---
title: "ISO 42001 vs EU AI Act: differences, overlap and mapping"
description: "ISO/IEC 42001 vs the EU AI Act: legal force, scope, certification and a topic-by-topic clause mapping with links to the obligations and patterns."
canonical: https://aigovernanceengineer.com/resources/crosswalk/iso-42001-vs-eu-ai-act
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-27
---

# ISO 42001 vs EU AI Act: differences, overlap and mapping

> The EU AI Act is binding law, directly applicable in every Member State; it reaches providers, deployers, importers and distributors whose AI systems are placed on the EU market or whose output is used there. ISO/IEC 42001 is a voluntary, certifiable AI management-system standard for any organisation; its certificate confers no presumption of conformity with the Act.

**In short**

ISO/IEC 42001 and the EU AI Act work on many of the same topics but are different kinds of instrument. The EU AI Act is binding law: prohibitions and AI literacy apply since 2 February 2025, GPAI obligations since 2 August 2025 and Annex III high-risk duties from 2 December 2027, and fines for prohibited practices reach EUR 35 million or 7% of worldwide annual turnover. ISO/IEC 42001 is a voluntary AI management-system standard; certification bodies audit organisations against it, under ISO/IEC 42006. A 42001 certificate evidences a management system and confers no presumption of conformity with the Act: only harmonised standards cited in the Official Journal and the Commission's common specifications do. In the crosswalk, both file clauses under 20 of 25 topics, 13 of them strongly. The AIMS still earns its place: its risk assessment, impact assessment and documentation processes produce evidence the Act's duties ask for.

## At a glance

The two instruments side by side, as the Body of Knowledge states them, each cell with the primary source it rests on.

| Attribute | ISO/IEC 42001 | EU AI Act (post-Omnibus) |
|---|---|---|
| Type | Standard: ISO/IEC 42001:2023, the AI management-system (AIMS) standard (Source: [ISO/IEC 42001:2023](https://www.iso.org/standard/42001)) | Law: Regulation (EU) 2024/1689, as amended by the Digital Omnibus, Regulation (EU) 2026/1744 (Sources: [Regulation (EU) 2024/1689, consolidated text](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng), [Regulation (EU) 2026/1744 (Digital Omnibus)](https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng)) |
| Issuer | ISO/IEC (JTC 1/SC 42) (Source: [ISO/IEC 42001:2023](https://www.iso.org/standard/42001)) | European Union (Source: [Regulation (EU) 2024/1689, consolidated text](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng)) |
| Legal force | Voluntary. It is a management-system standard, not the Article 17 QMS, and its European adoption confers no presumption of conformity with the AI Act. (Sources: [ISO/IEC 42001:2023](https://www.iso.org/standard/42001), [AI Act Art. 17](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_17), [AI Act Art. 40](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_40)) | Binding and directly applicable in every Member State. Fines reach EUR 35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices, and EUR 15 million or 3% for operator obligations. (Sources: [Art. 99](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_99), [Art. 113](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_113)) |
