AI Act and ISO 42001: When Compliance Becomes an Operating Model

Published: Updated: 9 min read
AI Act and ISO 42001: When Compliance Becomes an Operating Model

AI Act and ISO 42001: When Compliance Is Not a Project, but an Operating Model

What is the difference between the AI Act and ISO 42001? Is an ISO certification enough for AI compliance? How can an organization build an operating model that not only meets legal obligations but is also sustainable in the long run?

Over the past year, AI compliance has gradually moved out of the exclusive remit of IT departments. More and more organizations are recognizing that the use of AI is not merely a technology issue, but also a matter of governance, risk management, and corporate oversight.

In recent years, roughly the same process has unfolded around artificial intelligence as previously took place in the fields of information security and data protection. First the technology appeared. Then the risks emerged. Finally, regulation arrived.

Many organizations are already aware that the EU AI Act will sooner or later affect them.More and more people are also hearing that the ISO/IEC 42001 standard exists, the first international AI management system standard. Yet the question is often the same:

If we implement ISO 42001, does that also make us compliant with the AI Act?

The short answer: no.

The longer answer, however, is where things become interesting.

Two worlds meet: legislation and a management system

The AI Act and ISO 42001 address the same problem, but from completely different perspectives.

The AI Act is a piece of legislation. It specifies what obligations organizations developing, distributing, or using AI systems must meet. It defines prohibited AI applications, the requirements for high-risk systems, transparency rules, and the way compliance must be demonstrated.

ISO 42001, by contrast, is not legislation but a management system standard. It does not specify what the law prohibits or allows, but how an organization should build an operational framework in which the use of AI is controlled, documented, and continuously monitored.

Put simply:

the AI Act answers the question of “what,”

ISO 42001 provides a framework for the question of “how.”

The ISO/IEC 42001 is not a harmonized standard under the AI Act, so on its own it does not create a presumption of conformity.

The value of the standard does not lie in “replacing” the requirements of the AI Act, but in creating a governance and control environment that significantly supports meeting them.

In other words, ISO 42001 does not replace AI Act compliance; it provides a structured framework for achieving and demonstrating it.

Why is ISO 42001 not enough on its own?

Many organizations fall into the same trap of thinking as they previously did with ISO 9001 or ISO 27001.

They view the standard as a certificate that automatically resolves all compliance questions.

In the world of AI, however, the situation is more complex.

ISO 42001 operates at the organizational level. Among other things, it requires the establishment of an AI policy, the definition of responsibilities, risk management, impact assessments, monitoring, and continual improvement.

The AI Act, on the other hand, examines the compliance of specific AI systems. Particularly for high-risk systems, it requires demonstrable risk assessments, validations, documentation, monitoring mechanisms, and human oversight.

ISO 42001, therefore, does not prove that a given AI system meets the requirements of the AI Act. It proves that the organization has the processes, responsibilities, and controls in place that enable compliance to be consistently established and maintained.

It is much like a regulatory inspection: it is not enough to state that the organization operates responsibly. It must be proven that it has the documented processes and control mechanisms that support this claim.

ISO 42001 creates exactly this kind of demonstrable operational framework.

AI Compliance Is Ultimately About Governance

AI compliance extends far beyond technology. It requires organizations to establish a governance framework that integrates risk management, incident management, documented information, clearly defined responsibilities, internal controls, and ongoing oversight across the entire AI lifecycle.

AI systems today are no longer purely IT systems; their operation has an impact on:

customers,

employees,

business decisions,

fundamental rights,

reputation,

data protection,

supplier relationships.

AI governance therefore cannot be solely the responsibility of the IT department; in successful organizations, AI compliance must create a common language across all business areas, such as:

legal,

compliance,

information security,

quality management,

data protection,

and the business areas.

ISO 42001 supports exactly this approach, putting the impact assessment of AI systems, the management of stakeholder expectations, and leadership responsibility at its center.

How can compliance be implemented in practice?

For most organizations, the biggest challenge is not the regulation itself, but where to start.

Based on experience, a five-step methodology works most effectively.

1. Developing an AI Inventory

Surprisingly many companies do not know exactly where they use AI.

ChatGPT licenses, Copilot usage, HR tools, marketing automation, customer service chatbots, or predictive analytics often appear across different organizational units.

The first step is always a complete mapping of AI systems.

2. Risk classification

Not every AI system falls into the same category.

Each AI system should be assessed to determine whether:

the system is a high-risk system,

it uses a GPAI model,

it affects the rights of natural persons,

it makes automated decisions,

any AI Act category applies to it.

This is when it becomes clear which systems require a detailed AI Act compliance program.

General Purpose AI (GPAI) models deserve special attention, as they can serve as the foundation for many different business applications. These include, for example, large language models and other generative AI solutions.

