Mapping · ISO 42001 ↔ EU AI Act

ISO 42001 to EU AI Act mapping:
shared evidence, separate obligations.

Every ISO/IEC 42001 Annex A control and EU AI Act article in the TryTrustable control library that is evidenced by the same control, and every one that is not.

9 shared controlsISO/IEC 42001: 32/38 reachedEU AI Act: 18/18 reachedCopy as CSV

Last updated Published by TryTrustableNot legal advice

01

How does ISO 42001 map to the EU AI Act?

In the TryTrustable control library, 9 shared controls are tested against both ISO/IEC 42001 and EU AI Act. Those controls reach 32 of the 38 ISO/IEC 42001 requirements the library models and 18 of the 18 EU AI Act requirements. Each row below is one control and the requirements on each side it is evidence for.

Both are broken into requirements, mapped to the controls that evidence them, and paired only through a shared control. The ISO side is the ISO/IEC 42001:2023 Annex A; the Act side is Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. For the programme-level comparison see EU AI Act vs ISO 42001.

Shared controlISO/IEC 42001EU AI Act
Human oversight of AI decisionsCTL-AI-HITL
A.9.2 Processes for responsible use of AI systems are established
Art.14 Human oversight: measures enabling effective oversight by natural persons
Art.26 Deployer obligations: use per instructions, human oversight, input data relevance
AI system inventoryCTL-AI-INVENTORY
A.3.2 AI roles and responsibilities are defined and allocated
A.4.2 Documentation of resources (data, tooling, compute, human) for AI systems
A.4.3 Data resources used for AI systems are documented
A.4.4 Tooling resources used for AI systems are documented
A.4.5 System and computing resources for AI systems are documented
A.6.2.7 AI system technical documentation maintained
A.9.4 Intended use of the AI system is defined and communicated
Art.5(1)(a) No AI using subliminal or purposefully manipulative techniques that distort behaviour
Art.5(1)(f) No emotion recognition in the workplace or education institutions
Art.11 Technical documentation drawn up before placing on market and kept up to date
Art.51 Classification of general-purpose AI models with systemic risk
Art.53 GPAI provider duties: technical documentation and copyright policy
AI transparency and disclosureCTL-AI-TRANSPARENCY
A.5.4 Assessing AI system impact on individuals or groups of individuals
A.8.2 System documentation and information for users is provided
A.8.3 External reporting mechanisms for AI systems are established
A.8.4 Communication of AI incidents to interested parties
A.8.5 Information for interested parties about their roles and responsibilities
A.10.4 Customer expectations and responsibilities for AI systems are addressed
Art.13 Transparency and provision of information to deployers
Art.50 Transparency: users informed they interact with AI; AI content is machine-marked
Data retention and disposalCTL-DATA-RETENTION
A.4.3 Data resources used for AI systems are documented
A.7.2 Data for development and enhancement of the AI system is managed
A.7.3 Acquisition of data is governed and documented
A.7.5 Data provenance is recorded across the AI data pipeline
A.7.6 Data preparation processes are defined and documented
Art.10 Data and data governance: training, validation and testing data quality criteria
Data protection impact assessmentCTL-DPIA
A.5.2 AI system impact assessment process is established
A.5.3 Documentation of AI system impact assessments
A.5.4 Assessing AI system impact on individuals or groups of individuals
A.5.5 Assessing societal impacts of AI systems
Art.9 Risk management system established, run and maintained for high-risk AI
Centralised, tamper-evident loggingCTL-LOGGING
A.6.2.6 AI system operation and monitoring in production
A.6.2.8 AI system recording of event logs
Art.12 Record-keeping: automatic logging of events over the system lifetime
Art.72 Post-market monitoring system to collect and analyse AI performance data
Model evaluation and monitoringCTL-MODEL-EVAL
A.6.2.4 AI system verification and validation performed and evidenced
A.6.2.6 AI system operation and monitoring in production
A.7.4 Quality of data for AI systems is assessed and maintained
Art.9 Risk management system established, run and maintained for high-risk AI
Art.10 Data and data governance: training, validation and testing data quality criteria
Art.15 Accuracy, robustness and cybersecurity appropriate to the intended purpose
Art.55 Systemic-risk GPAI: model evaluation, adversarial testing and incident reporting
Art.72 Post-market monitoring system to collect and analyse AI performance data
Policy review and attestationCTL-POLICY-REVIEW
A.2.2 AI policy: a policy for the development or use of AI systems is established
A.2.3 Alignment of the AI policy with other organizational policies
A.2.4 Review of the AI policy at planned intervals
A.3.2 AI roles and responsibilities are defined and allocated
A.6.1.2 Objectives for responsible development of AI systems are documented
A.9.2 Processes for responsible use of AI systems are established
A.9.3 Objectives for responsible use of AI systems are documented
Art.5(1)(a) No AI using subliminal or purposefully manipulative techniques that distort behaviour
Art.5(1)(b) No AI exploiting vulnerabilities of persons due to age, disability or social situation
Art.5(1)(c) No social scoring leading to detrimental or unjustified treatment
Art.16 Provider obligations: quality management system and conformity assessment
Vendor due diligence and monitoringCTL-VENDOR-DD
A.7.3 Acquisition of data is governed and documented
A.10.2 Responsibilities are allocated across third parties in the AI value chain
A.10.3 Suppliers of AI systems and components are governed
A.10.4 Customer expectations and responsibilities for AI systems are addressed
Art.53 GPAI provider duties: technical documentation and copyright policy

