AI Act vs ISO 42001 for SMEs: Differences, Overlaps, and Why You Need Both

TL;DR: ISO 42001 is a voluntary AI management standard; the AI Act is a mandatory EU regulation. They share between 40 and 50% of their controls, so obtaining ISO 42001 certification significantly accelerates AI Act compliance — but does not replace it. For Spanish SMEs, the optimal strategy is to integrate both frameworks into a single project, leveraging synergies in governance, documentation and risk assessment.

What is the AI Act? The essentials in 3 minutes

The AI Act is Regulation (EU) 2024/1689, approved by the European Parliament and in force since August 2024. It is the world's first comprehensive AI law and affects any company that develops, markets or uses AI systems in the European Union, regardless of where its headquarters is located.

The regulation classifies AI systems into four risk categories:

Fines for non-compliance are among the highest in all European legislation: up to €35 million or 7% of global annual turnover, whichever is higher, for the most serious cases. For less serious infringements, the ceiling is €15 million or 3% of turnover.

The AI Act applies in phases:

In Spain, the supervisory authority is AESIA (Spanish AI Supervisory Authority, Agencia Española de Supervisión de la Inteligencia Artificial), based in A Coruña, which will be the competent authority for monitoring AI Act compliance and applying the corresponding sanctions at national level.

A practical note for SMEs: even if your company does not develop AI, if you use it in processes that affect employees, customers or significant business decisions, you are probably a deployer under the AI Act and have specific obligations, particularly if the system you use is high-risk.

What is ISO 42001? The AI management system

ISO 42001 is an international AI management system standard, published in December 2023 by the International Organization for Standardization (ISO). Its full name is ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system.

The most useful analogy to understand ISO 42001 is to compare it with other ISO management standards you probably already know:

This means ISO 42001 is not a technical standard for building AI models, but an organisational management framework that defines how to govern, supervise, document and continuously improve the use and development of AI systems within an organisation.

The key elements of ISO 42001 include:

Like ISO 27001 or ISO 9001, ISO 42001 is certifiable. This means that an entity accredited by ENAC (Spain's National Accreditation Body) can audit your company and issue a certificate publicly attesting compliance with the standard. The main certification bodies operating in Spain are AENOR, Bureau Veritas, TÜV Rheinland, SGS and Lloyd's Register.

ISO 42001 certification is voluntary: no law requires you to obtain it. However, as we will see later, it is already beginning to appear as an evaluation criterion in public procurement tender specifications and may become a de facto requirement in certain sectors.

A key advantage of ISO 42001 is that it was designed from the outset to be compatible with the AI Act and other AI regulations. The standardisation committees that developed it worked in parallel with the European legislative process, so the standard's controls are intentionally aligned with the requirements of the AI Regulation.

Key differences: AI Act vs ISO 42001

To make the right decisions about what to implement, when and why, it is essential to understand clearly where these two frameworks differ. The following table summarises the most relevant differences for a Spanish SME:

AspectAI ActISO 42001
Legal natureMandatory legal regulationVoluntary certifiable standard
OriginEuropean Union (Regulation 2024/1689)ISO/IEC (international body)
Penalty for non-complianceFines up to €35M or 7% of global turnoverNo legal penalties; loss of certification
Primary focusRisk classification of specific AI systemsOrganisational AI management system
Application timelinesIn phases from 2025 to 2027No legal deadlines; at company's discretion
Supervisory authority in SpainAESIA (Spanish AI Supervisory Authority)ENAC-accredited certification body
Type of auditPublic inspections and conformity assessmentsPeriodic certification audits (3-year cycle)
Main benefitAvoid sanctions and operate legally in the EUCompetitive differentiation and risk management

The most important difference is substantive: the AI Act says what you cannot do and what obligations you have with certain AI systems; ISO 42001 says how you should internally organise AI management in your company. They answer different questions, though with much common ground.

What they share: the 40–50% overlap

Here is the practical key for any Spanish SME facing these two frameworks: between 40 and 50% of the AI Act's controls and requirements have a direct counterpart in ISO 42001. This is not a coincidence but the result of deliberate design: the drafters of ISO 42001 worked with the AI Act text as a reference.

