European Union AI rules mapped to ISO/IEC 42001
Each row is one legal duty recorded for European Union and the clause of ISO/IEC 42001:2023 it corresponds to. Use it to find which duties your existing evidence already reaches.
Coverage of this crosswalk
42 of 44 recorded European Union duties carry a mapping
The denominator is the number of duties this platform has broken out for European Union, not the number of duties the law contains. Unmapped duties are ones no reviewer has crosswalked yet, not ones the standard fails to address.
The mapping
| Legal duty | Binding? | ISO/IEC 42001 clause | Why they correspond | Confidence |
|---|---|---|---|---|
| Do not deploy or provide AI for prohibited practices EU AI Act, Article 5 | Legal requirement | Clause 6.1.2 and Annex A control on AI system impact assessment | Original editorial mapping: the AI-impact-assessment process is a natural place to screen for prohibited uses. | medium |
| Ensure AI literacy of staff operating AI systems EU AI Act, Article 4 | Legal requirement | Clause 7.2 Competence and 7.3 Awareness | Original editorial mapping. | high |
| Establish a risk management system for high-risk AI EU AI Act, Article 9 | Legal requirement | Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk | Original editorial mapping. | high |
| Apply data governance and quality criteria to training, validation and testing data EU AI Act, Article 10 | Legal requirement | Annex A controls on data for AI systems | Original editorial mapping. | medium |
| Draw up technical documentation before placing a high-risk system on the market EU AI Act, Article 11 and Annex IV | Legal requirement | Clause 7.5 Documented information; Annex A control on system documentation | Original editorial mapping. | high |
| Design high-risk systems to log events automatically EU AI Act, Article 12; Article 26(6) for deployers | Legal requirement | Annex A control on event logging | Original editorial mapping. | medium |
| Provide deployers with clear instructions for use EU AI Act, Article 13 | Legal requirement | Annex A controls on information for interested parties | Original editorial mapping. | medium |
| Enable and assign effective human oversight EU AI Act, Article 14; Article 26(2) for deployers | Legal requirement | Annex A control on human oversight | Original editorial mapping. | medium |
| Achieve appropriate accuracy, robustness and cybersecurity EU AI Act, Article 15 | Legal requirement | Annex A controls on AI system verification and validation | Original editorial mapping. | medium |
| Operate a quality management system EU AI Act, Article 17 | Legal requirement | Whole management system (Clauses 4–10) | ISO/IEC 42001 is a certifiable AI management system standard; certification is not a legal presumption of conformity under the AI Act. | high |
| Complete conformity assessment, CE marking and EU database registration EU AI Act, Articles 43, 47, 48 and 49; Annex VIII | Legal requirement | Clause 9 Performance evaluation; internal audit | Original editorial mapping; not a substitute for legal conformity assessment. | low |
| Use high-risk AI as instructed, monitor it and inform affected people EU AI Act, Article 26 | Legal requirement | Annex A controls on responsible use of AI systems | Original editorial mapping. | medium |
| Carry out a fundamental rights impact assessment before deployment EU AI Act, Article 27 | Legal requirement | Clause 6.1.4 AI system impact assessment; Annex A control on impact assessment | Original editorial mapping. | high |
| Disclose AI interaction and label synthetic content EU AI Act, Article 50 | Legal requirement | Annex A control on communication with interested parties | Original editorial mapping. | medium |
| Meet general-purpose AI model provider obligations EU AI Act, Article 53 and Annexes XI–XII | Legal requirement | Annex A controls on data provenance and documentation | Original editorial mapping. | medium |
| Operate a post-market monitoring system EU AI Act, Article 72 | Legal requirement | Clause 9.1 Monitoring, measurement, analysis and evaluation | Original editorial mapping. | high |
| Report serious incidents to market surveillance authorities EU AI Act, Article 73 | Legal requirement | Clause 10 Improvement; Annex A control on incident handling | Original editorial mapping. | medium |
| Verify conformity before importing or distributing high-risk AI EU AI Act, Articles 23 and 24 | Legal requirement | Annex A controls on third parties and suppliers | Original editorial mapping. | medium |
| Providers must meet the full set of provider duties for high-risk AI EU AI Act, Article 16 | Legal requirement | Clause 5.3; Annex A.3.2 | Original editorial mapping to roles, responsibilities and authorities. | medium |
| Providers must keep high-risk AI documentation for ten years EU AI Act, Article 18 | Legal requirement | Clause 7.5.3; Annex A.6.2.7 | Control of documented information and technical documentation. | high |
| Providers must retain automatically generated logs under their control EU AI Act, Article 19 | Legal requirement | Annex A.6.2.8 | AI system recording of event logs. | high |
| Providers must take corrective action and inform the supply chain about non-conforming high-risk AI EU AI Act, Article 20 | Legal requirement | Clause 10.2; Annex A.8.4 | Nonconformity and corrective action; communication of incidents. | high |
