Try all features for free — 3 credits included on sign-upTry for free
Skip to main content
Regulation · Technical Compliance

ISO 42001 and AI Act: how the two frameworks complement each other.

ISO/IEC 42001:2023 provides a structured framework to address AI Act requirements, but does not cover all technical obligations. Analysis of correspondences, limitations, and alignment strategies for European organisations.

Jérémy Pierre
Jérémy Pierre
AI Act Compliance Expert
13 August 2026 12 min read
ISO 42001 and AI Act: Aligning Compliance and Certification
Key takeaways · 4 figures to remember
Dec. 2023
Publication of ISO/IEC 42001:2023, the first international standard
63
AI Act recital citing international standards as a provisional reference
5,000-30,000€
Average cost of ISO 42001 certification depending on organisation size
Annex SL
Common structure of ISO standards aligning 42001 with 9001 and 27001
01 - ISO Standards

ISO 42001: an AI management system standard

Published in December 2023, ISO/IEC 42001:2023 is the first international standard dedicated to AI management systems.

Its objective: to provide a structured framework for developing, deploying, and overseeing AI systems responsibly. The standard follows the lineage of ISO management system standards, such as ISO 9001 for quality and ISO 27001 for information security.

ISO 42001 adopts the common Annex SL structure, facilitating its integration with other existing management systems. This modular approach enables organisations to build on their quality or security processes to incorporate AI governance specifics.

Annex SL structure
10 common sections: context, leadership, planning, support, operation, evaluation, improvement
Alignment with ISO 9001
Process approach, continuous improvement, customer focus
Alignment with ISO 27001
Risk management, non-conformity treatment, internal audits

The standard covers four key dimensions: governance, the AI system lifecycle, transparency, and accountability. It specifically requires the establishment of an AI policy, the designation of a governance officer, and the documentation of development and deployment processes.

02 - Regulatory correspondences

Mapping requirements between ISO 42001 and the AI Act

ISO 42001 and the AI Act share common objectives, but their approaches differ. The following table highlights the main correspondences between the standard's sections and the Regulation's articles.

ISO 42001 Section 4 (Context)
↔ AI Act Articles 3(1) and 52: Scope definition and system classification
ISO 42001 Section 5 (Leadership)
↔ AI Act Articles 4 and 17: Management responsibilities and governance
ISO 42001 Section 6 (Planning)
↔ AI Act Article 9: Risk management and impact assessment
ISO 42001 Section 7 (Support)
↔ AI Act Articles 10 and 13: Resources, competencies, and technical documentation
ISO 42001 Section 8 (Operation)
↔ AI Act Articles 10-15: Operational requirements (data, robustness, transparency)
ISO 42001 Section 9 (Evaluation)
↔ AI Act Article 72: Post-market monitoring and continuous oversight
ISO 42001 Section 10 (Improvement)
↔ AI Act Article 21: Incident handling and corrective actions
"ISO 42001 provides a methodology for addressing AI Act requirements, but does not replace a specific regulatory analysis. Organisations must supplement the standard with technical documentation compliant with Annex IV of the Regulation."

Recital 63 of the AI Act explicitly recognises the importance of international standards as a basis for provisional compliance. This provision allows organisations certified to ISO 42001 to demonstrate their commitment to AI governance while awaiting harmonised CEN/CENELEC standards.

03 - Limitations and differences

What ISO 42001 does not cover in the AI Act

Despite its correspondences with the EU Regulation, ISO 42001 has several limitations that organisations should anticipate.

1. Process approach vs technical requirements

ISO 42001 is a management system standard focused on organisational processes. It does not specify technical criteria for assessing the compliance of AI systems themselves. The AI Act, however, imposes precise requirements on:

  • The quality of training data (Article 10)
  • Robustness and cybersecurity (Article 15)
  • Explainability of decisions (Article 13)
  • Detailed technical documentation (Annex IV)

2. Geographical scope

ISO 42001 is an international standard, whereas the AI Act applies only to systems deployed or used in the European Union. Organisations operating outside the EU may limit themselves to ISO certification, but those targeting the EU market must comply with both frameworks.

3. Legal obligation vs voluntary approach

ISO 42001 certification remains a voluntary process without binding legal value. The AI Act, by contrast, is a legal text with penalties of up to 35 million euros or 7% of global turnover. ISO certification does not guarantee regulatory compliance but may facilitate its demonstration.

4. Absence of coverage for prohibited practices

ISO 42001 does not address the AI Act's specific prohibitions (Article 5), such as:

  • Subliminal manipulation
  • Exploitation of vulnerabilities
  • Social scoring
  • Real-time facial recognition in public spaces

These practices require a separate regulatory analysis, independent of ISO certification.

04 - Compliance strategy

Why adopt ISO 42001 now

Despite its limitations, ISO 42001 is a strategic lever for organisations subject to the AI Act.

