AI Act vs ISO 42001: what they share and how they differ

AI Act and ISO 42001 share 13 of 24 control themes and 14 checks. 69% of ISO 42001 requirements can be proven with checks AI Act already uses, 48% the other way round.

EURegulationPhasing in

AI Act

How to make an AI system compliant with the EU AI Act

33 requirementsNext Aug 2, 2027
INTLCertifiable standardVoluntary

ISO 42001

How to prepare for ISO/IEC 42001 certification

13 requirementsNext Dec 2026
13/24shared control themes
14shared checks
69%of ISO 42001 requirements covered by AI Act evidence
48%of AI Act requirements covered by ISO 42001 evidence

At a glance

AI Act ISO 42001
JurisdictionEuropean UnionInternational
KindRegulationCertifiable standard
StatusPhasing inVoluntary
BindingYesNo
Object analysedAI systemOrganisation
ScopeProviders, deployers, importers and distributors of AI systems; providers of GPAI models.Organisations providing or using AI systems.
Territorial reachExtraterritorial: applies when the system is placed on the EU market or its output is used in the EU.International.
PenaltiesUp to €35M or 7% of worldwide turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (incorrect information).None; certification lost or refused.
Qualification axesAI Act risk level, Organisation role, General-purpose modelSystem impact level (Cl. 6.1.4)
RolesProvider, Deployer, GPAI providerProvider, User, Producer
Requirements3313
Next milestoneAug 2, 2027, Annex I high risk (regulated products); GPAI placed on the market before Aug 2025Dec 2026, CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS)

Theme by theme

requirements per theme

What they share: one piece of evidence, two frameworks

14

CodeCheckRequirements AI ActRequirements ISO 42001
VER-001-F-01Documented and implemented AI training programme
VER-003-01Documented and up-to-date risk register
VER-004-01Documented data governance (collection process, bias, quality)
VER-004-02Input data relevant and representative in view of the intended purpose
VER-005-01Complete technical documentation compliant with Annex IV
VER-006-02Automatic logging operational and compliant
VER-007-01Instructions for use complete and compliant with Art. 13
VER-008-03Competent overseers assigned to the system
VER-013-F-01Documented non-conformity management procedure
VER-020-D-01FRIA carried out in accordance with Art. 27
VER-021-F-01Operational monitoring plan
VER-022-F-01Risk and incident response procedure
VER-026-F-01Contractual responsibilities documented between provider and third parties
VER-027-D-01Use compliant with the purpose intended by the provider verified

Differences: requirements specific to each framework

Requirements with no check serving the other framework: the extra work.

ISO 42001

4

ISO-4.3
Scope of the AIMS Cl. 4.3, 4.4
ISO-5.2
AI policy Cl. 5.2, A.2

Timelines

PastSet in the textPotentialTo verify
Apr 21, 2021AI Act · Commission proposal
Dec 18, 2023ISO 42001 · ISO/IEC 42001 published
Jul 12, 2024AI Act · Published in the Official Journal
Aug 1, 2024AI Act · Entry into force
Feb 2, 2025AI Act · Prohibited practices (Art. 5) and AI literacy (Art. 4)
May 2025ISO 42001 · ISO/IEC 42005 (impact assessment)
Jul 10, 2025AI Act · GPAI Code of Practice published
Jul 2025ISO 42001 · ISO/IEC 42006 (certification bodies)
Aug 2, 2025AI Act · GPAI obligations, governance, penalties, notified bodies
Nov 19, 2025AI Act · Digital Omnibus proposal: high-risk delay tied to standards
Aug 2, 2026AI Act · General application: Art. 50, sandboxes, Annex III high risk (unless Omnibus delay)
Dec 2026ISO 42001 · CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS)
Aug 2, 2027AI Act · Annex I high risk (regulated products); GPAI placed on the market before Aug 2025
Dec 2, 2027AI Act · Omnibus backstop for Annex III high risk
Aug 2, 2028AI Act · Omnibus backstop for Annex I high risk
Aug 2, 2030AI Act · High-risk systems of public authorities already in service (Art. 111)

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo