Organisations approaching the EU AI Act tend to treat it as a self-contained compliance problem. The Act sets out requirements; the organisation builds a programme to meet them; the programme is judged against the Act's text. This is a reasonable way to approach a regulation, and for the AI Act it leads organisations into a great deal of avoidable difficulty, because the Act specifies what must be achieved without specifying how to achieve it, and building the how from scratch, organisation by organisation, is slow, expensive, and error-prone.
There is a better route, and it is hiding in plain sight. ISO 42001, the international standard for AI management systems, provides much of the operational architecture that the EU AI Act requires but does not itself supply. The standard is not a compliance shortcut and does not by itself satisfy the Act. But it is the framework that makes the Act achievable, by providing the management system, the governance structures, and the operational disciplines through which an organisation can actually deliver what the Act demands. Organisations building AI Act compliance without ISO 42001 are building, at great cost, much of what the standard already provides.
The Gap Between Requirement and Implementation
The EU AI Act, like most outcome-focused regulation, specifies requirements rather than implementations. It requires risk management systems, human oversight, data governance, technical documentation, accuracy and robustness, post-market monitoring. It says what must be in place. It does not say how to build, operate, and maintain these things as a functioning organisational capability, because that is not the job of regulation. The Act defines the destination and leaves the route to the organisation.
This gap between requirement and implementation is where organisations struggle. Knowing that you need a risk management system for AI is not the same as knowing how to build one that works, integrates with your existing governance, operates continuously, and produces the evidence that demonstrates it is functioning. The Act's requirements, read in isolation, tell an organisation what it is missing without telling it how to build what it is missing. Each organisation is left to design the implementation itself, and most do not have the expertise to design it well, which produces implementations that are idiosyncratic, incomplete, and difficult to assure. This is precisely the gap that management system standards exist to fill.
What ISO 42001 Provides
ISO 42001 establishes the requirements for an AI management system: a systematic framework for governing an organisation's development and use of AI. It follows the structure common to ISO management system standards, the structure that underpins ISO 27001 for information security and ISO 9001 for quality, applied to the specific domain of artificial intelligence.
The standard provides the governance architecture: defined roles, responsibilities, and accountability for AI, including the leadership engagement and organisational structure that AI governance requires. This maps onto the AI Act's expectations of organisational accountability for AI systems, providing the structure through which that accountability is actually exercised rather than merely asserted. It provides the risk management architecture: a systematic approach to identifying, assessing, and treating AI-related risks, integrated into the organisation's broader risk management. This maps directly onto the AI Act's risk management system requirements.
It provides the operational disciplines: the data governance, the lifecycle management, the monitoring, the documentation, and the continuous improvement that systematic AI management requires. These map onto the AI Act's requirements for data governance, technical documentation, post-market monitoring, and the ongoing management of AI systems through their lifecycle. And it provides the assurance architecture: the audit, review, and certification mechanisms through which an organisation can demonstrate that its AI management system is genuinely functioning. This is significant for the AI Act, because the Act requires not just that the organisation does these things but that it can evidence doing them.
Why It Does Not Replace the Act
It is important to be precise about the relationship, because overstating it produces its own errors. ISO 42001 certification does not constitute EU AI Act compliance, and an organisation that treats the standard as a substitute for the Act will be wrong in consequential ways. The Act contains specific legal requirements that the standard does not address, including the conformity assessment procedures, the registration obligations, the specific prohibited practices, and the precise technical requirements for high-risk systems. These are legal obligations defined by the Act, and meeting them requires addressing the Act directly.
The relationship is better understood as foundational rather than substitutive. ISO 42001 provides the management system foundation on which AI Act compliance can be efficiently built. An organisation with a functioning ISO 42001 management system has the governance, risk management, operational disciplines, and assurance architecture that AI Act compliance requires, and can then address the Act's specific legal requirements on top of that foundation, rather than building both the foundation and the specific requirements simultaneously from nothing.
The Strategic Case
For CNI operators in particular, the strategic case for building AI Act compliance on an ISO 42001 foundation is strong, for reasons that extend beyond the immediate efficiency. CNI operators are subject to multiple, overlapping AI-relevant obligations, and the number is growing. The EU AI Act is one instrument; there are sector-specific AI requirements, the AI dimensions of broader regulations like DORA, and an expanding body of AI governance expectation across regulated sectors. An organisation that builds a bespoke compliance solution for each instrument is building a fragmented, duplicative, and unsustainable compliance estate. An organisation that builds a single AI management system, to the ISO 42001 standard, has a unified foundation that serves all of these obligations.
The certification dimension adds further strategic value. As AI governance becomes a matter of commercial and regulatory scrutiny, the ability to demonstrate genuine AI management maturity through recognised certification becomes an asset, in the same way that ISO 27001 certification became an asset for demonstrating information security maturity. CNI operators, their customers, their regulators, and their supply chain partners increasingly need to assess AI governance maturity, and a recognised certification provides a credible, externally validated signal of that maturity.
The organisations that understand this are building their AI governance on the ISO 42001 foundation and addressing the AI Act and other instruments on top of it. The organisations that are building AI Act compliance in isolation are doing more work, producing a less sustainable result, and forgoing the assurance and certification value that the standard provides. The EU AI Act tells organisations what they must achieve. ISO 42001 is the framework through which they can actually achieve it, and the gap between approaching the Act with that framework and approaching it without is the difference between a tractable programme and an avoidably difficult one.
