ISO 27001 · ISO 42001 · GDPR · PCI DSS · Loi 25

ISO 42001 and the EU AI Act: Where the Standard Meets the Regulation

ISO 42001 and the EU AI Act: Where the Standard Meets the Regulation

The EU AI Act is regulation — it tells you what you must do. ISO 42001 is a management system — it tells you how to run the organization that does it. An SMB subject to the Act gets a head start on conformity with an ISO 42001 system already in place, but the two are not the same document and one does not certify the other away.

The EU AI Act (Regulation (EU) 2024/1689) takes a risk-based approach to AI: the obligations an organization faces depend on the tier its AI system falls into. ISO/IEC 42001:2023 takes a risk-based approach to governing AI inside an organization. The overlap is real and useful — much of what 42001 asks you to do maps onto what the Act requires — but the Act is law with teeth and 42001 is a voluntary standard. This article maps the overlap for an SMB, names where 42001 is not enough, and tells you what to do per tier.

**Grounding note:** the EU AI Act is not in this site’s canon library; the Act details below are the well-established structural facts (risk tiers, high-risk requirements, generative-AI transparency), not a clause-by-clause legal analysis. For binding obligations, consult the official Regulation text and a lawyer.

The EU AI Act’s risk tiers

The Act sorts AI systems into four tiers, with obligations rising sharply by tier:

  • **Unacceptable risk** — prohibited (e.g. social scoring by public authorities, manipulative subliminal techniques). An SMB is unlikely to build these, but should confirm a vendor system does not cross the line.
  • **High risk** — permitted, but subject to a full set of requirements before and during deployment (listed below). Examples include AI used in employment (recruitment, promotion), essential-services access, biometric identification, and infrastructure. This is where an SMB’s exposure concentrates.
  • **Limited risk** — permitted, with **transparency obligations**: the user must know they are interacting with AI. Generative-AI content (deepfakes, synthetic media) and chatbots sit here for most SMB use cases.
  • **Minimal risk** — permitted, no specific obligations (e.g. spam filters, inventory forecasting). The vast majority of SMB AI use cases land here.

The first task is to classify each of your AI systems into a tier. That classification is the output your ISO 42001 AI impact assessment already produces — purpose, decisions informed, stakeholders affected, impact if it fails — which is why the two frameworks pair so well.

Where ISO 42001 maps onto the high-risk requirements

For high-risk systems, the Act requires a set of concrete things from the provider (and, in a narrower form, the deployer). Most map onto an existing 42001 control or process:

EU AI Act high-risk requirementISO 42001:2023 anchor
Risk management system for the AIClause 6.1 (AI risk assessment) + the impact assessment (6.1.4 / 8.4)
Data governance — training and test data qualityAnnex A data-quality control objectives; the impact assessment’s data-quality concern
Technical documentationClause 7.5 (documented information) + the SoA
Record-keeping / loggingClause 8 (operation) + integration with ISO 27001 A.8.15 logging
Transparency and user informationAnnex A transparency objectives; AI policy (5.2)
Human oversightAnnex A control objectives; the impact assessment’s human-in-the-loop control
Accuracy, robustness, cybersecurityIntegration with the ISO 27001 ISMS (A.8.x); lifecycle quality controls
Quality management systemClause 4–10 management system structure
Conformity assessment and registration<strong>Not covered by 42001</strong> — this is Act-specific, handled via the EU process

The mapping is the value. An SMB that has run the 42001 impact assessment, built the SoA, and integrated with its 27001 ISMS has produced most of the evidence a high-risk conformity assessment asks for. The gap is the conformity assessment itself — the Act’s registration and third-party assessment step — which 42001 does not touch.

What 42001 does not give you

Three things the standard cannot deliver, and an SMB subject to the Act must source elsewhere:

  • **Legal conformity.** 42001 certification is not a presumption of conformity with the Act. The European Commission may publish harmonized standards that carry a presumption of conformity; until then, 42001 is supporting evidence, not a substitute.
  • **Tier classification.** 42001’s impact assessment gives you the inputs, but the legal classification of a system as high-risk is a reading of the Act’s annexes, not a management-system output. Get that classification reviewed by someone who reads the Act.
  • **Conformity assessment and CE marking.** For high-risk systems, the Act requires a conformity assessment (self-assessment for most, third-party for some) and EU registration. That is a regulatory procedure, outside the scope of any management standard.

What to do per tier

Minimal risk — no Act obligation. Run the system under your 42001 management system anyway; the impact assessment is cheap insurance and keeps you ready if a use case drifts into a higher tier.

Limited risk — meet the transparency obligation: disclose AI to the user (chatbot greeting, AI-generated-content label). Record the disclosure method in your impact assessment. 42001’s transparency control objectives cover this directly.

High risk — this is the work. Run the full impact assessment, build the technical documentation from your 42001 documented information, ensure logging and human oversight are in place, and engage a conformity assessment. Use the joint 27001 + 42001 integrated system so the cybersecurity and logging requirements inherit your existing ISMS controls. Budget for the conformity assessment as a separate regulatory cost, not a standard cost.

Unacceptable risk — do not deploy. If a vendor system raises the question, get a legal read before signing.

How this fits the series

This is the cross-pillar piece for the ISO 42001 series, sitting beside the Annex A explainer and the AI impact assessment template. The classification work it describes is the regulatory use of the assessment those articles build. If you serve EU customers or operate in the EU, pair this with your GDPR program — the GDPR pillar covers the data-protection side that the AI Act complements.

What to do next

List your AI systems and classify each into one of the four tiers using the impact assessment you already have. For anything in limited risk, add the transparency disclosure this month. For anything potentially high risk, scope the conformity-assessment gap before you invest further — that is the one cost 42001 cannot absorb, and knowing it early changes the deployment decision.

Operating in the EU or serving EU customers? Book a 30-min **AI governance gap assessment** — we classify your AI use cases against the Act’s tiers, map the gaps to your ISO 42001 system, and flag which systems need a conformity assessment. Bilingual EN/FR, no obligation.

/iso-42001-assessment/

Get Your Free Security Readiness Assessment

Map your controls, identify compliance gaps, and secure your systems before the audit.

About the author

Alaa Damou

Governance, Risk, and Cybersecurity leader enabling enterprise resilience and SaaS scale through strategic security architecture. I design and lead integrated governance frameworks that align regulatory compliance, risk oversight, and business growth objectives. Certified ISO 27001 Lead Implementer with direct exposure to senior leadership and governance bodies across SaaS, cloud, and regulated environments.

View LinkedIn profile →

Related articles

Search

Stay Secure

Get weekly security insights and actionable guidance straight to your inbox.