As organisations throughout Azerbaijan and the wider region speed up AI adoption, two key compliance frameworks have become essential benchmarks: ISO/IEC 42001, the first international standard for AI management systems, and the EU AI Act, the first binding, comprehensive regulation specifically for AI. While both focus on governance and risk management, they vary notably in scope, legal standing, and audit approach. Recognising these differences is crucial for organisations working internationally or with EU-related clients.
What Is ISO 42001
ISO/IEC 42001:2023 is a voluntary, certifiable management system standard that governs how an organisation establishes, implements, maintains, and continually improves an Artificial Intelligence Management System (AIMS), addressing ethical, organisational, and technical considerations across the entire AI lifecycle. Critically, it certifies the management system used to govern AI , not a specific AI model, vendor, or tool, meaning it focuses on accountability structures, risk identification processes, and evidence of repeatable controls rather than technical performance benchmarks. It follows the same Annex SL structure as ISO 27001, which makes integration with existing information security management systems straightforward for organisations that already hold ISO certifications.
The ISO 42001 Audit Process
An ISO 42001 audit follows a structured, multi-stage certification lifecycle rather than a single event.
- Gap assessment: reviewing current AI governance practices against Annex A controls and defining scope, producing a readiness report and prioritised remediation plan.
- System design and implementation: building the AI governance framework, including policies, role accountability, and an AI risk register.
- Internal audit: verifying that controls are operating as designed and generating audit evidence, findings logs, and corrective actions.
- Certification audit (Stage 1 and Stage 2): an external review by an accredited certification body culminating in an audit report and certification decision.
- Ongoing surveillance and recertification: continuous monitoring, periodic surveillance audits, and improvement tracking.
An effective audit examines five core areas: a clearly defined scope with governance roles and decision rights, a consistent AI risk classification methodology, documented evidence that Annex A controls function in practice (not just on paper), a management review cadence with change history, and traceable corrective action closure.
What Is the EU AI Act
The EU AI Act, Regulation (EU) 2024/1689, came into force on 1 August 2024. It is a mandatory legal framework that categorises AI systems into risk levels: prohibited, high-risk, limited-risk, and minimal-risk, and sets specific obligations for providers and users based on these categories. Unlike ISO 42001, compliance is not optional for organisations deploying or marketing AI systems in the EU. Failure to comply can result in legal penalties, and high-risk systems must undergo mandatory conformity assessments and obtain CE marking before they can be marketed.
The EU AI Act Audit and Conformity Assessment Process
Conformity assessment routing depends on the AI system's classification: systems complying with harmonised standards may proceed via self-assessment (Annex VI), while those without applicable harmonised standards and all biometric or critical-infrastructure systems require third-party assessment by a designated Notified Body (Annex VII). For providers of high-risk systems, the audit examines seven core obligation areas:
Risk management system: a documented process for identifying, analysing, and mitigating risks across the AI lifecycle.
Risk management system: a documented process for identifying, analysing, and mitigating risks across the AI lifecycle.
- Data governance: quality, representativeness, and accuracy requirements for training data, plus provenance documentation for pre-trained/fine-tuned models.
- Technical documentation: architecture, training procedures, performance metrics, testing results, and known limitations.
- Record-keeping: automatic logging of relevant events to ensure decision traceability.
- Transparency: clear instructions enabling deployers to use the system correctly.
- Human oversight: technical measures enabling effective human monitoring and intervention.
- Accuracy, robustness, and cybersecurity: reliable performance and resilience against manipulation.
Providers must also implement a quality management system (QMS) covering design/development procedures, post-market monitoring, incident management, and AI supplier/API dependency management and ISO 42001 is increasingly recognised as the de facto standard for satisfying this QMS requirement. This overlap is strategically important: organisations that build an ISO 42001-certified AIMS create a substantial portion of the documentary and procedural evidence needed for EU AI Act conformity assessment, reducing duplicated audit effort.
Key Differences for Audit Planning
| Dimension | ISO 42001 | EU AI Act |
| Legal status | Voluntary international standard | Binding EU regulation with penalties |
| Certifies | Management system/governance process | Specific AI systems and their conformity |
| Assessor | Accredited certification body | Notified Body (high-risk) or self-assessment |
| Current deadline pressure | Ongoing/voluntary uptake | Annex III: Dec 2027; Annex I: Aug 2028 |
| Primary output | Certificate + surveillance audits | CE marking + EU database registration |
For clients approaching either audit, the practical recommendation is to pursue ISO 42001 certification first as a governance foundation, then layer EU AI Act-specific technical documentation, risk management, and conformity assessment work on top, leveraging the shared evidence base to accelerate both processes.

