AIPolicyTracker

European Union AI rules mapped to ISO/IEC 42001

Each row is one legal duty recorded for European Union and the clause of ISO/IEC 42001:2023 it corresponds to. Use it to find which duties your existing evidence already reaches.

Coverage of this crosswalk

42 of 44 recorded European Union duties carry a mapping

The denominator is the number of duties this platform has broken out for European Union, not the number of duties the law contains. Unmapped duties are ones no reviewer has crosswalked yet, not ones the standard fails to address.

The mapping

European Union AI duties mapped to ISO/IEC 42001:2023
Legal dutyBinding?ISO/IEC 42001 clauseWhy they correspondConfidence
Do not deploy or provide AI for prohibited practices EU AI Act, Article 5 Legal requirement Clause 6.1.2 and Annex A control on AI system impact assessment Original editorial mapping: the AI-impact-assessment process is a natural place to screen for prohibited uses. medium
Ensure AI literacy of staff operating AI systems EU AI Act, Article 4 Legal requirement Clause 7.2 Competence and 7.3 Awareness Original editorial mapping. high
Establish a risk management system for high-risk AI EU AI Act, Article 9 Legal requirement Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk Original editorial mapping. high
Apply data governance and quality criteria to training, validation and testing data EU AI Act, Article 10 Legal requirement Annex A controls on data for AI systems Original editorial mapping. medium
Draw up technical documentation before placing a high-risk system on the market EU AI Act, Article 11 and Annex IV Legal requirement Clause 7.5 Documented information; Annex A control on system documentation Original editorial mapping. high
Design high-risk systems to log events automatically EU AI Act, Article 12; Article 26(6) for deployers Legal requirement Annex A control on event logging Original editorial mapping. medium
Provide deployers with clear instructions for use EU AI Act, Article 13 Legal requirement Annex A controls on information for interested parties Original editorial mapping. medium
Enable and assign effective human oversight EU AI Act, Article 14; Article 26(2) for deployers Legal requirement Annex A control on human oversight Original editorial mapping. medium
Achieve appropriate accuracy, robustness and cybersecurity EU AI Act, Article 15 Legal requirement Annex A controls on AI system verification and validation Original editorial mapping. medium
Operate a quality management system EU AI Act, Article 17 Legal requirement Whole management system (Clauses 4–10) ISO/IEC 42001 is a certifiable AI management system standard; certification is not a legal presumption of conformity under the AI Act. high
Complete conformity assessment, CE marking and EU database registration EU AI Act, Articles 43, 47, 48 and 49; Annex VIII Legal requirement Clause 9 Performance evaluation; internal audit Original editorial mapping; not a substitute for legal conformity assessment. low
Use high-risk AI as instructed, monitor it and inform affected people EU AI Act, Article 26 Legal requirement Annex A controls on responsible use of AI systems Original editorial mapping. medium
Carry out a fundamental rights impact assessment before deployment EU AI Act, Article 27 Legal requirement Clause 6.1.4 AI system impact assessment; Annex A control on impact assessment Original editorial mapping. high
Disclose AI interaction and label synthetic content EU AI Act, Article 50 Legal requirement Annex A control on communication with interested parties Original editorial mapping. medium
Meet general-purpose AI model provider obligations EU AI Act, Article 53 and Annexes XI–XII Legal requirement Annex A controls on data provenance and documentation Original editorial mapping. medium
Operate a post-market monitoring system EU AI Act, Article 72 Legal requirement Clause 9.1 Monitoring, measurement, analysis and evaluation Original editorial mapping. high
Report serious incidents to market surveillance authorities EU AI Act, Article 73 Legal requirement Clause 10 Improvement; Annex A control on incident handling Original editorial mapping. medium
Verify conformity before importing or distributing high-risk AI EU AI Act, Articles 23 and 24 Legal requirement Annex A controls on third parties and suppliers Original editorial mapping. medium
Providers must meet the full set of provider duties for high-risk AI EU AI Act, Article 16 Legal requirement Clause 5.3; Annex A.3.2 Original editorial mapping to roles, responsibilities and authorities. medium
Providers must keep high-risk AI documentation for ten years EU AI Act, Article 18 Legal requirement Clause 7.5.3; Annex A.6.2.7 Control of documented information and technical documentation. high
Providers must retain automatically generated logs under their control EU AI Act, Article 19 Legal requirement Annex A.6.2.8 AI system recording of event logs. high
Providers must take corrective action and inform the supply chain about non-conforming high-risk AI EU AI Act, Article 20 Legal requirement Clause 10.2; Annex A.8.4 Nonconformity and corrective action; communication of incidents. high
