EU AI Act ↔ ISO/IEC 42001

EU AI Act vs ISO 42001 — Crosswalk and Integration Pattern

A side-by-side of the EU AI Act and ISO/IEC 42001:2023 AI Management Systems. Where they overlap, where they diverge, and how to leverage one to satisfy the other.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review

Why this comparison matters

The EU AI Act is regulation. ISO/IEC 42001:2023 is a management-system standard for AI management systems (AIMS), structured like ISO 9001 / 27001. They share a control vocabulary, but they answer different questions.

A team certified to ISO 42001 is not automatically EU AI Act compliant; an EU AI Act compliant provider is not automatically ISO 42001 certified. But the overlap is large enough that doing one puts you 70–80% of the way to the other.

Top-level structure

DimensionEU AI ActISO/IEC 42001:2023
TypeBinding regulationVoluntary management-system standard
ScopeHigh-risk AI systems + GPAI models + prohibited-practicesOrganisation-wide AIMS for any AI
ConformityArticle 43 conformity assessmentThird-party certification audit
StructureArticles 1–113 + 13 AnnexesAnnex SL high-level structure: Clauses 4–10 + Annex A controls
ForceEU-bindingVoluntary; certification is market signal
PenaltiesUp to €35M / 7% turnoverLoss of certification

Where they overlap

The Governancer crosswalk maps each 30-item EU AI Act checklist entry to ISO 42001 clauses and Annex A controls. Headline overlaps:

  • Article 9 risk management ↔ Clause 6.1.2 + 6.1.3. Risk assessment + risk treatment.
  • Article 10 data governance ↔ Annex A.7.4 + A.7.5 + A.7.6. Data quality, acquisition, provenance.
  • Article 11 technical documentation ↔ Clause 7.5 + Annex A.6.2. Documented information + AI lifecycle documentation.
  • Article 14 human oversight ↔ Annex A.9.2. Human oversight of AI systems.
  • Article 15 accuracy / cybersecurity ↔ Annex A.6.2.4 + A.6.2.5. Verification and validation; AI security.
  • Article 17 QMS ↔ entire AIMS structure (Clauses 4–10). ISO 42001 is an AIMS standard; Article 17 requires an AI-specific QMS.
  • Article 27 FRIA ↔ Clause 6.1.4 + Annex A.5.2. AI system impact assessment.
  • Article 72 post-market monitoring ↔ Clause 9.1 + Annex A.6.2.8. Performance evaluation + operation and monitoring.

Where they diverge — three gaps

  1. Conformity assessment vs certification. ISO 42001 certification is by an accredited certification body, with a three-year cycle and surveillance audits. The EU AI Act Article 43 procedure is per-system (often internal control under Annex VI), with the EU declaration of conformity signed before placement.
  2. Per-system vs per-organisation scope. ISO 42001 covers the AIMS at organisation level. The EU AI Act technical file is per high-risk AI system. A certified organisation can ship a non-conforming high-risk system; a compliant high-risk system can come from a non-certified organisation.
  3. Substantive legal obligations. EU AI Act has prohibited practices (Article 5), explicit deployer obligations (Article 26), worker-information duties (Article 26(7)), and the Article 27 FRIA. ISO 42001 has no equivalent prohibitions; it is process-focused.

Where ISO 42001 has more depth

ISO 42001 goes deeper on:

  • Annex A controls structured for an integrated management system. Useful for organisations already running ISO 9001 / 27001 / 14001.
  • Top-management leadership under Clause 5 — explicit AI-policy approval, named accountability.
  • Internal-audit programme under Clause 9.2 — formal audit cadence.
  • Continual-improvement loop under Clause 10 — formalised improvement cycle.

Integration pattern

The clean integration:

  1. Build the Article 17 QMS as an ISO 42001 AIMS. The Article 17(1) thirteen aspects map cleanly to the ISO 42001 clauses.
  2. Layer the AI-Act-specific scaffolding on top: per-system Annex IV files, Article 47 declarations, Article 49 registrations, Article 27 FRIAs where applicable.
  3. Pursue ISO 42001 certification as a market signal. Article 40 of the AI Act confers a presumption of conformity for high-risk AI systems where harmonised standards are applied — and ISO/IEC 42001:2023 is among the standards being considered for harmonisation under Commission Implementing Decision C(2023)3215.
  4. Communicate certification carefully: ISO 42001 is not equivalent to AI Act compliance. Don't claim it.

