It is easy to assume that an ISO 42001 certificate means an organisation is covered under the European Union Artificial Intelligence Act (EU AI Act). The two are closely related, the language overlaps and the assumption is a common one.
ISO 42001 certification does not, on its own, make an organisation compliant with the EU AI Act. What it does is establish and independently verify, the governance foundation that any AI Act compliance case is built on. That is worth a great deal. Certification is the clearest evidence available that an organisation is governing AI deliberately rather than intending to, and it is the part of the work that takes longest to put in place. Organisations that hold it are not starting from nothing. They are starting from the hardest part already done.
This article sets out what certification covers under the Act, what it does not and where the certificate carries genuine evidentiary weight.
ISO 42001 in brief
ISO 42001, published in December 2023, is the first internationally certifiable standard for an artificial intelligence management system (AIMS). It specifies requirements for establishing, implementing, maintaining and continually improving organisation-wide governance of AI, and is supported by an Annex A control set covering areas including policies for AI, internal organisation, resources, impact assessment, the AI system life cycle, data, information for interested parties, use of AI systems and third-party relationships. It was adopted as a European Standard, EN ISO 42001:2026, in March 2026, with no change to its technical requirements.
Why certification alone is not compliance
The EU AI Act rewards one specific thing: harmonised European standards. These are standards the European Commission commissions to support the legislation, which are then cited in the Official Journal of the European Union. Meet one and you gain a presumption of conformity. In practice that reverses the burden of proof. A regulator challenging you has to show the standard falls short, rather than you having to show it does not.
ISO 42001 was never commissioned for that purpose. It carries no Annex ZA, the annex that ties a harmonised standard to the legal text, and it confers no presumption of conformity.
The standard written for that job is EN 18286, published in July 2026 as the first European standard supporting the Act. It has not yet been cited in the Official Journal, so for the moment no standard confers the presumption on anyone.
Three further limits are worth knowing.
The Act regulates systems, not organisations. Documentation, logging, oversight and accuracy have to be demonstrated for each high-risk system you place on the market. A management system supports that work. It does not replace it.
Prohibitions remain prohibitions. A certified system that carefully documents a prohibited use case is still a prohibited use case.
Conformity assessment is a separate legal step that certification does not satisfy.
Coverage reference: obligation by obligation
The table below sets out, for each principal obligation, what ISO 42001 contributes and what remains outstanding. All EU AI Act obligations are drawn from the consolidated text of Regulation (EU) 2024/1689; the ISO 42001 contributions from the standard itself.
|
EU AI Act obligation |
What ISO 42001 contributes |
What certification does not cover |
|
Article 4: AI literacy |
Competence, training and awareness requirements applied across the organisation |
Role-specific literacy calibrated to the provider or deployer duties the organisation actually holds |
|
Article 5: prohibited practices |
Impact assessment and life cycle controls that help surface prohibited uses early |
Nothing. The prohibition is absolute and unaffected by certification status |
|
Article 9: risk management system |
Close structural alignment: risk assessment methodology, treatment, review and continual improvement |
Application to each individual high-risk system across its life cycle, as a product-level obligation |
|
Article 10: data and data governance |
Annex A controls on data for AI systems, including provenance, quality and preparation |
Dataset-level examination for the specific system, including bias examination and representativeness testing |
|
Article 11: technical documentation |
Documented information discipline, version control and retention practice |
The prescribed Annex IV content, produced per system and kept current |
|
Article 12: record-keeping and logging |
Governance around retention and traceability |
Automatic logging designed into the system, meeting the specified retention requirements |
|
Article 13: transparency and instructions for use |
Annex A controls on information for interested parties |
Instructions for use meeting the prescribed content, issued with each system |
|
Article 14: human oversight |
Annex A controls on the use of AI systems and defined accountability |
Oversight measures designed into the individual system and demonstrated as effective |
|
Article 15: accuracy, robustness and cybersecurity |
Governance requiring these matters to be addressed |
