Appearance
EN 18286 vs ISO/IEC 42001
EN 18286:2026 and ISO/IEC 42001:2023 are the two management-system standards an EU-focused AI provider is most likely to weigh against each other, and the comparison is close enough to be genuinely confusing: both govern AI through a clauses 4–10 management system, and EN 18286's own Annex C maps its clauses to EN ISO/IEC 42001:2026. The short version: ISO 42001 is a certifiable management-system standard; EN 18286 is a regulatory instrument whose value is presumption of conformity under the EU AI Act once it is cited in the Official Journal. They are complementary, but the overlap is thinner than the similar skeletons suggest, and this page quantifies where it actually is.
Quick decision
- You provide high-risk AI systems in the EU → EN 18286 is the harmonized route to the Article 17 QMS duty you already have. Whether or not you also run ISO 42001, plan for EN 18286.
- You want a certificate to show customers and procurement → ISO/IEC 42001. EN 18286 conformity surfaces inside the AI Act's conformity assessment, not as a standalone certificate.
- You already run ISO 42001 and the EU AI Act reaches you → keep it and layer EN 18286 on top; the management-system shell carries over conceptually, but plan for the EN's regulatory substance as new work (see why the overlap is smaller than people expect).
- You are outside EU scope entirely → ISO 42001 alone; EN 18286's purpose is EU AI Act compliance.
TL;DR
- EN 18286:2026 specifies a quality management system for EU AI Act regulatory purposes, prepared by CEN/CLC/JTC 21 under standardization request M/613 and approved 12 July 2026. Quality is defined as compliance with the applicable regulatory requirements. Presumption of conformity attaches once EN 18286:2026 is cited in the Official Journal of the European Union, for the provisions in its Annex ZA (Article 17(1) and the first sentence of Article 11(1)).
- ISO/IEC 42001:2023 is the certifiable AI management system (AIMS) standard: Annex SL clauses 4–10, AI risk and impact assessment, Annex A reference controls, third-party certification by accredited bodies. It carries no EU AI Act presumption.
- The Annex C correspondence maps clauses and subclauses only, not requirements and concepts. Treat it as navigation, not equivalence.
- Consequence: EU providers of high-risk AI systems typically end up with both: ISO 42001 for certified governance, EN 18286 for the Article 17 compliance trail. But budget honestly: the direct Control sharing between the two template pairs is small; EN 18286's heavyweight reuse partner in Modulos is the EU AI Act estate, not ISO 42001 (numbers below).
Side-by-side comparison
| Dimension | EN 18286:2026 | ISO/IEC 42001:2023 |
|---|---|---|
| Publisher | CEN/CENELEC (CEN/CLC/JTC 21) | ISO/IEC (joint) |
| Status | Approved 12 July 2026; OJ citation pending | Published 18 December 2023 |
| Type | Harmonized-standard candidate: QMS for regulatory purposes | Management-system standard (AIMS), certifiable |
| Purpose | Implement the EU AI Act Article 17 QMS duty; carry presumption of conformity | Govern AI systems responsibly across their lifecycle |
| Object of "quality" | Compliance with applicable EU AI Act regulatory requirements | The organization's AI management objectives |
| Legal effect | Presumption of conformity for Annex ZA provisions once cited in the OJ | None; voluntary certification signal |
| Primary audience | Providers of (primarily high-risk) AI systems in or entering the EU market | Any organization developing, providing or using AI |
| Structure | Clauses 4–10; Annexes A, B (ISO 9001), C (ISO/IEC 42001), ZA | Annex SL clauses 4–10; Annexes A–D |
| Risk machinery | Requires a life-cycle risk management system (clause 8.2), process detail deferred to prEN 18228; Annex ZA row (g) conditions presumption on Article 9 compliance | AI risk assessment + AI system impact assessment + risk treatment with Annex A reference controls |
| Improvement model | No continual-improvement obligation; maintain effectiveness, evaluated through management review | Clause 10 continual improvement |
| Regulatory specifics | Compliance strategy per essential requirement, technical documentation duties, identification and traceability, serious-incident deadlines (2/10/15 days), non-compliance remedial menu, market-surveillance notification | Not in scope |
| Assessment route | Inside the AI Act conformity assessment (Annex VI / VII) | Accredited certification-body audit |
| In Modulos | OFF-19 + MFF-19 (24 Requirements, 83 Controls) | OFF-10 + MFF-10 |
Why the overlap is smaller than people expect
The expectation usually comes from the skeletons: two standards, same clauses 4–10 shape, an official correspondence annex between them. The overlap is real, but it thins out layer by layer.
