AI Act vs ISO 42001 for SMEs: Differences, Overlaps, and Why You Need Both
TL;DR: ISO 42001 is a voluntary AI management standard; the AI Act is a mandatory EU regulation. They share between 40 and 50% of their controls, so obtaining ISO 42001 certification significantly accelerates AI Act compliance — but does not replace it. For Spanish SMEs, the optimal strategy is to integrate both frameworks into a single project, leveraging synergies in governance, documentation and risk assessment.
What is the AI Act? The essentials in 3 minutes
The AI Act is Regulation (EU) 2024/1689, approved by the European Parliament and in force since August 2024. It is the world's first comprehensive AI law and affects any company that develops, markets or uses AI systems in the European Union, regardless of where its headquarters is located.
The regulation classifies AI systems into four risk categories:
- Unacceptable risk: systems prohibited outright, such as government social scoring or subliminal manipulation.
- High risk: systems affecting fundamental rights, employment, education, access to essential services or critical infrastructure. Subject to the strictest requirements for documentation, conformity assessment and human oversight.
- Limited risk: systems with transparency obligations, such as chatbots that must identify themselves as AI.
- Minimal risk: the vast majority of AI applications, with no additional obligations.
Fines for non-compliance are among the highest in all European legislation: up to €35 million or 7% of global annual turnover, whichever is higher, for the most serious cases. For less serious infringements, the ceiling is €15 million or 3% of turnover.
The AI Act applies in phases:
- February 2025: prohibitions on unacceptable-risk systems and AI literacy obligations for all operators enter into force.
- August 2026: transparency (Art. 50), general-purpose AI and the enforcement regime — the Annex III (high-risk) obligations are deferred to December 2027.
- August 2027: full general application.
In Spain, the supervisory authority is AESIA (Spanish AI Supervisory Authority, Agencia Española de Supervisión de la Inteligencia Artificial), based in A Coruña, which will be the competent authority for monitoring AI Act compliance and applying the corresponding sanctions at national level.
A practical note for SMEs: even if your company does not develop AI, if you use it in processes that affect employees, customers or significant business decisions, you are probably a deployer under the AI Act and have specific obligations, particularly if the system you use is high-risk.
What is ISO 42001? The AI management system
ISO 42001 is an international AI management system standard, published in December 2023 by the International Organization for Standardization (ISO). Its full name is ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system.
The most useful analogy to understand ISO 42001 is to compare it with other ISO management standards you probably already know:
- ISO 9001 establishes a management system for quality.
- ISO 27001 establishes a management system for information security.
- ISO 14001 establishes a management system for the environment.
- ISO 42001 establishes a management system for artificial intelligence.
This means ISO 42001 is not a technical standard for building AI models, but an organisational management framework that defines how to govern, supervise, document and continuously improve the use and development of AI systems within an organisation.
The key elements of ISO 42001 include:
- Organisational AI policy: a formal statement of the company's principles and commitments regarding AI.
- AI systems inventory: a register of all AI systems the organisation uses or develops.
- Impact and risk assessment: a structured methodology for identifying and mitigating the risks of each system.
- Governance and roles: definition of internal responsibilities over AI.
- AI system lifecycle: controls from design through to the retirement of each system.
- Transparency and communication: procedures for informing stakeholders about AI use.
- Continuous improvement: internal audits and management reviews to maintain the effectiveness of the management system.
Like ISO 27001 or ISO 9001, ISO 42001 is certifiable. This means that an entity accredited by ENAC (Spain's National Accreditation Body) can audit your company and issue a certificate publicly attesting compliance with the standard. The main certification bodies operating in Spain are AENOR, Bureau Veritas, TÜV Rheinland, SGS and Lloyd's Register.
ISO 42001 certification is voluntary: no law requires you to obtain it. However, as we will see later, it is already beginning to appear as an evaluation criterion in public procurement tender specifications and may become a de facto requirement in certain sectors.
A key advantage of ISO 42001 is that it was designed from the outset to be compatible with the AI Act and other AI regulations. The standardisation committees that developed it worked in parallel with the European legislative process, so the standard's controls are intentionally aligned with the requirements of the AI Regulation.
