ISO 42001 vs EU AI Act: the short answer
ISO/IEC 42001:2023 AI Management System is industry standard and applies to Any organization providing, developing, or using AI products or services. Certifiable management-system standard analogous to ISO 27001 for AI. EU AI Act (Regulation 2024/1689) is regulatory and applies to Providers, deployers, importers, and distributors of AI systems placed on the EU market or whose output is used in the EU. Includes non-EU providers serving EU users. The practical tension is that whether a certifiable management system actually helps you satisfy a regulator, and where it stops short.
They are not substitutes. Across the fifteen governance dimensions compared here, 15 are addressed substantively by both, 0 are materially stronger in ISO 42001, and 0 are materially stronger in EU AI Act. Treating either as a superset of the other is the most common and most expensive mistake.
At a glance
ISO/IEC 42001:2023 AI Management System
Type: Industry standard. Jurisdiction: International. In force: December 18, 2023. Exposure for getting it wrong: Certification withdrawal; no statutory penalty. Best suited to: Enterprises seeking a third-party-auditable AI management certification
EU AI Act (Regulation 2024/1689)
Type: Regulatory. Jurisdiction: European Union (extraterritorial). In force: August 1, 2024 (staggered through August 2, 2027). Exposure for getting it wrong: Up to EUR 35 million or 7% of global turnover (Article 99). Best suited to: Any organization shipping AI products to EU users or processing data of EU residents
The penalty asymmetry is usually what decides sequencing. EU AI Act carries legal consequences and ISO 42001 does not, so EU AI Act sets your deadline while ISO 42001 sets your method.
Where the work genuinely overlaps
These are the dimensions both frameworks address substantively, which means one piece of evidence can often satisfy both. This is where a combined programme saves real effort rather than just feeling tidy.
Governance + accountability. ISO 42001 (Clauses 5.1-5.3; A.2.x): Clauses 5.1-5.3 require leadership commitment, AI policy, and assigned organisational roles for the AIMS. EU AI Act (Articles 17, 26): Article 17 requires a quality management system for high-risk providers; deployers need internal governance under Article 26.
Risk management process. ISO 42001 (Clause 6.1; A.5.1-A.5.5): Clause 6.1 requires AI risk assessment, treatment, and AI system impact assessment (Annex A.5). EU AI Act (Article 9): Article 9 mandates a risk management system across the lifecycle of high-risk AI systems.
Data handling + minimisation. ISO 42001 (A.7.1-A.7.6): Annex A.7 governs data for AI systems: provenance, quality, preparation, and data-management plans. EU AI Act (Article 10): Article 10 sets quality, governance, and bias-testing requirements for training, validation, and test datasets.
Model lifecycle controls. ISO 42001 (A.6.1-A.6.2): Annex A.6 covers AI system lifecycle: design, development, verification, deployment, operation, retirement. EU AI Act (Articles 9, 11, 17): Article 9, 11, 17 cover risk management, technical documentation, and quality management across lifecycle.
Transparency + disclosure. ISO 42001 (A.8.1-A.8.5): Annex A.8 requires information for interested parties: system documentation, user docs, intended use. EU AI Act (Articles 13, 50, 53): Article 13 (high-risk) and Article 50 (chatbots, synthetic content) impose user-disclosure obligations; Article 53 covers GPAI documentation.
Human oversight + intervention. ISO 42001 (A.9.1-A.9.4): Annex A.9 requires human oversight and use of AI systems by humans in a defined manner. EU AI Act (Articles 14, 26): Article 14 mandates effective human oversight for high-risk AI; specific roles per Article 26 for deployers.
The caveat worth stating: overlapping subject matter does not mean interchangeable evidence. ISO 42001 and EU AI Act frequently want the same control documented to a different standard of proof, so plan to write once and format twice.
Which to tackle first
Start with EU AI Act (Regulation 2024/1689). It is regulatory, it is in force from August 1, 2024 (staggered through August 2, 2027), and non-compliance carries Up to EUR 35 million or 7% of global turnover (Article 99). Deadlines and penalties dictate sequencing regardless of which framework is intellectually tidier.
Then layer ISO/IEC 42001:2023 AI Management System. Because it is industry standard, it earns its place by making the first one repeatable and evidenced rather than by adding a separate obligation. Teams that invert this order tend to build an elegant management system and still miss a statutory deadline.
The efficient path is to scope ISO 42001 around the evidence EU AI Act already forces you to produce, rather than running two programmes side by side.
How Areebi maps to ISO 42001 and EU AI Act
Areebi does not certify you against either framework. What it does is produce the runtime evidence both of them ask for, from the same control plane, so the overlap above becomes real rather than theoretical.
For ISO 42001: AIMS-ready policy library accelerates Stage 1 audit readiness against Clause 5.2 and Annex A.2. Per-tenant policy enforcement satisfies A.6.2 lifecycle controls during runtime. Immutable audit log + management dashboards provide Clause 9.1 + 9.3 monitoring evidence. Vendor governance workflows align with A.10 third-party requirements.
For EU AI Act: Article 12 logging obligations satisfied by immutable audit log with 6-month minimum retention. DLP + provider routing supports Article 10 data-governance and Article 15 cybersecurity. Per-tenant evaluation harness aligned with Article 14 human-oversight workflows. Incident-response runbook templates align with Article 73 reporting window.
The common thread is that both frameworks want to know what your AI systems actually did, not what your policy said they should do. That is an operational logging and enforcement problem before it is a documentation problem.
Frequently Asked Questions
Does complying with ISO 42001 mean we comply with EU AI Act?
No. Of the fifteen dimensions compared, 0 are materially stronger in EU AI Act. ISO 42001 compliance is useful evidence toward EU AI Act but does not satisfy it.
Which of ISO 42001 and EU AI Act is legally binding?
EU AI Act (Regulation 2024/1689) is regulatory in European Union (extraterritorial), in force from August 1, 2024 (staggered through August 2, 2027), with exposure of Up to EUR 35 million or 7% of global turnover (Article 99). ISO/IEC 42001:2023 AI Management System is industry standard and carries no direct statutory penalty, though it is increasingly a procurement requirement.
What do ISO 42001 and EU AI Act agree on?
15 of fifteen dimensions are addressed substantively by both, notably governance + accountability, risk management process, data handling + minimisation, model lifecycle controls. Evidence produced for one can usually be reused for the other, though the required standard of proof often differs.
Is there anything neither ISO 42001 nor EU AI Act covers?
Between them the two frameworks cover all fifteen dimensions to at least a partial standard, which is unusual and makes this a strong pairing.
Which should we implement first, ISO 42001 or EU AI Act?
EU AI Act, because it is enforceable from August 1, 2024 (staggered through August 2, 2027) and carries Up to EUR 35 million or 7% of global turnover (Article 99). Scope the second framework around the evidence the first already forces you to produce.
How current is this comparison?
Every cell is tied to a specific clause reference and is maintained alongside the full crosswalk of twelve frameworks across fifteen dimensions, which is published openly under CC BY 4.0. Source texts: https://www.iso.org/standard/81230.html and https://eur-lex.europa.eu/eli/reg/2024/1689/oj.
Ready to switch from EU AI Act?
Migration support included
Get a personalized demo and see how Areebi compares for your specific requirements.