Layer 1: the shared shell (real, but shallow). EN 18286's Annex B corresponds its clauses to EN ISO 9001:2015 and Annex C to EN ISO/IEC 42001:2026, and both annexes state that they correspond clauses and subclauses only, not the requirements and concepts. What genuinely lines up is the management shell: scope-setting, leadership commitment, a policy, objectives, competence, documented information, management review. An organization that has run any modern management system will recognize the architecture immediately.
Layer 2: the substance (diverges fast). The correspondence is weakest exactly where EN 18286 earns its keep: the clause 4.4 strategy for regulatory compliance with its per-essential-requirement measure selection, the clause 8 realization duties written against the AI Act's essential requirements, identification and traceability at market placement, and the clause 9.6–9.7 incident and non-compliance machinery with its deadlines, remedial menu and market-surveillance notification. None of that exists in ISO 42001. Conversely, ISO 42001's defining content, the AI system impact assessment and the Annex A reference-control catalog, has no EN 18286 counterpart; the EN never requires it. EN 18286's design kinship is with EN ISO 13485, the medical-device regulatory QMS, more than with the AIMS tradition.
Layer 3: the working level (the surprise). In Modulos, as of templates 1.0.26, the direct Control intersection between the two template pairs is small:
| Template pair | Shared with OFF-19 (37 Controls) | Shared with MFF-19 (46 Controls) |
|---|---|---|
ISO 42001 (OFF-10 / MFF-10) | 7 (the documented-information family OCF-120–OCF-126) | 0 |
EU AI Act (OFF-1 / MFF-1) | 8 | 28 (roughly 60%) |
The reason is what EN 18286 is for. Its Requirements were mapped against the obligations the standard implements, and those are EU AI Act obligations, so the application side reuses the EU AI Act lifecycle, testing, data, documentation and monitoring families wholesale. The shell similarity with ISO 42001, by contrast, is conceptual: both frameworks demand a policy, objectives, leadership and management review, but each template elicits those artifacts through its own Controls, so the evidence trails stay separate even where the work substance rhymes.
What this means in practice
- You run the EU AI Act templates and add EN 18286 → substantial direct reuse, especially per application: a Control executed once, with its Evidence, serves every framework that maps it, and 28 of
MFF-19's 46 Controls arrive already shared. - You run only ISO 42001 and add EN 18286 → expect a conceptual head start, not automatic evidence flow. The shell duties (policy, objectives, leadership, review) will be evidenced under each framework's own Controls; only the documented-information family carries over directly.
- You run both plus the EU AI Act → the realistic full stack for an EU high-risk provider. The organization does the QMS thinking once; the per-framework trails stay clean for auditors, and the 15 EN-specific overlay Controls carry what neither neighbor elicits.
The operationalizing playbook lists the overlays; the ISO 42001 guide covers the AIMS side.
Related pages
EN 18286 guide
The standard, Annex ZA coverage, and the OFF-19 / MFF-19 templates
ISO/IEC 42001 guide
The certifiable AIMS: clauses, annexes, certification path
Harmonized standards overview
Presumption of conformity mechanics and the JTC 21 pipeline
ISO 42001 vs ISO 27001
The adjacent standards-stack comparison
Source attribution
EN 18286:2026, Artificial intelligence — Quality management system for EU AI Act regulatory purposes (CEN/CENELEC, approved 12 July 2026), and ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system (ISO/IEC, December 2023). Comparison statements reflect the two standards' published structures and the Modulos template mappings as of templates 1.0.26; the Annex C correspondence caveat is the standard's own.
Disclaimer
This page is for general informational purposes and does not constitute legal advice.