Key differences: AI Act vs ISO 42001
To make the right decisions about what to implement, when and why, it is essential to understand clearly where these two frameworks differ. The following table summarises the most relevant differences for a Spanish SME:
| Aspect | AI Act | ISO 42001 |
|---|---|---|
| Legal nature | Mandatory legal regulation | Voluntary certifiable standard |
| Origin | European Union (Regulation 2024/1689) | ISO/IEC (international body) |
| Penalty for non-compliance | Fines up to €35M or 7% of global turnover | No legal penalties; loss of certification |
| Primary focus | Risk classification of specific AI systems | Organisational AI management system |
| Application timelines | In phases from 2025 to 2027 | No legal deadlines; at company's discretion |
| Supervisory authority in Spain | AESIA (Spanish AI Supervisory Authority) | ENAC-accredited certification body |
| Type of audit | Public inspections and conformity assessments | Periodic certification audits (3-year cycle) |
| Main benefit | Avoid sanctions and operate legally in the EU | Competitive differentiation and risk management |
The most important difference is substantive: the AI Act says what you cannot do and what obligations you have with certain AI systems; ISO 42001 says how you should internally organise AI management in your company. They answer different questions, though with much common ground.
What they share: the 40–50% overlap
Here is the practical key for any Spanish SME facing these two frameworks: between 40 and 50% of the AI Act's controls and requirements have a direct counterpart in ISO 42001. This is not a coincidence but the result of deliberate design: the drafters of ISO 42001 worked with the AI Act text as a reference.
The most relevant shared controls are:
1. AI Governance
Both the AI Act (Article 26 for deployers and Article 16 for providers) and ISO 42001 (clauses 5.1 and 5.2) require the organisation to define a formal AI policy, assign clear responsibilities and establish an internal oversight system. ISO 42001 requires you to document who makes decisions about AI and how. The AI Act requires you to demonstrate that you have such a system in place.
2. AI Systems Inventory and Classification
To comply with the AI Act, you need to know which AI systems you use or develop and classify them by risk level. For ISO 42001, you need to maintain an up-to-date inventory of all your AI systems. It is the same register, with the same purpose: without knowing what you have, you cannot manage or comply with anything.
3. Risk Assessment
Article 9 of the AI Act requires risk management systems for high-risk AI systems. Clause 6.1 of ISO 42001 requires assessment of the risks of all the organisation's AI systems. The approach and methodology are largely the same: identify threats, estimate probability and impact, define controls.
4. Technical Documentation and Traceability
Articles 11 and 12 of the AI Act (event logging, technical documentation) and clauses 7.5 and 8.1 of ISO 42001 (documented information) overlap almost entirely. If you document your AI systems following ISO 42001, you will have 80% of the documentation the AI Act requires for high-risk systems already prepared.
5. Transparency Towards Users and Stakeholders
Article 50 of the AI Act requires users to be informed when they interact with AI systems (especially chatbots and emotion/biometrics systems). Clause 8.5 of ISO 42001 requires transparency procedures for all stakeholders. Implementing ISO 42001 gives you the framework to comply with the AI Act on this point as well.
6. AI System Lifecycle
From design through to retirement, both the AI Act and ISO 42001 require controls at all phases of the lifecycle: validation before deployment, monitoring during use and decommissioning procedures.
7. Supplier and Third-Party Management
If you use third-party AI systems (increasingly common in SMEs), both the AI Act and ISO 42001 require you to manage that supply chain: what data they share, what risks the vendor introduces and how you audit their compliance.
8. AI Training and Literacy
Article 4 of the AI Act, which entered into force in February 2025, requires all AI system operators to ensure their staff have the level of AI literacy needed for their roles. Clause 7.2 of ISO 42001 establishes exactly the same: competence and training of personnel involved in AI systems.
