ISO 42001 vs the AI Act: Two of the most significant developments in AI governance are often confused: ISO 42001 and the EU AI Act. They are instruments of a different nature, and understanding the difference is key to implementing them effectively.
ISO 42001: a management system
ISO 42001 is the international standard for an Artificial Intelligence Management System (AIMS). Like ISO 27001 for security or ISO 37301 for compliance, it defines how governance is done: policies, objectives, roles, controls, audits, and continual improvement. It is voluntary and certifiable.
The AI Act: a regulation
The EU AI Act is law. It defines what you must comply with: risk classification, prohibited practices, obligations for high-risk and general-purpose AI, transparency, and conformity assessment. It is mandatory, with penalties.
How they relate
The relationship is complementary. The AI Act defines the obligations; ISO 42001 gives you the operational machinery to meet them in a repeatable way. Implement the management system and you will have the structure — risk processes, oversight, documentation — into which the Regulation’s requirements fit.
- AI Act → the legal requirements and risk classification.
- ISO 42001 → the governance processes that satisfy them.
- Shared controls → a single set of controls evidences both.
Sell and run it as a single suite
The mistake organisations make is treating this as two projects — an “ISO 42001 module” and an “AI Act module”. In reality, they govern the same AI systems, the same risks, and the same evidence. Run them as a single AI Governance suite: one inventory, one risk model, one evidence library, two layers of requirements on top.
That’s how iComply structures AI governance — and why adding ISO 42001 certification on top of AI Act compliance costs a fraction of doing either one in isolation.