| Scope and reach | Any organisation that develops, provides or uses AI. It specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. (Source: [ISO/IEC 42001:2023](https://www.iso.org/standard/42001)) | Risk-tiered: prohibited practices, high-risk systems (Annex I products, Annex III uses), transparency cases and GPAI models. It reaches providers placing AI systems or GPAI models on the EU market wherever they are established, deployers in the Union, third-country providers and deployers whose output is used in the Union, importers and distributors. (Sources: [Art. 2](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_2), [Art. 5](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_5), [Art. 6](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_6), [Art. 50](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_50), [Art. 51](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_51)) |
| Certifiable | Yes. Certification bodies audit organisations against it; ISO/IEC 42006:2025 sets their additional requirements on top of ISO/IEC 17021-1. The certificate evidences a management system; it does not make a system compliant. (Source: [ISO/IEC 42006:2025](https://www.iso.org/standard/44546.html)) | No certificate of the Act as a whole. A high-risk system passes a conformity assessment (internal control, or a notified body where required), then the provider draws up an EU declaration of conformity, affixes the CE marking and registers the system in the EU database. (Sources: [Art. 43](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_43), [Art. 47](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_47), [Art. 48](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_48), [Art. 49](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_49)) |
| Key artefacts | Clauses 4 to 10 in the Harmonized Structure: AI policy, roles, AI risk assessment (6.1.2), risk treatment (6.1.3) and system impact assessment (6.1.4), internal audit, management review. Annex A control objectives in nine areas (A.2 to A.10), justified in a Statement of Applicability. (Source: [ISO/IEC 42001:2023](https://www.iso.org/standard/42001)) | Risk classification, risk management system, technical documentation, quality management system, logs, human oversight, fundamental rights impact assessment, serious-incident reports. (Sources: [Art. 6](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_6), [Art. 9](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_9), [Art. 11](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_11), [Art. 12](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_12), [Art. 14](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_14), [Art. 17](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_17), [Art. 27](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_27), [Art. 73](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_73)) |
| Dates | Published 2023. No application date: it applies to an organisation from the day it adopts the standard. (Source: [ISO/IEC 42001:2023](https://www.iso.org/standard/42001)) | In force 2024-08-01. Prohibitions and AI literacy from 2025-02-02; GPAI obligations from 2025-08-02; Omnibus in force 2026-07-27; high-risk Annex III from 2027-12-02 and Annex I from 2028-08-02. (Sources: [Art. 113](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_113), [Regulation (EU) 2026/1744 (Digital Omnibus)](https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng)) |
| In the Body of Knowledge | [22. The ISO/IEC management-system trio](https://aigovernanceengineer.com/bok/principles-and-standards#the-management-system-trio) · [13. ISO 31000, ISO/IEC 23894 and ISO/IEC 42001](https://aigovernanceengineer.com/bok/risk-management#iso-31000-isoiec-23894-and-isoiec-42001) | [18. The EU AI Act in one pass](https://aigovernanceengineer.com/bok/eu-ai-act) · [08. The regulatory map: EU AI Act](https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus) |