Control mapping table: what ISO 42001 gives you for the AI Act
The following mapping table shows the direct correspondence between ISO 42001 clauses and the AI Act articles they cover. It is a practical reference for planning an integrated compliance project:
| ISO 42001 Control | Clause | AI Act Article Covered |
|---|---|---|
| Organisational AI policy | 6.2 | Art. 9 – Risk management |
| AI systems inventory | 9.1 | Basis for all risk classification (implicit in Arts. 6–9) |
| Fundamental rights impact assessment | 8.4 | Art. 27 – Deployer impact assessment |
| Internal conformity assessment | 9.2 | Art. 43 – Conformity assessment |
| AI system change control | 8.4 | Art. 9.6 – System monitoring and updating |
| AI competence and training | 7.2 | Art. 4 – AI literacy |
| Transparency towards users | 8.5 | Art. 50 – Transparency and user information |
| Monitoring, metrics and review | 9.3 | Art. 72 – Post-market monitoring |
| Event logging and traceability | 7.5 | Arts. 11–12 – Technical documentation and event logging |
| AI vendor management | 8.3 | Art. 25 – Distributor obligations |
The practical interpretation of this table: if you correctly implement the ISO 42001 controls listed in the left column, you will have substantially covered the AI Act articles in the right column — not 100%, because the AI Act has sector- and system-specific requirements beyond this, but you will have advanced between 40 and 50% of the way.
When you need both and when just one?
Not all companies are in the same situation or have the same needs. The following decision tree will help you determine the most appropriate strategy for your SME:
Option A: AI Act compliance only (no ISO 42001 certification)
When it makes sense: your company uses low- or minimal-risk AI systems, does not tender for Spanish Public Administration contracts, does not operate in regulated sectors (finance, health, insurance, employment) and has no competitive advantage to gain from external certification.
What it involves: you will need to comply with AI Act obligations according to the phased timetable, but without the cost and effort of formal certification. For many general-services SMEs, this is sufficient in the short term.
The risk: without a formal management system like ISO 42001, it is harder to demonstrate to AESIA or your clients that you have the controls in place. In the event of an inspection, the burden of proof is higher.
Option B: ISO 42001 certification only (without focusing on the AI Act now)
When it makes sense: your company wants competitive differentiation and access to public tenders, but your AI systems are currently low- or minimal-risk under the AI Act, or you have not yet reached the mandatory deadlines for your sector.
What it involves: you obtain the certificate and competitive advantage without waiting for the AI Act to require it. When the legal deadlines arrive, you will already have covered 40–50% of the ground.
The risk: if your AI systems are high-risk under the AI Act, you cannot defer legal compliance. ISO 42001 does not protect you from the Regulation's sanctions.
Option C: Both frameworks integrated (recommended for most)
When it makes sense: you operate in regulated sectors (finance, health, human resources, critical infrastructure), you are a software provider with AI components, you regularly tender for Spanish Public Administration contracts, or you simply want to do things right from the start without having to repeat the work.
What it involves: a single AI governance project that addresses both frameworks in an integrated way, exploiting synergies and avoiding duplication. This is the most economically efficient approach and the one I recommend for the majority of SMEs already making strategic decisions about AI use.
The economic case for integrating both frameworks
A very common question among SME directors and managers is: how much does AI Act + ISO 42001 cost? And, more importantly: does it make sense to do them together or separately?
The economic answer is clear: doing them in an integrated way costs 30 to 40% less than doing them separately. The reason is simple: they share the same base of work.
When you do them together:
- A single AI systems inventory that complies with both.
- A single risk assessment in the correct format for both.
- A single AI policy that satisfies the requirements of both frameworks.
- A single training programme covering Article 4 of the AI Act and clause 7.2 of ISO 42001.
Indicative figures for a Spanish SME with 10 to 50 employees and 2–5 AI systems:
- AI Act + ISO 42001 separately: between €25,000 and €60,000 (consultancy, implementation, certification and training).
- AI Act + ISO 42001 integrated: between €15,000 and €40,000.
The saving is real and significant. Also worth considering are the synergies with ISO 27001: if your company is already certified in information security, approximately 30% of ISO 42001 controls will already be covered or easily extensible from your existing information security management system. This can reduce the ISO 42001 implementation effort by a further 25–35%.