The most relevant shared controls are:

1. AI Governance

Both the AI Act (Article 26 for deployers and Article 16 for providers) and ISO 42001 (clauses 5.1 and 5.2) require the organisation to define a formal AI policy, assign clear responsibilities and establish an internal oversight system. ISO 42001 requires you to document who makes decisions about AI and how. The AI Act requires you to demonstrate that you have such a system in place.

2. AI Systems Inventory and Classification

To comply with the AI Act, you need to know which AI systems you use or develop and classify them by risk level. For ISO 42001, you need to maintain an up-to-date inventory of all your AI systems. It is the same register, with the same purpose: without knowing what you have, you cannot manage or comply with anything.

3. Risk Assessment

Article 9 of the AI Act requires risk management systems for high-risk AI systems. Clause 6.1 of ISO 42001 requires assessment of the risks of all the organisation's AI systems. The approach and methodology are largely the same: identify threats, estimate probability and impact, define controls.

4. Technical Documentation and Traceability

Articles 11 and 12 of the AI Act (event logging, technical documentation) and clauses 7.5 and 8.1 of ISO 42001 (documented information) overlap almost entirely. If you document your AI systems following ISO 42001, you will have 80% of the documentation the AI Act requires for high-risk systems already prepared.

5. Transparency Towards Users and Stakeholders

Article 50 of the AI Act requires users to be informed when they interact with AI systems (especially chatbots and emotion/biometrics systems). Clause 8.5 of ISO 42001 requires transparency procedures for all stakeholders. Implementing ISO 42001 gives you the framework to comply with the AI Act on this point as well.

6. AI System Lifecycle

From design through to retirement, both the AI Act and ISO 42001 require controls at all phases of the lifecycle: validation before deployment, monitoring during use and decommissioning procedures.

7. Supplier and Third-Party Management

If you use third-party AI systems (increasingly common in SMEs), both the AI Act and ISO 42001 require you to manage that supply chain: what data they share, what risks the vendor introduces and how you audit their compliance.

8. AI Training and Literacy

Article 4 of the AI Act, which entered into force in February 2025, requires all AI system operators to ensure their staff have the level of AI literacy needed for their roles. Clause 7.2 of ISO 42001 establishes exactly the same: competence and training of personnel involved in AI systems.

Control mapping table: what ISO 42001 gives you for the AI Act

The following mapping table shows the direct correspondence between ISO 42001 clauses and the AI Act articles they cover. It is a practical reference for planning an integrated compliance project:

ISO 42001 ControlClauseAI Act Article Covered
Organisational AI policy6.2Art. 9 – Risk management
AI systems inventory9.1Basis for all risk classification (implicit in Arts. 6–9)
Fundamental rights impact assessment8.4Art. 27 – Deployer impact assessment
Internal conformity assessment9.2Art. 43 – Conformity assessment
AI system change control8.4Art. 9.6 – System monitoring and updating
AI competence and training7.2Art. 4 – AI literacy
Transparency towards users8.5Art. 50 – Transparency and user information
Monitoring, metrics and review9.3Art. 72 – Post-market monitoring
Event logging and traceability7.5Arts. 11–12 – Technical documentation and event logging
AI vendor management8.3Art. 25 – Distributor obligations

The practical interpretation of this table: if you correctly implement the ISO 42001 controls listed in the left column, you will have substantially covered the AI Act articles in the right column — not 100%, because the AI Act has sector- and system-specific requirements beyond this, but you will have advanced between 40 and 50% of the way.

When you need both and when just one?

Not all companies are in the same situation or have the same needs. The following decision tree will help you determine the most appropriate strategy for your SME:

Option A: AI Act compliance only (no ISO 42001 certification)

When it makes sense: your company uses low- or minimal-risk AI systems, does not tender for Spanish Public Administration contracts, does not operate in regulated sectors (finance, health, insurance, employment) and has no competitive advantage to gain from external certification.

What it involves: you will need to comply with AI Act obligations according to the phased timetable, but without the cost and effort of formal certification. For many general-services SMEs, this is sufficient in the short term.

The risk: without a formal management system like ISO 42001, it is harder to demonstrate to AESIA or your clients that you have the controls in place. In the event of an inspection, the burden of proof is higher.

Option B: ISO 42001 certification only (without focusing on the AI Act now)

When it makes sense: your company wants competitive differentiation and access to public tenders, but your AI systems are currently low- or minimal-risk under the AI Act, or you have not yet reached the mandatory deadlines for your sector.

