ISO 42001 and the EU AI Act: Complementary, Not Duplicative

In the last eighteen months, I’ve had some version of the same conversation with about thirty senior enterprise leaders. It begins with the leader saying that they are being asked

Picture of Dr. Yassin Miheisi

Dr. Yassin Miheisi

Published March 2026 · 7 min read

In the last eighteen months, I’ve had some version of the same conversation with about thirty senior enterprise leaders. It begins with the leader saying that they are being asked to comply with both ISO 42001 and the EU AI Act, that these seem to duplicate each other, and that they are trying to work out whether to prioritise one or run two parallel programmes. The leader is usually stressed, usually under time pressure, and usually has been told by someone — a consulting firm, a vendor, an internal compliance colleague — that this is a difficult choice with meaningful resource implications.

It isn’t. The choice is false. The two frameworks are related but distinct, they operate at different levels of the organisation, and any serious implementation of one produces most of the requirements of the other as a by-product. Organisations that treat them as competing demands end up duplicating effort; organisations that treat them as an integrated whole get both, for not much more than the cost of one.

The confusion is understandable. Both frameworks arrived in enterprise consciousness within roughly twelve months of each other — ISO 42001 was published in December 2023, the EU AI Act was agreed in May 2024 — and both use similar vocabulary: risk management, governance, controls, documentation, oversight. The consulting market, sensing demand, has produced offerings for each, priced each separately, and rarely troubled to explain how they relate. The result is a senior leadership audience that has been trained to see them as parallel programmes. They aren’t, and the cost of that misperception is real.

What each framework actually is

The first clarification is categorical. The EU AI Act is law. Specifically, it is a regulation of the European Union, binding on organisations that place AI systems on the EU market or use them in the EU. Breach of its obligations carries administrative fines — up to seven per cent of global turnover for the most serious violations, which is a number that concentrates the mind. The Act does not ask for your cooperation; it requires compliance, and its enforcement mechanism is member-state regulators with statutory powers.

ISO 42001 is not law. It is a voluntary international standard, specifically a management system standard, sitting in the same structural family as ISO 27001 (information security), ISO 9001 (quality), and ISO 14001 (environmental). Compliance is voluntary unless a specific contract, tender, or regulatory regime makes it contractually required. Certification against the standard is available from accredited bodies but is itself voluntary. Non-compliance does not carry a fine. It carries, at most, loss of certification — if you were certified — and whatever reputational or commercial consequence flows from that.

This is the first distinction, and it’s the easiest one to internalise. One of these frameworks is binding law; the other is a voluntary framework that has the weight you and your counterparties give it. That distinction matters for resource allocation, for escalation pathways, and for the register the work sits in on your enterprise risk register. If a leader is equating the EU AI Act with ISO 42001 in a board paper, they have not yet understood either.

Law and standard, system and organisation, specific and general. The two frameworks never cover the same territory, and treating them as alternatives misses the point of both.

They operate at different levels

The second distinction is the more consequential one. The EU AI Act operates at the level of individual AI systems. Its obligations attach to specific systems, classified by their use case against the Act’s risk categories (prohibited, high-risk, limited-risk, minimal-risk), and the obligations vary by category. A single organisation will have multiple AI systems, each classified separately, each with its own obligations, its own technical documentation, its own risk management arrangements, and its own registration in the EU database if high-risk.

ISO 42001 operates at the level of the organisation. Its obligations attach to the organisation’s management of AI as a whole — the policy, the roles and responsibilities, the risk assessment methodology, the internal audits, the continual improvement process, the management review. ISO 42001 does not tell you what to do about your credit-scoring model specifically; it tells you how the organisation that makes the credit-scoring model should be structured to govern AI properly.

This is the architectural difference. The Act is a framework for individual systems; ISO 42001 is a framework for the organisation that builds and runs those systems. They meet at the intersection — the organisation’s management system determines how individual system obligations are discharged — but they cover mostly different ground. An organisation can in principle be compliant with the EU AI Act on a system-by-system basis without any coherent management system, and it can in principle be ISO 42001 aligned without having any specific high-risk system to regulate. In practice, both of those positions are fragile and temporary, and the organisations that achieve them quickly find themselves in trouble.

Where they reinforce each other

Having made the distinctions, the more useful point is this: serious implementation of either framework produces most of what the other requires. This is not accidental. Both were drafted by committees aware of the other’s existence, and both were designed to work with rather than against existing governance practice.

Take a concrete example. The EU AI Act requires, for every high-risk system, a risk management system that is iterative, documented, and kept up to date. This is a system-level obligation. ISO 42001 requires the organisation to have a risk assessment methodology that is documented, applied consistently, and reviewed when the risk landscape changes. This is an organisation-level obligation. An organisation that satisfies the ISO 42001 requirement — a documented methodology, trained assessors, regular review — has the scaffolding it needs to produce the Act-compliant risk management systems for its individual high-risk systems. The individual systems still need their own implementations, but the methodology is shared. Two obligations, one underlying discipline.

