
"Our customers ask us for ISO 42001, and our AI screens candidates. Does that make us compliant with the AI Act?"
They are two standards for two questions. ISO/IEC 42001 sets out how an organisation governs its AI. EN 18286 sets out how a high-risk AI product is made. They are easier to understand together, and with a case.
ISO 42001 and EN 18286, question by question
- What for
- ISO/IEC 42001For processes: how the organisation governs all the AI it uses or develops.
- EN 18286For the product: the high-risk AI system placed on the market.
- Who for
- ISO/IEC 42001For those who deploy AI and those who produce it: any organisation that uses, develops or offers it.
- EN 18286Only for those who produce it: the provider of a high-risk system, which is who Article 17 applies to.
- Shown to whom
- ISO/IEC 42001An accredited certification body. Customers, boards and tenders ask for the certificate.
- EN 18286The product's conformity assessment, carried out by the provider or by a notified body depending on the system.
- Since when
- ISO/IEC 42001In force since December 2023. Its European version, with the same text, since March 2026.
- EN 18286Published by CEN in July 2026. Article 17 applies to Annex III high-risk systems from 2 December 2027.
- Presumption of conformity
- ISO/IEC 42001None, even with an EN version: it was not prepared for the AI Act.
- EN 18286It will give presumption of conformity once its reference is published in the OJEU, for what it covers of Articles 8 to 15. For Article 17, the AI Act does not provide for it.
- What they share
- Both are management systems: policy, responsibilities, objectives, resources, documented information and management review. They are built once.
- How they fit together
- EN 18286 organises how the high-risk system is built; ISO 42001, how the organisation uses it in its processes. Whoever builds and uses its own AI needs both.
A case: a full-stack HR company
An HR company does everything. It builds its own AI, uses it to select candidates and presents the candidates that come out of that process to its customers. The AI publishes job offers on its website and targets them at the right profiles, analyses incoming applications, filters them and ranks the candidates for each vacancy. For the candidates, it also runs a transparency portal.
As provider: its AI, under EN 18286
Placing targeted job advertisements, analysing and filtering applications and evaluating candidates is, almost word for word, the first employment use case in Annex III, point 4(a): high-risk AI. The company built it and puts it into service under its own name, so it is its provider, and Article 17 requires a quality management system for that product.
That is where EN 18286 comes in, built around the product rather than the organisation. It walks through what the system needs: design and development, verification and validation, data management, post-market monitoring, serious incident reporting and change control. For an employment system, the conformity assessment is the internal control of Annex VI: the company itself verifies that its quality system meets Article 17, and the market surveillance authority can ask for the evidence.
As user: the selection, within ISO 42001
The same company uses its AI to decide which candidates it presents to each customer, so it is also its deployer. That use is an organisational process, and ISO 42001 is the standard that organises it: who oversees what the system proposes, what risks the selection carries for candidates and for the business, what happens when someone complains, and how the company checks that everything works as decided.
It is also what its customers look at. They receive candidates, they do not use the system, and they want to know that the process that selected them can be trusted. The ISO 42001 certificate shows them that.
For the candidates: a transparency portal
The candidates are the people affected. The portal tells them that an AI takes part in their selection, what it does and how to ask for a person to review their case. It answers the AI Act and ISO 42001 at once. As deployer, the company has to inform the people the system decides on or helps decide on (Article 26(11)), and Article 86 gives them a right to an explanation of decisions that significantly affect them. ISO 42001 covers it among its controls as information for interested parties.
What they share and how they fit together
The company builds one system for both standards. The final draft of EN 18286 submitted to formal vote (FprEN 18286, May 2026), which is the text we have read, also includes a table mapping it to ISO 42001 clause by clause. What changed between the enquiry draft and the published text is summarised here.
The ISO 42001 certificate answers customers; the product's quality system and its technical file answer the authority; the portal answers the candidates. None replaces the others.
One piece is left to fit: risk. In the draft's table, the risk part of the quality system carries the note "Subject to use of a risk management system compliant with Article 9" (FprEN 18286, Annex ZA, Table ZA.1). The European standard for Article 9, prEN 18228, was not approved at enquiry and is back with its working group. In the meantime, the method is the ISO/IEC 23894 guidance.
What neither gives yet
Presumption of conformity. As of this article, we are not aware of any reference published in the Official Journal under the AI Act. EN ISO/IEC 42001:2026 is the 2023 ISO text adopted in Europe, and the EN prefix does not turn it into a route to presumption. And the presumption granted by Article 40 reaches, for high-risk systems, the product requirements of Articles 8 to 15; Article 17 falls outside that paragraph.
The status of each requirement and its standard is in the high-risk pillar table.
Proof, not promises.
— Rodrigo