Security

Real offensive depth

Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Compliance

ISO 42001 vs the EU AI Act: How They Fit Together

ISO 42001 is a certifiable management system standard for how an organization governs artificial intelligence, while the EU AI Act is binding law that sets legal obligations based on an AI system's risk level. They are not competing frameworks: ISO 42001 gives you the operational structure to actually meet what the EU AI Act demands, and increasingly, regulators and customers treat certification as evidence of good-faith compliance.

For Canadian companies building or deploying AI, whether that's a healthtech startup in Toronto or a fintech scale-up in Waterloo selling into Europe, this distinction matters more than it looks. One is a governance blueprint you choose to adopt. The other is law you may be forced to follow the moment a European user touches your product. Understanding how they fit together is the difference between building an AI program once, correctly, and rebuilding it twice under deadline pressure.

What ISO 42001 Actually Certifies

ISO/IEC 42001 is the first international standard for an Artificial Intelligence Management System (AIMS). Like ISO 27001 for information security, it does not tell you which AI model to use or how accurate it must be. It tells you how to run a management system around AI: risk assessment, impact assessment, data governance, human oversight, incident response, supplier management for third-party models, and continuous monitoring.

An organization gets audited against ISO 42001 by an accredited certification body and, if it passes, holds a certificate that is renewed annually with periodic surveillance audits. That certificate is portable. It means something to a procurement team in Boston, a regulator in Brussels, or a board in Calgary, because it is issued against a fixed, internationally recognized set of controls.

What the EU AI Act Actually Requires

The EU AI Act is a regulation, not a voluntary standard. It classifies AI systems into risk tiers, unacceptable risk (banned outright), high-risk, limited-risk, and minimal-risk, and attaches specific legal obligations to each tier. High-risk systems (think hiring tools, credit scoring, medical device AI, critical infrastructure controls) carry the heaviest load: conformity assessments, technical documentation, human oversight requirements, data quality obligations, and post-market monitoring.

Crucially, the Act applies extraterritorially. A Canadian SaaS company with no EU office can still fall under it if its AI-powered product is used by people in the EU or its output affects EU residents. That catches a lot of Canadian B2B software companies expanding south and east that assumed the Act was someone else's problem.

Where the Two Actually Map to Each Other

This is the part most articles skip. ISO 42001's clauses were written with an eye toward regulatory alignment, and the overlap with the EU AI Act's Article 9 (risk management system) and Article 17 (quality management system) requirements for high-risk AI is substantial:

  • Risk management: ISO 42001's ongoing AI risk assessment process (Clause 6) covers most of what Article 9's risk management system demands, including identification of foreseeable misuse.
  • Documentation and traceability: ISO 42001's requirement for documented information on data provenance and model changes lines up with the Act's technical documentation obligations.
  • Human oversight: Both frameworks require named human oversight mechanisms rather than "fully automated with no override."
  • Data governance: ISO 42001 Annex A controls on data quality and bias assessment map closely to the Act's data governance requirements for high-risk systems.
  • Post-deployment monitoring: Both require you to keep watching the system after launch, not just at the certification or conformity assessment moment.

What ISO 42001 does not do is replace the EU AI Act's legal conformity assessment for high-risk systems, that's a specific regulatory process with its own paperwork. But holding ISO 42001 certification means most of the underlying governance work is already done, so the conformity assessment becomes a documentation exercise instead of a build-from-scratch project.

Where NIST AI RMF Fits Alongside Both

Canadian and US-facing companies often layer in the NIST AI Risk Management Framework as well, particularly if US enterprise buyers ask for it during due diligence. NIST AI RMF is voluntary and US-originated, but its four functions (Govern, Map, Measure, Manage) sit comfortably inside an ISO 42001 AIMS. In practice, we build the AIMS once and cross-reference it against ISO 42001 clauses, EU AI Act articles, and NIST AI RMF functions in a single control matrix, so a company doesn't run three separate governance programs for three audiences that are really asking for the same evidence in different formats.

Why Canadian Companies Can't Ignore Either One

Canada doesn't have an EU AI Act equivalent in force yet, but that doesn't mean Canadian companies are exempt. Ontario tech firms selling into the EU, Quebec companies already navigating Law 25's data governance requirements, and Vancouver or Ottawa startups embedding AI features into products sold to US enterprise buyers are all facing the same pressure from a different direction: customers and regulators want proof of AI governance, not a promise.

We're also seeing procurement teams at larger enterprises add "AI governance certification" to vendor security questionnaires the same way they added SOC 2 a decade ago. If your product touches AI in any customer-facing way, ISO 42001 is becoming table stakes for enterprise sales cycles the way SOC 2 already is for SaaS.

How to Sequence a Certifiable AI Governance Program

The order that works best for most clients:

  • Scope the AIMS. Identify which AI systems, in-house models, embedded third-party models, or vendor tools, fall inside the management system boundary.
  • Classify against the EU AI Act risk tiers even if you have no current EU exposure, because it forces you to think about impact before a regulator does it for you.
  • Build the AIMS controls (risk assessment, data governance, human oversight, incident response) to ISO 42001 Annex A.
  • Cross-map to NIST AI RMF if US enterprise sales require it.
  • Run an internal audit, then the external certification audit.

This sequencing means a single governance build satisfies a certifiable standard, a legal regulation you may already be subject to, and a voluntary framework your biggest customers might ask about, without three separate projects.

Building This Alongside Existing Compliance Work

Most companies we work with are not starting from zero. They already hold or are pursuing SOC 2, and the AIMS should plug into that existing compliance program rather than sit beside it as a separate silo. Shared evidence, shared audit calendar, shared risk register. That's the boutique advantage over a pure software checklist tool: someone actually maps the overlap instead of leaving you to reconcile three spreadsheets.

Get ISO 42001 Ready Without the Guesswork

traztech runs ISO 42001 readiness engagements for Canadian companies that need to move fast on AI governance, whether the driver is EU AI Act exposure, enterprise procurement pressure, or getting ahead of Canadian regulation before it lands. We work with teams in Toronto, Waterloo, Ottawa, Montreal, Calgary, and Vancouver, in person where it helps and remotely where it doesn't matter. If you're not sure whether you need ISO 42001, EU AI Act conformity work, or both, contact us and we'll map your actual exposure before recommending a scope.

Not ready for a call? Same.

Get the playbook, not a sales pitch

If this was useful, Jacob sends a few short, practical notes on locking down your startup without a big security team. No fluff, unsubscribe in one click. Just reply if you want to talk; it reaches him directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Need help with any of this?

We help startups build secure, scalable infrastructure. Book a free strategy call and let's talk about your stack.

Book a free consultation