISO 42001:2023EU AI Act
  1. Clause 6.1AI risk assessment and treatmentArticle 9Risk management system
  2. 6.1.4, A.5AI system impact assessmentArticle 27Fundamental rights impact assessment
  3. A.7Data for AI systemsArticle 10Data and data governance
  4. 7.5, A.6Documented information, AI life cycleArticles 11–12Technical documentation and record-keeping
  5. A.8Information for interested partiesArticles 13, 50Transparency
  6. A.9Use of AI systemsArticles 14, 26Human oversight and deployer duties
  7. Clauses 4–10The management systemArticle 17Quality management system
  8. 7.2, 7.3Competence and awarenessArticle 4AI literacy
Full mappingPartial mappingIndicative mapping. Check each row against the Regulation and the standard before relying on it.

Do you need one, the other, or both?

Start with the law. Work out whether the Act applies to you, in which role (provider, deployer, importer or distributor) and in which risk class. Then decide how to meet those duties. ISO 42001 is a sound way to build the management system behind them, and it is also what customers increasingly ask for as proof of responsible AI. If you already hold ISO 27001, the two standards share a structure, so the same management system can be extended to AI.

Checklist

Preparing for both

0 of 6 done

This article is general information, not legal advice. Dates reflect the Act as amended in 2026; check the current text before relying on them.

Put this into practice on QULDEX

Frequently asked questions

Does ISO 42001 certification make me EU AI Act compliant?

No. It supports compliance by putting risk management, documentation and oversight in place, but it is not a harmonised standard under the Act and does not prove conformity.

Is ISO 42001 mandatory under the EU AI Act?

No. The Act does not require ISO 42001. Providers of high-risk systems need a quality management system, which ISO 42001 can help deliver.

Should we start with ISO 42001 or the EU AI Act?

First work out whether the Act applies to you and in which risk class. Then use ISO 42001 to build the management system that meets those duties.

How many controls does ISO 42001 have?

38 Annex A controls, alongside the requirements in clauses 4 to 10.

When do the EU AI Act's high-risk rules apply?

From 2 December 2027, after the 2026 Digital Omnibus. Prohibitions have applied since 2 February 2025.

Sources

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act), EUR-Lex
  2. ISO/IEC 42001:2023 Artificial intelligence management system, ISO
  3. Regulatory framework for AI, European Commission
  4. NIST AI Risk Management Framework, NIST