AEGIS

Compliance Bridge · Open Analysis

ISO 42001 vs the EU AI Act: what certification covers — and where it stops

ISO/IEC 42001 certification is not EU AI Act compliance. The standard genuinely supports several AI Act obligations — risk management, data governance, transparency, human oversight — but five core obligations have no ISO 42001 equivalent at all: conformity assessment, CE marking, EU database registration, post-market monitoring, and serious-incident reporting. Anyone selling certification as conformity is selling the first half and hiding the second.

11
Mappings, source-verified
4
High alignment
2
Partial alignment
5
No ISO equivalent

Where ISO 42001 supports the AI Act

ISO/IEC 42001EU AI ActAlignmentWhat it means in practice
Clause 6.1Actions to address risks and opportunitiesArt. 9Risk management systemHighISO 42001 risk-management processes directly support AI Act Art. 9. Enhancement: risk assessment must explicitly address health, safety and fundamental rights across the full lifecycle.
Clause 6.2 + Annex BAI objectives & data governance guidanceArt. 10Data and data governanceHighBoth cover data quality, bias mitigation and provenance. AI Act Art. 10 is more prescriptive (relevance, representativeness, error-free), requiring enhanced documentation.
Clause 7.5Documented informationArt. 11 + Annex IVTechnical documentationPartialISO 42001 establishes documentation practice but not the specific Annex IV format and content. Additional technical documentation is required, retained 10 years after market placement.
Clause 9.1Monitoring, measurement, analysis, evaluationArt. 12Record-keeping / automatic loggingPartialISO 42001 requires monitoring but allows flexibility. Art. 12 mandates automatic event logging with traceability and retention — a technical gap requiring continuous logging infrastructure.
Annex A.8Information for interested parties / transparencyArt. 13Transparency & information to deployersHighBoth emphasise transparency and explainability. AI Act Art. 13 requires specific 'instructions for use' content that may need enhancement.
Annex A.9Use of AI systems / human oversightArt. 14Human oversightHighStrong alignment on human oversight, override and intervention. Specific documentation of override mechanisms may need enhancement.

The five obligations certification does not touch

These are not enhancements or documentation deltas — they are regulatory acts and systems the standard has no mechanism for. An organisation can hold a flawless ISO 42001 certificate and have done none of the following.

Art. 43Conformity assessmentNo ISO equivalent

ISO 42001 certification is management-system focused. AI Act conformity assessment evaluates the specific system; some high-risk systems require notified-body assessment — entirely separate from ISO certification.

Art. 48CE markingNo ISO equivalent

CE marking is a regulatory process with no ISO 42001 equivalent.

Art. 49 + 71Registration in EU databaseNo ISO equivalent

High-risk systems must be registered in the public EU database before market placement (Art. 49, 71). No ISO 42001 equivalent.

Art. 72Post-market monitoringNo ISO equivalent

AI Act requires a specific post-market monitoring system (Art. 72) beyond ISO 42001's management-system monitoring.

Art. 73Serious incident reportingNo ISO equivalent

Serious incident reporting to national competent authorities within statutory deadlines (Art. 73). No ISO 42001 equivalent.

Frequently asked questions

Does ISO/IEC 42001 certification make an organisation EU AI Act compliant?

No. ISO/IEC 42001 is a management-system standard; the EU AI Act is product legislation. Certification provides no presumption of conformity: conformity assessment, CE marking, EU database registration, post-market monitoring and serious-incident reporting all sit outside the standard.

Which AI Act obligations does ISO 42001 directly support?

Four obligations show high alignment in this crosswalk: risk management (Clause 6.1 → Art. 9), data and data governance (Clause 6.2 + Annex B → Art. 10), transparency and information to deployers (Annex A.8 → Art. 13), and human oversight (Annex A.9 → Art. 14). Each still requires AI Act-specific enhancements.

Where is ISO 42001 support only partial?

Two places: technical documentation — Clause 7.5 establishes documentation practice but not the specific Annex IV content, retained 10 years after market placement — and record-keeping, where Clause 9.1 requires monitoring while Art. 12 mandates automatic event logging with traceability and retention.

Which AI Act obligations have no ISO 42001 equivalent at all?

Five: conformity assessment (Art. 43), CE marking (Art. 48), registration in the EU database (Art. 49 and 71), post-market monitoring (Art. 72), and serious-incident reporting (Art. 73).

Can any standard give a presumption of conformity with the AI Act?

Under Article 40, presumption of conformity attaches to harmonised European standards once they are cited in the Official Journal — standardisation work led by CEN-CENELEC JTC 21 (see prEN 18286). ISO/IEC 42001 itself carries no such presumption.

Is this mapping legal advice?

No. It reflects published crosswalk analysis and the primary legal text, and must be validated against the current legal text before reliance.

Method and sources

Every mapping on this page is rendered directly from the source-verified crosswalk behind the AEGIS Compliance Bridge — grounded in the ISO/IEC 42001:2023 clause and Annex A structure, the primary text of Regulation (EU) 2024/1689 (Arts. 9–14, 11 + Annex IV, 43, 48, 49, 71, 72, 73), and published control-by-control crosswalk analyses (Glacis, Modulos, prEN 18286 Annex D). Sources verified June 2026.

ISO/IEC 42001 certification does not by itself establish EU AI Act conformity. The two are complementary: ISO 42001 covers organisational AI management processes; the AI Act imposes product-level obligations, conformity assessment and enforcement. This mapping reflects published crosswalk analysis and must be validated against the current legal text before reliance.

Use this crosswalk

The full mapping is published as an open dataset — machine-readable JSON, schema-validated, versioned, CC BY 4.0, with GitHub-native citation. Corrections are welcome with primary sources. The interactive version — click a clause, light up the articles it supports — lives in the AEGIS Compliance Bridge (contributor access).

Open the dataset →Interactive Compliance Bridge

Related: classify your system under the AI Act · the EU high-risk systems map · who publishes public-sector code in Europe