What it involves: you obtain the certificate and competitive advantage without waiting for the AI Act to require it. When the legal deadlines arrive, you will already have covered 40–50% of the ground.

The risk: if your AI systems are high-risk under the AI Act, you cannot defer legal compliance. ISO 42001 does not protect you from the Regulation's sanctions.

Option C: Both frameworks integrated (recommended for most)

When it makes sense: you operate in regulated sectors (finance, health, human resources, critical infrastructure), you are a software provider with AI components, you regularly tender for Spanish Public Administration contracts, or you simply want to do things right from the start without having to repeat the work.

What it involves: a single AI governance project that addresses both frameworks in an integrated way, exploiting synergies and avoiding duplication. This is the most economically efficient approach and the one I recommend for the majority of SMEs already making strategic decisions about AI use.

The economic case for integrating both frameworks

A very common question among SME directors and managers is: how much does AI Act + ISO 42001 cost? And, more importantly: does it make sense to do them together or separately?

The economic answer is clear: doing them in an integrated way costs 30 to 40% less than doing them separately. The reason is simple: they share the same base of work.

When you do them together:

Indicative figures for a Spanish SME with 10 to 50 employees and 2–5 AI systems:

The saving is real and significant. Also worth considering are the synergies with ISO 27001: if your company is already certified in information security, approximately 30% of ISO 42001 controls will already be covered or easily extensible from your existing information security management system. This can reduce the ISO 42001 implementation effort by a further 25–35%.

The role of Kit Consulting

For eligible Spanish SMEs, the Kit Consulting programme (managed by Red.es through digital-agent providers) includes the solution for Strategic AI Advisory, with a maximum subsidisable amount of up to €24,000 depending on the company segment.

This advisory service can specifically cover the initial phase of an integrated AI Act + ISO 42001 project: current-state diagnosis, AI systems inventory, AI Act risk classification, gap analysis against ISO 42001, and action plan. In other words, steps 1 to 3 of the roadmap below can be largely funded by Kit Consulting, making the realistic entry point considerably more accessible for many SMEs.

ISO 42001 and public procurement: an emerging competitive advantage

One of the strongest arguments for an SME to obtain ISO 42001 certification before it is strictly required for AI Act compliance is the competitive advantage in the public procurement market.

Spanish Public Administration bodies are in a unique position regarding the AI Act: they are simultaneously deployers of AI systems (with their own legal obligations) and buyers of technology services from private companies. This dual role leads them to increasingly require their technology suppliers to demonstrate AI governance capabilities.

Precedents already exist in regulated European sectors, particularly in finance and healthcare, where ISO 42001 certification has started appearing as an evaluation criterion in public tenders. In Spain, with the progressive application of the AI Act and pressure on contracting bodies to demonstrate regulatory compliance, it is reasonable to expect this pattern to be replicated in the next 12–24 months.

For companies already working with the public sector or aspiring to do so, ISO 42001 certification brings three concrete advantages:

  1. Differentiation in tender specifications: in contracts that value certified management systems, ISO 42001 adds points and can be decisive against uncertified competitors.
  2. Demonstration of proactive compliance: public administration bodies with AI Act obligations prefer suppliers who already have their own controls in place, because it reduces risk for the contracting authority.
  3. Faster due diligence: when a Spanish Public Administration body must audit its AI suppliers (an obligation the AI Act imposes on deployers of high-risk systems), holding a valid ISO 42001 certificate simplifies and accelerates that process.

This trend also connects to the Spanish National Security Framework (ENS, Esquema Nacional de Seguridad): companies that provide digital services to Spanish Public Administration and are already ENS-certified will have an additional advantage when implementing ISO 42001, because many of the risk management and documentation controls are equivalent or complementary between the two frameworks.

How to start: a 4-step roadmap for SMEs

Step 1: AI systems inventory (2–4 weeks)

Before anything else, you need to know exactly which AI systems your company uses or develops. This inventory must include:

The most common surprise in this step is that companies discover they use more AI systems than they thought: AI-integrated recruitment tools, credit scoring systems, website chatbots, predictive analytics tools, fraud detection systems, etc. Many of these can be high-risk under the AI Act without the company having considered it.

