By Rafael Luque Ocaña

ISO/IEC 42001 and the EU AI Act: what it is, what it does not require and how it fits an SME

ISO/IEC 42001 is the international standard for AI management systems. It is voluntary, it gives no presumption of conformity with the AI Act and the Regulation does not require it. When it pays off for an SME, and how to start without it.

ISO/IEC 42001 turns up more and more in supplier questionnaires and in some tenders, often in the same question as the EU AI Act. They are not the same thing, not by a long way. ISO/IEC 42001 is a voluntary management system standard. The AI Act is a binding European regulation. Following the standard gives no presumption of conformity with the Regulation, and the Regulation does not require the standard. What they do share is the groundwork: knowing which AI you use, who is accountable for it, what risks it carries and what evidence you keep.

What ISO/IEC 42001 is

ISO/IEC 42001:2023 is titled Information technology — Artificial intelligence — Management system. ISO and IEC published it on 18 December 2023 (first edition), and it is developed by the joint committee ISO/IEC JTC 1/SC 42, which works on artificial intelligence.

According to its public page (also on the ISO website), it sets requirements and guidance for establishing, implementing, maintaining and continually improving an AI management system within an organisation. It is aimed at organisations of any type and size that develop, provide or use AI-based products and services.

It is therefore a management system standard: it does not describe how a particular AI system should work, but how a company should organise itself to govern the systems it uses or builds. And, like any ISO standard, it is adopted voluntarily, unless a contract or a customer asks for it.

ISO 42001 and the AI Act: two different instruments

Regulation (EU) 2024/1689 has a mechanism through which a technical standard produces legal effects: the presumption of conformity in Article 40(1). It reserves it for harmonised standards, or parts thereof, «the references of which have been published in the Official Journal of the European Union». Systems in conformity with one of those standards are presumed to be in conformity with the requirements that the standard covers.

ISO/IEC 42001 is not one of those standards. Following it does not trigger the presumption, however good it is as a practice. We have explained this in detail in why there is still no presumption of conformity and in the case of EN 18286:2026, the first European standard for the AI Act.

There is another common misunderstanding. Article 17 requires providers of high-risk AI systems to put a quality management system in place. It is an obligation of the provider, not of the company that uses the system, and its content is set by the article itself, not by an ISO standard. We cover it in Article 17 is not the deployer's.

What the AI Act does not require regarding ISO 42001

If your company uses a high-risk AI system, its obligations as a deployer are in Article 26: using it in accordance with its instructions for use, assigning human oversight to people with the necessary competence, training and authority, monitoring its operation and keeping the logs it generates, among others. Those obligations do not apply yet (the dates are in the calendar). None of them consists of adopting ISO/IEC 42001 or any other management system standard.

So the answer to an SME asking whether it «needs ISO 42001 for the AI Act» is no. What it needs, if it uses high-risk systems, is to be able to show how it handles each obligation in Article 26 once it applies. A management standard can help organise that work, but it neither replaces it nor proves it on its own.

ISO 42001 for SMEs: when it makes sense and when it does not

It makes sense when the market asks for it. That happens mainly in three situations:

  • Customer questionnaires. A large company buying from an SME wants to know how the SME governs the AI it puts into its products or services, and a recognised standard is a way of answering within a framework the customer already knows.
  • Tenders. A tender may ask which management frameworks the bidder works with, and a recognised standard gives an answer that can be checked.
  • SMEs that build AI and sell it to customers with demanding procurement teams.

It does not make sense, or not yet, when the company uses a handful of third-party AI tools, no customer is asking and there is still no inventory of what it uses. Implementing a management system and putting it through an external audit takes time and money. Without the groundwork, the standard stays on paper.

How to start without the standard

The work that any AI management system requires, and that also makes the AI Act easier to meet, is the same and does not depend on any standard:

  1. Inventory: which AI systems the company uses or builds, from which provider, for what and with what data. It is the foundation of everything else.
  2. Accountability: who decides on each system, who oversees it and to whom a problem is escalated.
  3. Risks: what can go wrong with each system, how serious it would be and what is done about it.
  4. Evidence: what was decided, by whom, when and with which document, kept so that it can be shown.

With that in place, deciding whether the standard pays off is a business decision, not a leap in the dark. For the full legal framework, see the EU AI Act guide for companies.

Where Alethexis fits

Alethexis does not prepare a company for ISO/IEC 42001 or map its controls to the clauses of the standard. It treats the standard as a reference best practice, not as a feature. Nor does it take part in an external audit: if the company wants one, it is carried out by an independent audit body.

What Alethexis does is document the groundwork this article describes: the inventory of AI systems, their accountable people, the risk register, the decision log and the evidence, with the SHA-256 fingerprint of each document it generates recorded at the moment it is generated. It is the same groundwork any management system needs, whether or not the standard is adopted.

Content in accordance with Articles 17, 26 and 40 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (OJ of 24 July 2026). The information on ISO/IEC 42001 comes from its public pages at ISO and IEC; this article does not reproduce the text of the standard.

This article is for information only and does not constitute legal advice.

Frequently asked questions

Is ISO/IEC 42001 mandatory to comply with the EU AI Act?

No. It is a voluntary standard. The obligations of a company that uses high-risk AI systems are in Article 26 of the Regulation, and none of them consists of adopting a management system standard.

Does following ISO/IEC 42001 give a presumption of conformity with the AI Act?

No. Under Article 40(1), the presumption comes from harmonised standards the references of which have been published in the Official Journal of the European Union. ISO/IEC 42001 is not one of them.

Who checks that a company follows ISO/IEC 42001?

If the company wants to show it to third parties, the usual route is an audit by an independent body authorised to carry it out. Neither the Regulation nor Alethexis takes part in that process.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Data protection — newsletter

Controller: ALETHEXIS, S.L. (NIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Recipients and transfers: we use providers acting on behalf of Alethexis for hosting, security and email delivery. No disclosure of your data to third parties for their own purposes is planned, except where required by law. Some providers may process data outside the EEA with the safeguards set out in the additional information. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es) or with the supervisory authority of your Member State (Article 77 GDPR). More information in the privacy policy.