AI governance
ISO 42001 vs the EU AI Act
One is a standard you can certify to. The other is a law with fines. Product teams keep being asked for both. Here is what each requires, where they overlap, and the order to do them in.
8 min read · Certifyi compliance team · Updated September 2026
Short answer. ISO/IEC 42001 is a voluntary, certifiable standard for an AI management system. The EU AI Act is mandatory law for AI systems placed on the EU market or whose output is used in the EU, with obligations that depend on the system’s risk tier. They are not alternatives: an ISO 42001 management system is the most practical way to organise the evidence the AI Act requires, and the certificate is what customers ask to see.
What ISO 42001 is
Published in December 2023, ISO 42001 follows the same clause structure as ISO 27001: context, leadership, planning, support, operation, performance evaluation and improvement. Its Annex A lists AI-specific controls covering the AI policy, roles, resources, impact assessment, system lifecycle, data, information for interested parties, use of AI systems and third-party relationships. An accredited certification body audits it in two stages and issues a three-year certificate.
What the EU AI Act is
Regulation (EU) 2024/1689 classifies AI systems by risk. Prohibited practices (social scoring, certain biometric uses) are banned. High-risk systems, listed in Annex III (employment, credit, education, critical infrastructure, essential services, law enforcement, biometrics) and product-safety areas, carry the heaviest obligations: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, conformity assessment and registration. Limited-risk systems have transparency duties; general-purpose AI models have their own obligations.
| Milestone | Date | Who it affects |
|---|---|---|
| Prohibited practices apply | 2 February 2025 | Everyone |
| General-purpose AI obligations apply | 2 August 2025 | GPAI model providers |
| Most high-risk obligations apply | 2 August 2026 | Providers and deployers of Annex III systems |
| High-risk systems in regulated products | 2 August 2027 | Product-safety categories |
Where they overlap
Almost everywhere that matters. The AI Act’s risk management system, data governance, technical documentation, logging, human oversight and post-market monitoring map directly onto ISO 42001’s impact assessment, data controls, lifecycle documentation, monitoring and improvement clauses. The European Commission has signalled that harmonised standards will be the route to presumption of conformity, and ISO 42001 is the closest existing management-system standard.
Where they differ
- Scope: ISO 42001 applies to any organisation using or developing AI; the AI Act applies by market and risk tier.
- Output: a certificate versus legal compliance and, for high-risk systems, a conformity assessment and EU database registration.
- Enforcement: certification bodies versus national market-surveillance authorities with fines up to 7% of global turnover.
- Specificity: the AI Act names exact documentation and logging requirements for high-risk systems; ISO 42001 leaves depth to your risk assessment.
Which to do first
If you sell to enterprises, start with ISO 42001 on top of ISO 27001. It produces the certificate buyers ask for and builds the inventory, impact assessments and lifecycle controls the AI Act needs. Then classify each AI system against the Act’s tiers. If any is high-risk, add the Act-specific artefacts: technical documentation in the Annex IV format, logging design, the conformity assessment route and registration. If none is high-risk, your remaining obligations are mostly transparency, and the ISO 42001 system already documents them.
The two documents to build first
An AI system inventory and an impact assessment per system. Every other requirement in both frameworks hangs off them. Certifyi keeps them in the same register as your security risks, so the AI overlay reuses the governance, document control and audit machinery you already run.
Frequently asked questions
Does ISO 42001 certification prove EU AI Act compliance?
Not by itself. It shows you run a conforming AI management system, which covers most of the Act’s organisational requirements. High-risk systems still need the Act-specific documentation and conformity assessment.
We only use third-party models through an API. Does any of this apply?
Yes. Under the Act you are a deployer, with obligations on oversight, transparency and, for high-risk uses, monitoring. ISO 42001 applies to users of AI as well as developers.
How long does ISO 42001 take if we already hold ISO 27001?
Four to six weeks to audit-ready in a Certifyi engagement, because the management-system clauses are shared and the AI controls are an overlay.
Get audit-ready in 8 to 12 weeks
Certifyi pairs the platform with a named compliance lead who implements with your team, priced on scope and due at audit sign-off.