Use ISO/IEC 42001:2023 to operate an organisational AI management system, but assess every EU AI Act duty separately. The Commission says the standard is not aligned with the Act's Article 17 quality management system.
For product, model-risk, legal, security, procurement, privacy, audit, and compliance teams comparing AI Act role and risk duties with management-system governance.
Use the two frameworks for different decisions. The EU AI Act is binding EU law for covered AI systems and general-purpose AI models, with duties determined by the facts, operator role, and legal category. specifies requirements for an organisational AI management system and applies to organisations that provide or use products or services involving AI systems. It can organise governance, risk, lifecycle, supplier, audit, and improvement evidence. It does not replace AI Act classification, prohibited-practice screening, conformity assessment, GPAI obligations, Article 50 transparency, registration, CE marking, or enforcement duties. The European Commission also states that ISO/IEC 42001:2023 is not aligned with the quality management system required by Article 17 of the AI Act.
Side-by-side comparison
EU AI Act vs ISO/IEC 42001: what each one controls
Use these rows to decide which workstream owns the legal answer, which workstream owns management-system controls, and which evidence can be reused without overstating assurance.
Binding EU regulation for AI systems and general-purpose AI models, with obligations driven by role, risk category, use case, market placement, deployment, transparency, and enforcement route.
Second framework
ISO/IEC 42001
AI management-system standard for organisations that provide or use AI systems, focused on governance, policy, risk, controls, documented information, audit, review, and improvement.
EU AI Act vs ISO/IEC 42001: what each one controls
Starts from AI Act jurisdiction and activity: AI systems or GPAI models placed on the EU market, put into service, used in the Union, or producing outputs used in the Union, subject to the Act's scope and exclusions.
Starts from the organisation's defined AI management-system boundary: the activities, products, services, AI systems, roles, interested parties, requirements, and locations included in the management-system scope.
A supplier's ISO/IEC 42001 scope can be narrower than the AI Act fact pattern for the supplied AI system; request both the management-system scope and the AI Act role/risk classification.
Uses legal operator roles such as provider, deployer, importer, distributor, authorised representative, product manufacturer, and GPAI model provider, with duties varying by role.
Uses organisational responsibilities such as top management, AI management-system owner, risk owner, process owner, product owner, supplier owner, audit owner, and control performer.
Map both role systems. A team may own an ISO/IEC 42001 control but still need a separate legal owner for the AI Act provider, deployer, or GPAI model-provider obligation.
International management-system standard for establishing, implementing, maintaining, and continually improving an AI management system within an organisation.
ISO/IEC 42001 management-system evidence can support governance evidence, but it is not AI Act compliance evidence for a specific system, model, role, or use case unless it is tied to the exact AI Act duty.
High-risk providers must address AI Act requirements such as risk management, data governance, technical documentation, record-keeping, transparency to deployers, human oversight, accuracy, robustness, cybersecurity, quality management, conformity assessment, declaration, CE marking where applicable, registration where required, post-market monitoring, and incident reporting.
ISO/IEC 42001 can organise policy, role assignment, lifecycle governance, risk treatment, impact assessment, supplier controls, monitoring, audit, management review, and corrective action. It does not perform the AI Act conformity assessment or supply every system-specific record the Act requires.
For each high-risk system, keep an AI Act conformity file. Link ISO/IEC 42001 controls as supporting evidence only where the record satisfies the exact AI Act requirement being assessed.
Article 17 requires providers of high-risk AI systems to put a documented quality management system in place. It must cover regulatory compliance strategy, design and development, testing, data management, technical documentation, record-keeping, conformity assessment, post-market monitoring, incident reporting, authority communications, resource management, accountability, and corrective action.
requires an organisation to establish, implement, maintain, and continually improve an AI management system within its defined scope. The Commission says its goals and definitions are not aligned with the Article 17 quality management system.
Cross-reference useful ISO/IEC 42001 processes, but run a separate Article 17 gap assessment for each high-risk provider. Do not call an ISO/IEC 42001 certificate an Article 17 certificate.
Evidence is legal and system/model specific: AI Act role and risk classification, Annex basis or exception, prohibited-practice review, technical documentation, logs, instructions for use, FRIA where applicable, EU database registration, declaration, transparency notices, post-market monitoring, serious-incident records, and GPAI documentation.
