ISO/IEC 42001 vs the EU AI Act: what certification proves and what it does not
Certification is not conformity. An obligation-by-clause crosswalk that shows where ISO/IEC 42001 helps with the EU AI Act, where it stops, and how CISOs should use both.
Different kinds of instrument
The EU AI Act is binding law with obligations that attach to specific AI systems by risk category. ISO/IEC 42001 is a voluntary, certifiable management-system standard describing how an organisation governs AI across its portfolio. Certification demonstrates a functioning management system; it is not a presumption of conformity with the AI Act, and it does not replace conformity assessment or registration for high-risk systems.
Where they overlap
Both expect leadership accountability, a risk process, impact assessment, competence and awareness, documented information, operational controls over data and development, monitoring, incident handling and continual improvement. An organisation running ISO/IEC 42001 will already produce much of the evidence the AI Act's quality-management, risk-management and post-market monitoring articles require.
Where the law goes further
The AI Act prescribes system-level outputs: Annex IV technical documentation, logging capability, instructions for use, specific human-oversight design features, conformity assessment, CE marking, EU database registration, serious-incident time limits and, for general-purpose models, training-content summaries and copyright policies. Treat these as controls inside the management system rather than assuming the standard covers them.
How to use the crosswalk below
Each mapping is an original editorial judgement with a confidence level; it references clause numbers only and reproduces no standard text. Use it to organise evidence, then validate against the standard and legal advice.
Crosswalk from recorded obligations
Original editorial mappings with confidence levels; clause references only, no standard text.
| Obligation | Instrument | Framework reference | Confidence |
|---|---|---|---|
| Carry out a data protection impact assessment for high-risk AI processing | ICO AI guidance | Clause 6.1.4 AI system impact assessment Original editorial mapping. | high |
| Identify consent or an applicable PDPA exception before using personal data in AI | PDPC AI advisory guidelines | Annex A controls on data for AI systems Original editorial mapping. | medium |
| Do not deploy or provide AI for prohibited practices | EU AI Act | Clause 6.1.2 and Annex A control on AI system impact assessment Original editorial mapping: the AI-impact-assessment process is a natural place to screen for prohibited uses. | medium |
| Collect and use personal information only with consent and for the stated purpose | Nepal Privacy Act 2075 | Annex A controls on data for AI systems Original editorial mapping. | low |
| Establish AI governance policies, roles and accountability (Govern) | NIST AI RMF | Clauses 4–5 and 7 Original editorial mapping: leadership, context and support. | high |
| Deployers must implement a risk management policy and programme | Colorado AI Act | Whole management system (named in the statute) The statute names ISO/IEC 42001 as a recognised framework. | high |
| Process personal data only with valid consent or a legitimate use, after notice | India DPDP Act | Annex A controls on data for AI systems Original editorial mapping. | medium |
| Ensure AI systems are safe, secure and robust throughout their lifecycle | UK AI regulation framework | Clause 6.1 and Annex A risk controls Original editorial mapping. | medium |
| Establish internal governance structures and measures for AI | Singapore Model AI Governance Framework | Clause 5 Leadership Original editorial mapping. | high |
| Establish accountability processes and a risk-management process (guardrails 1 and 2) | Australian Voluntary AI Safety Standard | Clauses 5 and 6 The standard states it is aligned with ISO/IEC 42001 and the NIST AI RMF. | high |
| Conduct a data protection impact assessment for high-risk processing using new technologies | UAE PDPL | Clause 6.1.4 AI system impact assessment Original editorial mapping. | medium |
| Map context, intended use and potential impacts (Map) | NIST AI RMF | Clause 6.1.4 AI system impact assessment Original editorial mapping. | high |
| Deployers must complete impact assessments for high-risk AI | Colorado AI Act | Clause 6.1.4 AI system impact assessment Original editorial mapping. | high |
| Ensure AI literacy of staff operating AI systems | EU AI Act | Clause 7.2 Competence and 7.3 Awareness Original editorial mapping. | high |
| Establish a risk management system for high-risk AI | EU AI Act | Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk Original editorial mapping. | high |
| Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits | India DPDP Act | Clause 6.1.4 AI system impact assessment Original editorial mapping. | medium |
| Manage data quality, model development and monitoring across the lifecycle | Singapore Model AI Governance Framework | Clause 8 Operation; Annex A data controls Original editorial mapping. | medium |
| Measure and test trustworthiness characteristics (Measure) | NIST AI RMF | Clause 9 Performance evaluation; Annex A verification controls Original editorial mapping. | medium |
| Apply data governance and quality criteria to training, validation and testing data | EU AI Act | Annex A controls on data for AI systems Original editorial mapping. | medium |
| Establish accountability and governance for AI | UK AI regulation framework | Clause 5 Leadership Original editorial mapping. | high |
| Prioritise, respond to and monitor AI risks (Manage) | NIST AI RMF | Clauses 8 and 10 Operation and improvement. | medium |
| Draw up technical documentation before placing a high-risk system on the market | EU AI Act | Clause 7.5 Documented information; Annex A control on system documentation Original editorial mapping. | high |
| Design high-risk systems to log events automatically | EU AI Act | Annex A control on event logging Original editorial mapping. | medium |
| Provide deployers with clear instructions for use | EU AI Act | Annex A controls on information for interested parties Original editorial mapping. | medium |
| Enable and assign effective human oversight | EU AI Act | Annex A control on human oversight Original editorial mapping. | medium |
| Achieve appropriate accuracy, robustness and cybersecurity | EU AI Act | Annex A controls on AI system verification and validation Original editorial mapping. | medium |
| Operate a quality management system | EU AI Act | Whole management system (Clauses 4–10) ISO/IEC 42001 is a certifiable AI management system standard; certification is not a legal presumption of conformity under the AI Act. | high |
| Complete conformity assessment, CE marking and EU database registration | EU AI Act | Clause 9 Performance evaluation; internal audit Original editorial mapping; not a substitute for legal conformity assessment. | low |
| Use high-risk AI as instructed, monitor it and inform affected people | EU AI Act | Annex A controls on responsible use of AI systems Original editorial mapping. | medium |
| Carry out a fundamental rights impact assessment before deployment | EU AI Act | Clause 6.1.4 AI system impact assessment; Annex A control on impact assessment Original editorial mapping. | high |
| Disclose AI interaction and label synthetic content | EU AI Act | Annex A control on communication with interested parties Original editorial mapping. | medium |
| Meet general-purpose AI model provider obligations | EU AI Act | Annex A controls on data provenance and documentation Original editorial mapping. | medium |
| Operate a post-market monitoring system | EU AI Act | Clause 9.1 Monitoring, measurement, analysis and evaluation Original editorial mapping. | high |
| Report serious incidents to market surveillance authorities | EU AI Act | Clause 10 Improvement; Annex A control on incident handling Original editorial mapping. | medium |
| Verify conformity before importing or distributing high-risk AI | EU AI Act | Annex A controls on third parties and suppliers Original editorial mapping. | medium |
Frequently asked questions
- Does ISO/IEC 42001 certification mean EU AI Act compliance?
- No. Certification shows you operate an AI management system. EU AI Act compliance is assessed obligation by obligation for each AI system, including conformity assessment for high-risk systems.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.