AI Act vs ISO 42001: what they share and how they differ
AI Act and ISO 42001 share 13 of 24 control themes and 14 checks. 69% of ISO 42001 requirements can be proven with checks AI Act already uses, 48% the other way round.
Phasing in
AI Act
How to make an AI system compliant with the EU AI Act
33 requirementsNext Aug 2, 2027
Voluntary
ISO 42001
How to prepare for ISO/IEC 42001 certification
13 requirementsNext Dec 2026
13/24shared control themes
14shared checks
69%of ISO 42001 requirements covered by AI Act evidence
48%of AI Act requirements covered by ISO 42001 evidence
At a glance
| AI Act | ISO 42001 | |
|---|---|---|
| Jurisdiction | European Union | International |
| Kind | Regulation | Certifiable standard |
| Status | Phasing in | Voluntary |
| Binding | Yes | No |
| Object analysed | AI system | Organisation |
| Scope | Providers, deployers, importers and distributors of AI systems; providers of GPAI models. | Organisations providing or using AI systems. |
| Territorial reach | Extraterritorial: applies when the system is placed on the EU market or its output is used in the EU. | International. |
| Penalties | Up to €35M or 7% of worldwide turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (incorrect information). | None; certification lost or refused. |
| Qualification axes | AI Act risk level, Organisation role, General-purpose model | System impact level (Cl. 6.1.4) |
| Roles | Provider, Deployer, GPAI provider | Provider, User, Producer |
| Requirements | 33 | 13 |
| Next milestone | Aug 2, 2027, Annex I high risk (regulated products); GPAI placed on the market before Aug 2025 | Dec 2026, CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS) |
Theme by theme
requirements per theme
AI ActISO 42001
Governance
Assessment
Build
People & use
Lifecycle & third parties
What they share: one piece of evidence, two frameworks
14
| Code | Check | Requirements AI Act | Requirements ISO 42001 |
|---|---|---|---|
| VER-001-F-01 | Documented and implemented AI training programme | ||
| VER-003-01 | Documented and up-to-date risk register | ||
| VER-004-01 | Documented data governance (collection process, bias, quality) | ||
| VER-004-02 | Input data relevant and representative in view of the intended purpose | ||
| VER-005-01 | Complete technical documentation compliant with Annex IV | ||
| VER-006-02 | Automatic logging operational and compliant | ||
| VER-007-01 | Instructions for use complete and compliant with Art. 13 | ||
| VER-008-03 | Competent overseers assigned to the system | ||
| VER-013-F-01 | Documented non-conformity management procedure | ||
| VER-020-D-01 | FRIA carried out in accordance with Art. 27 | ||
| VER-021-F-01 | Operational monitoring plan | ||
| VER-022-F-01 | Risk and incident response procedure | ||
| VER-026-F-01 | Contractual responsibilities documented between provider and third parties | ||
| VER-027-D-01 | Use compliant with the purpose intended by the provider verified |
Differences: requirements specific to each framework
Requirements with no check serving the other framework: the extra work.
AI Act
17
EX-002
Prohibited practices Art. 5
EX-009
EX-010
QMS Art. 17
EX-011
10-year retention Art. 18
EX-015
EU declaration of conformity Art. 47
EX-016
CE marking Art. 48
EX-017
EU database registration Art. 49
EX-018
Transparency for all systems Art. 50
EX-019
DPIA Art. 26§9
EX-023
Accessibility Art. 16(l)
EX-024
Conformity assessment Art. 43
EX-025
EX-029
Information to affected persons Art. 26§11
EX-030
Information to workers' representatives Art. 26§7
EX-031
GPAI obligations Art. 53
EX-032
EX-033
ISO 42001
4
ISO-4.3
Scope of the AIMS Cl. 4.3, 4.4
ISO-5.2
AI policy Cl. 5.2, A.2
ISO-5.3
Roles, responsibilities, reporting of concerns Cl. 5.3, A.3
ISO-9
Internal audit and management review Cl. 9.2, 9.3
Timelines
PastSet in the textPotentialTo verify
Apr 21, 2021AI Act · Commission proposal
Dec 18, 2023ISO 42001 · ISO/IEC 42001 published
Jul 12, 2024AI Act · Published in the Official Journal
Aug 1, 2024AI Act · Entry into force
Feb 2, 2025AI Act · Prohibited practices (Art. 5) and AI literacy (Art. 4)
May 2025ISO 42001 · ISO/IEC 42005 (impact assessment)
Jul 10, 2025AI Act · GPAI Code of Practice published
Jul 2025ISO 42001 · ISO/IEC 42006 (certification bodies)
Aug 2, 2025AI Act · GPAI obligations, governance, penalties, notified bodies
Nov 19, 2025AI Act · Digital Omnibus proposal: high-risk delay tied to standards
Aug 2, 2026AI Act · General application: Art. 50, sandboxes, Annex III high risk (unless Omnibus delay)
Dec 2026ISO 42001 · CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS)
Aug 2, 2027AI Act · Annex I high risk (regulated products); GPAI placed on the market before Aug 2025
Dec 2, 2027AI Act · Omnibus backstop for Annex III high risk
Aug 2, 2028AI Act · Omnibus backstop for Annex I high risk
Aug 2, 2030AI Act · High-risk systems of public authorities already in service (Art. 111)
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.