How the AI Act and ISO 42001 Work Together

What each framework covers, where they overlap and how to use ISO 42001 as a lever for AI Act compliance: a practical analysis for compliance, legal and product teams working with artificial intelligence systems.
The AI Act and ISO 42001 represent two complementary responses to the same challenge: how to develop and deploy artificial intelligence systems responsibly, traceably and sustainably. One is a mandatory regulation for the European market; the other is an international management standard that provides the internal system to comply with it.
Understanding how they work together prevents two common mistakes: treating the AI Act as a purely legal problem that only concerns the legal team, and treating ISO 42001 as a technical certification disconnected from regulatory obligations. In practice, both frameworks share territory and reinforce each other.
Urgent context: deadlines that can no longer wait
Regulation (EU) 2024/1689, the AI Act, entered into force on 1 August 2024 with a phased application: prohibitions on unacceptable practices from 2 February 2025; obligations for general-purpose AI (GPAI) models and AI literacy from 2 August 2025; full obligations for high-risk systems under Annex III from 2 August 2026; and high-risk systems embedded in regulated products from 2 August 2027.
The most relevant date for most organisations is 2 August 2026, when full obligations for high-risk AI systems under Annex III enter into force: critical infrastructure, employment, essential services, education, law enforcement and others. In Spain, the supervisory authority, the Agencia Española de Supervisión de la Inteligencia Artificial (AESIA), based in A Coruña, began supervising prohibited practices in February 2025 and has had full sanctioning powers since August 2025.
What each framework covers: the starting difference
The AI Act is a regulation with direct effect across all Member States. It classifies AI systems by risk level, unacceptable, high, limited and minimal, and imposes specific obligations on providers and deployers. For high-risk AI systems, obligations include conformity assessments, technical documentation, human oversight, risk management and quality records.
ISO/IEC 42001:2023 is an international standard specifying requirements for an AI Management System (AIMS). It does not classify AI systems by risk or impose legal obligations, it provides the organisational framework, policies, roles, processes, impact assessment, risk management and continuous improvement, for an organisation to systematically manage the lifecycle of its AI systems.
The key distinction: the AI Act says what must be complied with; ISO 42001 provides a system for how to manage it internally in a sustainable way.
The penalty framework
Fines for non-compliance with the AI Act scale according to the severity of the infringement: prohibited practices can reach up to €35 million or 7% of global annual turnover; non-compliance with obligations for high-risk systems or other Regulation obligations up to €15 million or 3%; and incorrect information provided to supervisory bodies up to €7.5 million or 1%. SMEs and startups have a somewhat more favourable regime in the determination of penalties.
Where they overlap: five bridges between both frameworks
1. AI risk management
The AI Act requires providers of high-risk systems to have a risk management system specific to the AI system. ISO 42001 includes a process of risk and opportunity assessment for the AIMS that covers exactly that territory, applied at organisational level rather than per system.
2. Technical documentation and traceability
The AI Act requires specific technical documentation for high-risk systems (Annex IV). ISO 42001's informative annexes reference traceability controls, data management and AI system lifecycle documentation that align directly with those requirements.
3. Human oversight
The AI Act requires high-risk systems to be designed to enable effective human oversight. ISO 42001 includes the principle of human accountability and controls aimed at ensuring automated decisions can be reviewed and corrected.
4. Transparency and user information
The AI Act imposes transparency obligations. ISO 42001 covers, in its interested parties and communication dimension, the mechanisms for maintaining that transparency systematically.
5. Continuous improvement and management review
The AI Act anticipates that AI systems evolve. ISO 42001 explicitly includes management review and continuous improvement mechanisms for the AIMS, creating the organisational cycle the AI Act presupposes but does not detail internally.
How to use ISO 42001 as a lever for AI Act compliance
ISO 42001 is not a substitute for AI Act compliance, but it is a highly efficient lever for achieving it. Certification does not automatically grant presumption of conformity with the AI Act. However, it provides evidence that a structured AI management system exists, an internal framework for organising required technical documentation, credibility with customers and regulators, and a basis for conformity assessments where the system applies to high-risk categories.