The role of Kit Consulting
For eligible Spanish SMEs, the Kit Consulting programme (managed by Red.es through digital-agent providers) includes the solution for Strategic AI Advisory, with a maximum subsidisable amount of up to €24,000 depending on the company segment.
This advisory service can specifically cover the initial phase of an integrated AI Act + ISO 42001 project: current-state diagnosis, AI systems inventory, AI Act risk classification, gap analysis against ISO 42001, and action plan. In other words, steps 1 to 3 of the roadmap below can be largely funded by Kit Consulting, making the realistic entry point considerably more accessible for many SMEs.
ISO 42001 and public procurement: an emerging competitive advantage
One of the strongest arguments for an SME to obtain ISO 42001 certification before it is strictly required for AI Act compliance is the competitive advantage in the public procurement market.
Spanish Public Administration bodies are in a unique position regarding the AI Act: they are simultaneously deployers of AI systems (with their own legal obligations) and buyers of technology services from private companies. This dual role leads them to increasingly require their technology suppliers to demonstrate AI governance capabilities.
Precedents already exist in regulated European sectors, particularly in finance and healthcare, where ISO 42001 certification has started appearing as an evaluation criterion in public tenders. In Spain, with the progressive application of the AI Act and pressure on contracting bodies to demonstrate regulatory compliance, it is reasonable to expect this pattern to be replicated in the next 12–24 months.
For companies already working with the public sector or aspiring to do so, ISO 42001 certification brings three concrete advantages:
- Differentiation in tender specifications: in contracts that value certified management systems, ISO 42001 adds points and can be decisive against uncertified competitors.
- Demonstration of proactive compliance: public administration bodies with AI Act obligations prefer suppliers who already have their own controls in place, because it reduces risk for the contracting authority.
- Faster due diligence: when a Spanish Public Administration body must audit its AI suppliers (an obligation the AI Act imposes on deployers of high-risk systems), holding a valid ISO 42001 certificate simplifies and accelerates that process.
This trend also connects to the Spanish National Security Framework (ENS, Esquema Nacional de Seguridad): companies that provide digital services to Spanish Public Administration and are already ENS-certified will have an additional advantage when implementing ISO 42001, because many of the risk management and documentation controls are equivalent or complementary between the two frameworks.
How to start: a 4-step roadmap for SMEs
Step 1: AI systems inventory (2–4 weeks)
Before anything else, you need to know exactly which AI systems your company uses or develops. This inventory must include:
- Name and description of the system.
- Vendor (if third-party) or development team (if in-house).
- What data it processes and who is responsible for that data.
- Which business processes it is used in and what decisions it supports or automates.
- Who the affected internal and external users are.
The most common surprise in this step is that companies discover they use more AI systems than they thought: AI-integrated recruitment tools, credit scoring systems, website chatbots, predictive analytics tools, fraud detection systems, etc. Many of these can be high-risk under the AI Act without the company having considered it.
Step 2: Risk classification under the AI Act (1–2 weeks)
With the inventory in hand, the next step is to classify each AI system according to the AI Act's risk categories. This classification determines which specific legal obligations apply to each system:
- High-risk systems (e.g. recruitment software, credit scoring systems, medical diagnostic tools) require technical documentation, conformity assessment, registration in the EU database and post-deployment monitoring systems.
- Limited-risk systems (chatbots, deepfakes) have mainly transparency obligations.
- Minimal-risk systems (spam filters, content recommenders) have no additional obligations under the AI Act.
Step 3: Gap analysis against ISO 42001 (2–3 weeks)
With the inventory and classification completed, the third step is to conduct a gap analysis against ISO 42001 requirements. This analysis compares the current state of your AI management controls with what the standard requires and identifies which areas need additional work.
The most common gaps found by SMEs in this analysis are:
- Absence of a formal AI policy approved by management.
- Incomplete or non-existent AI systems inventory.
- No stakeholder impact assessment procedures.
- Insufficient or undocumented AI training for staff.
- Contracts with AI vendors that do not include risk management clauses.