Classifies AI Act treatment by prohibited practices, high-risk systems, transparency-risk systems, minimal/no-risk systems, and GPAI model rules; Annex I and Annex III routes drive high-risk analysis.
Uses organisation-defined AI risk criteria, risk assessment, risk treatment, AI system impact assessment, and management-system controls rather than AI Act risk categories.
Do not substitute an ISO risk rating for an AI Act risk category. Keep a legal high-risk/prohibited/transparency/GPAI determination beside management-system risk records.
Enforced through AI Act governance, market-surveillance, supervisory, AI Office, and penalty mechanisms depending on the obligation, operator, and model/system type.
Assured through customer due diligence, contracts, internal audits, management review, corrective-action processes, and any external management-system assessment the organisation chooses to use; ISO/IEC 42001 does not create AI Act penalties.
Regulatory exposure follows the AI Act, while assurance findings follow the management-system route. Escalate legal noncompliance, audit nonconformities, and customer evidence gaps through different owners.
The AI Act benefits from strong governance evidence, especially for high-risk risk management, quality management, documentation, monitoring, incident handling, and instructions for use.
ISO/IEC 42001 benefits from legal requirements as interested-party or applicable requirements that feed AI policy, risk criteria, operational controls, audit plans, and management review.
Build one AI governance operating model with two labels on each control: the AI Act duty it supports, if any, and the ISO/IEC 42001 requirement or control objective it supports.
Use the AI Act whenever the question is: is this practice prohibited, is this system high-risk, what operator role applies, what GPAI duties apply, what transparency notice is required, what conformity route applies, or what regulator-facing evidence is needed?
Use ISO/IEC 42001 whenever the question is: does the organisation have a defined AI management-system scope, policy, roles, risk criteria, controls, monitoring, internal audit, management review, and improvement process for AI?
A reliable compliance file answers both questions separately and only reuses evidence after the relevant legal owner and management-system owner confirm the same artifact satisfies their different tests.
Starts from AI Act jurisdiction and activity: AI systems or GPAI models placed on the EU market, put into service, used in the Union, or producing outputs used in the Union, subject to the Act's scope and exclusions.
Starts from the organisation's defined AI management-system boundary: the activities, products, services, AI systems, roles, interested parties, requirements, and locations included in the management-system scope.
A supplier's ISO/IEC 42001 scope can be narrower than the AI Act fact pattern for the supplied AI system; request both the management-system scope and the AI Act role/risk classification.
Uses legal operator roles such as provider, deployer, importer, distributor, authorised representative, product manufacturer, and GPAI model provider, with duties varying by role.
Uses organisational responsibilities such as top management, AI management-system owner, risk owner, process owner, product owner, supplier owner, audit owner, and control performer.
Map both role systems. A team may own an ISO/IEC 42001 control but still need a separate legal owner for the AI Act provider, deployer, or GPAI model-provider obligation.
International management-system standard for establishing, implementing, maintaining, and continually improving an AI management system within an organisation.
ISO/IEC 42001 management-system evidence can support governance evidence, but it is not AI Act compliance evidence for a specific system, model, role, or use case unless it is tied to the exact AI Act duty.
High-risk providers must address AI Act requirements such as risk management, data governance, technical documentation, record-keeping, transparency to deployers, human oversight, accuracy, robustness, cybersecurity, quality management, conformity assessment, declaration, CE marking where applicable, registration where required, post-market monitoring, and incident reporting.
ISO/IEC 42001 can organise policy, role assignment, lifecycle governance, risk treatment, impact assessment, supplier controls, monitoring, audit, management review, and corrective action. It does not perform the AI Act conformity assessment or supply every system-specific record the Act requires.
For each high-risk system, keep an AI Act conformity file. Link ISO/IEC 42001 controls as supporting evidence only where the record satisfies the exact AI Act requirement being assessed.
Article 17 requires providers of high-risk AI systems to put a documented quality management system in place. It must cover regulatory compliance strategy, design and development, testing, data management, technical documentation, record-keeping, conformity assessment, post-market monitoring, incident reporting, authority communications, resource management, accountability, and corrective action.
requires an organisation to establish, implement, maintain, and continually improve an AI management system within its defined scope. The Commission says its goals and definitions are not aligned with the Article 17 quality management system.
Cross-reference useful ISO/IEC 42001 processes, but run a separate Article 17 gap assessment for each high-risk provider. Do not call an ISO/IEC 42001 certificate an Article 17 certificate.
