Certify once. Comply twice.

    ISO 42001 and the EU AI Act ask for the same evidence. Build the management system once and it answers both.

    app.whisperly.ai / eu-ai-act
    Back
    AI Recruitment Scoring Module
    High risk
    ISO 42001
    MK
    Owner
    Maya Kessler, People Ops
    1
    Classification
    Risk tiering
    2
    Data & training
    Provenance
    3
    Human oversight
    Art. 14
    4
    Technical docs
    Annex IV
    Risk classification
    Scored against risk criteria. Employment and worker management.
    72 / 100
    Data sensitivityHigh
    Automation levelMedium
    Human oversightDocumented
    TransparencyPartial

    Where ISO 42001 meets the EU AI Act.

    Not a claim, a mapping. Each Annex A control group produces evidence a specific article of the Act asks for, which is why implementing one accelerates the other.

    A.2 Policies for AI
    Policy framework and management commitment
    Art. 17 quality management system
    AI policy set, approvals, review cycle
    A.3 Internal organisation
    Roles, responsibilities and authorities
    Art. 17, 22 governance and authorised representative
    Ownership register, delegation records
    A.5 Assessing impacts of AI
    Societal, environmental and individual impact
    Art. 27 fundamental rights impact assessment
    Impact assessments, affected groups, mitigations
    A.6 AI system lifecycle
    Design through decommissioning
    Art. 9, 11 risk management and technical documentation
    Lifecycle records, test results, change history
    A.7 Data for AI systems
    Acquisition, quality, processing, retention
    Art. 10 data and data governance
    Dataset provenance, quality checks, bias testing
    A.8 Information for interested parties
    Communicating use, capability and limits
    Art. 13, 50 transparency and disclosure
    Instructions for use, user notices, labelling
    A.9 Use of AI systems
    Acceptable use and oversight mechanisms
    Art. 14, 26 human oversight and deployer duties
    Oversight procedures, logs, training records
    A.10 Third-party and supplier relations
    Vendor AI risk and contractual terms
    Art. 25 responsibilities along the value chain
    Vendor assessments, contract clauses, monitoring
    A.4 resources and the remaining controls map across too.
    Whisperly ships all 38 controls with their cross-references to the EU AI Act, ISO 27001 and GDPR, so evidence you produce for one is counted for the others rather than rebuilt.
    See the EU AI Act page

    Overlapping, not interchangeable.

    The evidence overlaps heavily. The instruments do not. Anyone telling you certification discharges your obligations under the Act is selling you something.

    ISO 42001

    A certifiable management system

    Status
    Voluntary international standard, published November 2023
    Scope
    Organisation-wide: how you govern AI as a whole
    Proof
    A certificate from an accredited body, renewed by surveillance audit
    If you skip it
    No penalty, but enterprise buyers increasingly ask for it
    EU AI Act

    Binding law with penalties

    Status
    Regulation in force, phased application to 2028
    Scope
    Per system, by risk tier and by your role in the chain
    Proof
    Conformity assessment, CE marking and registration for high risk
    If you skip it
    Up to 35 million euro or 7% of global annual revenue
    So why certify at all?
    Because certification forces the operating discipline the Act assumes you already have. It gives you a governance structure an auditor has tested, a documented risk methodology, and a credential your customers recognise, all built from the evidence base your high-risk conformity assessment will draw on.

    Your AIMS, without the spreadsheets.

    Most organisations spend six to twelve months assembling an AIMS by hand. Whisperly generates the documentation and collects the evidence continuously.

    01

    Scope and inventory

    Catalogue every AI system with purpose, inputs, outputs, stakeholders and risk level, then define the AIMS boundary. The same register serves your EU AI Act classification.

    Free AI inventory template →
    02

    Risk assessment and controls

    Structured identification, scoring and treatment for bias, security, ethical and operational risk, with treatments mapped to all 38 Annex A controls and their AI Act counterparts.

    See the control mapping →
    03

    Documentation and evidence

    Policies, procedures, the Statement of Applicability and risk treatment plans generated automatically, with logs, records and change tickets gathered as work happens rather than before an audit.

    AI policy generator →
    04

    Audit and surveillance

    Organised packages for Stage 1 and Stage 2, nonconformities tracked to closure, and continuous monitoring that keeps you ready for annual surveillance and recertification.

    Publish to your Trust Center →

    Frequently asked questions

    No, and the distinction matters. ISO 42001 certifies that you have a functioning AI management system. The Act imposes obligations on specific systems by risk tier, and high-risk systems need conformity assessment, CE marking and registration regardless of your certificate. What certification does give you is most of the underlying evidence: governance structure, documented risk methodology, data governance records, oversight procedures and supplier controls. That is why the two are best run together rather than sequentially.

    One system. Both frameworks.

    See the Annex A controls mapped against the EU AI Act in your own environment, and what evidence you already have.