Comparison

    EU AI Act or ISO 42001 — what do you actually need?

    One is law you cannot opt out of. The other is a certificate you can show a customer. They overlap in the evidence they demand — and they solve different problems. Here is the difference in one table.

    Comparison of the EU AI Act and ISO 42001
    AspectEU AI ActISO 42001
    NatureEU law — binding, with fines for non-complianceVoluntary international standard you can be certified against
    Applies toProviders and deployers of AI systems in the EU marketAny organisation that develops, provides or uses AI systems
    Core questionIs this specific AI system allowed, and under which obligations?Do you manage AI responsibly as an organisation, repeatably?
    Starting pointRisk classification per system (prohibited, high-risk, limited, minimal)Scope definition and gap analysis of your management system
    EvidenceTechnical documentation, risk management, logging, human oversightPolicies, roles, objectives, internal audit, management review
    Who checksMarket surveillance authorities, notified bodies for high-risk systemsAn accredited certification body
    ResultLawful operation — no certificate to showA certificate you can put in a tender or a customer questionnaire
    Typical timelineWeeks for classification, months for high-risk obligationsSix to nine months from gap analysis to certification audit

    What you need, by situation

    You sell AI into the EU

    Start with risk classification under the AI Act. It is mandatory, it is fast, and it determines everything else.

    A tender asks for certification

    ISO 42001 is the answer. Budget six to nine months and start with a gap analysis against what you already have.

    Both, eventually

    Classify first, then build the management system so AI Act evidence is produced continuously instead of assembled in a panic.

    Questions we get

    Does ISO 42001 certification make us EU AI Act compliant?

    No. The management system helps you produce and maintain the evidence the AI Act asks for, but compliance is judged per system against the law, not against the certificate.

    We are not high-risk. Do we still have obligations?

    Yes — transparency duties, AI literacy requirements and the prohibitions apply regardless. The risk classification tells you which ones.

    Which one should we do first?

    If the regulation applies to you, classify your systems first — it is a legal obligation and it takes weeks. Start ISO 42001 when a customer, tender or insurer asks for a certificate, or when you want the management system to keep AI Act evidence alive.

    We already have ISO 27001. Does that count?

    A large part of it does. ISO 42001 is structured to sit next to 27001, so the gap analysis usually shows you are further along than expected.