Compliance Bridge · Open Analysis
ISO 42001 vs the EU AI Act: what certification covers — and where it stops
ISO/IEC 42001 certification is not EU AI Act compliance. The standard genuinely supports several AI Act obligations — risk management, data governance, transparency, human oversight — but five core obligations have no ISO 42001 equivalent at all: conformity assessment, CE marking, EU database registration, post-market monitoring, and serious-incident reporting. Anyone selling certification as conformity is selling the first half and hiding the second.
Where ISO 42001 supports the AI Act
The five obligations certification does not touch
These are not enhancements or documentation deltas — they are regulatory acts and systems the standard has no mechanism for. An organisation can hold a flawless ISO 42001 certificate and have done none of the following.
ISO 42001 certification is management-system focused. AI Act conformity assessment evaluates the specific system; some high-risk systems require notified-body assessment — entirely separate from ISO certification.
CE marking is a regulatory process with no ISO 42001 equivalent.
High-risk systems must be registered in the public EU database before market placement (Art. 49, 71). No ISO 42001 equivalent.
AI Act requires a specific post-market monitoring system (Art. 72) beyond ISO 42001's management-system monitoring.
Serious incident reporting to national competent authorities within statutory deadlines (Art. 73). No ISO 42001 equivalent.
Frequently asked questions
Does ISO/IEC 42001 certification make an organisation EU AI Act compliant?
No. ISO/IEC 42001 is a management-system standard; the EU AI Act is product legislation. Certification provides no presumption of conformity: conformity assessment, CE marking, EU database registration, post-market monitoring and serious-incident reporting all sit outside the standard.
Which AI Act obligations does ISO 42001 directly support?
Four obligations show high alignment in this crosswalk: risk management (Clause 6.1 → Art. 9), data and data governance (Clause 6.2 + Annex B → Art. 10), transparency and information to deployers (Annex A.8 → Art. 13), and human oversight (Annex A.9 → Art. 14). Each still requires AI Act-specific enhancements.
Where is ISO 42001 support only partial?
Two places: technical documentation — Clause 7.5 establishes documentation practice but not the specific Annex IV content, retained 10 years after market placement — and record-keeping, where Clause 9.1 requires monitoring while Art. 12 mandates automatic event logging with traceability and retention.
Which AI Act obligations have no ISO 42001 equivalent at all?
Five: conformity assessment (Art. 43), CE marking (Art. 48), registration in the EU database (Art. 49 and 71), post-market monitoring (Art. 72), and serious-incident reporting (Art. 73).
Can any standard give a presumption of conformity with the AI Act?
Under Article 40, presumption of conformity attaches to harmonised European standards once they are cited in the Official Journal — standardisation work led by CEN-CENELEC JTC 21 (see prEN 18286). ISO/IEC 42001 itself carries no such presumption.
Is this mapping legal advice?
No. It reflects published crosswalk analysis and the primary legal text, and must be validated against the current legal text before reliance.
Method and sources
Every mapping on this page is rendered directly from the source-verified crosswalk behind the AEGIS Compliance Bridge — grounded in the ISO/IEC 42001:2023 clause and Annex A structure, the primary text of Regulation (EU) 2024/1689 (Arts. 9–14, 11 + Annex IV, 43, 48, 49, 71, 72, 73), and published control-by-control crosswalk analyses (Glacis, Modulos, prEN 18286 Annex D). Sources verified June 2026.
ISO/IEC 42001 certification does not by itself establish EU AI Act conformity. The two are complementary: ISO 42001 covers organisational AI management processes; the AI Act imposes product-level obligations, conformity assessment and enforcement. This mapping reflects published crosswalk analysis and must be validated against the current legal text before reliance.
Use this crosswalk
The full mapping is published as an open dataset — machine-readable JSON, schema-validated, versioned, CC BY 4.0, with GitHub-native citation. Corrections are welcome with primary sources. The interactive version — click a clause, light up the articles it supports — lives in the AEGIS Compliance Bridge (contributor access).
Related: classify your system under the AI Act · the EU high-risk systems map · who publishes public-sector code in Europe