Skip to content

ISO 42001 vs the EU AI Act: how they fit together

5 min read by John Bagnall

Updated July 8, 2026

The EU AI Act is law that tells you what you must do with AI. ISO 42001 is a voluntary standard that tells you how to organise yourself to do it. They are complementary, not competing: a well-run ISO 42001 management system gives you most of the machinery the Act expects, in an auditable form. The one thing to be clear on is that the ISO 42001 certificate is not the same as legal compliance with the Act.

People treat them as rival options, or assume one cancels out the other. Neither is true. Here is how they actually relate.

What each one is

The EU AI Act (Regulation (EU) 2024/1689) is binding law. It classifies AI by risk, from prohibited practices through high-risk and limited-risk to minimal, and attaches obligations to each tier, with penalties up to €35M or 7% of global turnover for the most serious breaches. It tells you, as a legal requirement, what you must and must not do. We covered the deployer side in the EU AI Act for deployers.

ISO/IEC 42001 is the international standard for an AI Management System (AIMS). It is voluntary, and it describes how to run AI governance as a system: policy, roles, an inventory, risk assessment, controls, oversight, monitoring and records. It tells you how to organise so that doing the right thing is repeatable and provable. We covered whether you need it in do you need ISO 42001?.

Side by side

EU AI ActISO 42001
What it isLawVoluntary management-system standard
Tells youWhat you must doHow to organise to do it
Mandatory?Yes, if you are in scopeNo
ScopeAI placed on or used in the EU marketAny organisation that uses or builds AI
StructureRisk tiers and obligationsA management system you run and improve
Enforced byNational regulatorsOptional audit by an accredited body
Get it wrongFines up to €35M / 7% turnoverNo legal penalty; lost trust and tenders
ProofYou must be able to demonstrate complianceA certificate, if you choose to certify

How they fit together

The cleanest way to think about it: the Act is the requirements list, ISO 42001 is the operating system that delivers against it.

The Act says, for example, that high-risk systems need human oversight, logging, risk management, technical documentation and post-market monitoring. ISO 42001 is precisely the framework that produces those things as a matter of routine:

  • The Act expects you to know and classify your AI. ISO 42001 starts with an inventory and risk classification.
  • The Act expects human oversight on high-risk systems. ISO 42001 builds oversight and responsible-use controls in.
  • The Act expects documentation and traceability. ISO 42001 runs on documented information and an evidence trail.
  • The Act expects risk management. ISO 42001 is a risk-based management system by design.
  • The Act expects AI literacy (Article 4). ISO 42001 covers competence and awareness.

Run a real ISO 42001 system and you are doing most of what the Act asks, in the structure an auditor or regulator recognises. That is why procurement teams increasingly ask for ISO 42001: it is shorthand for “this organisation can show its AI is controlled.”

The misconception to avoid

The trap is assuming the certificate equals compliance. It does not.

  • ISO 42001 certification is not a legal compliance statement. It confirms you run a conforming management system; it does not certify that every system meets the Act’s specific obligations.
  • EU AI Act compliance does not require ISO 42001. You can be compliant without ever certifying. ISO 42001 just makes getting there, and proving it, far easier.

Treat ISO 42001 as how you operationalise the law, and the Act as the legal baseline you have to hit either way. One is the engine, the other is the destination.

Where to start

Do not run them as two projects. Start by getting an honest read on both:

  1. Classify against the EU AI Act to see which obligations actually apply to your systems. The free EU AI Act check does this in about ten minutes.
  2. Assess against ISO 42001 to see how much governance you already have. The free ISO 42001 check gives you a maturity read, also in about ten minutes.

Then build one AI Management System that satisfies both: the inventory, risk classification, controls and evidence serve the standard and the law at the same time.

The short version

The EU AI Act is the law you must comply with; ISO 42001 is the management system that makes complying with it practical, repeatable and provable. They are not alternatives, and neither replaces the other. Use the Act to know what is required, use ISO 42001 to deliver it, and remember that the certificate proves your system runs, not that you are legally compliant.

If you want both mapped to your actual AI estate, in one system rather than two, talk to us.

For the full picture, see the AI governance guide and the EU AI Act guide.

Frequently asked questions

What is the difference between ISO 42001 and the EU AI Act?

The EU AI Act is law: it sets out mandatory, risk-based obligations for AI, with penalties for getting it wrong. ISO 42001 is a voluntary international standard for an AI Management System: it sets out how to organise yourself to govern AI responsibly. One tells you what you must do; the other tells you how to run things so you can do it consistently.

Does ISO 42001 certification make me EU AI Act compliant?

No, not automatically. ISO 42001 gives you the inventory, risk assessment, controls, oversight and evidence the Act expects, in an auditable structure, so it gets you most of the way and makes compliance far easier to demonstrate. But the certificate is not a legal compliance statement, and you still have to meet the Act's specific obligations for your systems.

Do I need both ISO 42001 and EU AI Act compliance?

If you are in scope of the EU AI Act, its obligations are mandatory whether or not you ever touch ISO 42001. ISO 42001 is optional, but it is the most practical way to meet those obligations in a structured, repeatable way, and it increasingly shows up as a procurement requirement. Most organisations use the standard to operationalise the law.

Which should I start with?

Start by finding out where you stand on both: classify your AI systems against the EU AI Act to see which obligations apply, and assess your governance maturity against ISO 42001 to see what you already have. Then build one AI Management System that satisfies both, rather than treating them as two separate projects.

Is ISO 42001 or the EU AI Act mandatory?

The EU AI Act is mandatory for organisations in its scope, including many outside the EU that place AI on the EU market or whose AI output is used there. ISO 42001 is never mandatory by law; it is a voluntary standard you can adopt and, if you choose, certify against.


Building something you need to govern?

Start with a fixed-scope AI Opportunity & Risk Audit.

Meet an Expert