Evidence is legal and system/model specific: AI Act role and risk classification, Annex basis or exception, prohibited-practice review, technical documentation, logs, instructions for use, FRIA where applicable, EU database registration, declaration, transparency notices, post-market monitoring, serious-incident records, and GPAI documentation.
Classifies AI Act treatment by prohibited practices, high-risk systems, transparency-risk systems, minimal/no-risk systems, and GPAI model rules; Annex I and Annex III routes drive high-risk analysis.
Uses organisation-defined AI risk criteria, risk assessment, risk treatment, AI system impact assessment, and management-system controls rather than AI Act risk categories.
Do not substitute an ISO risk rating for an AI Act risk category. Keep a legal high-risk/prohibited/transparency/GPAI determination beside management-system risk records.
Enforced through AI Act governance, market-surveillance, supervisory, AI Office, and penalty mechanisms depending on the obligation, operator, and model/system type.
Assured through customer due diligence, contracts, internal audits, management review, corrective-action processes, and any external management-system assessment the organisation chooses to use; ISO/IEC 42001 does not create AI Act penalties.
Regulatory exposure follows the AI Act, while assurance findings follow the management-system route. Escalate legal noncompliance, audit nonconformities, and customer evidence gaps through different owners.
The AI Act benefits from strong governance evidence, especially for high-risk risk management, quality management, documentation, monitoring, incident handling, and instructions for use.
ISO/IEC 42001 benefits from legal requirements as interested-party or applicable requirements that feed AI policy, risk criteria, operational controls, audit plans, and management review.
Build one AI governance operating model with two labels on each control: the AI Act duty it supports, if any, and the ISO/IEC 42001 requirement or control objective it supports.
Use the AI Act whenever the question is: is this practice prohibited, is this system high-risk, what operator role applies, what GPAI duties apply, what transparency notice is required, what conformity route applies, or what regulator-facing evidence is needed?
Use ISO/IEC 42001 whenever the question is: does the organisation have a defined AI management-system scope, policy, roles, risk criteria, controls, monitoring, internal audit, management review, and improvement process for AI?
A reliable compliance file answers both questions separately and only reuses evidence after the relevant legal owner and management-system owner confirm the same artifact satisfies their different tests.
How should teams use ISO/IEC 42001 for EU AI Act compliance planning?
Use ISO/IEC 42001 to run the governance system: scope, policy, objectives, roles, risk criteria, impact assessment, operational controls, supplier oversight, monitoring, audit, management review, and corrective action.
Use the EU AI Act to answer legal classification and obligation questions: prohibited practice, high-risk status, operator role, GPAI status, transparency duty, conformity route, registration, declaration, post-market monitoring, incident reporting, and enforcement exposure.
For a high-risk provider, compare the Article 17 list directly with the scoped ISO/IEC 42001 processes and record every uncovered requirement; the Commission says the two quality-management systems are not aligned.
For each AI system or GPAI model, keep one row that states what ISO/IEC 42001 evidence exists and a separate row that states what AI Act obligation that evidence supports.
Treat ISO/IEC 42001 conformity or audit evidence as assurance about the management system, not proof that each AI system or GPAI model satisfies the AI Act.
Use the comparison to keep law and management-system assurance separate
Start with the AI Act fact pattern: whether there is an AI system or general-purpose AI model, which operator role applies, whether the use is prohibited, high-risk, transparency-limited, GPAI, or minimal/no-risk, and whether outputs are used in the Union.
Then scope ISO/IEC 42001 separately: which organisation, business unit, products, services, AI systems, roles, interested-party requirements, and AI management-system processes are inside the management-system boundary.
Assess the two quality-management concepts separately. Article 17 requires each high-risk AI system provider to maintain a documented quality management system covering the listed regulatory procedures and controls. ISO/IEC 42001 establishes a broader organisational AI management system. The Commission says its goals and definitions are not aligned with the Article 17 system.
AI Act provisions apply on different dates. Regulation (EU) 2026/1744 was published on 24 July 2026 and enters into force on 27 July 2026. It keeps 2 August 2026 as the general application date but applies Chapter III Sections 1-3 from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Article 6(1) product-linked systems. Record the legal text and application date used in the same crosswalk as the ISO/IEC 42001 edition.
