Audience: Organizations with or pursuing ISO/IEC 42001 certification, EU AI Act compliance teams, certification bodies (BSI, RvA, ANAB), Notified Body assessors, procurement teams evaluating vendor AI certifications, and quality managers aligning management systems with European regulatory requirements.

Assessor notice: This guide covers the EN harmonization of ISO/IEC 42001 -- the process by which an international standard is adopted as a European Norm and gains legal significance under EU legislation. It does not replace the clause-by-clause crosswalk. For detailed clause mapping, see the ISO 42001 Crosswalk. For assessor workpapers, see the ISO 42001 Assessor Workpaper.

Status: GREEN -- EN adoption underway, national adoption by September 2026. CEN-CENELEC has initiated the EN adoption process for ISO/IEC 42001. National standards bodies across EU and EEA member states must adopt the standard by September 2026. Once cited in the Official Journal of the European Union, EN ISO/IEC 42001 will create a legal presumption of conformity with relevant EU AI Act obligations.

Quick Reference

EN adoption date2026 (CEN-CENELEC harmonization process initiated)
National adoption deadlineSeptember 2026 -- all CEN-CENELEC members must publish as national standard
Relationship to EU AI ActPresumption of conformity with Article 9 (risk management), Article 17 (quality management), and related obligations once cited in the Official Journal
Certified organizationsAWS, Anthropic, Microsoft, SAP, Cornerstone OnDemand, and others
Certification validity3 years (with annual surveillance audits)
Base standardISO/IEC 42001:2023 -- AI Management System (AIMS)
Accredited certification bodiesBSI (UK/UKAS), RvA (Netherlands), ANAB (US), and national accreditation body-approved CBs

Contents

1. What EN Harmonization Means 2. The EU AI Act Bridge 3. Three-Way Mapping: ISO 42001, EU AI Act, SWT3 4. Procedure Cards 5. Certification and Procurement Considerations 6. Quick Start 7. References

1. What EN Harmonization Means

When an international standard is adopted as a European Norm (EN), it undergoes a formal process managed by CEN-CENELEC (the European Committee for Standardization and the European Committee for Electrotechnical Standardization). This process transforms a voluntary international standard into a document with specific legal significance within the European single market.

European Norm Status

An EN-prefixed standard carries obligations that its ISO counterpart does not:

The practical result: once EN ISO/IEC 42001 is adopted, all 34 CEN-CENELEC member countries will have an identical AI management system standard, eliminating fragmentation across the European market.

Presumption of Conformity

The most significant legal consequence of EN harmonization occurs when the European Commission cites the standard in the Official Journal of the European Union (OJEU). Once cited, compliance with the EN creates a presumption of conformity with the corresponding EU AI Act obligations. This means:

This is not automatic compliance. The presumption is rebuttable, and the EN may not cover every EU AI Act obligation. However, it provides the strongest available baseline for demonstrating regulatory alignment.

National Adoption Timeline

The September 2026 deadline requires all CEN-CENELEC national members to:

Organizations already certified to ISO/IEC 42001:2023 will hold a certification that is technically identical to the EN version. No re-certification is required -- the content is the same. The EN adoption changes the legal status, not the technical content.

2. The EU AI Act Bridge

ISO/IEC 42001 was designed as a general-purpose AI management system standard, applicable globally. The EU AI Act imposes specific obligations on providers and deployers of AI systems within the European market. EN harmonization creates a bridge between these two frameworks -- allowing organizations to satisfy EU regulatory requirements through an internationally recognized certification.

How ISO 42001 Addresses EU AI Act Obligations

The following EU AI Act obligations are directly addressed by ISO/IEC 42001 clauses and annexes:

What EN Harmonization Adds

Organizations already certified to ISO/IEC 42001 gain three advantages from EN harmonization:

3. Three-Way Mapping: ISO 42001, EU AI Act, SWT3

The table below maps ISO/IEC 42001 clauses to the corresponding EU AI Act article and the SWT3 witness procedure that produces evidence of implementation. Each row represents a requirement that spans all three frameworks -- the management system clause defines the process, the EU AI Act article defines the legal obligation, and the SWT3 procedure generates cryptographic evidence that the process executed.

ISO 42001 Clause EU AI Act Article SWT3 Procedure
6.1.2 -- AI risk assessment Art. 9 -- Risk management system AI-GOV.1 -- Governance policy witness
9.2 -- Internal audit Art. 17 -- Quality management system AI-AUDIT.1 -- Audit log integrity
Annex B.2 -- Data quality for AI Art. 10 -- Data and data governance AI-DATA.1 -- Data provenance witness
7.3 -- Awareness Art. 13 -- Transparency and information AI-TRANS.1 -- Transparency disclosure
6.1.4 -- AI risk treatment Art. 9(4) -- Risk mitigation measures AI-SEC.1 -- Security boundary witness
Annex B.5 -- AI system lifecycle Art. 9(1) -- Risk management system AI-LCM.1 -- Lifecycle stage witness
10.1 -- Continual improvement Art. 72 -- Post-market monitoring AI-DRIFT.1 -- Statistical drift detection
Annex B.7 -- Third-party and supplier management Art. 28 -- Obligations of deployers (provider duties) AI-SUPPLY.1 -- Supply chain witness
Annex B.3 -- Bias management Art. 10(2)(f) -- Bias examination and mitigation AI-FAIR.1 -- Fairness and bias witness
8.4 -- AI system impact assessment Art. 27 -- Fundamental rights impact assessment AI-IMPACT.1 -- Impact assessment witness
9.1 -- Monitoring, measurement, analysis Art. 9(2) -- Testing and validation AI-PERF.1 -- Performance benchmark witness
8.2 -- AI system lifecycle processes Art. 14 -- Human oversight AI-HITL.1 -- Human-in-the-loop witness

Each SWT3 procedure produces a timestamped, SHA-256 fingerprinted witness anchor. The anchor records that the corresponding process executed, when it executed, and with what observable parameters -- without prescribing how the organization implements the underlying control. This separation between the management system (ISO 42001), the legal obligation (EU AI Act), and the evidence layer (SWT3) allows organizations to maintain a single evidence chain that satisfies all three frameworks simultaneously.

