ISO 42001 to EU AI Act mapping:
shared evidence, separate obligations.
Every ISO/IEC 42001 Annex A control and EU AI Act article in the TryTrustable control library that is evidenced by the same control, and every one that is not.
Last updated Published by TryTrustableNot legal advice
How does ISO 42001 map to the EU AI Act?
In the TryTrustable control library, 9 shared controls are tested against both ISO/IEC 42001 and EU AI Act. Those controls reach 32 of the 38 ISO/IEC 42001 requirements the library models and 18 of the 18 EU AI Act requirements. Each row below is one control and the requirements on each side it is evidence for.
Both are broken into requirements, mapped to the controls that evidence them, and paired only through a shared control. The ISO side is the ISO/IEC 42001:2023 Annex A; the Act side is Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. For the programme-level comparison see EU AI Act vs ISO 42001.
| Shared control | ISO/IEC 42001 | EU AI Act |
|---|---|---|
| Human oversight of AI decisionsCTL-AI-HITL | A.9.2 Processes for responsible use of AI systems are established | Art.14 Human oversight: measures enabling effective oversight by natural persons Art.26 Deployer obligations: use per instructions, human oversight, input data relevance |
| AI system inventoryCTL-AI-INVENTORY | A.3.2 AI roles and responsibilities are defined and allocated A.4.2 Documentation of resources (data, tooling, compute, human) for AI systems A.4.3 Data resources used for AI systems are documented A.4.4 Tooling resources used for AI systems are documented A.4.5 System and computing resources for AI systems are documented A.6.2.7 AI system technical documentation maintained A.9.4 Intended use of the AI system is defined and communicated | Art.5(1)(a) No AI using subliminal or purposefully manipulative techniques that distort behaviour Art.5(1)(f) No emotion recognition in the workplace or education institutions Art.11 Technical documentation drawn up before placing on market and kept up to date Art.51 Classification of general-purpose AI models with systemic risk Art.53 GPAI provider duties: technical documentation and copyright policy |
| AI transparency and disclosureCTL-AI-TRANSPARENCY | A.5.4 Assessing AI system impact on individuals or groups of individuals A.8.2 System documentation and information for users is provided A.8.3 External reporting mechanisms for AI systems are established A.8.4 Communication of AI incidents to interested parties A.8.5 Information for interested parties about their roles and responsibilities A.10.4 Customer expectations and responsibilities for AI systems are addressed | Art.13 Transparency and provision of information to deployers Art.50 Transparency: users informed they interact with AI; AI content is machine-marked |
| Data retention and disposalCTL-DATA-RETENTION | A.4.3 Data resources used for AI systems are documented A.7.2 Data for development and enhancement of the AI system is managed A.7.3 Acquisition of data is governed and documented A.7.5 Data provenance is recorded across the AI data pipeline A.7.6 Data preparation processes are defined and documented | Art.10 Data and data governance: training, validation and testing data quality criteria |
| Data protection impact assessmentCTL-DPIA | A.5.2 AI system impact assessment process is established A.5.3 Documentation of AI system impact assessments A.5.4 Assessing AI system impact on individuals or groups of individuals A.5.5 Assessing societal impacts of AI systems | Art.9 Risk management system established, run and maintained for high-risk AI |
| Centralised, tamper-evident loggingCTL-LOGGING | A.6.2.6 AI system operation and monitoring in production A.6.2.8 AI system recording of event logs | Art.12 Record-keeping: automatic logging of events over the system lifetime Art.72 Post-market monitoring system to collect and analyse AI performance data |
| Model evaluation and monitoringCTL-MODEL-EVAL | A.6.2.4 AI system verification and validation performed and evidenced A.6.2.6 AI system operation and monitoring in production A.7.4 Quality of data for AI systems is assessed and maintained | Art.9 Risk management system established, run and maintained for high-risk AI Art.10 Data and data governance: training, validation and testing data quality criteria Art.15 Accuracy, robustness and cybersecurity appropriate to the intended purpose Art.55 Systemic-risk GPAI: model evaluation, adversarial testing and incident reporting Art.72 Post-market monitoring system to collect and analyse AI performance data |
| Policy review and attestationCTL-POLICY-REVIEW | A.2.2 AI policy: a policy for the development or use of AI systems is established A.2.3 Alignment of the AI policy with other organizational policies A.2.4 Review of the AI policy at planned intervals A.3.2 AI roles and responsibilities are defined and allocated A.6.1.2 Objectives for responsible development of AI systems are documented A.9.2 Processes for responsible use of AI systems are established A.9.3 Objectives for responsible use of AI systems are documented | Art.5(1)(a) No AI using subliminal or purposefully manipulative techniques that distort behaviour Art.5(1)(b) No AI exploiting vulnerabilities of persons due to age, disability or social situation Art.5(1)(c) No social scoring leading to detrimental or unjustified treatment Art.16 Provider obligations: quality management system and conformity assessment |
| Vendor due diligence and monitoringCTL-VENDOR-DD | A.7.3 Acquisition of data is governed and documented A.10.2 Responsibilities are allocated across third parties in the AI value chain A.10.3 Suppliers of AI systems and components are governed A.10.4 Customer expectations and responsibilities for AI systems are addressed | Art.53 GPAI provider duties: technical documentation and copyright policy |
Generated from the TryTrustable control library. Requirement descriptions are the library's own short wording of what the control is tested against, not the text of the standard or law. A mapping we could not stand behind on review is left out until it is corrected in the library.