What we ship

  • Pro. Full per-checklist-item ISO 42001 crosswalk with rationale; downloadable PDF for ISO auditors and buyer due-diligence.

The mapping cites public sources only (A-LIGN clause-by-clause guide, IAPP, BSI overview, ISO online TOC). No normative ISO text is reproduced.


Disclaimer. Reference; not legal advice. We are not ISO 42001-certified; we provide a crosswalk reference only. Reg text from Regulation (EU) 2024/1689; ISO 42001 reference from ISO online TOC.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 11 · Starter tier · critical

    Draft technical documentation (system purpose, design, risk)

    Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.

  • Article 9 · Starter tier · high

    Establish risk management system

    A continuous iterative process. Identify foreseeable risks, estimate impact, document mitigations, review at least quarterly.

  • Article 17 · Starter tier · medium

    Set up quality management system (QMS)

    Covers development, testing, validation, change management, post-market monitoring. Can build on ISO 9001 if you have it.

  • Annex IV · Pro tier · medium

    List ISO/IEC 42001 + 23894 + 24029 alignment

    Annex IV(2)(h) requires a list of harmonised standards applied in full or in part. ISO 42001 (AIMS), 23894 (risk), 24029 (robustness) are the core trio.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art11-tech-docsISO/IEC 42001:2023 Clause 7.5 — Documented informationArticle 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions.
art11-tech-docsISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentationAnnex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation.
art9-risk-mgmtISO/IEC 42001:2023 Clause 6.1.2 — AI risk assessmentA continuous Article 9 risk management process is the EU-AI-Act realisation of Clause 6.1.2 risk assessment.
art9-risk-mgmtISO/IEC 42001:2023 Clause 6.1.3 — AI risk treatmentArticle 9 mitigation, residual-risk recording and quarterly review provide the risk-treatment evidence required by Clause 6.1.3.
art17-qmsISO/IEC 42001:2023 Clause 4 — Context of the organisationArticle 17 QMS includes scope, interested parties and AIMS boundaries — the substance of Clause 4 context.
art17-qmsISO/IEC 42001:2023 Clause 5 — Leadership and AI policyA QMS that names accountable leadership and approves an AI policy satisfies the Clause 5 leadership requirements.
art17-qmsISO/IEC 42001:2023 Clause 9 — Performance evaluationQMS internal audit, management review and KPI monitoring are exactly the practices required by Clause 9.
annexiv-harmonised-standardsISO/IEC 42001:2023 Clause 4.4 — AI management systemListing harmonised-standard alignment (ISO 42001/23894/24029) is the AIMS-establishment evidence of Clause 4.4.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art11-tech-docsNIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitationsArticle 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1.
art11-tech-docsNIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewedMaintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4.
art9-risk-mgmtNIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documentedEU AI Act Article 9 risk management explicitly captures the regulatory requirements GOVERN 1.1 wants documented.
art9-risk-mgmtNIST AI RMF MANAGE 1.3 — Responses to the AI risks deemed high priority are developed, planned, and documentedArticle 9 mitigation plans for residual high-priority risks are exactly the responses MANAGE 1.3 expects.
art17-qmsNIST AI RMF GOVERN 1.2 — The characteristics of trustworthy AI are integrated into organizational policies, processes, and proceduresA QMS that integrates trustworthy-AI characteristics across product lifecycle is the practice expected by GOVERN 1.2.
art17-qmsNIST AI RMF GOVERN 2.1 — Roles, responsibilities, and lines of communication for AI risk management are documentedQMS organisational charts and accountability matrices are the documented roles GOVERN 2.1 expects.
annexiv-harmonised-standardsNIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documentedListing harmonised-standard alignment (ISO 42001/23894/24029) is the documented standards landscape GOVERN 1.1 expects.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.