Do not label an AI system compliant with the AI Act merely because an organisation has ISO/IEC 42001 controls.
Use ISO/IEC 42001 to structure AI policy, risk criteria, lifecycle controls, supplier controls, audits, management review, nonconformity, and continual improvement.
Keep AI Act evidence tied to the exact legal duty: role, risk tier, article, annex, conformity route, registration item, disclosure, incident report, or GPAI obligation.
Where one record serves both workstreams, tag the same evidence with both the AI Act obligation and the ISO/IEC 42001 clause/control purpose.
ISO/IEC 42001 is useful when the practical problem is management: setting AI policy, defining scope, assigning responsibilities, assessing AI risks and impacts, integrating controls into operations, maintaining documented information, auditing, and improving the system.
The AI Act still determines the legal duties. High-risk providers need AI Act technical documentation, Article 17 quality management, the applicable conformity assessment, an EU declaration of conformity, CE marking, EU database registration where required, post-market monitoring, and serious-incident handling. GPAI model providers need their own model documentation, downstream information, copyright policy, public training-content summary, and, for models with systemic risk, assessment, mitigation, incident, testing, and cybersecurity records.
ISO/IEC 42001 implementation or certification addresses the AI management system within its stated scope. It does not certify every AI system, model, use case, or operator role against the AI Act. Review the scope statement, covered entities and locations, exclusions, and the specific evidence linked to each legal duty.
The ISO/IEC 42001 statement of applicability records the controls the organisation considers necessary and the reasons for including or excluding them. Treat it as a management-system control decision, not an AI Act exemption record. An excluded ISO control does not remove a binding AI Act requirement, and an included control proves little until the system-specific record shows how it operated.
Use ISO/IEC 42001 as governance infrastructure for evidence readiness, not as a substitute legal test.
Use the AI Act to decide whether a model or system can be placed on the EU market, put into service, deployed, registered, labelled, or kept in operation.
Treat an AI Act harmonised standard separately from ISO/IEC 42001. A presumption of conformity depends on the relevant harmonised standard being referenced in the Official Journal and applies only to the legal requirements its reference covers.
For vendor assurance, ask both questions: what is inside the supplier's ISO/IEC 42001 scope, and what AI Act role and risk obligations apply to the supplied AI system or GPAI model?
Evidence boundaries for a combined AI Act and ISO/IEC 42001 programme
Keep one inventory and separate conclusions. The same AI inventory entry can list intended purpose, role, supplier, users, geography, data, lifecycle stage, risk controls, notices, logs, and owner, while the AI Act conclusion and the ISO/IEC 42001 conclusion remain distinct fields.
Audits and disputes require this separation. An ISO/IEC 42001 audit can show whether a management system is implemented and maintained within its scope. It does not by itself prove that a specific high-risk AI system passed the right AI Act conformity route, that an Annex III exception was documented correctly, that a GPAI model provider made the required information available, or that Article 50 notices were shown in the product experience.
Build the crosswalk at requirement level. For each AI Act duty, name the ISO/IEC 42001 clause or Annex A control that supports it, the shared record, any missing legal field, the legal owner, the management-system owner, and the reassessment trigger. Do not map an entire AI Act article to a policy title without checking the underlying procedure and evidence.
AI Act evidence fields: operator role, risk tier, prohibited-practice result, high-risk basis or exception, applicable obligations, technical documentation, conformity route, registration, declaration, CE marking, transparency notice, post-market monitoring, and incident handling.
ISO/IEC 42001 evidence fields: management-system scope, AI policy, interested-party requirements, role assignments, AI objectives, risk criteria, risk assessment, risk treatment, AI system impact assessment, operational controls, monitoring, internal audit, management review, corrective action, and continual improvement.
Shared evidence fields: AI inventory, intended use, lifecycle owner, supplier record, user instructions, logs, test results, human oversight controls, change history, security controls, data-quality controls, and management approvals.
Boundary field: the legal or assurance question each evidence item answers, so later reviewers do not infer one framework's conclusion from the other's paperwork.
Separate AI Act obligations from ISO/IEC 42001 controls before audit or launch
Sorena can help convert this comparison into role classification, risk-tier decisions, ISO/IEC 42001 control mapping, evidence requests, and review-ready supporting source references.
Commission source for GPAI provider scope guidance, AI Office submission context, and the distinction between legal obligations and voluntary support tools.