
ISO 42001 vs the EU AI Act: What Overlaps and What Does Not
ISO 42001 and the EU AI Act are often mentioned together and are genuinely different things: one is a voluntary management-system standard, the other is law. Here's where they overlap, where they don't, and why one set of controls can serve both.
- Katya SavenkovaDirector of Operations
In this article
Teams building AI governance keep hitting the same two names — ISO 42001 and the EU AI Act — and often treat them as interchangeable compliance work. They aren't. One is a voluntary standard for how you manage AI; the other is a law about what AI systems must do. Understanding the difference is what lets you satisfy both with one set of controls instead of two parallel projects.
Two different kinds of thing
ISO 42001 is a management-system standard: it describes how an organization should establish, run, and continually improve a system for governing AI — roles, processes, risk management, monitoring. You can be certified against it by an accredited body, voluntarily. The EU AI Act is legislation: it imposes obligations on AI systems based on their risk, and compliance is not optional for systems in scope. One is about your management process; the other is about your systems' behavior and your legal duties.
Where they overlap
Despite being different kinds of thing, they point at many of the same practices, because good AI governance looks similar whoever's asking:
- Risk management — both expect you to identify and mitigate AI risks continuously.
- Data governance — both care that the data your AI uses is appropriate and controlled.
- Record-keeping and monitoring — both expect you to log operation and watch for problems over time.
- Human oversight and accountability — both expect a human to be able to understand and intervene.
This overlap is the good news: the controls that satisfy one substantially serve the other.
Where they diverge
| Dimension | ISO 42001 | EU AI Act |
|---|---|---|
| Nature | Voluntary standard | Law |
| Focus | How you manage AI | What AI systems must do |
| Proof | Certification by a body | Conformity + obligations, enforced |
| Scope | Your whole AI management system | Systems in scope by risk tier |
The divergence matters for planning: ISO 42001 is a framework you adopt to run AI well and can be certified against; the EU AI Act is a duty you must meet for in-scope systems whether or not you hold any certification.
One control set, two masters
Because the overlap is large, the efficient path is to operate one set of governed controls — risk management, access governance, record-keeping, security, human oversight — and map their evidence to both frameworks. The controls run once; the evidence answers both 'how do you manage AI' (ISO's question) and 'does this system meet its obligations' (the Act's question). Running two separate compliance programs for substantially the same practices is wasted effort.
One is a standard for how you manage AI; the other is a law about what your AI must do. The practices they ask for largely coincide — so run the controls once and map the evidence to both, rather than standing up two programs over the same ground.
An honest word on certification
To be precise: mapping controls to these frameworks is not the same as holding a certification or a conformity determination. ISO 42001 certification comes from an accredited body assessing your management system; EU AI Act conformity is your responsibility to establish for in-scope systems. What a governed platform provides is the operating controls and the evidence that makes both far more achievable — not a badge it can confer on your behalf.
Frequently asked questions
Satisfy both with one control set. See how governed controls and their evidence map to both ISO 42001 practices and EU AI Act obligations — run once, evidenced for both. Book a walkthrough.
Part of