ISO 42001 vs the AI Act: how they fit together

A management system meets a regulation — and why you operationalise both as a single AI governance suite.

The iComply Team
AI Governance

ISO 42001 vs the AI Act: Two of the most significant developments in AI governance are often confused: ISO 42001 and the EU AI Act. They are instruments of a different nature, and understanding the difference is key to implementing them effectively.

ISO 42001: a management system

ISO 42001 is the international standard for an Artificial Intelligence Management System (AIMS). Like ISO 27001 for security or ISO 37301 for compliance, it defines how governance is done: policies, objectives, roles, controls, audits, and continual improvement. It is voluntary and certifiable.

The AI Act: a regulation

The EU AI Act is law. It defines what you must comply with: risk classification, prohibited practices, obligations for high-risk and general-purpose AI, transparency, and conformity assessment. It is mandatory, with penalties.

How they relate

The relationship is complementary. The AI Act defines the obligations; ISO 42001 gives you the operational machinery to meet them in a repeatable way. Implement the management system and you will have the structure — risk processes, oversight, documentation — into which the Regulation’s requirements fit.

  • AI Act → the legal requirements and risk classification.
  • ISO 42001 → the governance processes that satisfy them.
  • Shared controls → a single set of controls evidences both.

Sell and run it as a single suite

The mistake organisations make is treating this as two projects — an “ISO 42001 module” and an “AI Act module”. In reality, they govern the same AI systems, the same risks, and the same evidence. Run them as a single AI Governance suite: one inventory, one risk model, one evidence library, two layers of requirements on top.

That’s how iComply structures AI governance — and why adding ISO 42001 certification on top of AI Act compliance costs a fraction of doing either one in isolation.

Here’s how iComply puts this into practice

A platform for every regulation, law and risk — focused on controls and powered by AI.

Read on

Bar chart showing salaries within a defined range, illustrating an analysis of the gender pay gap at iComply

Analysis of pay gaps, pay bands and auditable remuneration criteria — what to implement now.

Seven ascending layers representing the stages involved in building a unified governance programme with iComply

A step-by-step approach to scope, controls, evidence and ongoing assurance — designed to be scalable across domains.

One evidence document linked to three requirements from different frameworks, demonstrating evidence reuse in iComply

Stop duplicating documents. Map the supporting evidence once and let it fulfil all the requirements that refer to it.