Step 2: Risk classification under the AI Act (1–2 weeks)

With the inventory in hand, the next step is to classify each AI system according to the AI Act's risk categories. This classification determines which specific legal obligations apply to each system:

Step 3: Gap analysis against ISO 42001 (2–3 weeks)

With the inventory and classification completed, the third step is to conduct a gap analysis against ISO 42001 requirements. This analysis compares the current state of your AI management controls with what the standard requires and identifies which areas need additional work.

The most common gaps found by SMEs in this analysis are:

Step 4: Integrated remediation plan (3–6 months)

The fourth and final step before starting formal certification is to implement the missing controls, following a plan that simultaneously addresses AI Act and ISO 42001 requirements. The key is not to design two separate projects but a single one with a unified set of documents, a single training programme and a single monitoring system.

The indicative timeline for this step depends on the complexity of your AI systems and your company's size. For an SME of fewer than 25 employees with 2–3 AI systems, it is realistic to complete implementation in 3–4 months. For larger companies or those with more complex systems, 6 months is a realistic target.

Once implementation is complete, the ISO 42001 certification process itself (Stage 1 audit + Stage 2 audit by the certification body) typically takes a further 4–8 weeks.

If you have questions about the best entry point for your company, or want to run the initial AI systems diagnosis together, you can get in touch with me without any commitment. I also recommend reading my guide on the AI Act obligations for your SME in August 2026 for the complete picture of the legal timetable. If your company also works with the Spanish Public Administration, the Spanish National Security Framework (ENS) is another framework worth integrating into your compliance strategy. And if you are already certified or in the process of being certified in ISO 27001, the move to ISO 42001 will be considerably shorter than you might expect.

If after this comparison you want to apply it to your own company, here is everything I cover on the AI Act.

Frequently asked questions about AI Act and ISO 42001

Is ISO 42001 mandatory for AI Act compliance?
No. ISO 42001 is a voluntary standard. The AI Act is mandatory for companies within its scope. However, implementing ISO 42001 covers between 40 and 50% of the AI Act's controls, making it highly efficient to have both frameworks in place in an integrated way.
Does ISO 42001 replace the AI Act?
No. They are complementary, not alternatives. The AI Act is European law with fines of up to €35 million; ISO 42001 is a voluntarily certifiable management system. Implementing ISO 42001 accelerates and facilitates AI Act compliance, but does not legally substitute it. No ISO certificate exempts a company from complying with applicable laws.
How much does ISO 42001 certification cost in Spain?
ISO 42001 certification in Spain ranges from €4,000 to €15,000 for SMEs, depending on company size, the complexity of AI systems and the chosen certification body. To this cost you must add that of prior implementation (consultancy, training, documentation), which can be a further €8,000 to €25,000. Kit Consulting can cover the strategic advisory phase prior to certification, with a maximum amount of up to €24,000.
Are ISO 27001 and ISO 42001 compatible?
Yes, they are highly synergistic and share the common High Level Structure (HLS) common to all ISO management system standards. If your company is already ISO 27001 certified, approximately 30% of ISO 42001 controls will already be covered or easily extensible from your existing information security management system (ISMS). This significantly reduces the time and cost of implementing ISO 42001.
How long does it take to implement ISO 42001 in an SME?
For an SME without prior management systems, between 6 and 12 months from start to certificate. For companies that already have ISO 27001 or ISO 9001, the process can be shortened to 3–6 months thanks to the reuse of existing controls, documentation and methodologies.
Does Kit Consulting cover ISO 42001?
Yes. Kit Consulting includes the AI advisory solution, which can cover the diagnosis phase, AI systems inventory, risk classification and integrated AI Act + ISO 42001 action plan. The maximum amount varies by company segment but can reach up to €24,000. It is important that the selected digital agent has specific expertise in this area to maximise the value of the advisory service.
Which body certifies ISO 42001 in Spain?
The main ENAC-accredited certification bodies offering or preparing ISO 42001 certification in Spain are AENOR, Bureau Veritas, TÜV Rheinland, SGS and Lloyd's Register. It is advisable to request quotes from several bodies, as prices and timelines can vary considerably.
Which SMEs should get ISO 42001 certified first?
Priority candidates are: software or technology service providers with integrated AI components, SMEs that regularly tender for Spanish Public Administration contracts, companies in regulated sectors such as finance, insurance, healthcare or human resources, and any organisation that uses AI systems in decisions that significantly affect people (recruitment, credit, access to services). For these companies, certification delivers immediate competitive advantage in addition to facilitating legal compliance.