AI Governance · From the Auditor's Desk

ISO 42001 for UK businesses: comply before the EU AI Act's August 2026 high-risk deadline

The EU AI Act's high-risk obligations become applicable on 1 August 2026 — and they reach UK companies whose AI output lands in the EU. ISO/IEC 42001 is the fastest structured route to readiness. Here is what the duties require, how the standard maps onto them, and — just as important — where it stops.

Jason Misters · IRCA® Registered Principal Auditor · 17 July 2026

Most UK businesses I speak to have filed the EU AI Act under "not our problem — we left." That is a costly misreading. The Act is extraterritorial by design: it bites where the AI system is placed on the EU market, and where the output of an AI system is used inside the EU. Neither test asks where your company is registered.

So a Portsmouth software firm with Dutch customers is potentially in scope. So is a UK consultancy whose AI-assisted reports are relied on by a client in Dublin. And with the bulk of the high-risk obligations becoming applicable on 1 August 2026, the window to build the governance evidence — not just claim it — is now measured in weeks.

This piece sets out three things: what the high-risk duties actually require, an indicative mapping showing how far ISO/IEC 42001 (the AI management system standard) carries you, and an honest account of the gaps the standard will not close on its own.

The scope test in one line

If an AI system you build, sell, or operate produces output that is used in the EU, assume you are in scope until a documented assessment tells you otherwise — and keep that assessment as evidence.

First: are you actually "high-risk"?

The Act is tiered, not blanket. Most business software is not high-risk. The high-risk category is defined by use case, not by how clever the model is — and it covers AI used in areas such as employment and worker management (CV screening, promotion or task-allocation decisions), access to essential services including creditworthiness assessment, education and vocational training decisions, biometrics, critical infrastructure, and safety components of regulated products.

That last one catches people out. If your AI is a safety component of a product that already falls under EU product-safety legislation, it can be high-risk regardless of how mundane it looks.

The first deliverable, therefore, is not a policy — it is an AI inventory. Every AI system you develop, embed, buy, or operate; what it does; whose data it touches; whether its output reaches the EU; and a reasoned classification against the Act's tiers. Auditors and regulators alike will ask for this before anything else, and "we don't think we're high-risk" is not an answer unless you can show the working.

What the high-risk obligations require

For systems that are high-risk, the Act sets out a cluster of provider duties. In practical terms you need to be able to evidence all of the following:

  • A risk management system running across the whole lifecycle — identifying, evaluating and mitigating foreseeable risks to health, safety and fundamental rights, and revisited as the system changes.
  • Data and data governance — training, validation and testing datasets that are relevant and sufficiently representative, with examination for bias and appropriate governance over how data is collected and prepared.
  • Technical documentation — drawn up before the system goes to market and kept current, in enough depth for an authority to assess conformity.
  • Record-keeping and logging — automatic logging of events over the system's lifetime, sufficient for traceability.
  • Transparency and instructions for use — deployers must be given information clear enough to interpret and use the output properly.
  • Human oversight — designed in, so a competent person can understand, monitor, intervene and override.
  • Accuracy, robustness and cybersecurity — appropriate to the intended purpose, and consistently performing across the lifecycle.
  • A quality management system — the organisational scaffolding that makes all of the above repeatable rather than heroic.

Read that list again and it should feel familiar. It is, almost line for line, the shape of a management system: govern the risk, control the data, document the thing, log what it does, tell people how to use it, keep a human in the loop, test it, and run a QMS over the top.

Where ISO 42001 does the heavy lifting

ISO/IEC 42001:2023 is the international AI management system standard. It uses the same Harmonised Structure as ISO 9001, ISO 14001, ISO 45001 and ISO 27001 — context, leadership, planning, support, operation, performance evaluation, improvement — with an Annex A control set specific to AI: AI policy, internal organisation, resources for AI systems, AI system impact assessment, lifecycle management, data for AI systems, information for interested parties, responsible use, and third-party relationships.

The overlap with the Act's high-risk duties is substantial. This is an indicative mapping — it is a planning aid, not a conformity claim — but it shows why so many UK firms are using 42001 as the delivery vehicle:

