Skip to main content
AI Governance

ISO 42001 and the EU AI Act: What the Standard Covers and What It Does Not

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

12 min read

Contents

    The most common misunderstanding I encounter about ISO 42001 is the belief that certification delivers EU AI Act compliance. It does not, and an organisation that treats it that way will find the gap at exactly the wrong moment.

    The relationship is real and useful. ISO 42001 gives you the management system through which most EU AI Act obligations are operationalised. It does not give you the obligations themselves, and several of them have no ISO 42001 equivalent at all.

    This is a practitioner read on what each instrument does, where the overlap is genuine, and where organisations relying on the certificate alone will be exposed.

    A standard and a regulation are different instruments

    ISO 42001 is a voluntary international standard. You choose to implement it. A certification body accredited to audit against it issues a certificate. Nobody compels you, and no regulator enforces it. Its value is commercial and evidentiary: it demonstrates to buyers, investors, and regulators that you operate a governed AI management system.

    The EU AI Act is a regulation with direct effect across the European Union. It applies whether or not you want it to, based on what your AI systems do and where they are placed on the market or used. It carries enforcement, penalties, and market access consequences.

    The practical implication: ISO 42001 certification is evidence of good governance. It is not a compliance defence. A regulator examining a high-risk AI system will ask whether the specific obligations were met, not whether you hold a certificate.

    What the EU AI Act actually requires

    The regulation classifies AI systems by risk and attaches obligations accordingly.

    Prohibited practices are banned outright. These include certain manipulative techniques, social scoring by public authorities, and specified uses of biometric categorisation and emotion recognition.

    High-risk systems carry the heaviest obligations. The category covers AI used as a safety component in regulated products, and AI used in specified areas including employment and worker management, education and vocational training, access to essential services, law enforcement, migration, and administration of justice. Obligations include a risk management system, data governance requirements, technical documentation, record-keeping, transparency to deployers, human oversight, accuracy and robustness requirements, a quality management system, conformity assessment, and post-market monitoring.

    Limited-risk systems carry transparency obligations. People must be told when they are interacting with an AI system, and certain synthetic content must be marked as artificially generated.

    General-purpose AI models carry their own obligations on documentation, copyright policy, and training data summaries, with additional requirements where a model presents systemic risk.

    Obligations also differ by role. A provider who develops and places a system on the market carries different duties from a deployer who uses one. Many organisations are both, for different systems, and the first task in any programme is establishing which role applies where.

    The enforcement timetable

    The regulation entered into force in August 2024 with obligations phasing in across several years.

    Prohibited practices and AI literacy obligations applied from February 2025 and are unchanged. General-purpose AI model obligations and the governance framework applied from 2 August 2025.

    From 2 August 2026, the transparency obligations under Article 50 apply, except Article 50(2), which does not apply to systems already on the market at that date. From 2 December 2026, the Article 50(2) transparency requirements apply to those legacy systems, and the new prohibited practices apply. By 2 August 2027, member states must establish at least one national AI regulatory sandbox.

    From 2 December 2027, the high-risk obligations apply to Annex III standalone systems, covering employment and worker management, creditworthiness, education, access to essential services, law enforcement, migration, and administration of justice. From 2 August 2028, they apply to Annex I systems, meaning AI embedded in products already regulated under EU product safety legislation, including medical devices.

    The original timetable set 2 August 2026 as the application date for high-risk obligations. The Digital Omnibus on AI, proposed by the European Commission in November 2025, amended this. Political agreement was reached on 7 May 2026, the European Parliament endorsed it on 16 June, and the Council gave final approval on 29 June 2026. The effect is a sixteen-month deferral for Annex III standalone systems and a two-year deferral for Annex I embedded systems. The transparency obligations under Article 50 were not deferred and apply from 2 August 2026 as originally scheduled.

    The obligations themselves are unchanged in substance. A provider or deployer still needs a risk management system, data governance documentation, technical documentation, human oversight procedures, and a fundamental rights impact assessment where required. Building that retrospectively under deadline pressure inside a system already running in production is materially harder than building it in from the start. Organisations treating the deferral as a reason to start now rather than to wait will spend less overall.

    Where ISO 42001 supports compliance

    The overlap is genuine and it is concentrated in the management system requirements.

    The EU AI Act requires providers of high-risk systems to operate a quality management system covering the design, development, and deployment of those systems. ISO 42001 specifies a management system of exactly that shape. The clause structure, the documented information requirements, the internal audit and management review architecture all serve this obligation directly.

    Risk management is required under the regulation and specified in the standard. An AI risk management process built to ISO 42001 addresses the substance of what the regulation expects, though the regulation carries specifics on residual risk acceptability that the standard does not prescribe.

    Data governance obligations covering training, validation, and testing data have a clear ISO 42001 counterpart in the data controls.

    Human oversight requirements are addressed in the standard's oversight controls. Transparency to deployers, record-keeping, and post-market monitoring all have management system counterparts.

    A reasonable practitioner estimate, and it is an estimate rather than a measured figure, is that ISO 42001 addresses approximately 40 to 50 percent of the substantive EU AI Act requirements for a high-risk system, and a higher proportion of the management and process requirements specifically. That is a useful proportion. It is not compliance.

