Learn · TrustedAIGov® Enterprise Knowledge Platform
Informational Fresh portal_guide: AUD-ACT-101

This journey is for auditing an organisation's readiness against the EU AI Act. It is deliberately separate from the ISO/IEC 42001 journey, and you should run them as separate exercises.

Why they are kept apart

ISO/IEC 42001 is a certifiable management system: an accredited body assesses conformity and issues a certificate. The EU AI Act is law: obligations bind by role and risk class, carry statutory deadlines, and no certificate discharges them. An organisation can hold a valid ISO 42001 certificate and still be in breach of the Act.

The product never frames the Act inside the standard. If you find a surface that does, raise it.

Role decides almost everything

Obligations attach to your role for each system — provider, deployer, importer, distributor — and to its risk class. The same model can make one organisation a provider and another a deployer, with entirely different duties. Establish the role before you test any obligation.

Where you will work

app.trustedaigov.io, under the EU AI Act navigation group, signed in with a read-only external-auditor account.