EU AI Act high-risk duty Where ISO/IEC 42001 builds it Fit
Risk management system across the lifecycle Clause 6.1 (actions to address risks & opportunities); Annex A AI system impact assessment Strong
Data & data governance, bias examination Annex A — data for AI systems (provenance, quality, preparation) Strong
Technical documentation Clause 7.5 (documented information) + lifecycle documentation controls Partial — structure yes, EU-specified format no
Record-keeping & automatic logging Clause 9.1 (monitoring, measurement, analysis); lifecycle operation controls Partial — the standard expects records; the Act specifies logging
Transparency & information for deployers Annex A — information for interested parties Strong
Human oversight Annex A — responsible use of AI systems; competence (Clause 7.2) Strong
Accuracy, robustness, cybersecurity Lifecycle verification & validation; interfaces with ISO 27001 Annex A for the security half Partial — pair with ISO 27001
Quality management system The whole of ISO 42001 Clauses 4-10 Strong
Conformity assessment, CE marking, EU declaration, EU database registration Not covered
Post-market monitoring & serious-incident reporting to authorities Clause 10 improvement gives the mechanism, not the regulatory reporting duty Partial at best
Treat ISO 42001 as the engine, not the MOT certificate. It builds most of the machinery the Act assumes you already have — but the Act's product-level duties, CE marking, declaration of conformity, database registration and incident reporting to authorities, sit outside the standard entirely.

Be honest about the gap

You will see vendors imply that an AI governance module makes you EU AI Act compliant. It does not, and an assessor will not thank you for repeating it. Three things are worth stating plainly:

ISO 42001 is not a harmonised standard under the Act. Certification does not confer a presumption of conformity in the way a harmonised standard would. It is powerful evidence that you run a disciplined AI management system; it is not a passport.

The product-level duties are genuinely separate. Conformity assessment, the EU declaration of conformity, CE marking and registration in the EU database are regulatory steps with their own process. No management-system standard delivers them.

Roles matter. The Act distributes duties between providers, deployers, importers and distributors. A UK firm that merely uses a third-party high-risk system carries deployer duties — meaningful, but different from a provider's. Getting your role wrong is the fastest way to build the wrong evidence pack.

A practical sequence for the next few weeks

1

Build the AI inventory

List every AI system you develop, embed, buy or operate. Capture purpose, data used, who relies on the output, and whether that output reaches the EU. This single artefact drives everything downstream.

2

Classify and record your role

For each system: which tier, and are you provider or deployer? Write down the reasoning. A defensible "not high-risk" conclusion is worth as much as a compliance project — but only if it is documented.

3

Run an AI system impact assessment

For anything high-risk or borderline, assess the risks to health, safety and fundamental rights, and record the mitigations. This is the 42001 Annex A control that most directly answers the Act's risk-management duty.

4

Fix the data governance evidence

Provenance, representativeness, bias examination, preparation steps. This is where most organisations are thinnest, and it is the hardest to reconstruct retrospectively.

5

Wire in logging and human oversight

Traceable logs over the system's lifetime, and a named competent person who can interpret, monitor, intervene and override — with the training record to prove competence.

6

Put the obligation on your legal register

Record the Act itself, your role, the applicable articles and the 1 August 2026 milestone, with a review date. If you hold ISO 27001, control A.5.31 already expects this discipline — extend it to AI.

Why this pairs so well with ISO 27001

Almost every UK organisation I take through 42001 already holds, or is working towards, ISO 27001. That is fortunate, because the Act's accuracy-robustness-cybersecurity requirement is half an information-security problem, and the transparency and documentation duties lean on records discipline you have already built.

Because both standards share the Harmonised Structure, you are not running two management systems. You are extending one: the same context, leadership, competence, documented-information, internal-audit and management-review machinery, with an AI-specific Annex A layered on top. In practice that turns a daunting programme into an extension of something already certified — which is the difference between a nine-month project and a focused quarter.

Doing it in PICMS

This is precisely the problem PICMS was built for. The platform ships the ISO 42001 Annex A control set alongside ISO 27001's 93 Annex A controls, so the AI management system sits next to the information security management system rather than in a separate silo. The legal register carries the EU AI Act as a tracked obligation with its own review date, and AI evidence mapping links the documents you already hold to the controls they satisfy — so when an assessor asks "show me your AI impact assessment and the data-governance evidence behind it", the answer is a filter, not a fortnight.

To be plain about what software does and does not do: PICMS does not make you compliant, and this article is general guidance rather than legal advice. What it does is hold the obligation on your register, keep the control set and its evidence current, and make the gap between where you are and where 1 August 2026 requires you to be visible while there is still time to close it.

Jason Misters — IRCA® Registered Principal Auditor

Lead auditor and ISO consultant. Founder of Training Assurance Consultancy and PICMS. Writes from years of hands-on experience implementing and auditing management systems in UK businesses. Verifiable on the CQI-IRCA register.

Get your AI management system evidenced before August.

PICMS ships the ISO 42001 Annex A control set alongside ISO 27001, tracks the EU AI Act on your legal register, and maps your existing evidence to the controls it satisfies.

Start a Free Trial Book a Demo