Technical performance testing, metrics and declared accuracy levels for each system |
|
Article 17: quality management system |
Substantial organisational overlap, and the two documents are formally mapped against one another in EN 18286 |
Equivalence. Article 17 is answered by EN 18286, not by ISO 42001 |
|
Articles 26 and 27: deployer obligations and fundamental rights impact assessment |
Impact assessment methodology and operational controls |
The fundamental rights impact assessment as a distinct statutory instrument with prescribed content |
|
Articles 43 and 47 to 49: conformity assessment, declaration, CE marking and registration |
Audit readiness and documentary discipline |
The procedures themselves, which are separate legal steps involving, in some cases, a notified body |
|
Article 72: post-market monitoring |
Monitoring, measurement, internal audit and improvement cycles |
A post-market monitoring plan specific to each high-risk system |
|
Article 73: serious incident reporting |
Incident management and corrective action processes |
Reporting to market surveillance authorities within the statutory timelines |
The pattern is consistent. Certification builds the machinery: the processes, accountabilities, competence and evidence trails that the Act assumes an organisation already has. The Act then asks for system-specific output from that machinery. Organisations that treat certification as the endpoint discover the gap late; those that treat it as the foundation run the system-level work in parallel and arrive with evidence rather than intentions.
Where certification does carry weight
None of this diminishes what a certificate demonstrates.
An accredited ISO 42001 certificate is independently verified evidence that an organisation’s AI governance actually works. Risks assessed on a defined method. Accountability allocated. Competence maintained. Suppliers managed. The whole system audited and improved.
That is not proof of conformity with any particular article, and it should not be sold as one. It is something more practical. It removes the question of whether the underlying governance exists at all, which is the question that otherwise dominates regulatory engagement, procurement, customer due diligence and board assurance.
Accreditation is what makes that evidence hold. LRQA are a UKAS accredited certification body for ISO 42001, which means our own competence and impartiality have been independently assessed.
The timetable has moved, the direction has not
The Digital Omnibus on AI, proposed by the European Commission in November 2025, entered into force on 27 July 2026. It postponed high-risk obligations for standalone Annex III systems, covering domains including biometrics, employment and recruitment, credit scoring, education and critical infrastructure, to 2 December 2027, and for high-risk AI embedded in Annex I regulated products to 2 August 2028.
Several obligations were not postponed. Article 50 transparency requirements applied from August 2026, with a short extension to December 2026 for the watermarking requirement affecting systems already on the market. The prohibitions and the AI literacy duty continue to apply, and the Omnibus added a further prohibition to Article 5 covering AI-generated non-consensual intimate imagery and child sexual abuse material.
Penalties remain substantial: up to thirty-five million euros or seven per cent of total worldwide annual turnover for prohibited practices, and up to fifteen million euros or three per cent for other infringements.
The extension provides a better-resourced window in which to build documentation and governance. It is not a reason to defer the work.
For organisations already certified to ISO 27001
ISO 42001 is written to the harmonised structure set out in Annex SL of the ISO/IEC Directives, the common ten-clause framework and shared terminology that ISO management system standards follow. ISO 27001 uses the same structure, which is what makes the two straightforward to operate as a single integrated system rather than as parallel ones.
Organisations with an established information security management system therefore already hold much of the required infrastructure: documented processes, management review cycles, internal audit programmes and competence records. In our experience, extending an existing system into AIMS scope is faster and less resource-intensive than building from a blank page, and integrated audits reduce ongoing certification overhead.
The system-level work in the table above remains additional and needs its own timeline. It does not need to start from zero.
AI governance you can prove, not just promise
The organisations that will be in the strongest position in December 2027 are not those holding the most certificates. They are those that can show, at both organisational and system level, that their governance works and that someone independent has checked. ISO 42001, delivered through a UKAS-accredited certification body, is where that evidence starts.
Learn more about our ISO 42001 services
