EU AI Act or ISO 42001 — what do you actually need?
One is law you cannot opt out of. The other is a certificate you can show a customer. They overlap in the evidence they demand — and they solve different problems. Here is the difference in one table.
| Aspect | EU AI Act | ISO 42001 |
|---|---|---|
| Nature | EU law — binding, with fines for non-compliance | Voluntary international standard you can be certified against |
| Applies to | Providers and deployers of AI systems in the EU market | Any organisation that develops, provides or uses AI systems |
| Core question | Is this specific AI system allowed, and under which obligations? | Do you manage AI responsibly as an organisation, repeatably? |
| Starting point | Risk classification per system (prohibited, high-risk, limited, minimal) | Scope definition and gap analysis of your management system |
| Evidence | Technical documentation, risk management, logging, human oversight | Policies, roles, objectives, internal audit, management review |
| Who checks | Market surveillance authorities, notified bodies for high-risk systems | An accredited certification body |
| Result | Lawful operation — no certificate to show | A certificate you can put in a tender or a customer questionnaire |
| Typical timeline | Weeks for classification, months for high-risk obligations | Six to nine months from gap analysis to certification audit |
What you need, by situation
You sell AI into the EU
Start with risk classification under the AI Act. It is mandatory, it is fast, and it determines everything else.
A tender asks for certification
ISO 42001 is the answer. Budget six to nine months and start with a gap analysis against what you already have.
Both, eventually
Classify first, then build the management system so AI Act evidence is produced continuously instead of assembled in a panic.
Questions we get
Does ISO 42001 certification make us EU AI Act compliant?
No. The management system helps you produce and maintain the evidence the AI Act asks for, but compliance is judged per system against the law, not against the certificate.
We are not high-risk. Do we still have obligations?
Yes — transparency duties, AI literacy requirements and the prohibitions apply regardless. The risk classification tells you which ones.
Which one should we do first?
If the regulation applies to you, classify your systems first — it is a legal obligation and it takes weeks. Start ISO 42001 when a customer, tender or insurer asks for a certificate, or when you want the management system to keep AI Act evidence alive.
We already have ISO 27001. Does that count?
A large part of it does. ISO 42001 is structured to sit next to 27001, so the gap analysis usually shows you are further along than expected.