Many companies already using AI in real processes ask the same question: "where do we start with governance, so the legal obligations don't catch us unprepared?" The short answer: with an AI management system. ISO/IEC 42001 is the international standard defining such a system, and the EU AI Act obligations for high-risk systems rest, to a large extent, on exactly the components the standard requires. This article explains what the standard is, how it maps to the AI Act and — just as important — what it does not solve.

What ISO/IEC 42001 is

ISO/IEC 42001:2023 is the first international standard for an AI management system (AIMS). It does not certify a model or a product, but the way the organisation governs AI: policies, roles, risk and impact assessment, data and lifecycle management, documentation and continual improvement.

The standard uses the harmonised structure shared by modern management standards — the same one used by ISO 27001 (information security) and ISO 9001 (quality): context of the organisation (clause 4), leadership (5), planning (6), support (7), operation (8), performance evaluation (9) and improvement (10). For organisations already certified to 27001, that means the foundation — policies, internal audit, risk treatment — already exists and can be extended rather than rebuilt.

Why it matters now: the EU AI Act obligations

The EU AI Act (Regulation 2024/1689) is law, not a voluntary standard. For high-risk systems, Articles 9–17 impose exactly the kind of organisational discipline ISO 42001 structures:

  • risk management across the whole lifecycle (Art. 9);
  • data governance — quality, relevance, bias (Art. 10);
  • technical documentation and record-keeping (Art. 11–12);
  • transparency towards users (Art. 13);
  • human oversight (Art. 14);
  • a quality management system (Art. 17).

On deadlines: the obligations for Annex III high-risk systems were set for 2 August 2026. In May 2026 a provisional agreement was reached to postpone them to December 2027; until formal adoption, however, the original date remains in force. The practical reading: the preparation window has widened, but governance is not built in the last quarter — assembling documentation, defining roles and instilling data discipline takes months, not weeks.

To be honest about it: ISO 42001 certification does not equal AI Act compliance. Conformity assessment, registration in the EU database and the rules for general-purpose models are distinct legal obligations, outside any voluntary standard. The standard builds the governance foundation those obligations can rest on — that much and nothing more.

Annex A: the 38 controls, by category

The practical core of the standard is Annex A — a set of AI-specific controls organised under nine objectives. The organisation selects and justifies the applicable controls based on its risks, through a statement of applicability, just like in ISO 27001:

CategoryWhat it covers
A.2 — AI policiesThe organisation’s AI policy and its alignment with existing policies
A.3 — Internal organisationClear roles and responsibilities, a channel for reporting concerns
A.4 — ResourcesInventory of resources: data, tooling, systems, human competence
A.5 — Impact assessmentThe impact of AI systems on individuals, groups and society
A.6 — LifecycleRequirements, design, verification, deployment, operation, monitoring
A.7 — DataQuality, provenance and preparation of data for AI systems
A.8 — Information for interested partiesTransparency: what you communicate to users and stakeholders, incident reporting
A.9 — Responsible useObjectives for responsible use, use according to intended purpose
A.10 — Third partiesSuppliers, partners and customers: allocating responsibilities along the chain

Two observations from practice. First, impact assessment (A.5) is the pivot: the standard is risk-based, and without a serious impact assessment you cannot decide which other controls apply and at what depth. Second, category A.7 (data) is usually the most underestimated — data quality and provenance are the condition for any other control to mean anything, and they are also the central requirement of Art. 10 of the AI Act.

What implementation looks like, broadly

  1. AI system inventory — what you use, where, with what data and what decision role; without an inventory there is no scope.
  2. Gap analysis — what you already have (especially if 27001-certified) against clauses 4–10 and the Annex A controls.
  3. AI policy, roles and impact assessment — the governance foundation; this is where accountability is decided.
  4. Operational controls — lifecycle, data, transparency, third parties, applied proportionally to risk.
  5. Internal audit and improvement — the system only works if it is measured and corrected; only then does certification become a meaningful conversation.

Certification itself is optional and comes at the end, not the beginning. The real value of the standard is not the certificate but the fact that it turns "we use AI responsibly" from a statement of intent into a system with roles, evidence and discipline — exactly what both the law and your customers will ask for.