Skip to main content
ISO 4200118 Jun 2026 · 5 min read

ISO/IEC 42001 and the EU AI Act: how an AI management system earns your compliance

ISO/IEC 42001:2023 provides a certifiable AI management system that mirrors many EU AI Act duties organisationally — but it does not replace the legal presumption of conformity, which only harmonised standards can grant.

What ISO/IEC 42001:2023 actually is

ISO/IEC 42001:2023, published in December 2023, is the first internationally certifiable management-system standard for artificial intelligence (an AI management system, or AIMS). It follows the same Annex SL structure as ISO 9001 or ISO/IEC 27001 and runs as a Plan-Do-Check-Act cycle: define context and scope, assess risks and impacts, implement controls, evaluate effectiveness, and improve continually.

The heart of the standard is Annex A, with 38 controls grouped into nine areas — from AI policies and roles through data quality and lifecycle management to transparency and impact assessment. These controls are not blanket-mandatory: you select the applicable ones on a risk basis and justify any exclusions in a documented statement of applicability.

Why certification is not the same as AI Act conformity

The EU AI Act (Regulation (EU) 2024/1689) was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024; the transparency obligations apply from 2 August 2026, while the core obligations for standalone high-risk AI (Annex III) apply from 2 December 2027 following the 2026 Digital Omnibus amendment. Under Article 40, only harmonised standards whose references are published in the EU Official Journal grant a rebuttable presumption of conformity — and these are being drafted by CEN-CENELEC (JTC 21).

ISO/IEC 42001 is an international standard and sits outside this EU harmonisation process; a certificate therefore does not, on its own, confer a presumption of conformity under the AI Act. An organisation relying on it alone retains the full evidentiary burden if challenged. The practical value lies elsewhere: the AIMS supplies exactly the organisational structure — governance, risk process, documentation — on which later Act conformity is built.

The organisational backbone that carries many Act duties

Several building blocks of the AIMS overlap substantively with core AI Act requirements for high-risk systems, without replacing the legal presumption. An organisation that runs its AIMS seriously has already generated the evidence an audit will ask for.

  • Risk management: the AIMS's ongoing PDCA risk process mirrors the duty to run continuous risk management for high-risk systems (Article 9).
  • Documentation and traceability: the statement of applicability plus lifecycle and data-management records provide the basis for technical documentation and record-keeping duties.
  • Human oversight: the Annex A controls on oversight and roles feed directly into the human-oversight requirements (Article 14).

ISO/IEC 23894 and 42005 as companion standards

ISO/IEC 42001 points to two non-certifiable guidance documents that deepen specific clauses. ISO/IEC 23894:2023 adapts the risk-management principles of ISO 31000 to AI and describes how the risk process is actually operated inside the AIMS. ISO/IEC 42005:2025 complements it with AI system impact assessment across the lifecycle — the point closest in spirit to the AI Act's fundamental-rights considerations.

Together they establish a clear division of roles: ISO/IEC 42001 is the certifiable management layer, 23894 is the risk process inside it, and 42005 is the impact-assessment methodology. None of these standards is itself a legal instrument — but together they form a durable foundation that leaves an organisation audit-ready for the harmonised standards to come.

Key takeaway

Treat an ISO/IEC 42001 certification as the organisational backbone for AI Act readiness, not as legal proof of conformity — and track the harmonised standards in the EU Official Journal in parallel.

Book a demo

Turn the regulation into a running system.

30 minutes, scoped to your frameworks and integrations. You leave with a concrete plan — not a sales loop.