1. Reducing regulatory risks

The standard provides a structured methodology for identifying and mitigating risks associated with AI systems. Its systematic approach facilitates the demonstration of due diligence in the event of an inspection by competent authorities, such as the AI Office or national supervisory authorities.

2. Preparing for harmonised standards

Harmonised CEN/CENELEC standards, expected in 2027-2028, will likely build on existing international standards. ISO 42001 certification positions organisations ahead of these future requirements, reducing transition costs.

3. Integration with existing systems

Thanks to its Annex SL structure, ISO 42001 can be integrated with existing quality (ISO 9001) or security (ISO 27001) management systems. This integrated approach allows for resource pooling and reduced compliance costs.

4. Competitive advantage

According to several studies, ISO 42001 certification is perceived as a mark of quality and responsibility by clients and partners. It can facilitate access to public procurement and enhance stakeholder trust.

Synergies with ISO 9001
Management review process, non-conformity management, internal audits
Synergies with ISO 27001
Risk analysis, incident management, data access control
Synergies with GDPR
Impact assessment, processing register, data subject rights
05 - Certification and bodies

Process and certification bodies for ISO 42001

ISO 42001 certification follows a standardised process, similar to that of other ISO management system standards.

Certification steps

  1. Initial assessment: Evaluation of the current state against the standard's requirements.
  2. Compliance implementation: Deployment of missing processes (AI policy, risk management, documentation).
  3. Internal audit: Verification of compliance by an internal team or consultant.
  4. Certification audit: Conducted by an accredited body, in two phases (documentary and on-site).
  5. Certificate issuance: Valid for 3 years, with annual surveillance audits.

Certification bodies

Several bodies offer ISO 42001 certification in Europe:

  • BSI (UK)
  • DNV
  • Bureau Veritas
  • LRQA
  • SGS
  • TÜV SÜD

In France, several organisations obtained certification in 2024-2025, particularly in the banking, insurance, and technology sectors.

Costs and duration

The cost of certification varies depending on the size and complexity of the organisation:

SMEs (50-250 employees)
5,000 to 12,000€, duration 6 to 12 months
Large enterprises
15,000 to 30,000€, duration 12 to 18 months

These costs typically include audits but not investments required to bring processes into compliance.

Is your organisation ready for the AI Act?

Identify your regulatory obligations and assess your compliance level with our free 3-minute assessment.

06 - FAQ

Frequently asked questions

Answers to compliance officers' and auditors' questions on the relationship between ISO 42001 and the AI Act.

No. ISO 42001 covers governance and management aspects of AI systems but does not meet all the AI Act's technical requirements. For example, it does not specify criteria for training data quality (Article 10) or technical documentation (Annex IV). ISO 42001 certification can facilitate compliance demonstration but must be supplemented by a specific regulatory analysis and tailored technical documentation.

The two standards share the same Annex SL structure, but their objectives differ. ISO 27001 focuses on information security, while ISO 42001 specifically addresses risks related to AI systems. For example:

  • ISO 42001 includes requirements on AI system transparency (explainability, documentation)
  • It addresses algorithmic bias and fairness, which are absent from ISO 27001
  • It requires an analysis of societal impacts, beyond purely informational risks

However, the two standards can be integrated, particularly for common aspects such as risk management or internal audits.

Section 6 of ISO 42001 (Planning) provides a structured methodology for meeting the requirements of Article 9 of the AI Act. It specifically requires:

  • Identification of risks specific to AI systems (bias, robustness, explainability)
  • Implementation of a continuous impact assessment process
  • Documentation of mitigation measures
  • Regular review of control effectiveness

This systematic approach enables the demonstration of due diligence in risk management, as required by the AI Act. However, ISO 42001 does not specify technical criteria for assessing risks, which must be defined based on regulatory requirements.

Several international bodies offer ISO 42001 certification in France, including:

  • Bureau Veritas
  • DNV
  • LRQA
  • SGS
  • TÜV SÜD

These bodies are accredited by COFRAC or equivalent European bodies. It is recommended to verify their specific accreditation for ISO 42001 before proceeding. Several French organisations, particularly in the banking and technology sectors, obtained this certification in 2024-2025.

Integrating ISO 42001 with an existing ISO 9001 system is facilitated by their common Annex SL structure. Here is a step-by-step approach:

  1. Process mapping: Identify existing processes (management review, internal audits, non-conformity management) that can be extended to AI governance.
  2. Extending responsibilities: Appoint an AI officer within the existing quality structure.
  3. Risk integration: Add AI-specific risks to the quality risk register.
  4. Unified documentation: Create common procedures for cross-cutting aspects (training, communication, continuous improvement).
  5. Combined audits: Conduct internal audits covering both ISO 9001 and ISO 42001 requirements.

This approach enables resource pooling and reduces compliance costs. It is particularly suitable for organisations with a mature quality culture.

Jérémy Pierre
Jérémy Pierre
Founder aiacto.eu · AI Act Compliance Expert

Supports AI providers and deployers in regulatory compliance, with particular expertise in aligning international standards with EU requirements.

Share this article