| ISO/IEC 42001 7.2 | EU AI Act: AI literacy duty | Art. 4 literacy training feeds 7.2, but ISO also requires documented competence determination and evidence for all AIMS roles (assessors, auditors, leadership). |
| ISO/IEC 42001 7.3 | EU AI Act: AI literacy duty | Awareness of the AI policy and the consequences of nonconformance supports staff literacy but is not role-specific AI training. |
| ISO/IEC 42001 A.8 | EU AI Act: AI interaction disclosure | A.8 user-information processes are the natural home for interaction disclosure, but Art. 50(1) requires a specific in-product notice at or before first interaction. |
| ISO/IEC 42001 A.8 | EU AI Act: Deep fake disclosure | Transparency-to-affected-parties processes support deep-fake labelling, but the specific disclosure duty and its artistic-works carve-out have no ISO clause equivalent. |
| ISO/IEC 42001 A.8 | EU AI Act: Public-interest text disclosure | Disclosures for AI-generated public-interest text can ride on A.8 communication processes, but the publication duty and its editorial-review exemption are EU-specific. |
| ISO/IEC 42001 A.8 | EU AI Act: Emotion & biometric notification | Informing exposed persons that the system operates fits A.8 information duties; lawful biometric-data processing under GDPR requires separate work. |
| ISO/IEC 42001 A.6 | EU AI Act: GPAI technical documentation | A.6 life-cycle technical-documentation practice supplies the habit, but Annexes XI/XII prescribe specific model documentation content the standard does not. |
| ISO/IEC 42001 A.8 | EU AI Act: GPAI technical documentation | Providing system information to downstream integrators is an A.8 interested-party information duty; Art. 53 fixes the exact content and recipients. |
| ISO/IEC 42001 A.7 | EU AI Act: GPAI copyright & training summary | Documented data provenance and acquisition processes feed the training-content summary, but the copyright policy and the public summary itself are additional artifacts. |
| ISO/IEC 42001 6.1.2 | EU AI Act: Systemic-risk GPAI duties | A defined AI risk assessment process supports systemic-risk assessment, but Art. 55 also demands model evaluations, adversarial testing, and Commission notification. |
| ISO/IEC 42001 A.6 | EU AI Act: Systemic-risk GPAI duties | A.6 verification-and-validation practice contributes to the required model evaluations, not to the adversarial-testing, incident-reporting, or cybersecurity duties. |
| ISO/IEC 42001 A.8 | EU AI Act: Systemic-risk GPAI duties | A.8 incident-reporting processes support serious-incident reporting, but Art. 55 sets specific recipients and timelines. |
| ISO/IEC 42001 4.4 | EU AI Act: High-risk provider obligations | An operating AIMS supplies much of the Art. 17 quality-management-system skeleton, but the Act prescribes elements (conformity procedures, post-market plan) the standard does not. |
| ISO/IEC 42001 6.1.2 | EU AI Act: High-risk provider obligations | The ISO risk assessment process is the backbone of the Art. 9 risk-management system, which is one component of the conformity bundle. |
| ISO/IEC 42001 A.6 | EU AI Act: High-risk provider obligations | A.6 life-cycle controls produce technical documentation and verification evidence toward Arts. 11 and 15, a fraction of the full package. |
| ISO/IEC 42001 A.7 | EU AI Act: High-risk provider obligations | A.7 data management maps to the Art. 10 data-governance duty but not to the specific training/validation/test data criteria the Act prescribes. |
| ISO/IEC 42001 A.3 | EU AI Act: High-risk deployer duties | Defined AI roles and life-cycle accountability support assigning human oversight, one element of the Art. 26 bundle. |
| ISO/IEC 42001 A.6 | EU AI Act: High-risk deployer duties | Operation-and-monitoring stage processes contribute to the monitoring duty; log retention, worker notification, and input-data checks remain. |
| ISO/IEC 42001 A.9 | EU AI Act: High-risk deployer duties | Responsible-use-per-intended-purpose processes directly support using the system per the provider's instructions, but the other Art. 26 duties remain. |
| ISO/IEC 42001 6.1.4 | EU AI Act: Fundamental rights impact assessment | A one-shot pre-use FRIA contributes to 6.1.4 but is not its repeatable lifecycle impact-assessment process; reverse misses Art. 27 prescribed fields and the authority notification. |
| ISO/IEC 42001 A.5 | EU AI Act: Fundamental rights impact assessment | A single FRIA contributes to A.5 but not its established lifecycle assessment process across the AI portfolio; reverse misses Art. 27 content and the market-surveillance notification. |
| ISO/IEC 42001 8.4 | EU AI Act: Fundamental rights impact assessment | Re-performing impact assessments on significant change keeps a FRIA current, but the initial pre-use assessment must exist first. |
| ISO/IEC 42001 A.10 | EU AI Act: Importer duties for high-risk AI | Supply-chain requirements management supports verifying provider conformity, but CE-mark checks, labelling, and 10-year retention are EU-specific. |
| ISO/IEC 42001 A.10 | EU AI Act: Distributor duties for high-risk AI | Third-party assurance processes support distributor verification, but the CE-marking checks and market-surveillance cooperation duties are EU-specific. |