EU AI Act ↔ ISO/IEC 42001
EU AI Act vs ISO 42001 — Crosswalk and Integration Pattern
A side-by-side of the EU AI Act and ISO/IEC 42001:2023 AI Management Systems. Where they overlap, where they diverge, and how to leverage one to satisfy the other.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review
Why this comparison matters
The EU AI Act is regulation. ISO/IEC 42001:2023 is a management-system standard for AI management systems (AIMS), structured like ISO 9001 / 27001. They share a control vocabulary, but they answer different questions.
A team certified to ISO 42001 is not automatically EU AI Act compliant; an EU AI Act compliant provider is not automatically ISO 42001 certified. But the overlap is large enough that doing one puts you 70–80% of the way to the other.
Top-level structure
| Dimension | EU AI Act | ISO/IEC 42001:2023 |
|---|---|---|
| Type | Binding regulation | Voluntary management-system standard |
| Scope | High-risk AI systems + GPAI models + prohibited-practices | Organisation-wide AIMS for any AI |
| Conformity | Article 43 conformity assessment | Third-party certification audit |
| Structure | Articles 1–113 + 13 Annexes | Annex SL high-level structure: Clauses 4–10 + Annex A controls |
| Force | EU-binding | Voluntary; certification is market signal |
| Penalties | Up to €35M / 7% turnover | Loss of certification |
Where they overlap
The Governancer crosswalk maps each 30-item EU AI Act checklist entry to ISO 42001 clauses and Annex A controls. Headline overlaps:
- Article 9 risk management ↔ Clause 6.1.2 + 6.1.3. Risk assessment + risk treatment.
- Article 10 data governance ↔ Annex A.7.4 + A.7.5 + A.7.6. Data quality, acquisition, provenance.
- Article 11 technical documentation ↔ Clause 7.5 + Annex A.6.2. Documented information + AI lifecycle documentation.
- Article 14 human oversight ↔ Annex A.9.2. Human oversight of AI systems.
- Article 15 accuracy / cybersecurity ↔ Annex A.6.2.4 + A.6.2.5. Verification and validation; AI security.
- Article 17 QMS ↔ entire AIMS structure (Clauses 4–10). ISO 42001 is an AIMS standard; Article 17 requires an AI-specific QMS.
- Article 27 FRIA ↔ Clause 6.1.4 + Annex A.5.2. AI system impact assessment.
- Article 72 post-market monitoring ↔ Clause 9.1 + Annex A.6.2.8. Performance evaluation + operation and monitoring.
Where they diverge — three gaps
- Conformity assessment vs certification. ISO 42001 certification is by an accredited certification body, with a three-year cycle and surveillance audits. The EU AI Act Article 43 procedure is per-system (often internal control under Annex VI), with the EU declaration of conformity signed before placement.
- Per-system vs per-organisation scope. ISO 42001 covers the AIMS at organisation level. The EU AI Act technical file is per high-risk AI system. A certified organisation can ship a non-conforming high-risk system; a compliant high-risk system can come from a non-certified organisation.
- Substantive legal obligations. EU AI Act has prohibited practices (Article 5), explicit deployer obligations (Article 26), worker-information duties (Article 26(7)), and the Article 27 FRIA. ISO 42001 has no equivalent prohibitions; it is process-focused.
Where ISO 42001 has more depth
ISO 42001 goes deeper on:
- Annex A controls structured for an integrated management system. Useful for organisations already running ISO 9001 / 27001 / 14001.
- Top-management leadership under Clause 5 — explicit AI-policy approval, named accountability.
- Internal-audit programme under Clause 9.2 — formal audit cadence.
- Continual-improvement loop under Clause 10 — formalised improvement cycle.
Integration pattern
The clean integration:
- Build the Article 17 QMS as an ISO 42001 AIMS. The Article 17(1) thirteen aspects map cleanly to the ISO 42001 clauses.
- Layer the AI-Act-specific scaffolding on top: per-system Annex IV files, Article 47 declarations, Article 49 registrations, Article 27 FRIAs where applicable.
- Pursue ISO 42001 certification as a market signal. Article 40 of the AI Act confers a presumption of conformity for high-risk AI systems where harmonised standards are applied — and ISO/IEC 42001:2023 is among the standards being considered for harmonisation under Commission Implementing Decision C(2023)3215.
