EU AI Act · comparison
EU AI Act vs ISO/IEC 42001: Does Certification Make You Compliant?
ISO/IEC 42001 is a voluntary AI management system standard; the EU AI Act is binding law. What 42001 covers, what it misses, and how to use it as scaffolding for AI Act compliance.
Classify my system in 3 minutesThe bottom line
ISO/IEC 42001 gives you the “how we govern AI” layer: policies, risk process, roles, records, audits. The AI Act additionally demands a “this specific system meets these specific requirements” layer that 42001 does not define. Use 42001 to satisfy the quality management system duty (Art. 17) and to organise the evidence; produce the Annex IV technical file, the conformity assessment and the registration separately.
ISO/IEC 42001 is the first international management-system standard for AI, published in December 2023. Like ISO 27001 for security, it certifies that an organisation runs a governed, auditable process around its AI: policies, roles, risk assessment, impact assessment, lifecycle controls and continual improvement. Auditors love it, procurement teams increasingly ask for it, and it is the closest thing to a ready-made governance backbone for the AI Act.
It is not, however, the AI Act. The EU AI Act sets product-level requirements for specific systems (technical documentation, accuracy thresholds, human oversight design, conformity assessment, registration) that a management-system standard does not specify. The European Commission has asked CEN-CENELEC to develop harmonised standards that will give presumption of conformity; ISO 42001 is not one of them, although it is expected to be referenced.
Side by side
EU AI Act vs ISO/IEC 42001
Reuse this
Where ISO/IEC 42001 work counts toward the AI Act
- Art. 17 quality management system: a certified AIMS covers most of the listed elements (regulatory strategy, design control, data management, risk management, post-market monitoring, record keeping, accountability).
- Clause 6.1 risk assessment and the A.5 impact assessment give the process behind the Art. 9 risk management file.
- Roles and competence (clause 7) document the AI literacy duty (Art. 4).
- Internal audit and management review produce the evidence trail regulators ask for under Art. 21 cooperation.
Still needed
What ISO/IEC 42001 does not cover
- Classification of each system against Annex III and Art. 5; 42001 does not tell you which tier you are in.
- Annex IV technical documentation content, Art. 12 logging specifications, Art. 15 accuracy and robustness metrics.
- Conformity assessment route, EU declaration of conformity, CE marking, EU database registration.
- User-facing transparency copy and synthetic-content marking under Art. 50.
- Serious-incident reporting deadlines (Art. 73) and the specific post-market monitoring plan template the Commission will publish.
Know exactly where you stand under the AI Act
Free 7-question assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.
FAQ
Frequently asked questions
Will ISO 42001 certification give presumption of conformity with the AI Act?
No. Presumption of conformity comes from harmonised standards published in the Official Journal of the EU, which CEN-CENELEC JTC 21 is drafting. ISO 42001 may be referenced or adapted, but certification alone does not create the legal presumption.
Should a startup with one high-risk system get certified?
Usually not first. Build the system-level file (classification, technical documentation, risk management, human oversight) that the law requires; adopt the 42001 structure informally as your quality management system and certify later when customers ask for it.
Do notified bodies accept ISO 42001 evidence?
They can use it as evidence that the quality management system exists (Art. 17), which is one part of the Annex VII assessment. The technical documentation and the system-level requirements are assessed separately.
This page is general information, updated 2026-09-19. It is not legal advice; always check current guidance for both frameworks against your specific system.