The question of ISO 42001 versus AI Act is often framed as a choice: pursue certification or prepare for regulation. For compliance teams, that is the wrong starting point. The EU AI Act creates binding duties for defined actors and AI systems. ISO/IEC 42001 provides a management-system structure for governing AI across the organisation. One tells you what the law requires; the other can make those requirements operational, repeatable and auditable.
Treating either framework as a standalone exercise creates avoidable gaps. An ISO 42001 certificate does not prove EU AI Act compliance. Equally, a narrow EU AI Act programme can leave an organisation without the ownership model, control environment or improvement cycle needed to sustain compliance as its AI estate changes.
ISO 42001 versus AI Act: the core difference
The EU AI Act is a directly applicable EU regulation. It assigns obligations according to an organisation’s role – including provider, deployer, importer, distributor and authorised representative – and the type of AI system involved. Its requirements are legally enforceable, with significant administrative fines for non-compliance.
ISO/IEC 42001 is an international standard for an Artificial Intelligence Management System, or AIMS. It follows the familiar management-system model used in standards such as ISO 27001: establish scope, set policy and objectives, assign responsibilities, assess risks, implement controls, monitor performance, conduct internal audits and improve.
The distinction matters in practice. The AI Act asks whether a system is prohibited, high-risk, subject to transparency requirements, or otherwise regulated. It may require technical documentation, instructions for use, human oversight measures, logging, post-market monitoring and incident reporting. ISO 42001 asks whether the organisation has a controlled way to identify and manage AI-related risks, impacts and obligations over time.
Put simply, the AI Act is a legal rulebook. ISO 42001 is an organisational operating model.
Legal obligation versus voluntary assurance
For organisations within the Act’s territorial scope, applicable AI Act duties are not optional. The regulation applies not only to EU-based providers and deployers, but can also reach organisations outside the EU where an AI system’s output is used in the Union. UK organisations serving EU customers should therefore assess applicability rather than assuming Brexit removes the issue.
The Act has been phased in. Prohibited AI practices and AI literacy obligations have applied since February 2025. Rules for general-purpose AI models began applying from August 2025. Most provisions, including many high-risk AI system obligations, apply from August 2026, with certain requirements for high-risk systems embedded in regulated products following later.
ISO 42001 certification is voluntary unless a customer, procurement framework, insurer or contractual commitment makes it effectively mandatory. Certification can provide independent assurance that an AIMS conforms to the standard, but the certificate is not a regulatory safe harbour. A regulator assessing an AI Act breach will examine the relevant legal obligations and evidence for the particular system, not simply whether the organisation holds an ISO certificate.
That said, voluntary does not mean peripheral. For boards and procurement teams, ISO 42001 can demonstrate that AI governance is managed as a continuing control programme rather than a one-off legal review.
Different scopes, overlapping evidence
The AI Act is primarily system- and role-specific. Its central question is: what is this AI system, who is responsible for it, where is it used, and which obligations follow? Classification is therefore foundational. A model used to draft internal meeting notes is not governed in the same way as a system used to screen job applicants, assess creditworthiness or support clinical decision-making.
ISO 42001 has a wider organisational scope. An AIMS can cover internally developed models, third-party SaaS tools, generative AI assistants, embedded AI features and the processes used to procure, approve, deploy and monitor them. It also addresses AI-specific impacts beyond conventional legal risk, including fairness, transparency, accountability, data quality and human oversight.
There is substantial overlap in the evidence both frameworks need. A well-run programme will maintain an AI inventory, defined system owners, documented purposes, data and supplier records, risk and impact assessments, approval decisions, control evidence, monitoring records and review dates.
The overlap is useful, but it should not be overstated. ISO 42001 controls require tailoring to the organisation’s context and risk treatment plan. The AI Act contains prescriptive duties that cannot be satisfied by vague policy statements. For a high-risk provider, for example, technical documentation and quality management obligations need to meet the regulation’s specific requirements. A generic risk register is not enough.
Where ISO 42001 helps with AI Act compliance
ISO 42001 is particularly valuable where AI Act readiness is being held together by spreadsheets, informal approvals and scattered documents. It introduces the governance mechanics that make compliance defensible when a customer, auditor or regulator asks for proof.
An effective AIMS can support AI Act implementation by establishing four practical disciplines:
- a complete and maintained AI inventory, including the business owner, vendor, purpose, deployment location and user population for each system;
- a classification workflow that identifies organisational role, relevant AI Act category and applicable obligations;
- a risk, impact and control process that records decisions, residual risk, approval conditions and review triggers; and
- an assurance cycle covering performance monitoring, internal audit, management review, corrective action and retained evidence.
These disciplines are also valuable for systems outside the AI Act’s high-risk category. A transparency obligation may be lighter than a high-risk conformity assessment, but the organisation still needs to know that the system exists, who owns it and how users are instructed to use it appropriately.
Where ISO 42001 does not close the gap
The most common implementation error is to map ISO clauses to AI Act articles and declare the work complete. Mappings are useful planning tools. They are not proof that each legal duty has been met.
For example, ISO 42001 may require an organisation to identify relevant legal and other requirements. The AI Act then requires the organisation to determine exactly which obligations apply to a particular system and role. If the organisation is a provider of a high-risk AI system, it may need a formal conformity assessment, EU declaration of conformity, CE marking, registration in the EU database and post-market monitoring. Those are legal deliverables, not optional management-system artefacts.
The same applies to general-purpose AI. Provider obligations around technical documentation, information for downstream providers, copyright policy and training-content summaries need specific assessment. Deployers also need to avoid assuming that supplier documentation transfers all responsibility. Their own use, oversight, staff competence and input data can create separate obligations.
ISO 42001 provides the structure to control this work. Legal analysis remains necessary.
Choosing the right starting point
The order depends on your exposure and maturity. If the organisation develops or places potentially high-risk AI systems on the EU market, begin with AI Act applicability and classification. You need to know whether a prohibited practice, high-risk obligation or general-purpose AI requirement applies before designing the compliance plan.
If the organisation is mainly deploying third-party AI tools across several functions, start with a reliable inventory and governance baseline. In many mid-market organisations, the immediate weakness is not a lack of policies. It is the absence of a single record showing what AI is in use, who approved it, what data it accesses, what risks were accepted and when the decision must be revisited.
For organisations pursuing ISO 42001 certification, avoid building an AIMS detached from the AI Act. Include legal and regulatory obligations within the scope, risk assessment methodology, control mapping, internal audit programme and management review agenda. This prevents a certification project becoming a parallel documentation exercise with no regulatory value.
Build one evidence base, not two programmes
The practical answer is a dual-framework operating model. Maintain one authoritative inventory, assess each system through both a legal classification and a governance risk lens, then map controls and evidence to the relevant AI Act articles and ISO 42001 requirements.
This is where a purpose-built governance system has a material advantage over shared folders and spreadsheet trackers. Teams need versioned assessments, ownership workflows, approval trails, control testing, evidence retention and reporting that can be filtered by system, business unit, legal obligation or framework. Endaxi AIG is designed around that operational requirement: a single system of record for AI inventory, AI Act classification, ISO 42001 controls and audit-ready evidence.
The test is straightforward. If your organisation cannot produce a current list of AI systems, their accountable owners, legal classification, risk decisions and supporting evidence within a working day, governance is not yet operating at the level regulators, customers and boards will expect.
Start with the systems already affecting people, decisions or regulated processes. Make accountability visible, document the decisions that matter and build a review cycle that survives the next procurement, model update or audit request.

