The Foundational Distinction
ISO 42001 is a management system standard — it tells you how to govern AI. The EU AI Act is binding European law — it tells you what specific obligations apply to specific AI systems. These are different regulatory instruments with different legal status, different conformity assessment mechanisms, and different consequences for non-compliance. Understanding this distinction is the prerequisite for building a governance programme that satisfies both.
An ISO 42001 certificate demonstrates that your organisation has established a systematic approach to managing AI risks and opportunities — that you have an AI policy, conduct AI risk assessments, maintain AI documentation, monitor performance, and review your AI governance at management level. It says nothing specific about whether any particular AI system in your portfolio is legally compliant with EU AI Act obligations.
An EU AI Act conformity assessment demonstrates that a specific AI system — one that falls within the Act's scope and risk classification — meets the prescriptive technical requirements that the Act mandates for that system type. It says nothing about whether your organisation has a systematic governance approach to AI management broadly.
The Six-Step Integrated Programme
AI Governance specialists. Integrated programme proposal within 48 hours.