## Where they overlap, topic by topic

The crosswalk maps 25 AI governance topics. Both instruments file clauses under 20 of them, 13 strongly (a core clause on each side). 0 topics have a core clause only in ISO 42001 and 4 only in the EU AI Act; 1 more is touched by one side only in passing (a related clause, not a core one); 0 are reached by neither. A shared topic means the two deal with the same thing, not that meeting one meets the other.

Strong: both file a core clause. Partial: both file a clause, at least one only in passing. Only, in passing: one side files a related clause and the other none. The last column names a pattern only where it serves a core clause on both sides: the register entry of that clause lists it and the pattern's own "Maps to" line names the clause.

| Topic | What ISO 42001 asks for | What EU AI Act asks for | Overlap | Patterns for both |
|---|---|---|---|---|
| [Risk management](https://aigovernanceengineer.com/resources/crosswalk#topic-risk-management) | 6.1.2 AI risk assessment; 6.1.3 AI risk treatment; 8.2 AI risk assessment (operation); 8.3 AI risk treatment (operation); [A.6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system life cycle; 6.1.4 AI system impact assessment | [Art. 9](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9) Risk management system; Art. 3 Definitions | Strong |  |
| [Governance and accountability](https://aigovernanceengineer.com/resources/crosswalk#topic-governance-accountability) | 5.1 Leadership and commitment; 5.2 AI policy; 5.3 Roles, responsibilities and authorities; [A.2](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a2) Policies related to AI; [A.3](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a3) Internal organization; 9.3 Management review (not yet verified against the source); 7.2 Competence (not yet verified against the source); 9.2 Internal audit (not yet verified against the source); 10.1 Continual improvement (not yet verified against the source) | [Art. 17](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17) Quality management system; [Art. 4](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4) AI literacy; Art. 87 Reporting of infringements and protection of reporting persons | Strong |  |
| [Impact assessment](https://aigovernanceengineer.com/resources/crosswalk#topic-impact-assessment) | 6.1.4 AI system impact assessment; 8.4 AI system impact assessment (operation); [A.5](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a5) Assessing impacts of AI systems | [Art. 27](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art27) Fundamental rights impact assessment for high-risk AI systems; [Art. 9](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9) Risk management system | Strong |  |
| [Data governance](https://aigovernanceengineer.com/resources/crosswalk#topic-data-governance) | [A.7](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7) Data for AI systems; [A.7.3](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7) Acquisition of data (not yet verified against the source); [A.4](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a4) Resources for AI systems | [Art. 10](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10) Data and data governance; [Art. 10(2)(f)–(g)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10) Examination for possible biases; measures to detect, prevent and mitigate them; [Art. 4a](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a) Special-category data for bias detection; Art. 53 Obligations for providers of general-purpose AI models; Art. 53(1)(c) Copyright policy, including rights reservations; Art. 5(1)(e) Prohibited: untargeted scraping of facial images | Strong | [Training-Data Rights Ledger](https://aigovernanceengineer.com/patterns/training-data-rights-ledger) |
| [Documentation and transparency](https://aigovernanceengineer.com/resources/crosswalk#topic-documentation-transparency) | 7.5 Documented information; [A.6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system life cycle; [A.8](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8) Information for interested parties | [Art. 11](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art11) Technical documentation; [Art. 13](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13) Transparency and provision of information to deployers; [Art. 53](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53) Obligations for providers of general-purpose AI models; [Art. 50](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50) Transparency obligations for providers and deployers of certain AI systems; Art. 86 Right to explanation of individual decision-making; Art. 18 Documentation keeping; Art. 43 Conformity assessment; Art. 53(1)(d) Public summary of the content used for training; [Art. 50(2), 50(4)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50) Machine-readable marking of synthetic content; disclosure of deep fakes | Strong |  |
| [Inventory and registration](https://aigovernanceengineer.com/resources/crosswalk#topic-inventory-registration) | [A.4](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a4) Resources for AI systems | [Art. 49](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art49-71) Registration; [Art. 71](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art49-71) EU database for high-risk AI systems; [Art. 6](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art6) Classification rules for high-risk AI systems; Art. 3(1) Definition of an AI system; Art. 52 Procedure | Strong |  |
