ISO/IEC 42001 is a voluntary, certifiable management system standard. The EU AI Act is binding law. You can hold the certificate and still breach the Act, and you can comply with the Act without the certificate. Understanding what each actually does prevents an expensive category error.
The fundamental difference
- Force. ISO 42001 is adopted by choice, usually for market credibility. The AI Act applies by law to systems in scope, regardless of your preferences.
- What is assessed. ISO 42001 assesses whether you run a functioning AI management system. The Act assesses whether specific AI systems meet specific obligations.
- Unit of analysis. ISO 42001 is organisation-level. The Act is system-level - each AI system gets classified on its own.
- Outcome. ISO 42001 produces a certificate from an accredited body. The Act produces conformity obligations, documentation, and potential enforcement.
- Geography. ISO 42001 is international. The Act is EU law, though it reaches organisations outside the EU whose systems or outputs are used there.
Where they align
The overlap is substantial, which is why ISO 42001 is worth doing if the Act applies to you:
- AI inventory and accountability - both require knowing which AI systems exist and who owns them.
- Risk management across the AI lifecycle.
- Impact assessment - ISO 42001 requires AI system impact assessment; the Act expects assessment of effects on people for high-risk systems.
- Data governance - provenance, quality and appropriateness of training and grounding data.
- Human oversight - meaningful, not nominal.
- Documentation, logging and traceability.
- Monitoring in production and response when things degrade.
A useful way to hold it: ISO 42001 gives you the machinery. The AI Act tells you what the machinery must produce for particular systems. Neither substitutes for the other.
Run both from one AI inventory
GRC Copilot assesses your AI systems against ISO 42001 and EU AI Act expectations together - one inventory, one set of evidence, two reporting views.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Where ISO 42001 does not reach
The Act imposes things a management system standard does not:
- Prohibited practices - certain uses are banned outright. No management system makes them permissible.
- Risk classification with legal consequence - high-risk designation triggers defined obligations.
- Conformity assessment and CE marking for certain high-risk systems.
- Registration duties in EU databases where applicable.
- Role-specific obligations that differ sharply between provider and deployer.
- Transparency duties toward individuals interacting with AI or seeing generated content.
- General-purpose AI model obligations, with additional requirements for systemic-risk models.
Does certification help with the Act?
Materially, but indirectly. Harmonised standards are expected to play a role in demonstrating conformity under the Act, and ISO 42001 gives you the governance, documentation and evidence discipline that any conformity route will require. What it does not do is determine legal compliance - only the Act's own requirements and processes do that.
Anyone marketing ISO 42001 as "EU AI Act certification" is overselling it. Treat that claim as a signal to look more carefully at the rest of what they say.
Practical sequencing
- Build the AI inventory. Required by both, and everything else depends on it.
- Determine your role per system - provider or deployer under the Act.
- Classify by use case against the Act's risk tiers.
- Stand up the management system - ISO 42001 gives you a proven structure even if you never certify.
- Close Act-specific gaps - transparency notices, conformity route, registration, human oversight documentation.
- Certify if customers or tenders ask for it.
Frequently asked questions
Do we need ISO 42001 to comply with the AI Act?
No. It is voluntary. It makes demonstrating compliance considerably easier, which is why many organisations subject to the Act pursue it anyway.
If we only use third-party AI tools, does either apply?
The Act can apply to you as a deployer, with lighter obligations. ISO 42001 governance is still valuable, because you own the risk of how AI is used in your business.
Which should we start with?
The inventory - it serves both. Then let your legal exposure decide: if the Act clearly applies, prioritise classification and role determination.
Is there an equivalent elsewhere?
AI regulation is developing in several jurisdictions at different speeds. ISO 42001, being jurisdiction-neutral, is a reasonable hedge if you operate in multiple markets.
Key takeaways
- ISO 42001 is voluntary and organisation-level; the Act is law and system-level.
- Certification supports but never equals Act compliance.
- Prohibited practices, conformity assessment and registration have no ISO equivalent.
- Start with the AI inventory - both regimes depend on it.