AI governance

ISO 42001 vs the EU AI Act

One is a standard you can certify to. The other is a law with fines. Product teams keep being asked for both. Here is what each requires, where they overlap, and the order to do them in.
8 min read · Certifyi compliance team · Updated September 2026
Short answer. ISO/IEC 42001 is a voluntary, certifiable standard for an AI management system. The EU AI Act is mandatory law for AI systems placed on the EU market or whose output is used in the EU, with obligations that depend on the system’s risk tier. They are not alternatives: an ISO 42001 management system is the most practical way to organise the evidence the AI Act requires, and the certificate is what customers ask to see.

What ISO 42001 is

Published in December 2023, ISO 42001 follows the same clause structure as ISO 27001: context, leadership, planning, support, operation, performance evaluation and improvement. Its Annex A lists AI-specific controls covering the AI policy, roles, resources, impact assessment, system lifecycle, data, information for interested parties, use of AI systems and third-party relationships. An accredited certification body audits it in two stages and issues a three-year certificate.

What the EU AI Act is

Regulation (EU) 2024/1689 classifies AI systems by risk. Prohibited practices (social scoring, certain biometric uses) are banned. High-risk systems, listed in Annex III (employment, credit, education, critical infrastructure, essential services, law enforcement, biometrics) and product-safety areas, carry the heaviest obligations: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, conformity assessment and registration. Limited-risk systems have transparency duties; general-purpose AI models have their own obligations.
MilestoneDateWho it affects
Prohibited practices apply2 February 2025Everyone
General-purpose AI obligations apply2 August 2025GPAI model providers
Most high-risk obligations apply2 August 2026Providers and deployers of Annex III systems
High-risk systems in regulated products2 August 2027Product-safety categories

Where they overlap

Almost everywhere that matters. The AI Act’s risk management system, data governance, technical documentation, logging, human oversight and post-market monitoring map directly onto ISO 42001’s impact assessment, data controls, lifecycle documentation, monitoring and improvement clauses. The European Commission has signalled that harmonised standards will be the route to presumption of conformity, and ISO 42001 is the closest existing management-system standard.

Where they differ

Which to do first

If you sell to enterprises, start with ISO 42001 on top of ISO 27001. It produces the certificate buyers ask for and builds the inventory, impact assessments and lifecycle controls the AI Act needs. Then classify each AI system against the Act’s tiers. If any is high-risk, add the Act-specific artefacts: technical documentation in the Annex IV format, logging design, the conformity assessment route and registration. If none is high-risk, your remaining obligations are mostly transparency, and the ISO 42001 system already documents them.

The two documents to build first

An AI system inventory and an impact assessment per system. Every other requirement in both frameworks hangs off them. Certifyi keeps them in the same register as your security risks, so the AI overlay reuses the governance, document control and audit machinery you already run.

Frequently asked questions

Not by itself. It shows you run a conforming AI management system, which covers most of the Act’s organisational requirements. High-risk systems still need the Act-specific documentation and conformity assessment.

Yes. Under the Act you are a deployer, with obligations on oversight, transparency and, for high-risk uses, monitoring. ISO 42001 applies to users of AI as well as developers.

Four to six weeks to audit-ready in a Certifyi engagement, because the management-system clauses are shared and the AI controls are an overlay.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.
Scroll to Top