| [Logging and traceability](https://aigovernanceengineer.com/resources/crosswalk#topic-logging-traceability) | [A.6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system life cycle; [A.6.2.8](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system recording of event logs (not yet verified against the source) | [Art. 12](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12) Record-keeping; [Art. 26(6)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Deployers keep the automatically generated logs; [Art. 26](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Obligations of deployers of high-risk AI systems; Art. 19 Automatically generated logs | Strong |  |
| [Human oversight](https://aigovernanceengineer.com/resources/crosswalk#topic-human-oversight) | [A.9](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9) Use of AI systems | [Art. 14](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14) Human oversight; [Art. 26](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Obligations of deployers of high-risk AI systems; [Art. 14(4)(b)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14) Awareness of automation bias | Strong |  |
| [Runtime guardrails](https://aigovernanceengineer.com/resources/crosswalk#topic-runtime-guardrails) | [A.9](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9) Use of AI systems; [A.6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system life cycle | [Art. 5](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5) Prohibited AI practices; [Art. 15](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15) Accuracy, robustness and cybersecurity; [Art. 5(1)(a)–(b)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5) Manipulative techniques; exploitation of vulnerabilities | Partial |  |
| [Robustness, security and evaluations](https://aigovernanceengineer.com/resources/crosswalk#topic-robustness-security-evals) | [A.6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system life cycle; 9.1 Monitoring, measurement, analysis and evaluation | [Art. 15](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15) Accuracy, robustness and cybersecurity; [Art. 55](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55) Obligations for providers of general-purpose AI models with systemic risk; [Art. 60](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art60) Testing of high-risk AI systems in real-world conditions outside AI regulatory sandboxes; [Art. 15(3)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15) Declared accuracy levels and metrics; [Art. 9](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9) Risk management system; Art. 42(3) Presumption of conformity for cybersecurity (Cyber Resilience Act) | Strong |  |
| [Incident response and monitoring](https://aigovernanceengineer.com/resources/crosswalk#topic-incident-monitoring) | [A.8](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8) Information for interested parties; 10.2 Nonconformity and corrective action | [Art. 72](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72) Post-market monitoring by providers and post-market monitoring plan; [Art. 73](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art73) Reporting of serious incidents; [Art. 26(5)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Deployer monitoring, informing the provider and suspending use; [Art. 55](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55) Obligations for providers of general-purpose AI models with systemic risk; Art. 3(49) Definition of serious incident; Art. 20 Corrective actions and duty of information | Strong |  |
| [Supply chain and third parties](https://aigovernanceengineer.com/resources/crosswalk#topic-supply-chain) | [A.10](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a10) Third-party and customer relationships | [Art. 25](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25) Responsibilities along the AI value chain; [Art. 25(4)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25) Written agreement with third-party suppliers; [Art. 26](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Obligations of deployers of high-risk AI systems; Art. 22 Authorised representatives of providers of high-risk AI systems; Art. 23 Obligations of importers; Art. 24 Obligations of distributors; Art. 54 Authorised representatives of providers of general-purpose AI models | Strong | [Vendor / Model Due-Diligence Gate](https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate) |
| [Prohibited practices](https://aigovernanceengineer.com/resources/crosswalk#topic-prohibited-practices) | [A.9.4](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9) Intended use of the AI system (not yet verified against the source) | [Art. 5](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5) Prohibited AI practices | Partial |  |
| [Fairness and non-discrimination](https://aigovernanceengineer.com/resources/crosswalk#topic-fairness-non-discrimination) | [A.5.4](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a5) Assessing AI system impact on individuals or groups of individuals (not yet verified against the source) | [Art. 10(2)(f)–(g)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10) Examination for possible biases; measures to detect, prevent and mitigate them; [Art. 4a](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a) Special-category data for bias detection | Partial |  |
| [Privacy and data protection](https://aigovernanceengineer.com/resources/crosswalk#topic-privacy-data-protection) | [A.7](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a7) Data for AI systems | Art. 59 Further processing of personal data in the AI regulatory sandbox; [Art. 4a](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a) Special-category data for bias detection | Partial |  |
