Skip content

What ISO 42001 does, and does not get you under the EU AI Act

a regulatory focus on europe

Shirish Bapat Technical Product Manager (Information Security) Learn more

It is easy to assume that an ISO 42001 certificate means an organisation is covered under the European Union Artificial Intelligence Act (EU AI Act). The two are closely related, the language overlaps and the assumption is a common one.

ISO 42001 certification does not, on its own, make an organisation compliant with the EU AI Act. What it does is establish and independently verify, the governance foundation that any AI Act compliance case is built on. That is worth a great deal. Certification is the clearest evidence available that an organisation is governing AI deliberately rather than intending to, and it is the part of the work that takes longest to put in place. Organisations that hold it are not starting from nothing. They are starting from the hardest part already done.

This article sets out what certification covers under the Act, what it does not and where the certificate carries genuine evidentiary weight.

 

ISO 42001 in brief

ISO 42001, published in December 2023, is the first internationally certifiable standard for an artificial intelligence management system (AIMS). It specifies requirements for establishing, implementing, maintaining and continually improving organisation-wide governance of AI, and is supported by an Annex A control set covering areas including policies for AI, internal organisation, resources, impact assessment, the AI system life cycle, data, information for interested parties, use of AI systems and third-party relationships. It was adopted as a European Standard, EN ISO 42001:2026, in March 2026, with no change to its technical requirements.

 

Why certification alone is not compliance

The EU AI Act rewards one specific thing: harmonised European standards. These are standards the European Commission commissions to support the legislation, which are then cited in the Official Journal of the European Union. Meet one and you gain a presumption of conformity. In practice that reverses the burden of proof. A regulator challenging you has to show the standard falls short, rather than you having to show it does not.

ISO 42001 was never commissioned for that purpose. It carries no Annex ZA, the annex that ties a harmonised standard to the legal text, and it confers no presumption of conformity.

The standard written for that job is EN 18286, published in July 2026 as the first European standard supporting the Act. It has not yet been cited in the Official Journal, so for the moment no standard confers the presumption on anyone.

Three further limits are worth knowing.

The Act regulates systems, not organisations. Documentation, logging, oversight and accuracy have to be demonstrated for each high-risk system you place on the market. A management system supports that work. It does not replace it.

Prohibitions remain prohibitions. A certified system that carefully documents a prohibited use case is still a prohibited use case.

Conformity assessment is a separate legal step that certification does not satisfy.

 

Coverage reference: obligation by obligation

The table below sets out, for each principal obligation, what ISO 42001 contributes and what remains outstanding. All EU AI Act obligations are drawn from the consolidated text of Regulation (EU) 2024/1689; the ISO 42001 contributions from the standard itself.

 

EU AI Act obligation

What ISO 42001 contributes

What certification does not cover

Article 4: AI literacy

Competence, training and awareness requirements applied across the organisation

Role-specific literacy calibrated to the provider or deployer duties the organisation actually holds

Article 5: prohibited practices

Impact assessment and life cycle controls that help surface prohibited uses early

Nothing. The prohibition is absolute and unaffected by certification status

Article 9: risk management system

Close structural alignment: risk assessment methodology, treatment, review and continual improvement

Application to each individual high-risk system across its life cycle, as a product-level obligation

Article 10: data and data governance

Annex A controls on data for AI systems, including provenance, quality and preparation

Dataset-level examination for the specific system, including bias examination and representativeness testing

Article 11: technical documentation

Documented information discipline, version control and retention practice

The prescribed Annex IV content, produced per system and kept current

Article 12: record-keeping and logging

Governance around retention and traceability

Automatic logging designed into the system, meeting the specified retention requirements

Article 13: transparency and instructions for use

Annex A controls on information for interested parties

Instructions for use meeting the prescribed content, issued with each system

Article 14: human oversight

Annex A controls on the use of AI systems and defined accountability

Oversight measures designed into the individual system and demonstrated as effective

