ISO/IEC 42001 and the EU AI Act: Why an International Standard Is Not Enough
Many organisations preparing for AI Act compliance are relying on ISO/IEC 42001 as the foundation of their compliance programmes. The critical question is whether ISO/IEC 42001 certification alone demonstrates compliance with the AI Act. The short answer is: not quite. Understanding why and what to do about it matters when preparing for the AI Act.
A QMS Is Not Optional
Article 17 of the AI Act requires providers of high-risk AI systems to establish, implement, and maintain a documented quality management system (QMS). This is not a matter of governance maturity or best practice. It is a legal precondition for placing a high-risk AI system on the EU market.
Together with Article 16, Article 17 of the AI Act places the QMS at the organisational core of AI Act compliance. Its required content is not abstract but explicitly defined. It includes:
- A regulatory compliance strategy,
- Design, development, quality control, and assurance procedures,
- Examination, test, and validation processes,
- Technical specifications,
- Data governance and management,
- Risk management under Article 9,
- Post-market monitoring,
- Incident reporting,
- Communication with supervisory authorities,
- Record-keeping and documentation,
- Resource management and accountability structures.
In other words, Article 17 of the AI Act is concerned with demonstrable compliance rather than the existence of governance documentation.
ISO/IEC 42001 as the Right Starting Point
ISO/IEC 42001 (Information technology – Artificial intelligence – Management system) is the first management system standard specifically designed for artificial intelligence. Its plan-do-check-act structure, risk and impact assessment requirements, and control objectives for AI policy, lifecycle management, data governance, and third-party oversight reflect the procedural backbone of Article 17 of the AI Act.
For organisations building AI governance structures, ISO/IEC 42001, therefore, provides a structured and internationally recognised governance framework that aligns with many operational requirements of Article 17 of the AI Act.
Alignment, however, does not equal legal equivalence.
Where ISO/IEC 42001 Falls Short
The gap is structural. ISO/IEC 42001 is organisation-oriented. Certification demonstrates that an organisation operates an AI management system. The AI Act, by contrast, ultimately assesses whether each high-risk AI system complies with the applicable legal requirements. To that end, it requires organisations to implement processes that ensure system-level compliance.
Additional limitations follow from this distinction:
- ISO/IEC 42001 does not fully cover all elements required under Article 17 of the AI Act.
- The standard allows organisations to exclude controls they deem not applicable. While Article 17 para. 2 of the AI Act provides that implementation shall be proportionate to the size of the provider, it does not allow the exclusion of mandatory requirements.
- Certification under ISO/IEC 42001 does not trigger the presumption of conformity under Article 40 of the AI Act.
This last point has significant legal consequences in practice. The presumption of conformity shifts the burden of proof in favour of the provider in supervisory proceedings. ISO/IEC 42001, as an international standard and not a harmonised standard within the meaning of the AI Act, does not provide this effect.
The European Layer: EN 18286
The European standard EN 18286 (Artificial Intelligence – Quality Management System for EU AI Act Regulatory Purposes) is designed to close this gap. Rather than replacing ISO/IEC 42001, it translates Article 17 of the AI Act into an auditable governance framework tailored to AI Act compliance. Annex D provides for a structured mapping between the two standards, allowing organisations with existing ISO/IEC 42001 certification to extend rather than rebuild their governance systems.
Following its formal approval on 10 July 2026, EN 18286 is expected to become a harmonised standard once its reference is published in the Official Journal of the European Union. Only then will it confer the presumption of conformity under Article 40 of the AI Act.
What This Means in Practice
If your organisation relies on ISO/IEC 42001, you should treat this certification as a foundation, not as evidence of AI Act compliance. Three steps are particularly relevant:
- Map each requirement under Article 17 and the substantive obligations under Chapter III, Section 2 of the AI Act to existing controls and documented evidence.
- Ensure that no AI Act requirement is excluded via the statement of applicability.
- Establish and maintain a technical documentation file demonstrating conformity of each high-risk AI system with the AI Act.
The gap between ISO/IEC 42001 and EN 18286 is manageable, but not without targeted effort. Waiting for formal harmonisation before starting this work creates unnecessary time pressure. The underlying principle is straightforward. Compliance under the AI Act is demonstrated through a continuously maintained, system-specific, and auditable governance process, not by certification alone.
That is what Article 17 of the AI Act requires.