EU AI Act ↔ ISO/IEC 42001
9 canonical controls in Keel's library satisfy clauses of both EU AI Act and ISO/IEC 42001. Implement each once, attach the evidence once, and it counts toward each standard. The overlap is the work you don't repeat.
Controls that satisfy both
| Canonical control | EU AI Act clauses | ISO/IEC 42001 clauses |
|---|---|---|
| AI system inventory A maintained inventory of the AI systems the organization develops, deploys, or uses, with each system's purpose, owner, and risk classification. | HOBL-5 | A.4.2 |
| AI system impact assessment A process to assess the potential impacts of AI systems on individuals, groups, and society, and to document and act on the results. | HREQ-1 | A.5.2, A.5.4 |
| Human oversight of AI Appropriate human oversight of AI systems, so people can understand, monitor, and intervene in how an AI system operates. | HREQ-6 | A.6.2.6, A.9.2 |
| Data governance for AI Governance of the data used to develop and operate AI systems: sourcing, quality, provenance, and preparation of training and operational data. | HREQ-2 | A.4.3, A.7.2, A.7.3, A.7.4, A.7.5, A.7.6 |
| AI verification, validation & robustness Testing that an AI system meets its requirements and performs with appropriate accuracy, robustness, and security before and during use. | HREQ-7 | A.6.2.4 |
| AI technical documentation Maintained technical documentation of an AI system’s design, development, and impact assessments, sufficient to demonstrate how it works and was built. | HREQ-3 | A.5.3, A.6.2.7 |
| AI system logging & record-keeping Automatic recording of events over an AI system’s lifetime, retained to support traceability, monitoring, and post-incident review. | HREQ-4 | A.6.2.8 |
| AI transparency & disclosure Clear information for users and interested parties, including disclosing when people are interacting with an AI system and how to use it appropriately. | TRANS-1, HREQ-5 | A.8.2, A.8.5 |
| AI monitoring & malfunction reporting Ongoing monitoring of AI systems in operation, with a process to detect, communicate, and report malfunctions and serious incidents. | HOBL-6, HOBL-7 | A.6.2.6, A.8.4 |
Clause identifiers (EU AI Act and ISO/IEC 42001) are referenced factually for mapping. Keel is not affiliated with or endorsed by the bodies that publish these standards. Control descriptions are Keel's own; a framework's full authored control count is on its framework page.
Why this is one project, not two
On a crosswalk-native model, ISO/IEC 42001 mostly lights up controls you already built for EU AI Act. You're not re-uploading the same screenshot for a second audit. You apply the framework and see the genuine delta worth working. That's the whole idea behind collect once, comply everywhere.