Sphere wins 2026 Global Recognition Award
Sphere Partners
ISO 42001 vs the EU AI Act: What Overlaps and What Does Not

ISO 42001 vs the EU AI Act: What Overlaps and What Does Not

ISO 42001 and the EU AI Act are often mentioned together and are genuinely different things: one is a voluntary management-system standard, the other is law. Here's where they overlap, where they don't, and why one set of controls can serve both.

4 min read
In this article

Teams building AI governance keep hitting the same two names — ISO 42001 and the EU AI Act — and often treat them as interchangeable compliance work. They aren't. One is a voluntary standard for how you manage AI; the other is a law about what AI systems must do. Understanding the difference is what lets you satisfy both with one set of controls instead of two parallel projects.

Two different kinds of thing

ISO 42001 is a management-system standard: it describes how an organization should establish, run, and continually improve a system for governing AI — roles, processes, risk management, monitoring. You can be certified against it by an accredited body, voluntarily. The EU AI Act is legislation: it imposes obligations on AI systems based on their risk, and compliance is not optional for systems in scope. One is about your management process; the other is about your systems' behavior and your legal duties.

Where they overlap

Despite being different kinds of thing, they point at many of the same practices, because good AI governance looks similar whoever's asking:

  • Risk management — both expect you to identify and mitigate AI risks continuously.
  • Data governance — both care that the data your AI uses is appropriate and controlled.
  • Record-keeping and monitoring — both expect you to log operation and watch for problems over time.
  • Human oversight and accountability — both expect a human to be able to understand and intervene.

This overlap is the good news: the controls that satisfy one substantially serve the other.

Where they diverge

DimensionISO 42001EU AI Act
NatureVoluntary standardLaw
FocusHow you manage AIWhat AI systems must do
ProofCertification by a bodyConformity + obligations, enforced
ScopeYour whole AI management systemSystems in scope by risk tier

The divergence matters for planning: ISO 42001 is a framework you adopt to run AI well and can be certified against; the EU AI Act is a duty you must meet for in-scope systems whether or not you hold any certification.

One control set, two masters

Because the overlap is large, the efficient path is to operate one set of governed controls — risk management, access governance, record-keeping, security, human oversight — and map their evidence to both frameworks. The controls run once; the evidence answers both 'how do you manage AI' (ISO's question) and 'does this system meet its obligations' (the Act's question). Running two separate compliance programs for substantially the same practices is wasted effort.

The core idea

One is a standard for how you manage AI; the other is a law about what your AI must do. The practices they ask for largely coincide — so run the controls once and map the evidence to both, rather than standing up two programs over the same ground.

An honest word on certification

To be precise: mapping controls to these frameworks is not the same as holding a certification or a conformity determination. ISO 42001 certification comes from an accredited body assessing your management system; EU AI Act conformity is your responsibility to establish for in-scope systems. What a governed platform provides is the operating controls and the evidence that makes both far more achievable — not a badge it can confer on your behalf.

Frequently asked questions

It depends on your situation. If you operate AI systems in scope of the EU AI Act, the Act's obligations are legally required. ISO 42001 is voluntary but valuable as a management framework and increasingly expected by partners and procurement. Many organizations pursue the Act's obligations because they must and ISO 42001 because it's good practice — and one control set serves both.

No. They're different things — a management-system certification isn't a legal conformity determination, and vice versa. There's heavy overlap in the underlying practices, so doing one well makes the other easier, but neither substitutes for the other.

A platform can provide the shared operating controls and evidence that both draw on — risk management, record-keeping, access governance, security, oversight — and map that evidence to each framework. It can't grant a certification or make a legal determination; those come from assessors and your compliance team.

Start with the controls the two frameworks share, because that work is never wasted. Get risk management, record-keeping, access governance, security, and human oversight operating and recording evidence, then map that evidence to whichever framework you're pursuing.

Satisfy both with one control set. See how governed controls and their evidence map to both ISO 42001 practices and EU AI Act obligations — run once, evidenced for both. Book a walkthrough.

We'd love to hear from you!

Please provide your contact details, and our team will get back to you promptly.