The same is true across most of the overlap. Data governance, human oversight, post-market monitoring, incident response, documentation and record-keeping — these are all areas where the EU AI Act requires specific system-level controls and ISO 42001 requires the organisational capability to produce them reliably. An organisation with a mature management system produces the system-level compliance with relatively modest marginal effort. An organisation without one produces each system’s compliance by heroic effort, repeated every time a new system reaches production, and the repeated effort is where costs escalate and mistakes accumulate.

Any serious implementation of one framework produces most of what the other requires. The organisations that succeed build the management system first and discharge the system-specific obligations against it.

Why the confusion persists

If the relationship is as I’ve described it, why does the confusion persist? Three reasons, roughly in order of impact.

First, the market has an interest in selling them separately. A consulting firm that offers an ISO 42001 readiness assessment and a separate EU AI Act compliance programme can bill two engagements rather than one. Vendors offering tooling frame their products against whichever framework has better brand recognition at any given moment. This is not dishonesty; it is commercial incentive operating as commercial incentive usually does. But the leader reading the output of a market operating under those incentives should not be surprised to receive two separate proposals when a unified programme would serve them better.

Second, the internal ownership of the two frameworks often sits in different parts of the organisation. Legal and compliance tend to own the EU AI Act because it is law; risk and assurance tend to own ISO 42001 because it is a management system standard. These functions do not always coordinate well, and the duplication of effort between them is often a symptom of their separation rather than an inherent feature of the frameworks.

Third, the vocabulary is genuinely similar. Both frameworks talk about risk, governance, documentation, oversight, and accountability. Leaders who have not read either in depth can be forgiven for assuming that similar vocabulary implies similar content. It does not. The vocabulary is a product of their shared heritage in established governance traditions; the content is differentiated by the level at which each operates.

What this means in practice

For an enterprise leader trying to make a practical decision, the implication is straightforward. Do not design two programmes; design one, with two layers.

The organisational layer implements ISO 42001. It defines the AI policy, the risk methodology, the roles, the audits, the management review cadence, the continual improvement process. It is owned, ideally, by the AI-CoE Director or equivalent. It operates at the level of the organisation and is assessed periodically against the standard. If formal certification is useful for the organisation’s commercial position, the same layer supports certification; if not, the same layer supports internal assurance against the standard.

The system-specific layer implements the EU AI Act’s obligations for each individual AI system that falls within its scope. This layer is driven by the Model Development Lifecycle — the organisational process that every model passes through — and the EU AI Act’s obligations are discharged within that process, at defined stages, using templates and tools produced by the organisational layer. A high-risk system’s technical documentation, its risk management plan, its human oversight arrangements, its database registration: all of these are outputs of the lifecycle, informed by the organisational methodology.

Set up this way, the two frameworks stop being competing demands. They become layers of a single governance architecture, each covering the territory the other does not, each making the other easier to satisfy. The total cost is lower than running them separately. The quality of both is higher. The political cost of arguing between functions about which framework takes priority disappears, because there is no priority to argue about — they are doing different things.

A closing note on extraterritoriality

One practical matter worth naming. Organisations outside the EU frequently ask whether any of this applies to them. Two positions are common: “we’re not in the EU, so the EU AI Act doesn’t apply” and “we are a UK company, so only ISO 42001 is relevant to us”. Both are usually wrong.

The EU AI Act applies to providers and deployers of AI systems that are placed on the EU market or whose output is used in the EU, regardless of the organisation’s domicile. A UK insurance company that sells products to customers in Ireland is subject to the Act for systems affecting those customers. A US SaaS vendor with EU customers is subject to the Act for systems its EU customers use. The extraterritorial reach was designed deliberately, and it catches most organisations of meaningful size. ISO 42001 is globally available and there is no jurisdictional question; it is the same standard everywhere. The practical position, for most enterprises, is that both frameworks apply. The question is not whether to engage with them, but how to do so intelligently.

Which is to say: as a single programme, not as two.


A longer treatment of both frameworks appears in EIS-005: AI Governance with ISO 42001, and in Chapter 11 of EIS-001: AI Center of Excellence Guide, both published in the Enterprise Intelligence Series.

Picture of Dr. Yassin Miheisi

Dr. Yassin Miheisi

Founder of YM Consulting Group and the Enterprise Intelligence Institute. Advises enterprise organisations on the design and scaling of AI functions, with a focus on the operational discipline required to move AI from experimentation into durable, governed production. Author of the Enterprise Intelligence Series.

Picture of Dr. Yassin Miheisi

Dr. Yassin Miheisi

Founder of YM Consulting Group and the Enterprise Intelligence Institute. Advises enterprise organisations on the design and scaling of AI functions, with a focus on the operational discipline required to move AI from experimentation into durable, governed production. Author of the Enterprise Intelligence Series.

Keep Reading

Related Insights

Why Most AI Governance Frameworks Fail Before They Start

Why the Proof-of-Concept Trap is Killing Enterprise AI

The Federated Model Is Not a Compromise