If your organisation already works with ISO/IEC 27001 for information security, the move to ISO 42001 is natural: they share the High Level Structure, plan-do-check-act logic and many organisational controls.
AI Act risk classification vs ISO 42001 risk management
A common point of confusion: risk in the AI Act and risk in ISO 42001 are not exactly the same thing. The AI Act's system risk category classification (unacceptable, high, limited, minimal) determines which legal obligations apply. ISO 42001's AIMS risk assessment identifies risks to organisational objectives arising from AI activities, including risks to the rights and interests of people affected, and produces a treatment plan with controls and owners.
The correct integration: use the AI Act classification as a starting point to prioritise which systems need most attention in the ISO 42001 risk assessment, and use the AIMS as the internal system to manage and document the controls the AI Act requires for each category.
The role of impact assessment
The AI Act requires deployers of high-risk AI systems to carry out a fundamental rights impact assessment when those systems may affect a significant number of people. ISO 42001 includes informative controls on AI system impact assessment covering potential impacts on individuals, groups and society, including bias, discrimination and unintended effects. When implemented, this control provides the methodology and records the AI Act requires for its specific assessments.
Who needs both frameworks
Companies developing high-risk AI systems for the European market are obligated by the AI Act and have the strongest incentives to certify to ISO 42001. Companies using high-risk AI systems from third parties in professional contexts, deployers under the AI Act, get a framework for managing AI supplier assessment, human oversight and use documentation. Companies developing limited or minimal risk AI have no heavy obligations but can use ISO 42001 to differentiate themselves. Organisations already working with ISO 27001, NIS2 or DORA can integrate ISO 42001 naturally into the existing compliance ecosystem.
Practical steps to align both frameworks
Inventory AI systems; classify by AI Act risk; design the ISO 42001 AIMS (leveraging any existing ISO 27001 structure); map ISO 42001 controls to AI Act requirements; implement and evidence; and review periodically and after substantial changes.
What CB Partners offers for AI Act and ISO 42001 projects
We support compliance, legal and product teams in designing and implementing AI management systems that articulate the requirements of the AI Act with the structure of ISO 42001, integrating ISO 27001, GDPR and other regulatory frameworks when the organisation operates in a multi-compliance environment. We do not just design documentation, we build systems that the team can operate and that hold up in conversation with auditors and regulators.
Frequently Asked Questions
Does ISO 42001 certification mean automatic AI Act compliance?
Not automatically. ISO 42001 is not currently a harmonised standard under the AI Act that generates presumption of conformity. However, implementing and certifying ISO 42001 provides the management system and documentary evidence the AI Act presupposes in responsible providers.
Which organisations are obligated by the AI Act?
The AI Act affects providers placing AI systems on the EU market, deployers using high-risk AI systems in professional contexts, and importers and distributors. The most demanding obligations apply to high-risk systems defined in Annex III.
Can ISO 42001 and ISO 27001 be implemented together?
Yes, and it is the most efficient approach when the organisation already has ISO 27001. Both standards share the ISO High Level Structure, allowing policies, roles, and management review cycles to be integrated into a single management system.
What is a high-risk AI system under the AI Act?
Annex III lists high-risk categories: critical infrastructure, education and vocational training, employment and worker management, access to essential services, law enforcement, border management and migration, and administration of justice, among others.
When do AI Act obligations come into force?
The AI Act entered into force in August 2024 with phased application. Prohibitions from February 2025, GPAI obligations from August 2025, and full high-risk system obligations from August 2026.
What penalties does the AI Act provide for non-compliance?
Fines can reach €35 million or 7% of global turnover for violations of the prohibitions; €15 million or 3% for non-compliance with other obligations; and €7.5 million or 1% for supplying incorrect information. SMEs and startups benefit from a somewhat more favourable regime.
Ready to talk about your compliance roadmap?
Tell us which frameworks apply to you and we'll scope an engagement within days.