4. Procedure Cards

AI-GOV.1

Governance Policy Witness

Records the existence and version of an organization's AI governance policy. Maps to ISO 42001 Clause 6.1.2 (AI risk assessment) and EU AI Act Article 9 (risk management system). The witness anchor captures policy version, approval date, and scope -- providing auditors with evidence that governance structures are documented and current.

ISO 42001 relevance: Clause 6.1.2 requires organizations to identify and assess risks specific to their AI systems. The governance policy defines the organizational framework within which risk assessment occurs. Auditors verify that the policy exists, is approved by leadership (Clause 5.1), and is communicated to relevant parties (Clause 7.4).

Assessor Tip

During a Stage 2 audit, request the AI-GOV.1 anchor chain for the past 12 months. Verify that policy reviews occurred at least annually (Clause 10.1 continual improvement) and that the governance scope covers all AI systems within the AIMS boundary (Clause 4.3). A gap in the anchor chain may indicate a lapsed governance review cycle.

AI-AUDIT.1

Audit Log Integrity

Witnesses the integrity of audit trail records for AI system operations. Maps to ISO 42001 Clause 9.2 (internal audit) and EU AI Act Article 17 (quality management system). The witness anchor captures entry count, tamper detection result, and log integrity proof.

ISO 42001 relevance: Clause 9.2 requires internal audits at planned intervals to determine whether the AIMS conforms to organizational requirements and is effectively implemented. AI-AUDIT.1 provides cryptographic evidence that audit logs themselves have not been altered -- a critical control for audit credibility.

Assessor Tip

Verify that AI-AUDIT.1 anchors show consistent entry counts over time. A sudden drop in entry count between consecutive anchors may indicate log truncation or deletion. Cross-reference the tamper detection factor (factor_b) -- a value of 0 indicates tamper detection passed; 1 indicates a potential integrity issue requiring investigation.

AI-DATA.1

Data Provenance Witness

Records provenance and quality metadata for AI training, validation, and testing data. Maps to ISO 42001 Annex B.2 (data quality for AI) and EU AI Act Article 10 (data and data governance). The witness anchor captures data source, quality metrics, and lineage information.

ISO 42001 relevance: Annex B.2 requires organizations to define and implement data quality criteria appropriate to their AI systems. AI-DATA.1 provides evidence that data governance processes are active -- not merely documented -- by recording provenance metadata each time data flows through the AI pipeline.

Assessor Tip

For organizations processing personal data, cross-reference AI-DATA.1 anchors with the organization's data protection impact assessment (DPIA) records. Article 10 of the EU AI Act requires that training data meet quality criteria including representativeness. The data provenance witness provides a starting point for verifying that data governance controls are operational.

AI-DRIFT.1

Statistical Drift Detection

Monitors AI model behavior over time and records deviations from baseline performance. Maps to ISO 42001 Clause 10.1 (continual improvement) and EU AI Act Article 72 (post-market monitoring). The witness anchor captures drift metrics, statistical deviation measurements, and threshold status.

ISO 42001 relevance: Clause 10.1 requires organizations to continually improve the suitability, adequacy, and effectiveness of their AIMS. Drift detection is the operational mechanism that triggers improvement actions when model behavior degrades. Without drift monitoring, the continual improvement process lacks an objective signal.

Assessor Tip

Request the AI-DRIFT.1 anchor chain alongside the organization's nonconformity register (Clause 10.2). Drift events that exceeded defined thresholds should have corresponding nonconformity records with root cause analysis and corrective actions. The absence of any drift-triggered nonconformities over a 12-month period may warrant further investigation -- either the thresholds are too loose, or the monitoring system is not functioning as intended.

5. Certification and Procurement Considerations

For Certified Organizations

Organizations already certified to ISO/IEC 42001:2023 should:

For Procurement Teams

When evaluating vendor AI certifications:

6. Quick Start

Organizations can begin generating SWT3 witness evidence for their ISO 42001 controls immediately. Every wrap() call in the SDK produces a witness anchor that maps to the procedures listed in the three-way mapping table above.

Python

pip install swt3-ai

from swt3_ai import Witness
witness = Witness(api_key="your-key", tenant_id="your-tenant")
wrapped = witness.wrap(client) # OpenAI, Anthropic, Bedrock, LiteLLM

TypeScript

npm install @tenova/swt3-ai

import { Witness } from '@tenova/swt3-ai';
const witness = new Witness({ apiKey: 'your-key', tenantId: 'your-tenant' });
const wrapped = witness.wrap(client); // OpenAI, Anthropic, Bedrock

Every inference through the wrapped client produces a SWT3 Witness Anchor. Anchors accumulate into your evidence chain automatically. Named witness methods -- witness_drift(), witness_audit_integrity(), witness_data_provenance() -- generate evidence for specific ISO 42001 clauses without additional configuration.

Full SDK documentation: sovereign.tenova.io/docs

Create a free account: sovereign.tenova.io/signup

7. References