| [Explainability and right to explanation](https://aigovernanceengineer.com/resources/crosswalk#topic-explainability) | [A.8.2](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a8) System documentation and information for users (not yet verified against the source) | Art. 86 Right to explanation of individual decision-making; [Art. 13(3)(b)(iv)–(v)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13) Information relevant to explain output; performance for specific persons or groups | Partial |  |
| [AI literacy and competence](https://aigovernanceengineer.com/resources/crosswalk#topic-ai-literacy) | 7.2 Competence (not yet verified against the source); 7.3 Awareness (not yet verified against the source) | [Art. 4](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4) AI literacy; [Art. 26(2)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Oversight by people with the competence, training and authority it needs; Art. 95(2)(c) Codes of conduct: promoting AI literacy | Strong |  |
| [Conformity assessment and certification](https://aigovernanceengineer.com/resources/crosswalk#topic-conformity-assessment) | 9.2 Internal audit (not yet verified against the source) | [Art. 43](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art43) Conformity assessment; [Art. 47](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art47) EU declaration of conformity; Art. 48 CE marking; Art. 40 Harmonised standards and standardisation deliverables | Partial |  |
| [GPAI and foundation models](https://aigovernanceengineer.com/resources/crosswalk#topic-gpai-foundation-models) | Not mapped | [Art. 53](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53) Obligations for providers of general-purpose AI models; [Art. 55](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55) Obligations of providers of general-purpose AI models with systemic risk; Art. 51 Classification of general-purpose AI models as general-purpose AI models with systemic risk; Art. 56 Codes of practice | EU AI Act only |  |
| [IP and copyright](https://aigovernanceengineer.com/resources/crosswalk#topic-ip-copyright) | Not mapped | [Art. 53(1)(c)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53) Copyright policy, including rights reservations; Art. 53(1)(d) Public summary of the content used for training | EU AI Act only |  |
| [Agent identity and autonomy](https://aigovernanceengineer.com/resources/crosswalk#topic-agent-identity-autonomy) | Not mapped | [Art. 14](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14) Human oversight | EU AI Act only, in passing |  |
| [Content provenance and deepfakes](https://aigovernanceengineer.com/resources/crosswalk#topic-content-provenance) | Not mapped | [Art. 50(2)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50) Machine-readable marking of synthetic content; [Art. 50(4)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50) Disclosure of deep fakes; Art. 3(60) Definition of deep fake | EU AI Act only |  |
| [Sandboxes and real-world testing](https://aigovernanceengineer.com/resources/crosswalk#topic-sandboxes-real-world-testing) | [A.6.2.4](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system verification and validation (not yet verified against the source) | Art. 57 AI regulatory sandboxes; [Art. 60](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art60) Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes; Art. 58 Detailed arrangements for, and functioning of, AI regulatory sandboxes; Art. 59 Further processing of personal data in the AI regulatory sandbox; Art. 61 Informed consent to participate in testing in real world conditions | Partial |  |
| [Environmental impact](https://aigovernanceengineer.com/resources/crosswalk#topic-environmental-impact) | Not mapped | [Annex XI 1(2)(e)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53) Known or estimated energy consumption of the GPAI model; Art. 40(2) Standardisation deliverables on energy and resource performance; Art. 95(2)(b) Codes of conduct: environmental sustainability | EU AI Act only |  |
| [Deployment, change and decommissioning](https://aigovernanceengineer.com/resources/crosswalk#topic-deployment-change-decommissioning) | [A.6.2.5](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system deployment (not yet verified against the source); [A.6.2.6](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a6) AI system operation and monitoring (not yet verified against the source); [A.9](https://aigovernanceengineer.com/obligations/aige-obl-iso42001-a9) Use of AI systems | [Art. 26](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Obligations of deployers of high-risk AI systems; [Art. 25](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25) Responsibilities along the AI value chain; [Art. 43(4)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art43) New conformity assessment on substantial modification; Art. 20 Corrective actions and duty of information; Art. 79 Procedure at national level for dealing with AI systems presenting a risk; Art. 86 Right to explanation of individual decision-making | Strong | [Staged Rollout with Rollback Criteria](https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria); [Drift & Fairness Monitor](https://aigovernanceengineer.com/patterns/drift-fairness-monitor); [Deactivation, Localisation & Retirement Runbook](https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook) |