Providers must supply conformity evidence and log access to authorities on request EU AI Act, Article 21 Legal requirement Clause 7.5; Annex A.8.3 Documented information available for external reporting. medium
Non-EU providers must appoint an EU authorised representative for high-risk AI EU AI Act, Article 22 Legal requirement Clause 5.3; Annex A.10.2 Allocation of responsibilities to an external party. medium
Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI EU AI Act, Article 25(1) and 25(2) Legal requirement Clause 4.1; Annex A.10.2 Determining the organisation's role and allocating responsibilities along the chain. medium
Providers of high-risk AI must have written agreements with suppliers of components, tools and services EU AI Act, Article 25(4) Legal requirement Annex A.10.3 Supplier relationships aligned with the organisation's AI responsibilities. high
Providers must document and register a conclusion that an Annex III system is not high-risk EU AI Act, Article 6(4); Article 49(2) Legal requirement Clause 6.1.2; Annex A.6.2.7 Risk-based classification recorded in the technical documentation. medium
Deployers must ensure input data they control is relevant and representative EU AI Act, Article 26(4) Legal requirement Annex A.7.4, A.7.6 Data quality and data preparation. medium
Deployers must monitor high-risk AI, suspend use on risk and report serious incidents EU AI Act, Article 26(5) Legal requirement Clause 9.1; Annex A.6.2.6, A.8.4 Operation and monitoring; communication of incidents. high
Employers must inform workers and their representatives before using high-risk AI at work EU AI Act, Article 26(7) Legal requirement Annex A.8.5 Information for interested parties. medium
Public authorities must register their use of high-risk AI and must not use unregistered systems EU AI Act, Article 26(8); Article 49(3) and 49(4) Legal requirement Annex A.8.2, A.8.5 System documentation and information for interested parties. medium
Deployers must use the provider's transparency information in their data protection impact assessment EU AI Act, Article 26(9) Legal requirement Clause 6.1.4; Annex A.5.2 AI system impact assessment process. medium
Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually EU AI Act, Article 26(10) Legal requirement Annex A.9.2, A.9.4 Processes for responsible use and intended use. low
Deployers must tell natural persons that a high-risk AI system is used in decisions about them EU AI Act, Article 26(11) Legal requirement Annex A.8.5 Information for interested parties. medium
Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way EU AI Act, Article 50(2) Legal requirement Annex A.8.2, A.6.2.4 System documentation; verification and validation of the marking. low
Deployers of emotion recognition or biometric categorisation must inform exposed persons EU AI Act, Article 50(3) Legal requirement Annex A.8.5 Information for interested parties. medium
Deployers must disclose deepfakes and AI-generated text published on matters of public interest EU AI Act, Article 50(4) Legal requirement Annex A.9.2, A.8.5 Responsible-use processes and information to interested parties. low
Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold EU AI Act, Article 52(1) Legal requirement Clause 4.2; Annex A.8.3 Interested-party requirements and external reporting. low
Providers of GPAI models must maintain technical documentation and inform downstream providers EU AI Act, Article 53(1)(a) and 53(1)(b); Annexes XI and XII Legal requirement Annex A.6.2.7, A.8.2, A.10.4 Technical documentation, system documentation and information for customers. high
Non-EU providers of GPAI models must appoint an EU authorised representative EU AI Act, Article 54 Legal requirement Clause 5.3; Annex A.10.2 Responsibilities allocated to an external party. medium
Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office EU AI Act, Article 55(1)(c) Legal requirement Clause 10.2; Annex A.8.4 Corrective action and incident communication. high
Deployers must explain individual decisions taken with high-risk AI on request EU AI Act, Article 86 Legal requirement Annex A.8.5, A.9.2 Information for interested parties and responsible-use processes. medium

What a mapping means

The duty and the clause ask for overlapping work, so evidence produced for one is likely to be reusable for the other. Confidence records how direct that overlap is.

What it does not mean

ISO/IEC 42001 certification does not discharge a legal duty and carries no force in European Union. A mapped row still has to be complied with on the statute's own terms.

Instruments in this crosswalk

All ISO/IEC 42001 mappings across every jurisdiction →

ISO/IEC 42001 vs the EU AI Act: what certification proves and what it does not →

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Does ISO/IEC 42001 certification satisfy European Union AI rules?
No. ISO/IEC 42001 is a certifiable management system standard and carries no legal force in European Union. This crosswalk records that 42 of the 44 duties tracked here have a corresponding clause, which means the evidence may be reusable, not that the duty is discharged.
How many European Union AI duties map to ISO/IEC 42001?
42 of 44 duties recorded for European Union carry a mapping to ISO/IEC 42001:2023.