Does ISO 42001 satisfy the EU AI Act?
Short answer: no, and the reason is more useful than the answer. CEN-CENELEC looked at ISO/IEC 42001 for exactly this job, decided it did not fit, and wrote a different standard. Knowing why tells you precisely which of your existing controls carry over and which work you have not started.
The legal position, stated exactly
Article 40 of the AI Act creates a presumption of conformity: a high-risk AI system that conforms to harmonised standards whose references have been published in the Official Journal is presumed to conform with the Chapter III Section 2 requirements those standards cover. In practice the presumption shifts the burden: a market surveillance authority challenging you has to show the standard was inadequate, rather than you having to prove your approach was sufficient from first principles.
ISO/IEC 42001 does not carry that presumption
No EN ISO/IEC text has been cited in the Official Journal as a harmonised standard for the AI Act. Any vendor or consultant telling you that 42001 certification makes you AI Act compliant is either confused or hoping you are.
The reason is not bureaucratic. When JTC 21: the joint CEN-CENELEC technical committee responsible for AI Act standards, assessed ISO/IEC 42001 against the Article 17 quality management system requirement, it concluded that 42001's goals and definitions were not aligned with what Article 17 asks for. Article 17 is a product QMS obligation sitting inside a conformity assessment regime. ISO/IEC 42001 is an organisational management system in the ISO Annex SL family, closer in shape to ISO 9001 or ISO/IEC 27001. They answer different questions.
JTC 21 therefore developed a home-grown European standard, prEN 18286, Artificial intelligence — Quality management system for EU AI Act regulatory purposes, drafted specifically against Article 17 under the Commission's standardisation request. It has passed Enquiry and reached the Approval (Formal Vote) stage. Once finalised and cited in the Official Journal, applying it will confer the Article 40 presumption for the requirements it covers.
Status label
Verified fact: ISO/IEC 42001 is not currently a harmonised standard; prEN 18286 is the JTC 21 deliverable for Article 17. Expert analysis: the reasons we give for the structural mismatch. Unsettled: the final publication date of prEN 18286 and the date its reference appears in the Official Journal. We update this page when that changes.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
What actually transfers
This is the part worth your time. prEN 18286 includes an annex mapping its requirements onto ISO/IEC 42001 Annex A controls, precisely so that organisations already certified can reuse what they have rather than rebuild. If you hold 42001, you are not starting from zero — you are starting from roughly the organisational layer, with the system-level regulatory layer still to build.
| AI Act obligation | Nearest ISO/IEC 42001 anchor | Transfers? | What you still have to do |
|---|---|---|---|
| Art. 9 Risk management system | Clause 6.1, 8.2; Annex A AI risk assessment & treatment | Mostly | Re-scope from organisational risk to per-system, lifecycle-long, with residual-risk judgements documented per system. |
| Art. 10 Data & data governance | Annex A data-for-AI controls | Partly | Add the specific Art. 10 tests: relevance, representativeness, error examination, bias examination, and the Art. 10(5) special-category legal basis. |
| Art. 11 / Annex IV Technical documentation | Documented information (Clause 7.5) | Structure only | Annex IV is a prescribed contents list. 42001 tells you to control documents; it does not tell you what must be in them. |
| Art. 12 Logging | Annex A operational controls | Partly | Automatic recording over lifetime, with traceability appropriate to purpose. Usually an engineering change, not a policy change. |
| Art. 13 Transparency to deployers | Annex A information-for-interested-parties controls | Partly | Produce Art. 13 instructions for use containing the prescribed elements. |
| Art. 14 Human oversight | Annex A human oversight controls | Mostly | Design-level oversight measures built into the system, plus deployer-side competence under Art. 26(2). |
| Art. 15 Accuracy, robustness, cybersecurity | Annex A performance & security controls | Partly | Declared accuracy metrics in the instructions for use; resilience to feedback loops and adversarial manipulation. |
| Art. 17 Quality management system | The whole management system | Structure only | This is the specific gap prEN 18286 exists to fill. Expect to map, not to substitute. |
| Art. 27 FRIA | Annex A impact assessment controls | Structure only | A deployer obligation with prescribed contents, for public bodies and certain essential-service providers. Template → |
| Art. 43 Conformity assessment | — | No | Internal control or notified body route, then EU declaration of conformity and CE marking. 42001 certification is not a substitute at any point. |
| Art. 49 EU database registration | — | No | Registration in the EU database before placing on the market. |
| Art. 50 Transparency to people | — | No | Applies now, independently of high-risk status and independently of any management system. |
| Arts. 72–73 Post-market monitoring, incident reporting | Clause 9, 10; Annex A incident controls | Partly | A post-market monitoring plan per system, and serious-incident reporting to authorities on statutory deadlines. |
How to read this table. "Transfers" is our assessment of how much of the evidence you already hold under a certified 42001 AIMS can be re-used, not a legal opinion and not a conformity determination. Expert analysis, not verified fact. Confirm scope with your certification body and counsel.
So should you get certified?
Usually yes, but for reasons that have little to do with the AI Act deadline, which is now December 2027 for Annex III systems.
The real driver is procurement, not regulation
The pressure most organisations actually feel is a customer security questionnaire asking how AI is governed, an enterprise vendor review, or a supplier assurance programme. That pressure exists today, does not move when Brussels moves a date, and is answered by a certificate and a Statement of Applicability far more efficiently than by a policy document.
The layered pattern
What is emerging in practice is a stack rather than a single-standard answer: ISO/IEC 42001 for the organisational management system and certification; prEN 18286, once published, for the per-system Article 17 QMS; ISO/IEC 23894 as risk-management guidance; and sector standards such as ISO 13485 where they already apply. Choosing one and hoping it covers the rest is the common failure.
Where we would push back on ourselves
If you have no EU exposure, no enterprise customers asking, and no Annex III system, certification may be premature. A documented AI inventory, an AI policy and an Article 4 literacy record cost far less and cover the obligations that are actually live. We would rather tell you that than sell you a toolkit you do not need yet.
Build the 42001 layer, then map upward
Our sister site publishes the ISO/IEC 42001 documentation set — Statement of Applicability, Annex A control mapping, clause 4–10 playbooks, gap-analysis workbook, internal audit programme. Editable Word and Excel, instant download, unlimited internal use.
If you are already certified
Start with the four rows marked "Mostly" in the table above. They are where your existing evidence does the most work. Then treat Annex IV, Art. 43 and Art. 49 as new build.
Questions
Is ISO/IEC 42001 a harmonised standard under the AI Act?
No. As at August 2026, no EN ISO/IEC text has been cited in the Official Journal as a harmonised standard for the AI Act. Presumption of conformity under Article 40 attaches only to standards whose references have been published there, and only for the requirements those standards cover.
Will ISO/IEC 42001 eventually become harmonised?
Possible but not planned for Article 17 — JTC 21 wrote prEN 18286 for that requirement instead. JTC 21 has adopted some ISO/IEC texts into the European catalogue as guidance, and may adopt others as EN ISO/IEC standards. We do not predict this; we report it when it happens.
Does 42001 certification help with a conformity assessment?
Indirectly. It gives an assessor a functioning management system, documented risk treatment and an audit trail, which makes the assessment easier. It does not replace the assessment, the EU declaration of conformity, or CE marking.
What if we only have Article 50 obligations?
Then 42001 is not urgent for compliance reasons. Article 50 is a disclosure obligation on your product surface, live since 2 August 2026. Fix the disclosure first. Article 50 explained →
Found an error?
Standards move. If prEN 18286 has been published or cited in the Official Journal since our last review date, tell us and we will update this page and note what changed. Report it →