ISO 42001 vs EU AI Act for CISOs

A practical guide to where ISO 42001 helps, where the EU AI Act bites, and how to use both without building two separate programs.

Share
ISO 42001 vs EU AI Act for CISOs
Photo credit: mDee / ISO Media-Kit

AI governance is no longer a side project. It is now a security, legal, and operational priority.

For most CISOs, the real question is not which one matters. It is how do I avoid building two overlapping control programs that confuse everyone and satisfy nobody?

That is where ISO 42001 and the EU AI Act come in. They are related, but they are not the same.

ISO 42001 is a management system standard. The EU AI Act is regulation. One helps you build an AI governance system. The other tells you what the law expects when AI is used, placed on the market, or deployed in the EU.

That distinction matters.

TLDR

If you want the shortest useful answer:

ISO 42001:

  • ISO 42001 is voluntary.
  • ISO 42001 helps you design, run, and improve an AI management system.
  • Any organisation that develops, provides or uses AI can adopt ISO 42001.

EU AI Act:

  • EU AI Act is mandatory where it applies.
  • EU AI Act tells you which AI uses are allowed, restricted, or heavily regulated.
  • If you are a provider, deployer, importer or distributor with an EU market link, the EU AI Act applies to you.

That is the headline. But CISOs do not need headlines. They need decisions.

What Is It Exactly?

ISO 42001 (correct name is ISO/IEC 42001:2023) is the first international, certifiable standard for an AI Management System (AIMS).

Published in December 2023, it specifies how an organisation should establish, implement, maintain and continually improve the policies, processes and controls that govern how it develops, provides or uses AI.

In practice, ISO 42001 defines a management framework built on the familiar "Plan Do Check Act cycle". It requires leadership ownership, documented risk assessment, operational controls, records, internal audit, management review and corrective action. It certifies the management system, not individual models or algorithms.

The EU AI Act is an EU regulation (Regulation (EU) 2024/1689) that directly applies in all member states. It is not a management framework; it is a risk‑based legal regime that classifies AI systems and imposes obligations based on that classification.

The Act sorts AI systems into four tiers:

  • Prohibited – practices such as social scoring, certain manipulative AI, and un-targeted real‑time biometric monitoring in public spaces may not be placed on the market or used at all.
  • High‑risk – systems used in areas like hiring, credit assessment, critical infrastructure or medical devices must meet strict requirements (risk management, data governance, technical documentation, logging, human oversight, accuracy/robustness, cybersecurity, and conformity assessment).
  • Limited‑risk (transparency) – systems such as chatbots, deepfakes and AI‑generated content must inform users and label synthetic outputs.
  • Minimal‑risk – most everyday AI (e.g. spam filters, simple recommenders) has no specific obligations, though voluntary codes of conduct are encouraged.

In short:

ISO 42001: A rulebook for building and certifying an AI management system.

And:

EU AI Act: A law that says which AI uses are banned, which are heavily regulated, and what you must do for each.

Who Is Implicated?

ISO 42001 is intentionally broad: any organisation that develops, provides or uses AI can adopt it, regardless of size, sector or location. There is no “small company” or “vendor only” exemption, if AI is materially shaping decisions or processes in your organisation, it can be in scope for ISO 42001.

The EU AI Act is different. It applies by role and EU link, not by headquarters. It targets:

  • Providers placing AI systems or GPAI models on the EU market (including Swiss and other non‑EU companies).
  • Deployers using AI in a professional context in the EU.
  • Importers and distributors making AI systems available in the EU.
  • Non‑EU providers/deployers whose AI output is used in the EU.

Under Article 25, a deployer, importer or distributor can become a “provider” for a high‑risk system if they put their name/trademark on it, substantially modify it, or change its intended purpose. In practice, that means some “just users” or “just resellers” can inherit full provider obligations.

So:

ISO 42001: If you develop, provide or use AI, you can adopt this standard for that scope.

And

EU AI Act: If you are a provider, deployer, importer or distributor with an EU market link (including output used in the EU), the Act’s obligations apply to you by role.

What ISO 42001 actually gives you

ISO 42001 is built for management control. It gives you a framework for AI governance, risk management, accountability, documentation, and continual improvement.

That means it is useful when you need to answer questions like:

  • Who owns AI risk?
  • Which AI systems are in scope?
  • How are models approved?
  • What gets monitored after go-live?
  • How do we handle incidents, changes, and supplier risk?

In other words, ISO 42001 helps you create a system. Not just a policy. Not just a register. A system.

For a CISO, that is valuable because AI risk rarely stays inside one team. Security wants control. Legal wants defensibility. Procurement wants speed. Engineering wants flexibility. The standard gives you a common operating model.

What the EU AI Act actually does

The EU AI Act is different. It is not a management framework. It is a regulatory regime.

