EU AI Act vs ISO 42001:
a certificate is not conformity.
ISO 42001 certifies how your organisation governs AI. The EU AI Act regulates individual AI systems as products. They share a lot of controls, they are not interchangeable, and confusing the two is how companies arrive at December 2027 holding a certificate and no conformity assessment.
Last updated Published by TryTrustableNot legal advice
What is the difference between the EU AI Act and ISO 42001?
The EU AI Act is a law that regulates individual AI systems as products, with conformity assessment, registration and fines of up to €35 million or 7% of turnover. ISO/IEC 42001 is a voluntary standard that certifies how an organisation governs AI. The two overlap in controls, but a 42001 certificate is not an AI Act declaration of conformity.
| EU AI Act | ISO/IEC 42001 | |
|---|---|---|
| Nature | Law: Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 | A voluntary international management-system standard, ISO/IEC 42001:2023 |
| Who it binds | Providers, deployers, importers and distributors of AI systems whose output is used in the EU, wherever they are established | Nobody, until an organisation chooses to adopt it or a customer contract requires it |
| Who checks | The provider itself for most Annex III systems (internal control); a notified body for some biometric systems and for Annex I products under their sectoral law; national market surveillance authorities enforce | An accredited certification body, auditing to ISO/IEC 17021-1 and ISO/IEC 42006 |
| Unit of assessment | The individual AI system, per intended purpose | The organisation's AI management system (AIMS), within a scope it defines |
| What it proves | That a system meets the Act's requirements for its risk tier, via a declaration of conformity, CE marking and EU database registration | That the organisation runs a governance process for AI that conforms to the standard's clauses and its chosen Annex A controls |
| Legal effect | Mandatory. Harmonised standards cited in the Official Journal give a presumption of conformity under Article 40 | None under the Act. Not cited as a harmonised standard, and the Commission says it is not aligned with the Act's quality management system requirement |
| Penalties | Up to €35m or 7% of worldwide turnover for prohibited practices; €15m or 3% for most other obligations | None. A certificate can be suspended or withdrawn |
| Renewal | Continuous: post-market monitoring, serious-incident reporting, reassessment after substantial modification | Three-year certificate with surveillance audits in between |
| Overlap | Risk management, data governance, documentation, logging, human oversight, monitoring, incident handling, roles and competence | The same, expressed as management-system clauses and Annex A controls |
Checked September 2026. Harmonised standards for the AI Act are being written by CEN-CENELEC JTC 21; watch the Official Journal rather than vendor claims for their status.
Different objects, not different depths
The temptation is to read these as the same subject at two levels of rigour. They are not. They attach to different things, and that single distinction explains every other row in the table. A market surveillance authority asks about a system: what it is for, which tier it falls in, what its documentation says and whether it was assessed before it went live. A certification auditor asks about an organisation: whether it has an AI policy, assigned roles, a risk and impact assessment process, and evidence that the process runs and improves.
Both questions are legitimate, and a mature programme can answer both from the same evidence. What it cannot do is answer one with the other.
Where they genuinely overlap
The overlap is real at the level of controls and worth exploiting. A control you operate once produces evidence both can use.
- Risk management across the lifecycle: AI Act Article 9, ISO 42001 clauses 6.1 and 8
- Data governance: quality, provenance and preparation of training and test data; Article 10 and Annex A.7
- Documentation and record-keeping: though the Act specifies Annex IV content and the standard does not
- Human oversight: designed in, with a person able to understand and intervene
- Monitoring, measurement and incident handling after deployment
- Roles, competence and accountability for the people operating the system
What certification does not give you
This is the list that matters, because it is what a market surveillance authority will ask for and a certificate does not contain.
- A risk tier for each system. Whether a given system is Annex III high-risk is a legal classification, not a management-system output
- Annex IV technical documentation. Prescribed content, per system, complete before market placement
- Conformity assessment and CE marking. The actual legal mechanism by which a high-risk system becomes lawful to place on the market
- Registration in the EU database for standalone high-risk systems
- A presumption of conformity. That attaches only to harmonised standards cited in the Official Journal. ISO 42001 is not one of them
- Fundamental rights impact assessment, where a deployer owes one
Running the inverse is equally wrong: satisfying the Act for three systems does not give you a management system, and will not answer a customer asking for a certificate.
Doing both without doing everything twice
The overlap only pays if the controls are shared rather than duplicated. Evidencing human oversight once and mapping that result to AI Act Article 14 and to the relevant ISO 42001 control is the difference between a second framework that reuses your work and one that repeats it.
That is the model this platform is built on: see cross-framework mapping for how one control reaches several regimes, and the ISO 42001 guide for what the standard actually contains, clause by clause. For the Act's own timeline, including the dates that moved in July 2026, the EU AI Act compliance guide has the table.
The things people ask us
What is the difference between the EU AI Act and ISO 42001?
The EU AI Act is a law that regulates individual AI systems as products, with conformity assessment, registration and fines of up to €35 million or 7% of turnover. ISO/IEC 42001 is a voluntary standard that certifies how an organisation governs AI. The two overlap in controls, but a 42001 certificate is not an AI Act declaration of conformity.
Does ISO 42001 certification make us EU AI Act compliant?
No, and this is the most expensive misunderstanding in AI governance right now. ISO 42001 certifies a management system: how your organisation governs AI. The AI Act regulates AI systems as products, and requires conformity assessment of the system itself. A certificate is strong evidence that your governance is real; it is not a declaration of conformity for any particular system.
How much do ISO 42001 and the EU AI Act overlap?
Substantially at the level of controls, not at all at the level of legal mechanism. Risk management, data governance, documentation, human oversight, monitoring and incident handling appear in both. What ISO 42001 does not contain is the product-specific machinery: risk tiering under Annex III, Annex IV technical documentation, conformity assessment, CE marking, EU database registration and post-market monitoring.
Which should we do first?
If you sell into the EU and have a system that lands in Annex III, the Act is not optional and the date is 2 December 2027, so it sets the schedule. ISO 42001 is worth doing first only when the driver is commercial , customers asking for a certificate, or when you need the management system as scaffolding for the Act work anyway. Many organisations do both, using the certification to build the governance the Act then assumes you have.
Is ISO 42001 a harmonised standard under the AI Act?
No. Under Article 40, only harmonised standards cited in the Official Journal give a presumption of conformity. The Commission has said ISO/IEC 42001 is not aligned with the quality management system the Act requires, and asked CEN-CENELEC for a dedicated standard instead. So certification cannot stand in for conformity assessment, and a 42001 certificate carries no presumption of conformity.
Do we need ISO 27001 before ISO 42001?
Not formally: ISO 42001 can be certified on its own, unlike ISO 27701 which extends ISO 27001. In practice many organisations already hold ISO 27001 and integrate the two management systems, because the clause structure is shared and auditing them together is cheaper than auditing them apart.
Does either of them cover the GDPR or the DPDP Act?
Neither covers data protection law. An AI system that processes personal data engages the GDPR or the DPDP Act independently, with its own lawful basis, notice and rights obligations. The controls overlap heavily; the legal obligations do not substitute for one another.
One control, two regimes, one piece of evidence.
We show the same control result satisfying an AI Act requirement and an ISO 42001 clause at the same time, from live state rather than a spreadsheet.