62 rows: one per control and requirement, with the library description. Paste into a spreadsheet.
Which controls does only one side ask for?
A requirement can be reached through a general control and still need a specific one. These controls are mapped to requirements on one side only, so evidence for them does nothing for the other framework.
Only ISO/IEC 42001:
- Formal change management CTL-CHANGE-MGMT: A.6.2.5
- Incident response plan and exercise CTL-IR-PLAN: A.3.3, A.8.4
- Secure software development lifecycle CTL-SDLC: A.6.1.2, A.6.1.3, A.6.2.2, A.6.2.3
- Security awareness training CTL-TRAINING: A.4.6
Only EU AI Act:
- AI red-teaming and adversarial testing CTL-AI-REDTEAM: Art.15, Art.55
Reading this mapping without over-reading it
The strongest rows are evidence rows: the AI inventory, model evaluation, event logging and impact assessment each produce records that serve an Annex A control and an AI Act article at once. The weakest are policy rows. A reviewed AI policy is mapped to the Article 5 prohibitions because a policy is how an organisation forbids those practices, but no policy proves a system does not use them; that needs the inventory and a per-system classification.
The Commission has said, in its standardisation FAQ, that ISO/IEC 42001 is not aligned with the Act's quality management system requirement, and the Act regulates each system as a product. Use the rows to avoid gathering the same evidence twice, and the EU AI Act guide for what each article actually requires. The ISO 42001 guide covers the standard, and AI governance the product side.
The things people ask us
Does ISO 42001 certification satisfy the EU AI Act?
No. ISO/IEC 42001 certifies an organisation's AI management system; the EU AI Act regulates individual AI systems, with risk classification, technical documentation and conformity assessment per system. ISO/IEC 42001 has not been cited as a harmonised standard under the Act, so a certificate gives no presumption of conformity. The shared rows are reusable evidence, not compliance.
Which EU AI Act obligations apply now?
The prohibitions in Article 5 and the AI literacy duty have applied since February 2025, the general-purpose AI model duties since August 2025, and the Article 50 transparency duties since 2 August 2026. As amended by the Digital Omnibus, standalone Annex III high-risk obligations apply from 2 December 2027 and Annex I embedded systems from 2 August 2028.
Which AI Act articles are in this mapping?
The library models 18 points: the Article 5 prohibitions it can evidence, the high-risk requirements in Articles 9 to 16, the deployer duties in Article 26, Article 50 transparency, the general-purpose AI articles 51, 53 and 55, and post-market monitoring in Article 72. It is a working subset of the Act, not the full text.
How many ISO 42001 Annex A controls are mapped?
All 38 Annex A controls, A.2 to A.10, are modelled in the library. Those that share a control with an EU AI Act article appear in the table; the rest, such as change management for AI deployment, human resources and competence, and the channel for reporting concerns, are listed in the gap section because the library maps them to no AI Act article.
Can I download this mapping?
Use Copy as CSV below the table. It copies one line per control and requirement with the library's description, ready to paste into a spreadsheet. The mapping is generated from the control library the product uses, so it changes when the library does.
Evidence ISO 42001 and the AI Act from one inventory.
Thirty minutes. We register a model, run a judged evaluation and show the record landing against an Annex A control and an AI Act article together.