Its job is to classify AI systems by risk and impose obligations based on that classification. That means the first question is not “Do we have an AI program?” The first question is “What kind of AI system is this, and what obligations follow?”

That is a legal and operational classification problem.

For CISOs, that matters because the AI Act can affect:

  • governance expectations
  • documentation
  • technical controls
  • human oversight
  • transparency duties
  • monitoring and incident handling
  • supplier and third-party assurance

If your organisation builds, buys, integrates, or deploys AI in the EU, this is not optional background noise. It is part of your control environment.

The real difference

The easiest way to think about it is this:

Topic ISO 42001 EU AI Act
Nature Standard Regulation
Purpose Build an AI management system Regulate AI use by risk
Status Voluntary Mandatory where applicable
Main focus Governance and continual improvement Legal obligations and compliance
Best use Internal control framework External compliance requirement

That table is the essence of it.

ISO 42001 tells you how to organise your management system. The EU AI Act tells you what is regulated, and by how much.

Why CISOs should care about both

Because one without the other creates a gap.

If you only chase the EU AI Act, you may end up with a compliance checklist and no durable operating model. That is brittle. It usually collapses under change.

If you only adopt ISO 42001, you may build a neat governance structure that still misses specific legal obligations. That is dangerous. A standard is not a shield against regulation. A certificate is not a waiver. And a policy binder is not evidence that your AI use is lawful.

CISOs need both layers. The framework. And the law.

Where ISO 42001 helps the most

ISO 42001 is strongest when you need repeatability. It helps you turn AI governance into something that can scale.

That matters in areas like:

  • AI inventory and ownership
  • risk assessments
  • supplier due diligence
  • approval workflows
  • monitoring and review
  • incident management
  • audit readiness
  • roles and responsibilities

It is especially useful if AI is already spreading across business units faster than central control can keep up. And that is most organisations.

A good management system gives you a way to say: “This is how we decide whether an AI use case is acceptable.”

That statement alone is worth a lot.

Where the EU AI Act bites hardest

The EU AI Act is strongest where legal exposure is highest. It becomes especially important when AI is used in contexts with elevated risk, such as systems that affect people’s rights, access, safety, or material outcomes.

For a CISO, the operational impact is that AI governance can no longer be limited to security controls alone.

You also need:

  • classification logic
  • evidence retention
  • supplier assurance
  • traceability
  • human oversight design
  • change control
  • monitoring for misuse or drift
  • escalation paths for non-compliance

That is why AI governance cannot sit only inside security. It has to connect security, legal, privacy, compliance, procurement, and engineering.

If it does not, the control gaps will show up later. Usually at the worst possible time.

What this means in practice

For most CISOs, the right move is not to choose. It is to sequence.

Start with an AI inventory. You cannot govern what you cannot see.

Then define ownership. Someone has to be accountable for each material AI use case.

Then classify the systems. Not every AI tool deserves the same treatment.

Then map obligations. Some controls will be internal governance controls. Some will be regulatory controls. Some will be both.

After that, build a shared control set. Do not create one process for ISO 42001 and another for the AI Act if they can be aligned. That is how teams end up doing duplicate reviews, duplicative approvals, and contradictory evidence packs. Nobody enjoys that. And nobody maintains it well.

A good CISO approach

A sensible model looks like this:

  • Use ISO 42001 as the management backbone.
  • Use the EU AI Act as the legal constraint set.
  • Build one AI inventory.
  • Run one risk assessment workflow.
  • Maintain one evidence repository.
  • Define one approval path for high-risk use cases.
  • Map each control to both governance and compliance needs where possible.

That approach reduces friction. It also makes audits and regulatory questions easier to answer. Not because it removes complexity. Because it makes complexity legible.

The mistake most teams make

The common mistake is treating AI governance as an AI team problem. It is not. It is a business risk problem with security implications.

That means CISOs need to resist two traps.

The first trap is over-engineering. A beautiful framework that nobody follows is a shelf ornament.

The second trap is under-engineering. A few slides and a policy statement do not create control. Yes you need them, but they are not enough.

The goal is a practical operating model that can survive real use. Real suppliers. Real exceptions. Real incidents. Real pressure from the business.

The question to ask your team

If your organisation is serious about AI, ask this:

If a regulator, auditor, customer, or board member asked us how we govern AI today, could we show them a coherent answer?

If the answer is no, you have a gap. If the answer is “sort of,” you probably have several. And if the answer is yes, the next question is whether that answer is consistent across security, legal, procurement, and the AI team.

That is where maturity shows up.

Bottom line for CISOs

ISO 42001 gives you the management system. The EU AI Act gives you the legal requirement.

Use ISO 42001 to build disciplined AI governance. Use the EU AI Act to make sure that governance is aligned with regulation.

Do not treat them as competitors. Treat them as layers in the same control stack.

That is the difference between AI governance that looks good in a presentation and AI governance that survives contact with reality.