- Communicate certification carefully: ISO 42001 is not equivalent to AI Act compliance. Don't claim it.
What we ship
- Pro. Full per-checklist-item ISO 42001 crosswalk with rationale; downloadable PDF for ISO auditors and buyer due-diligence.
The mapping cites public sources only (A-LIGN clause-by-clause guide, IAPP, BSI overview, ISO online TOC). No normative ISO text is reproduced.
Internal links
Disclaimer. Reference; not legal advice. We are not ISO 42001-certified; we provide a crosswalk reference only. Reg text from Regulation (EU) 2024/1689; ISO 42001 reference from ISO online TOC.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 11 · Starter tier · critical
Draft technical documentation (system purpose, design, risk)
Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.
Article 9 · Starter tier · high
Establish risk management system
A continuous iterative process. Identify foreseeable risks, estimate impact, document mitigations, review at least quarterly.
Article 17 · Starter tier · medium
Set up quality management system (QMS)
Covers development, testing, validation, change management, post-market monitoring. Can build on ISO 9001 if you have it.
Annex IV · Pro tier · medium
List ISO/IEC 42001 + 23894 + 24029 alignment
Annex IV(2)(h) requires a list of harmonised standards applied in full or in part. ISO 42001 (AIMS), 23894 (risk), 24029 (robustness) are the core trio.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art11-tech-docs | ISO/IEC 42001:2023 Clause 7.5 — Documented information | Article 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions. |
art11-tech-docs | ISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentation | Annex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation. |
art9-risk-mgmt | ISO/IEC 42001:2023 Clause 6.1.2 — AI risk assessment | A continuous Article 9 risk management process is the EU-AI-Act realisation of Clause 6.1.2 risk assessment. |
art9-risk-mgmt | ISO/IEC 42001:2023 Clause 6.1.3 — AI risk treatment | Article 9 mitigation, residual-risk recording and quarterly review provide the risk-treatment evidence required by Clause 6.1.3. |
art17-qms | ISO/IEC 42001:2023 Clause 4 — Context of the organisation | Article 17 QMS includes scope, interested parties and AIMS boundaries — the substance of Clause 4 context. |
art17-qms | ISO/IEC 42001:2023 Clause 5 — Leadership and AI policy | A QMS that names accountable leadership and approves an AI policy satisfies the Clause 5 leadership requirements. |
art17-qms | ISO/IEC 42001:2023 Clause 9 — Performance evaluation | QMS internal audit, management review and KPI monitoring are exactly the practices required by Clause 9. |
annexiv-harmonised-standards | ISO/IEC 42001:2023 Clause 4.4 — AI management system | Listing harmonised-standard alignment (ISO 42001/23894/24029) is the AIMS-establishment evidence of Clause 4.4. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art11-tech-docs | NIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitations | Article 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1. |
art11-tech-docs | NIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewed | Maintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4. |
art9-risk-mgmt | NIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documented | EU AI Act Article 9 risk management explicitly captures the regulatory requirements GOVERN 1.1 wants documented. |
art9-risk-mgmt | NIST AI RMF MANAGE 1.3 — Responses to the AI risks deemed high priority are developed, planned, and documented | Article 9 mitigation plans for residual high-priority risks are exactly the responses MANAGE 1.3 expects. |
art17-qms | NIST AI RMF GOVERN 1.2 — The characteristics of trustworthy AI are integrated into organizational policies, processes, and procedures | A QMS that integrates trustworthy-AI characteristics across product lifecycle is the practice expected by GOVERN 1.2. |
art17-qms | NIST AI RMF GOVERN 2.1 — Roles, responsibilities, and lines of communication for AI risk management are documented | QMS organisational charts and accountability matrices are the documented roles GOVERN 2.1 expects. |
annexiv-harmonised-standards | NIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documented | Listing harmonised-standard alignment (ISO 42001/23894/24029) is the documented standards landscape GOVERN 1.1 expects. |
Related
Article 17
EU AI Act Article 17 — Quality Management System (QMS)
Article 9
EU AI Act Article 9 — Risk Management System Requirements
Article 11
EU AI Act Article 11 — Technical Documentation Requirements
EU AI Act ↔ NIST AI RMF
EU AI Act vs NIST AI RMF — Crosswalk and Practical Differences
Articles 51 / 53 / 55
GPAI Compliance — Obligations for General-Purpose AI Model Providers
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.