| Providers must supply conformity evidence and log access to authorities on request EU AI Act, Article 21 | Legal requirement | Clause 7.5; Annex A.8.3 | Documented information available for external reporting. | medium |
| Non-EU providers must appoint an EU authorised representative for high-risk AI EU AI Act, Article 22 | Legal requirement | Clause 5.3; Annex A.10.2 | Allocation of responsibilities to an external party. | medium |
| Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI EU AI Act, Article 25(1) and 25(2) | Legal requirement | Clause 4.1; Annex A.10.2 | Determining the organisation's role and allocating responsibilities along the chain. | medium |
| Providers of high-risk AI must have written agreements with suppliers of components, tools and services EU AI Act, Article 25(4) | Legal requirement | Annex A.10.3 | Supplier relationships aligned with the organisation's AI responsibilities. | high |
| Providers must document and register a conclusion that an Annex III system is not high-risk EU AI Act, Article 6(4); Article 49(2) | Legal requirement | Clause 6.1.2; Annex A.6.2.7 | Risk-based classification recorded in the technical documentation. | medium |
| Deployers must ensure input data they control is relevant and representative EU AI Act, Article 26(4) | Legal requirement | Annex A.7.4, A.7.6 | Data quality and data preparation. | medium |
| Deployers must monitor high-risk AI, suspend use on risk and report serious incidents EU AI Act, Article 26(5) | Legal requirement | Clause 9.1; Annex A.6.2.6, A.8.4 | Operation and monitoring; communication of incidents. | high |
| Employers must inform workers and their representatives before using high-risk AI at work EU AI Act, Article 26(7) | Legal requirement | Annex A.8.5 | Information for interested parties. | medium |
| Public authorities must register their use of high-risk AI and must not use unregistered systems EU AI Act, Article 26(8); Article 49(3) and 49(4) | Legal requirement | Annex A.8.2, A.8.5 | System documentation and information for interested parties. | medium |
| Deployers must use the provider's transparency information in their data protection impact assessment EU AI Act, Article 26(9) | Legal requirement | Clause 6.1.4; Annex A.5.2 | AI system impact assessment process. | medium |
| Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually EU AI Act, Article 26(10) | Legal requirement | Annex A.9.2, A.9.4 | Processes for responsible use and intended use. | low |
| Deployers must tell natural persons that a high-risk AI system is used in decisions about them EU AI Act, Article 26(11) | Legal requirement | Annex A.8.5 | Information for interested parties. | medium |
| Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way EU AI Act, Article 50(2) | Legal requirement | Annex A.8.2, A.6.2.4 | System documentation; verification and validation of the marking. | low |
| Deployers of emotion recognition or biometric categorisation must inform exposed persons EU AI Act, Article 50(3) | Legal requirement | Annex A.8.5 | Information for interested parties. | medium |
| Deployers must disclose deepfakes and AI-generated text published on matters of public interest EU AI Act, Article 50(4) | Legal requirement | Annex A.9.2, A.8.5 | Responsible-use processes and information to interested parties. | low |
| Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold EU AI Act, Article 52(1) | Legal requirement | Clause 4.2; Annex A.8.3 | Interested-party requirements and external reporting. | low |
| Providers of GPAI models must maintain technical documentation and inform downstream providers EU AI Act, Article 53(1)(a) and 53(1)(b); Annexes XI and XII | Legal requirement | Annex A.6.2.7, A.8.2, A.10.4 | Technical documentation, system documentation and information for customers. | high |
| Non-EU providers of GPAI models must appoint an EU authorised representative EU AI Act, Article 54 | Legal requirement | Clause 5.3; Annex A.10.2 | Responsibilities allocated to an external party. | medium |
| Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office EU AI Act, Article 55(1)(c) | Legal requirement | Clause 10.2; Annex A.8.4 | Corrective action and incident communication. | high |
| Deployers must explain individual decisions taken with high-risk AI on request EU AI Act, Article 86 | Legal requirement | Annex A.8.5, A.9.2 | Information for interested parties and responsible-use processes. | medium |
What a mapping means
The duty and the clause ask for overlapping work, so evidence produced for one is likely to be reusable for the other. Confidence records how direct that overlap is.
What it does not mean
ISO/IEC 42001 certification does not discharge a legal duty and carries no force in European Union. A mapped row still has to be complied with on the statute's own terms.
Instruments in this crosswalk
- EU AI Act — European Union
All ISO/IEC 42001 mappings across every jurisdiction →
ISO/IEC 42001 vs the EU AI Act: what certification proves and what it does not →
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Does ISO/IEC 42001 certification satisfy European Union AI rules?
- No. ISO/IEC 42001 is a certifiable management system standard and carries no legal force in European Union. This crosswalk records that 42 of the 44 duties tracked here have a corresponding clause, which means the evidence may be reusable, not that the duty is discharged.
- How many European Union AI duties map to ISO/IEC 42001?
- 42 of 44 duties recorded for European Union carry a mapping to ISO/IEC 42001:2023.