ISO 42001 certification does not establish EU AI Act compliance. The standard can support AI governance, but whether to certify is a separate business decision.
A company can find ISO 42001 useful without needing certification immediately. It can also hold a certificate and still have legal work to do under the EU AI Act. Separating those questions helps avoid unnecessary expenditure and misplaced confidence.
The starting point is the AI activity your organisation undertakes. Establish what legal obligations apply, then decide how you will manage that activity and whether external certification would serve a clear purpose.
What ISO 42001 covers
ISO/IEC 42001:2023 is a management-system standard for organisations developing, providing or using AI. Its subject is how the organisation manages that activity within a defined scope, including responsibility, risk assessment and ongoing improvement. ISO's overview of the standard
An organisation can use the standard to guide its work and decide separately whether to seek certification. An independent certification body assesses conformity. ISO publishes standards but does not certify organisations. ISO's explanation of certification
If your company is considering certification primarily to support sales or customer assurance, read whether ISO 42001 certification is worth it for your business. The answer depends on the assurance you need, the scope and your ability to maintain the system.
What the EU AI Act covers
The EU AI Act is legislation. Obligations depend on the organisation's role, the AI system or model concerned and the relevant use. A provider bringing a high-risk system to market and an employer using a third-party tool do not have an identical set of responsibilities.
The Act includes prohibited practices, requirements for high-risk systems, transparency duties and provisions for general-purpose AI models. Its obligations apply on different dates. The European Commission's current AI Act overview and timetable should be checked alongside the legal text when assessing a particular deployment.
It would be misleading to say that the Act leaves management systems entirely unspecified. Article 17 requires providers of high-risk AI systems to have a quality management system. That provision covers areas such as regulatory compliance, risk management, documentation and post-market monitoring. The requirements are proportionate to the provider's size, while maintaining the necessary level of protection. AI Act, Article 17
Nor is a fundamental-rights impact assessment a universal requirement for every AI user. Article 27 specifies the deployers and high-risk uses to which that obligation applies. The legal assessment must establish whether the organisation falls within those conditions.
Where the work can overlap
A functioning AI management system can help keep responsibilities and evidence organised. Some records may be relevant to both the management system and a legal assessment: for example, who owns a system, how changes are reviewed and how incidents are handled.
That does not support a blanket percentage claim about compliance. The overlap depends on your role, systems, scope and the requirements being assessed. It must be checked in detail. A policy that mentions both frameworks does not establish that either has been satisfied.
For example, an AI inventory can support discovery of systems that need further assessment. It does not determine their legal classification by itself. A review record can show that a decision was considered; it still needs enough substance to support the particular obligation at issue.
The AI Register ISO 42001 guide explains how a register fits into the wider management system. It is one supporting record, not evidence that the whole organisation is ready for certification.
What certification does not settle
A certificate is scoped assurance about a management system. It is not a general legal clearance for every AI product or every use of that product.
You still need to establish which AI Act provisions apply and whether the relevant obligations have been met. Where the law requires conformity assessment or particular documentation, those requirements need their own assessment. A customer's intended use may also differ from the activity covered by your certificate.
Conversely, the AI Act does not impose a general requirement on every organisation to obtain ISO 42001 certification. Applicable legal obligations remain mandatory whether or not a company chooses to certify.
How to decide what to do first
If a legal obligation already applies, address it. Certification timing should not delay that work. If a customer asks for a certificate, clarify the required scope and deadline with them before commissioning preparation.
Where the business case is less clear, assess current governance against the risks of the AI activity and the needs of customers. You may decide to prepare gradually, use an existing management system as a starting point, or defer certification while making necessary improvements.
NSAI describes a staged certification process that assesses readiness and then implementation. Maintaining certification involves further review and surveillance. Planning should therefore allow for the continuing work as well as the initial audit. NSAI's ISO 42001 certification service
How Acuity can help
Ger Perdisatt holds the ISO/IEC 42001 Lead Auditor qualification. That is his personal qualification. It is distinct from Acuity holding organisational certification or acting as an accredited certification body.
Our AI governance work can help you assess the practical gaps and the case for certification. We can explain the preparation involved and challenge unsupported readiness claims. We cannot promise a successful external audit or eliminate the possibility of findings. The independent certification body makes its own assessment and decision.
For the practical evidence question, see what should be in place before a certification audit.