Generated from the TryTrustable control library. Requirement descriptions are the library's own short wording of what the control is tested against, not the text of the standard or law. A mapping we could not stand behind on review is left out until it is corrected in the library.

62 rows: one per control and requirement, with the library description. Paste into a spreadsheet.

02

Which ISO/IEC 42001 requirements have no shared control with EU AI Act?

These ISO/IEC 42001 requirements are modelled in the library but share no control with any EU AI Act requirement. They are the work that EU AI Act does not cover for you, or places where the library has not linked them yet.

  • A.3.3 Reporting of concerns about the organization's AI systems through defined channels
  • A.4.6 Human resources and competencies for AI systems are documented
  • A.6.1.3 Processes for responsible design and development of AI systems
  • A.6.2.2 AI system requirements and specification are defined
  • A.6.2.3 Documentation of AI system design and development
  • A.6.2.5 AI system deployment follows a controlled process

And the EU AI Act requirements with no shared control on the ISO/IEC 42001 side:

None.

03

Which controls does only one side ask for?

A requirement can be reached through a general control and still need a specific one. These controls are mapped to requirements on one side only, so evidence for them does nothing for the other framework.

Only ISO/IEC 42001:

  • Formal change management CTL-CHANGE-MGMT: A.6.2.5
  • Incident response plan and exercise CTL-IR-PLAN: A.3.3, A.8.4
  • Secure software development lifecycle CTL-SDLC: A.6.1.2, A.6.1.3, A.6.2.2, A.6.2.3
  • Security awareness training CTL-TRAINING: A.4.6

Only EU AI Act:

  • AI red-teaming and adversarial testing CTL-AI-REDTEAM: Art.15, Art.55
04

Reading this mapping without over-reading it

The strongest rows are evidence rows: the AI inventory, model evaluation, event logging and impact assessment each produce records that serve an Annex A control and an AI Act article at once. The weakest are policy rows. A reviewed AI policy is mapped to the Article 5 prohibitions because a policy is how an organisation forbids those practices, but no policy proves a system does not use them; that needs the inventory and a per-system classification.

The Commission has said, in its standardisation FAQ, that ISO/IEC 42001 is not aligned with the Act's quality management system requirement, and the Act regulates each system as a product. Use the rows to avoid gathering the same evidence twice, and the EU AI Act guide for what each article actually requires. The ISO 42001 guide covers the standard, and AI governance the product side.

Questions

The things people ask us

Does ISO 42001 certification satisfy the EU AI Act?

No. ISO/IEC 42001 certifies an organisation's AI management system; the EU AI Act regulates individual AI systems, with risk classification, technical documentation and conformity assessment per system. ISO/IEC 42001 has not been cited as a harmonised standard under the Act, so a certificate gives no presumption of conformity. The shared rows are reusable evidence, not compliance.

Which EU AI Act obligations apply now?

The prohibitions in Article 5 and the AI literacy duty have applied since February 2025, the general-purpose AI model duties since August 2025, and the Article 50 transparency duties since 2 August 2026. As amended by the Digital Omnibus, standalone Annex III high-risk obligations apply from 2 December 2027 and Annex I embedded systems from 2 August 2028.

Which AI Act articles are in this mapping?

The library models 18 points: the Article 5 prohibitions it can evidence, the high-risk requirements in Articles 9 to 16, the deployer duties in Article 26, Article 50 transparency, the general-purpose AI articles 51, 53 and 55, and post-market monitoring in Article 72. It is a working subset of the Act, not the full text.

How many ISO 42001 Annex A controls are mapped?

All 38 Annex A controls, A.2 to A.10, are modelled in the library. Those that share a control with an EU AI Act article appear in the table; the rest, such as change management for AI deployment, human resources and competence, and the channel for reporting concerns, are listed in the gap section because the library maps them to no AI Act article.

Can I download this mapping?

Use Copy as CSV below the table. It copies one line per control and requirement with the library's description, ready to paste into a spreadsheet. The mapping is generated from the control library the product uses, so it changes when the library does.

Book a walkthrough

Evidence ISO 42001 and the AI Act from one inventory.

Thirty minutes. We register a model, run a judged evaluation and show the record landing against an Annex A control and an AI Act article together.