Step 4: Integrated remediation plan (3–6 months)
The fourth and final step before starting formal certification is to implement the missing controls, following a plan that simultaneously addresses AI Act and ISO 42001 requirements. The key is not to design two separate projects but a single one with a unified set of documents, a single training programme and a single monitoring system.
The indicative timeline for this step depends on the complexity of your AI systems and your company's size. For an SME of fewer than 25 employees with 2–3 AI systems, it is realistic to complete implementation in 3–4 months. For larger companies or those with more complex systems, 6 months is a realistic target.
Once implementation is complete, the ISO 42001 certification process itself (Stage 1 audit + Stage 2 audit by the certification body) typically takes a further 4–8 weeks.
If you have questions about the best entry point for your company, or want to run the initial AI systems diagnosis together, you can get in touch with me without any commitment. I also recommend reading my guide on the AI Act obligations for your SME in August 2026 for the complete picture of the legal timetable. If your company also works with the Spanish Public Administration, the Spanish National Security Framework (ENS) is another framework worth integrating into your compliance strategy. And if you are already certified or in the process of being certified in ISO 27001, the move to ISO 42001 will be considerably shorter than you might expect.
If after this comparison you want to apply it to your own company, here is everything I cover on the AI Act.
Frequently asked questions about AI Act and ISO 42001
- Is ISO 42001 mandatory for AI Act compliance?
- No. ISO 42001 is a voluntary standard. The AI Act is mandatory for companies within its scope. However, implementing ISO 42001 covers between 40 and 50% of the AI Act's controls, making it highly efficient to have both frameworks in place in an integrated way.
- Does ISO 42001 replace the AI Act?
- No. They are complementary, not alternatives. The AI Act is European law with fines of up to €35 million; ISO 42001 is a voluntarily certifiable management system. Implementing ISO 42001 accelerates and facilitates AI Act compliance, but does not legally substitute it. No ISO certificate exempts a company from complying with applicable laws.
- How much does ISO 42001 certification cost in Spain?
- ISO 42001 certification in Spain ranges from €4,000 to €15,000 for SMEs, depending on company size, the complexity of AI systems and the chosen certification body. To this cost you must add that of prior implementation (consultancy, training, documentation), which can be a further €8,000 to €25,000. Kit Consulting can cover the strategic advisory phase prior to certification, with a maximum amount of up to €24,000.
- Are ISO 27001 and ISO 42001 compatible?
- Yes, they are highly synergistic and share the common High Level Structure (HLS) common to all ISO management system standards. If your company is already ISO 27001 certified, approximately 30% of ISO 42001 controls will already be covered or easily extensible from your existing information security management system (ISMS). This significantly reduces the time and cost of implementing ISO 42001.
- How long does it take to implement ISO 42001 in an SME?
- For an SME without prior management systems, between 6 and 12 months from start to certificate. For companies that already have ISO 27001 or ISO 9001, the process can be shortened to 3–6 months thanks to the reuse of existing controls, documentation and methodologies.
- Does Kit Consulting cover ISO 42001?
- Yes. Kit Consulting includes the AI advisory solution, which can cover the diagnosis phase, AI systems inventory, risk classification and integrated AI Act + ISO 42001 action plan. The maximum amount varies by company segment but can reach up to €24,000. It is important that the selected digital agent has specific expertise in this area to maximise the value of the advisory service.
- Which body certifies ISO 42001 in Spain?
- The main ENAC-accredited certification bodies offering or preparing ISO 42001 certification in Spain are AENOR, Bureau Veritas, TÜV Rheinland, SGS and Lloyd's Register. It is advisable to request quotes from several bodies, as prices and timelines can vary considerably.
- Which SMEs should get ISO 42001 certified first?
- Priority candidates are: software or technology service providers with integrated AI components, SMEs that regularly tender for Spanish Public Administration contracts, companies in regulated sectors such as finance, insurance, healthcare or human resources, and any organisation that uses AI systems in decisions that significantly affect people (recruitment, credit, access to services). For these companies, certification delivers immediate competitive advantage in addition to facilitating legal compliance.