Article 15: accuracy, robustness and cybersecurity

Governance requiring these matters to be addressed

Technical performance testing, metrics and declared accuracy levels for each system

Article 17: quality management system

Substantial organisational overlap, and the two documents are formally mapped against one another in EN 18286

Equivalence. Article 17 is answered by EN 18286, not by ISO 42001

Articles 26 and 27: deployer obligations and fundamental rights impact assessment

Impact assessment methodology and operational controls

The fundamental rights impact assessment as a distinct statutory instrument with prescribed content

Articles 43 and 47 to 49: conformity assessment, declaration, CE marking and registration

Audit readiness and documentary discipline

The procedures themselves, which are separate legal steps involving, in some cases, a notified body

Article 72: post-market monitoring

Monitoring, measurement, internal audit and improvement cycles

A post-market monitoring plan specific to each high-risk system

Article 73: serious incident reporting

Incident management and corrective action processes

Reporting to market surveillance authorities within the statutory timelines

 

The pattern is consistent. Certification builds the machinery: the processes, accountabilities, competence and evidence trails that the Act assumes an organisation already has. The Act then asks for system-specific output from that machinery. Organisations that treat certification as the endpoint discover the gap late; those that treat it as the foundation run the system-level work in parallel and arrive with evidence rather than intentions.

 

Where certification does carry weight

None of this diminishes what a certificate demonstrates.

An accredited ISO 42001 certificate is independently verified evidence that an organisation’s AI governance actually works. Risks assessed on a defined method. Accountability allocated. Competence maintained. Suppliers managed. The whole system audited and improved.

That is not proof of conformity with any particular article, and it should not be sold as one. It is something more practical. It removes the question of whether the underlying governance exists at all, which is the question that otherwise dominates regulatory engagement, procurement, customer due diligence and board assurance.

Accreditation is what makes that evidence hold. LRQA are a UKAS accredited certification body for ISO 42001, which means our own competence and impartiality have been independently assessed.

 

The timetable has moved, the direction has not

The Digital Omnibus on AI, proposed by the European Commission in November 2025, entered into force on 27 July 2026. It postponed high-risk obligations for standalone Annex III systems, covering domains including biometrics, employment and recruitment, credit scoring, education and critical infrastructure, to 2 December 2027, and for high-risk AI embedded in Annex I regulated products to 2 August 2028.

Several obligations were not postponed. Article 50 transparency requirements applied from August 2026, with a short extension to December 2026 for the watermarking requirement affecting systems already on the market. The prohibitions and the AI literacy duty continue to apply, and the Omnibus added a further prohibition to Article 5 covering AI-generated non-consensual intimate imagery and child sexual abuse material.

Penalties remain substantial: up to thirty-five million euros or seven per cent of total worldwide annual turnover for prohibited practices, and up to fifteen million euros or three per cent for other infringements.

The extension provides a better-resourced window in which to build documentation and governance. It is not a reason to defer the work.

 

For organisations already certified to ISO 27001

ISO 42001 is written to the harmonised structure set out in Annex SL of the ISO/IEC Directives, the common ten-clause framework and shared terminology that ISO management system standards follow. ISO 27001 uses the same structure, which is what makes the two straightforward to operate as a single integrated system rather than as parallel ones.

Organisations with an established information security management system therefore already hold much of the required infrastructure: documented processes, management review cycles, internal audit programmes and competence records. In our experience, extending an existing system into AIMS scope is faster and less resource-intensive than building from a blank page, and integrated audits reduce ongoing certification overhead.

The system-level work in the table above remains additional and needs its own timeline. It does not need to start from zero.

 

AI governance you can prove, not just promise

The organisations that will be in the strongest position in December 2027 are not those holding the most certificates. They are those that can show, at both organisational and system level, that their governance works and that someone independent has checked. ISO 42001, delivered through a UKAS-accredited certification body, is where that evidence starts.

 

Learn more about our ISO 42001 services

 

Latest news, insights and upcoming events