ISO/IEC 42001 vs the EU AI Act: what certification proves and what it does not

Certification is not conformity. An obligation-by-clause crosswalk that shows where ISO/IEC 42001 helps with the EU AI Act, where it stops, and how CISOs should use both.

  1. Different kinds of instrument

    The EU AI Act is binding law with obligations that attach to specific AI systems by risk category. ISO/IEC 42001 is a voluntary, certifiable management-system standard describing how an organisation governs AI across its portfolio. Certification demonstrates a functioning management system; it is not a presumption of conformity with the AI Act, and it does not replace conformity assessment or registration for high-risk systems.

  2. Where they overlap

    Both expect leadership accountability, a risk process, impact assessment, competence and awareness, documented information, operational controls over data and development, monitoring, incident handling and continual improvement. An organisation running ISO/IEC 42001 will already produce much of the evidence the AI Act's quality-management, risk-management and post-market monitoring articles require.

  3. Where the law goes further

    The AI Act prescribes system-level outputs: Annex IV technical documentation, logging capability, instructions for use, specific human-oversight design features, conformity assessment, CE marking, EU database registration, serious-incident time limits and, for general-purpose models, training-content summaries and copyright policies. Treat these as controls inside the management system rather than assuming the standard covers them.

  4. How to use the crosswalk below

    Each mapping is an original editorial judgement with a confidence level; it references clause numbers only and reproduces no standard text. Use it to organise evidence, then validate against the standard and legal advice.

Crosswalk from recorded obligations

Original editorial mappings with confidence levels; clause references only, no standard text.

Framework crosswalk
ObligationInstrumentFramework referenceConfidence
Carry out a data protection impact assessment for high-risk AI processingICO AI guidanceClause 6.1.4 AI system impact assessment
Original editorial mapping.
high
Identify consent or an applicable PDPA exception before using personal data in AIPDPC AI advisory guidelinesAnnex A controls on data for AI systems
Original editorial mapping.
medium
Do not deploy or provide AI for prohibited practicesEU AI ActClause 6.1.2 and Annex A control on AI system impact assessment
Original editorial mapping: the AI-impact-assessment process is a natural place to screen for prohibited uses.
medium
Collect and use personal information only with consent and for the stated purposeNepal Privacy Act 2075Annex A controls on data for AI systems
Original editorial mapping.
low
Establish AI governance policies, roles and accountability (Govern)NIST AI RMFClauses 4–5 and 7
Original editorial mapping: leadership, context and support.
high
Deployers must implement a risk management policy and programmeColorado AI ActWhole management system (named in the statute)
The statute names ISO/IEC 42001 as a recognised framework.
high
Process personal data only with valid consent or a legitimate use, after noticeIndia DPDP ActAnnex A controls on data for AI systems
Original editorial mapping.
medium
Ensure AI systems are safe, secure and robust throughout their lifecycleUK AI regulation frameworkClause 6.1 and Annex A risk controls
Original editorial mapping.
medium
Establish internal governance structures and measures for AISingapore Model AI Governance FrameworkClause 5 Leadership
Original editorial mapping.
high
Establish accountability processes and a risk-management process (guardrails 1 and 2)Australian Voluntary AI Safety StandardClauses 5 and 6
The standard states it is aligned with ISO/IEC 42001 and the NIST AI RMF.
high
Conduct a data protection impact assessment for high-risk processing using new technologiesUAE PDPLClause 6.1.4 AI system impact assessment
Original editorial mapping.
medium
Map context, intended use and potential impacts (Map)NIST AI RMFClause 6.1.4 AI system impact assessment
Original editorial mapping.
high
Deployers must complete impact assessments for high-risk AIColorado AI ActClause 6.1.4 AI system impact assessment
Original editorial mapping.
high
Ensure AI literacy of staff operating AI systemsEU AI ActClause 7.2 Competence and 7.3 Awareness
Original editorial mapping.
high
Establish a risk management system for high-risk AIEU AI ActClauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk
Original editorial mapping.
high
Significant Data Fiduciaries must appoint a DPO and run impact assessments and auditsIndia DPDP ActClause 6.1.4 AI system impact assessment
Original editorial mapping.
medium
Manage data quality, model development and monitoring across the lifecycleSingapore Model AI Governance FrameworkClause 8 Operation; Annex A data controls
Original editorial mapping.
medium
Measure and test trustworthiness characteristics (Measure)NIST AI RMFClause 9 Performance evaluation; Annex A verification controls
Original editorial mapping.
medium
Apply data governance and quality criteria to training, validation and testing dataEU AI ActAnnex A controls on data for AI systems
Original editorial mapping.
medium
Establish accountability and governance for AIUK AI regulation frameworkClause 5 Leadership
Original editorial mapping.
high
Prioritise, respond to and monitor AI risks (Manage)NIST AI RMFClauses 8 and 10
Operation and improvement.
medium
Draw up technical documentation before placing a high-risk system on the marketEU AI ActClause 7.5 Documented information; Annex A control on system documentation
Original editorial mapping.
high
Design high-risk systems to log events automaticallyEU AI ActAnnex A control on event logging
Original editorial mapping.
medium
Provide deployers with clear instructions for useEU AI ActAnnex A controls on information for interested parties
Original editorial mapping.
medium
Enable and assign effective human oversightEU AI ActAnnex A control on human oversight
Original editorial mapping.
medium
Achieve appropriate accuracy, robustness and cybersecurityEU AI ActAnnex A controls on AI system verification and validation
Original editorial mapping.
medium
Operate a quality management systemEU AI ActWhole management system (Clauses 4–10)
ISO/IEC 42001 is a certifiable AI management system standard; certification is not a legal presumption of conformity under the AI Act.
high
Complete conformity assessment, CE marking and EU database registrationEU AI ActClause 9 Performance evaluation; internal audit
Original editorial mapping; not a substitute for legal conformity assessment.
low
Use high-risk AI as instructed, monitor it and inform affected peopleEU AI ActAnnex A controls on responsible use of AI systems
Original editorial mapping.
medium
Carry out a fundamental rights impact assessment before deploymentEU AI ActClause 6.1.4 AI system impact assessment; Annex A control on impact assessment
Original editorial mapping.
high
Disclose AI interaction and label synthetic contentEU AI ActAnnex A control on communication with interested parties
Original editorial mapping.
medium
Meet general-purpose AI model provider obligationsEU AI ActAnnex A controls on data provenance and documentation
Original editorial mapping.
medium
Operate a post-market monitoring systemEU AI ActClause 9.1 Monitoring, measurement, analysis and evaluation
Original editorial mapping.
high
Report serious incidents to market surveillance authoritiesEU AI ActClause 10 Improvement; Annex A control on incident handling
Original editorial mapping.
medium
Verify conformity before importing or distributing high-risk AIEU AI ActAnnex A controls on third parties and suppliers
Original editorial mapping.
medium

Frequently asked questions

Does ISO/IEC 42001 certification mean EU AI Act compliance?
No. Certification shows you operate an AI management system. EU AI Act compliance is assessed obligation by obligation for each AI system, including conformity assessment for high-risk systems.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.