Comparison between ISO/IEC 42001 and the EU AI Act for AI governance

ISO 42001 · AI ACT

ISO 42001 vs AI Act: Differences and How They Work Together

When an organisation begins to work seriously on artificial intelligence governance, two references tend to appear almost immediately:

ISO/IEC 42001 and the EU AI Act.

Both address risk, responsibilities, controls, transparency and oversight. But they are not the same.

ISO/IEC 42001 is an international management system standard. The AI Act is an EU Regulation establishing legal obligations for particular systems and operators.

An organisation may implement ISO/IEC 42001 without certification, become certified, fall within the AI Act, or find itself in all three situations at once.

The important question is not which framework is “better”. It is:

what each requires, where they overlap and how they can be used together without confusing management with legal compliance.

What is ISO/IEC 42001?

ISO/IEC 42001 is an international standard setting requirements to establish, implement, maintain and continually improve an Artificial Intelligence Management System, or AIMS.

It is not limited to one AI system. It seeks to give the organisation a stable structure for governing how it develops, provides or uses AI.

That management system may cover context and scope, leadership, policies, objectives, responsibilities, risks and opportunities, resources and competence, operational processes, controls, performance evaluation, internal audit, management review and continual improvement.

ISO/IEC 42001 therefore focuses primarily on how an organisation governs its relationship with AI. The guide on implementing ISO/IEC 42001 explains the practical process.

What is the EU AI Act?

The EU AI Act establishes a specific legal framework for artificial intelligence. Its logic is different: it does not create a general corporate management system.

It sets requirements and obligations according to the type of system, intended purpose, risk level, context of use, the organisation's role and the conditions under which it is marketed or used.

The Regulation covers prohibited practices, high-risk AI systems, obligations for certain providers and deployers, transparency, general-purpose AI models, and market surveillance and enforcement.

Its central question is not whether the organisation has a good management system, but which legal obligations apply to this system and this operator? The guide to the AI Act for business provides a broader overview.

The main difference: management system vs regulation

ISO/IEC 42001

Organises how the organisation governs AI.

AI Act

Establishes legal requirements that must be met when the Regulation applies.

ISO/IEC 42001 operates at organisational and management-system level. The AI Act focuses mainly on systems, uses, risks, operators and specific obligations.

They can therefore work together. ISO/IEC 42001 can structure decision-making, inventory, risk assessment, controls, evidence and performance review. The AI Act determines prohibited practices, high-risk classification, transparency duties, operator obligations and regulatory documentation.

ISO/IEC 42001 is voluntary; the AI Act may be mandatory

ISO/IEC 42001 is voluntary. An organisation may implement it to strengthen governance, assign responsibilities, manage risk, build trust, prepare for certification or integrate AI with other management systems.

The AI Act works differently. When an organisation, system or activity falls within its scope and the relevant conditions are met, applicable legal obligations do not depend on voluntary adoption.

An organisation may choose not to implement ISO/IEC 42001. It cannot choose to ignore applicable AI Act obligations.

Differences in scope

ISO/IEC 42001 can apply to organisations of different sizes and sectors that develop, provide or use AI systems. The AIMS scope can be defined to cover selected processes, units, products or activities.

The AI Act does not operate through a freely chosen organisational scope. Applicability follows the Regulation and requires the organisation to assess whether there is an AI system, its intended purpose, classification, operator role, place of marketing or use, and applicable obligations.

In short: the AIMS scope is defined within the management system; the AI Act's scope is determined legally.

Differences in the risk-based approach

Both frameworks address risk, but not in the same way.

ISO/IEC 42001 requires processes for managing AI-related risks and opportunities within the AIMS. Those risks must be identified, analysed, treated and reviewed systematically.

The AI Act uses a regulatory risk-based approach, with different rules for prohibited practices, certain high-risk AI systems, systems subject to transparency duties and other systems outside those categories.

Organisational risk and legal classification are not equivalent. A system may not be legally high-risk while remaining important because of operational, reputational, economic or human impacts.

Where they overlap

The frameworks overlap in governance, responsibilities, risk management, impact assessment, controls, competence and training, human oversight, documentation, traceability, supplier management, monitoring, incidents, audit and improvement.

ISO/IEC 42001 can provide the organisational structure for managing these activities systematically. The AI Act may supply concrete obligations that the structure must help identify, carry out and demonstrate.

The relationship can be summarised as follows: the AI Act may state what obligation exists; ISO/IEC 42001 can help organise how the organisation manages it.

Governance and responsibilities

Both frameworks value clear responsibilities but approach them differently.

ISO/IEC 42001 requires leadership, assigned responsibilities and a structure for managing the AIMS. The AI Act assigns duties to legally defined operators such as providers and deployers.