The AI Act establishes a separate set of requirements for these models, so organizations should identify and assess not only their AI systems but also the underlying foundation models they use.

In practice, this means it is not enough for an organization to record whether it uses, for example, a chatbot or an AI assistant. It also needs to know which GPAI model the given solution is built on, and whether that model carries any specific compliance or risk management obligations.

3. Building an AI governance framework

This is where the real value of ISO 42001 emerges.

The governance framework should include:

the AI policy,

the responsibility matrix,

the AI risk management process,

incident management,

the monitoring system,

the documentation structure,

AI literacy and competence development programs.

4. Compliance at the AI system level

This is where the AI Act takes centre stage.

This is where the following happens:

developing technical documentation,

risk assessment,

preparing impact assessments,

validation,

model monitoring,

checking supplier compliance,

documenting human oversight.

5. Competence and AI literacy

This is where many AI compliance initiatives ultimately succeed or fail.

An organization can have excellent policies and documents, but they are of little use if employees do not understand:

the possibilities and limitations of AI,

what an AI risk means,

how a generative model works,

when human oversight is needed,

how an AI incident can be handled.

ISO 42001 places special emphasis on competence and awareness, which aligns with the AI literacy expectations of the AI Act.

Ultimately, the success of AI governance systems is determined not by policies, but by people.

An organization is able to use artificial intelligence responsibly only if its employees understand the basic principles of how AI works, its possibilities and limitations, recognize the related risks, and know when human intervention or additional control is needed.

It is increasingly common for users to automatically accept the answers, recommendations, or analyses provided by AI without reviewing their correctness, soundness, or potential biases. Generative AI systems, however, are capable of making mistakes, drawing inaccurate conclusions, or even producing information that seems convincing but is untrue.

AI should enhance—not replace—human expertise and professional judgement. On the contrary: the more advanced the tools we use, the more important critical thinking, professional control, and the conscious interpretation of results become.

AI literacy is therefore not merely a training issue. It is the foundation of an organizational culture in which AI supports decisions but does not replace sound judgment.

In the long run, the difference between organizations will not be who uses artificial intelligence, but who can apply it responsibly, consciously, and under appropriate control.

Why is it worth starting now?

Most organizations still treat compliance as a future project.

Yet the AI Act's phased entry into force is already underway, and an increasing number of requirements are becoming applicable. At the same time, the market is also changing.

More and more customers, partners, and tender requirements are asking:

whether an AI governance system is in place,

whether AI use is documented,

whether a risk assessment has been carried out,

whether the organization has an AI governance framework.

AI compliance is therefore no longer merely a legal issue, but explicitly a matter of competitiveness.

Can Organizations Do Without ISO/IEC 42001?

In theory, yes.

In practice, less and less so.

The AI Act does not mandate ISO 42001 certification. The law does not say that every organization must implement a standard. It says that the organization must be able to demonstrate control over its AI systems, risk management, clarity of responsibilities, monitoring, incident management, and continuous review.

These are exactly the areas for which ISO 42001 provides a detailed and auditable methodology.

That is why organizations seriously preparing for AI Act compliance will, sooner or later, arrive at the same questions that ISO 42001 already addresses at a systemic level:

Who is responsible for the AI systems?
How is the risk assessment carried out?
What documentation is required?
How does monitoring work?
How can incidents be handled?
How can compliance be demonstrated?

In other words, it is not the ISO 42001 certificate that becomes inevitable, but the mindset and methodology on which the standard is built.

And this is where the real competitive advantage emerges.

While many organizations are only now beginning to map their AI use, companies that have already built a functioning AI governance system start with a significant advantage. Not only will compliance audits be easier for them, but they will also be able to demonstrate responsible AI use more credibly to customers, partners, and suppliers.

Within a few years, the question will likely no longer be whether an organization uses artificial intelligence, but whether it can prove its responsible and controlled operation.

And those who started building their AI governance system in time will be the ones with a head start.

Conclusion

The AI Act and ISO 42001 are not competitors. One regulates, the other builds a system.

The AI Act prescribes what an organization must prove. ISO 42001 helps ensure there is something to prove.

Companies that strive only to meet the legal minimum can expect to find themselves in a constant state of firefighting. Those that begin to think in terms of AI governance, however, build not only their compliance but also business trust in the use of AI.

And in the long run, this is likely to be the real competitive advantage.

Try the AI Act risk classifier

Find out in 5 minutes which risk category your AI system falls into — free, 100% private, with a detailed PDF result.

Start the assessment
H
Pallos Gabriella
Harvey's · AI & compliance team
Experts in AI Act compliance, testing and security audits. Reach out any time with questions.
LinkedIn

Harvey's newsletter

Stay up to date with our AI Act content

One practical monthly summary on EU AI Act compliance — no spam, unsubscribe any time.

← Back to the blog