    What ISO 42001 does not cover

    Six areas require work outside the standard.

    Conformity assessment. High-risk systems require a conformity assessment procedure before being placed on the market, either through internal control or through a notified body depending on the system. ISO 42001 certification is not a conformity assessment and does not substitute for one.

    CE marking and the declaration of conformity. These are regulatory artefacts with prescribed content. No management system standard produces them.

    Registration in the EU database. High-risk systems must be registered before being placed on the market. This is an administrative obligation with no standard equivalent.

    Technical documentation to the regulation's specification. The regulation prescribes the content of technical documentation for high-risk systems in detail. ISO 42001 expects documented information but does not prescribe this content.

    Fundamental rights impact assessment. Certain deployers, including public bodies and providers of specified services, must conduct one before putting a high-risk system into use. ISO 42001 expects an AI impact assessment, which is related but not the same instrument and does not cover the same ground.

    Serious incident reporting. The regulation carries specific reporting obligations to market surveillance authorities with defined timelines. An ISO 42001 incident process is the operational foundation but the regulatory reporting requirement sits on top of it.

    The harmonised standards question

    The European standardisation bodies have been developing harmonised standards to support the regulation. Where a harmonised standard is published in the Official Journal and an organisation conforms to it, that conformity carries a presumption of conformity with the corresponding regulatory requirement.

    This is the mechanism by which standards conformity becomes a legal shortcut rather than merely useful evidence. ISO 42001 is not currently a harmonised standard for the EU AI Act, and the European work is proceeding on its own track.

    The practical position for an organisation now: implement ISO 42001 because it builds the management system you will need regardless, and track the harmonised standards work rather than waiting for it. An AIMS built to ISO 42001 will map onto whatever emerges with far less effort than starting from nothing.

    How to sequence a programme

    The sequence that works, in my experience, has four stages.

    Establish scope and role. Inventory the AI systems, determine which risk category each falls into, and establish whether the organisation is a provider, a deployer, or both for each. Most organisations discover systems they had not counted and roles they had not considered.

    Build the management system. Implement ISO 42001. This produces the governance, risk, data, oversight, and monitoring architecture that the regulatory obligations sit on. It is the largest piece of work and it is reusable regardless of how the regulatory detail evolves.

    Address the regulation-specific artefacts. Technical documentation, conformity assessment route, registration, fundamental rights impact assessment where applicable, and incident reporting procedures. These are additive to the management system and cannot be derived from it.

    Certify and evidence. ISO 42001 certification gives you an independently audited demonstration of the management system. Regulatory compliance gives you the market access. They are separate outcomes from one connected programme.

    The organisations that struggle are the ones that treat these as alternatives rather than as sequence. Certification without regulatory work leaves you exposed. Regulatory work without a management system leaves you with a compliance file nobody operates.

    If you are establishing your EU AI Act exposure and want to know which of your AI systems carry which obligations, an AI governance readiness assessment produces an AI inventory, a risk tier classification, and a board-ready roadmap. Book a scoping call.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    Related reading

    ISO 42001

    8 min read

    Can the Consultancy That Built Your AIMS Also Audit It?

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    The rule everyone quotes is about your certification body, not your consultant. What ISO/IEC 17021-1 actually restricts, and where the real constraint lands.

    • ISO 42001
    • Internal Audit
    • Certification
    • AI Governance
    AI Governance

    9 min read

    Microsoft's Supplier Requirements Put ISO 42001 on the Table for AI Suppliers

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    Microsoft's Supplier Data Protection Requirements v12 add a dedicated AI section and accept ISO 42001 as an assurance route. What that means for AI suppliers.

    • AI Governance
    • ISO 42001
    • Enterprise Procurement
    ISO 42001

    11 min read

    ISO 27001 vs ISO 42001: What Each Standard Actually Governs

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    The practical difference between an information security management system and an AI management system, where the controls overlap, and which one to implement first.

    • ISO 42001
    • ISO 27001
    • AI Governance
    AI Governance

    9 min read

    ISO 42001 vs NIST AI RMF: Which AI Governance Framework Your Buyers Actually Want

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    A certifiable international standard and a voluntary US framework. What each covers, which buyers recognise which, and when holding both makes sense.

    • AI Governance
    • ISO 42001
    • NIST AI RMF
    ISO 42001

    9 min read

    Why a GRC Platform Is Not an AI Management System

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    What compliance platforms do well for ISO 42001, what they cannot do, and where the practitioner work actually sits.

    • ISO 42001
    • AI Governance
    • GRC
    AI Governance

    10 min read

    ISO 42001 for Recruitment and HR Technology: The Highest-Risk AI Category Nobody Planned For

    By Alfred Obeng, Founder and Principal Consultant

    CISSP | ISO 27001 LI & LA | ISO 42001 LI & LA | PMP

    Employment and worker management AI is named as high-risk under the EU AI Act. What that means for UK recruitment and HR tech, alongside Equality Act and ICO exposure.

    • ISO 42001
    • AI Governance
    • HR Technology

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.