These categories must not be confused. An internal AI governance lead does not automatically become an AI Act provider, and an internal system owner is not necessarily the regulatory deployer.

At organisational level, the question is who does what within AI governance. At legal level, it is which role the organisation performs in relation to the system. The guide to roles and responsibilities helps connect the two.

Risk and impact management

ISO/IEC 42001 can place AI risk management within a continuous process. It can also connect with ISO/IEC 23894 and ISO/IEC 42005 for AI impact assessment.

The AI Act contains risk-management requirements for certain systems, particularly high-risk AI systems, and sets specific obligations according to classification and role.

Integration avoids isolated processes: a regulatory risk can enter the internal risk register, while a risk found through the AIMS can trigger a new classification, impact or compliance review.

Controls, documentation and evidence

Policies and procedures are not enough; the organisation must also show that they operate.

ISO/IEC 42001 structures documents, records, decisions, reviews, audits, corrective actions and improvement. The AI Act requires particular documentation, records or information where relevant.

They are not necessarily the same documents, but they can be linked. The AI inventory can identify systems, classification can identify obligations, risk assessment can determine controls and evidence can demonstrate implementation and traceability.

The aim should be to avoid two entirely separate documentation systems where information can legitimately be reused.

How ISO/IEC 42001 can help organise compliance

ISO/IEC 42001 can provide a useful governance structure.

Inventory

Establish a process to identify and maintain AI systems.

Classification

Build in an assessment of each system under the AI Act.

Roles

Define who performs the assessment and who approves the conclusion.

Risks

Integrate regulatory, organisational and human risks.

Controls

Translate identified obligations into specific measures.

Evidence

Define which records must be retained.

Monitoring

Use system changes to trigger reassessment.

Internal audit

Check whether defined processes are genuinely followed.

Improvement

Bring incidents, nonconformities and regulatory change into the improvement cycle.

This integrates the AI Act into the operating model rather than treating it as an isolated legal project.

Team comparing ISO/IEC 42001 and the EU AI Act within an AI governance model

What ISO/IEC 42001 does not solve on its own

ISO/IEC 42001 does not replace legal analysis of the AI Act.

The organisation must still determine whether a tool is an AI system, whether a prohibited practice exists, whether the system is high-risk, whether Article 6(3) applies, which transparency duties exist, the organisation's role, the specific requirements and applicable dates.

Management system certification does not automatically change a system's legal classification.

Implementing ISO/IEC 42001 can greatly improve readiness and capability, but it does not remove the need to interpret and apply the Regulation correctly.

Does ISO 42001 certification demonstrate AI Act compliance?

This should not be claimed automatically.

ISO/IEC 42001 certification shows that the management system has been assessed against the standard's requirements within a defined scope. The AI Act contains different legal obligations.

AIMS evidence can be valuable in showing that governance, risk management, responsibilities and controls exist. But ISO/IEC 42001 certification and AI Act compliance are not equivalent.

An organisation may hold certification and still need to correct a specific AI Act obligation. It may also meet certain AI Act obligations without ISO/IEC 42001 certification.

Certification does not, by itself, create an automatic presumption of conformity under the AI Act.

How to integrate both frameworks in practice

A practical approach uses two layers.

Layer 1. Governance

ISO/IEC 42001 can provide the stable structure: scope, responsibilities, inventory, risks, controls, training, documentation, audit, review and improvement.

Layer 2. Regulatory requirements

The AI Act supplies specific requirements: classification, prohibited practices, high-risk rules, transparency, operator obligations, documentation, oversight and other applicable requirements.

The layers must then be connected:

AI system → classification → obligations → risks → controls → owners → evidence → monitoring.

This avoids treating ISO and the AI Act as separate projects and allows one governance structure to support multiple needs.

ISO 42001 and the AI Act are not alternative paths

The question should not be “Do we implement ISO/IEC 42001 or comply with the AI Act?”

They address different matters. The AI Act establishes legal obligations; ISO/IEC 42001 provides a management structure.

Used together correctly, they can turn dispersed regulatory requirements into everyday processes, responsibilities, controls and evidence.

The most useful summary is: the AI Act states what must be complied with when applicable; ISO/IEC 42001 helps build an organisation capable of managing it systematically.

References

  • ISO/IEC 42001:2023 — Artificial intelligence management system.
  • Regulation (EU) 2024/1689 — AI Act.
  • ISO/IEC 23894:2023 — Guidance on risk management.
  • ISO/IEC 42005:2025 — AI system impact assessment.

Does your organisation manage ISO 42001 and the AI Act within the same governance model?

Before creating separate documentation for each framework, it is useful to understand which AI systems the organisation uses, which obligations apply and which governance processes can already be reused.

Start the diagnostic →
Céntrika’s diagnostic can help identify that starting point.