Compliance Bridge · Open Analysis
ISO 42001 vs the EU AI Act: what certification covers — and where it stops
ISO/IEC 42001 certification is not EU AI Act compliance. The standard genuinely supports several AI Act obligations — risk management, data governance, transparency, human oversight — but five core obligations have no ISO 42001 equivalent at all: conformity assessment, CE marking, EU database registration, post-market monitoring, and serious-incident reporting. Anyone selling certification as conformity is selling the first half and hiding the second.
Where ISO 42001 supports the AI Act
The five obligations certification does not touch
These are not enhancements or documentation deltas — they are regulatory acts and systems the standard has no mechanism for. An organisation can hold a flawless ISO 42001 certificate and have done none of the following.
ISO 42001 certification is management-system focused. AI Act conformity assessment evaluates the specific system; some high-risk systems require notified-body assessment — entirely separate from ISO certification.
CE marking is a regulatory process with no ISO 42001 equivalent.
High-risk systems must be registered in the public EU database before market placement (Art. 49, 71). No ISO 42001 equivalent.
AI Act requires a specific post-market monitoring system (Art. 72) beyond ISO 42001's management-system monitoring.
Serious incident reporting to national competent authorities within statutory deadlines (Art. 73). No ISO 42001 equivalent.
Frequently asked questions
Does ISO/IEC 42001 certification make an organisation EU AI Act compliant?
No. ISO/IEC 42001 is a management-system standard; the EU AI Act is product legislation. Certification provides no presumption of conformity: conformity assessment, CE marking, EU database registration, post-market monitoring and serious-incident reporting all sit outside the standard.
Which AI Act obligations does ISO 42001 directly support?
Four obligations show high alignment in this crosswalk: risk management (Clause 6.1 → Art. 9), data and data governance (Clause 6.2 + Annex B → Art. 10), transparency and information to deployers (Annex A.8 → Art. 13), and human oversight (Annex A.9 → Art. 14). Each still requires AI Act-specific enhancements.
Where is ISO 42001 support only partial?
Two places: technical documentation — Clause 7.5 establishes documentation practice but not the specific Annex IV content, retained 10 years after market placement — and record-keeping, where Clause 9.1 requires monitoring while Art. 12 mandates automatic event logging with traceability and retention.
Which AI Act obligations have no ISO 42001 equivalent at all?
Five: conformity assessment (Art. 43), CE marking (Art. 48), registration in the EU database (Art. 49 and 71), post-market monitoring (Art. 72), and serious-incident reporting (Art. 73).
Can any standard give a presumption of conformity with the AI Act?
Under Article 40, presumption of conformity attaches to harmonised European standards once they are cited in the Official Journal — standardisation work led by CEN-CENELEC JTC 21 (see prEN 18286). ISO/IEC 42001 itself carries no such presumption.
Is this mapping legal advice?
No. It reflects published crosswalk analysis and the primary legal text, and must be validated against the current legal text before reliance.
Method and sources
Every mapping on this page is rendered directly from the source-verified crosswalk behind the AEGIS Compliance Bridge — grounded in the ISO/IEC 42001:2023 clause and Annex A structure, the primary text of Regulation (EU) 2024/1689 (Arts. 9–14, 11 + Annex IV, 43, 48, 49, 71, 72, 73), and published control-by-control crosswalk analyses (Glacis, Modulos, prEN 18286 Annex D). Crosswalk sources verified June 2026.
Amendment status. Regulation (EU) 2026/1744 (Digital Omnibus on AI) has been in force since 27 July 2026 and amends Regulation (EU) 2024/1689. The statements below were checked article by article against the consolidated text of 27 July 2026 (CELEX 02024R1689-20260727) on 25 August 2026.
- Article 11 — amended. The second subparagraph of Article 11(1) was replaced. SMEs, start-ups and small mid-cap enterprises may now provide the Annex IV elements in a simplified form, which notified bodies must accept. The first subparagraph, Article 11(2) and (3), and the requirement that the documentation contain at a minimum the elements of Annex IV are unchanged.
- Article 43 — not amended. The single-application and unified assessment procedure for conformity assessment bodies was inserted at Article 28(8) and (9), not in Article 43.
- Article 49 — obligation retained. Article 6(4) is unchanged and still refers providers who consider an Annex III system not to be high-risk to the registration obligation in Article 49(2).
- Article 10 — paragraph 5 deleted. Processing of special categories of personal data for bias detection and correction moved to the new Article 4a, which also extends it beyond high-risk systems.
- New Article 2(13). For Annex I high-risk systems, the application of Articles 9 to 15 and 17 to 25 may be limited where Union harmonisation legislation provides an equivalent or higher level of protection. The Commission is to specify the scope by delegated act by 2 August 2027.
The architecture the crosswalk relies on is unchanged: the same four risk classes and the same high-risk requirement structure, so the clause-level alignments below hold. Two caveats: an SME or small mid-cap using the simplified Annex IV form changes the documentary volume an ISO 42001 control has to support, not the requirement itself; and for Annex I systems the delegated act under Article 2(13) may narrow which of Articles 9 to 15 apply at all. Application also runs from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for Annex I systems.
ISO/IEC 42001 certification does not by itself establish EU AI Act conformity. The two are complementary: ISO 42001 covers organisational AI management processes; the AI Act imposes product-level obligations, conformity assessment and enforcement. This mapping reflects published crosswalk analysis and must be validated against the current legal text before reliance.
Use this crosswalk
The full mapping is published as an open dataset — machine-readable JSON, schema-validated, versioned, CC BY 4.0, with GitHub-native citation. Corrections are welcome with primary sources. The interactive version — click a clause, light up the articles it supports — lives in the AEGIS Compliance Bridge (contributor access).
Related: classify your system under the AI Act · the EU high-risk systems map · who publishes public-sector code in Europe