ISO/IEC 42001 vs the EU AI Act: what's the difference?
6 min read
They solve different problems
It's easy to lump AI governance requirements together, but ISO/IEC 42001 and the EU AI Act are fundamentally different instruments:
- ISO/IEC 42001 is a voluntary management-system standard. It describes how to build, run, and continually improve an AI Management System (AIMS) — governance, roles, risk assessment, controls, audits. You can be certified against it by an accredited body.
- The EU AI Act is a law (Regulation (EU) 2024/1689). It imposes binding obligations based on risk category, with real penalties. It applies if you provide or deploy AI systems that reach the EU market or affect people in the EU.
In short: ISO 42001 is *how you organize yourself*; the EU AI Act is *what you're legally required to do*.
Key differences at a glance
- Nature: standard (voluntary) vs. regulation (mandatory where in scope).
- Outcome: certification vs. legal compliance.
- Scope trigger: you choose to adopt it vs. it applies based on your role (provider/deployer) and risk category.
- Structure: management-system clauses + Annex A controls vs. risk tiers (prohibited, high-risk, limited/transparency, minimal) with specific duties.
How they complement each other
They're not competitors — they reinforce each other. A well-run ISO 42001 management system is one of the most efficient ways to *produce the evidence and controls the EU AI Act expects*: risk management, data governance, human oversight, record-keeping, and post-market monitoring. Adopt the management system once, and you're positioned to meet multiple obligations.
What to do now
- Determine your role and scope. Are you a provider or deployer? Do any use cases reach the EU or affect people there?
- Classify each AI use case (including the EU AI Act risk categories) and record the rationale.
- Stand up the management-system basics — inventory, risk assessment, human oversight, and record-keeping — regardless of which instrument you formally pursue.
- Keep the evidence. Both an ISO auditor and an EU AI Act inquiry will want documentation and logs.
One foundation, multiple frameworks
The efficient path is a single system of record that maps your work to both ISO/IEC 42001 and EU AI Act documentation categories — plus NIST AI RMF — so you don't rebuild governance per framework.
That's what AI Assurance Hub provides: one register, risk engine, and workflow, with live framework coverage. Explore the live demo or start free.
_This article is educational and not legal advice. Consult qualified counsel for obligations specific to your systems and jurisdiction._
Put this into practice.
Inventory, assess, approve, and evidence every AI use case in one place.