## Can you use ISO 42001 to comply with the EU AI Act?

Not on its own. A 42001 certificate evidences a management system; it is not a harmonised standard and confers no presumption of conformity with the Act. As of 2026-09-24 no harmonised standard is cited in the Official Journal. The AIMS still helps: its risk, impact-assessment and documentation processes produce evidence the Act's duties ask for.

## Which should you start with?

If your AI systems reach the EU market or their output is used there, start with the Act: its duties apply in stages, prohibitions and AI literacy since 2 February 2025 and Annex III high-risk duties from 2 December 2027. Add ISO/IEC 42001 for a certifiable management system around that work; it shares its clause structure with ISO/IEC 27001.

## Next step

Put the comparison to work on your own systems, in the browser.

- [Check where your system falls under the EU AI Act](https://aigovernanceengineer.com/toolkit/ai-act-triage): The EU AI Act risk classification checker: indicative roles and risk classes, each with its article, and a decision record to file.
- [List the EU AI Act obligations and deadlines that bind you](https://aigovernanceengineer.com/toolkit/obligations-planner): The obligations planner: the register rows for your roles, the artefact that evidences each and the date it applies.
- [Build the AI register both instruments start from](https://aigovernanceengineer.com/toolkit/ai-register-entry): The AI register entry builder: entries that validate against the published schemas, each field mapped to the EU database and an ISO/IEC 42001 Statement of Applicability.

Indicative, not legal advice and not a conformity claim. Nothing you enter leaves your browser.

## Frequently asked questions

### Does ISO 42001 certification give a presumption of conformity with the EU AI Act?

No. Only harmonised European standards whose references are published in the Official Journal (Article 40) and common specifications the Commission adopts by implementing act (Article 41) give a presumption of conformity, to the extent they cover the requirements. ISO/IEC 42001 is neither. As of 2026-09-24 no harmonised standard had been cited at all.

Sources: [Art. 40](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_40), [Art. 41](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_41), [European Commission: Standardisation of the AI Act](https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation)

### Is ISO 42001 the quality management system of Article 17?

No. ISO/IEC 42001 is an AI management-system standard, not the Article 17 quality management system the Act asks of high-risk providers. The standard written for Article 17 is EN 18286:2026, published by CEN-CENELEC in July 2026. Its reference is not yet published in the Official Journal (checked 2026-09-24), so it gives no presumption of conformity yet.

Sources: [Art. 17](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_17), [CEN-CENELEC: EN 18286 in the spotlight](https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/), [European Commission: Standardisation of the AI Act](https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation)

### When do the EU AI Act high-risk duties apply?

Since the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026), the Annex III high-risk duties apply from 2 December 2027 and the Annex I duties from 2 August 2028. ISO/IEC 42001 has no application date: an organisation adopts it when it chooses.

Sources: [Regulation (EU) 2026/1744 (Digital Omnibus)](https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng), [Art. 113](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_113)

### What does the EU AI Act cover that ISO 42001 does not?

In this crosswalk, 4 of the 25 topics have a core EU AI Act clause and no ISO 42001 clause mapped: GPAI and foundation models; IP and copyright; Content provenance and deepfakes; Environmental impact. Agent identity and autonomy is touched only in passing: the EU AI Act files a related clause there, not a core one, and ISO 42001 none. A topic with no ISO 42001 clause here is one this mapping does not reach, not one ISO 42001 is shown to leave out. The overlap table on this page lists the clauses; mappings are illustrative, not a claim of conformity.

## Illustrative mapping, not a conformity assessment

Mappings are illustrative, not a claim of conformity. A mapping cell is not evidence; see the [Framework Crosswalk pattern](https://aigovernanceengineer.com/patterns/framework-crosswalk) for what turns a crosswalk into an auditable control.

## Sources

- ISO/IEC 42001: https://www.iso.org/standard/42001
- EU AI Act (post-Omnibus): https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng
- ISO/IEC 42006:2025: https://www.iso.org/standard/44546.html
- Regulation (EU) 2026/1744 (Digital Omnibus): https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
- European Commission: Standardisation of the AI Act: https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation
- CEN-CENELEC: EN 18286 in the spotlight: https://www.cencenelec.eu/news-events/news/2026/en-in-the-spotlight/2026-07-30-ai-quality-management/

Every clause on this page, with its note and verification status, is in the [topic × framework crosswalk](https://aigovernanceengineer.com/resources/crosswalk) and its [JSON download](https://aigovernanceengineer.com/resources/crosswalk.json). Other comparisons: [NIST AI RMF vs ISO 42001](https://aigovernanceengineer.com/resources/crosswalk/nist-ai-rmf-vs-iso-42001) · [NIST AI RMF vs EU AI Act](https://aigovernanceengineer.com/resources/crosswalk/nist-ai-rmf-vs-eu-ai-act). The wider field: [AI governance, explained](https://aigovernanceengineer.com/ai-governance).
