The crosswalk: Articles 9–15 against 42001 and the JTC 21 pipeline

Lesson 4 of 5 in The EU AI Act Interface: Harmonized Standards and the 42001 Playbook.

Now the working tool of this module: a three-way map between what the law demands (Arts 9–15, plus the Art 17 QMS), what your AIMS already gives you (42001 clauses and Annex A controls), and what the standards pipeline will eventually certify against (JTC 21 deliverables). Used honestly, the crosswalk does two jobs at once — it shows how much Art 8–15 groundwork a real 42001 implementation buys you, and it shows exactly where the coverage runs out.

Read the verdicts with a cold eye. ‘Partial’ is the honest rating almost everywhere, for one structural reason you already know: 42001 makes you build organisational processes; the Act demands per-system technical outcomes. Your A.7 data-management process is real Art 10 groundwork — but Art 10 also wants this system’s training data examined for biases, relevant gaps, and representativeness in its specific context of use, to a depth no management-system clause specifies.

Crosswalk — EU AI Act high-risk requirements vs ISO/IEC 42001 vs JTC 21 deliverables (status as of Sept 2026: none cited in the OJEU)
AI Act articleWhat the Act demandsClosest 42001 anchorJTC 21 deliverable & statusCoverage verdict

Art 9 — risk management system

A continuous, iterative risk process across the system’s entire lifecycle: identify, estimate, evaluate, and treat risks to health, safety, and fundamental rights; test against defined metrics; consider vulnerable groups.

Cl 6.1.2 / 8.2 (AI risk assessment), 6.1.3 / 8.3 (treatment), 6.1.4 / 8.4 impact assessment and control A.5 supply the affected-party lens; ISO/IEC 23894 gives method

AI risk management EN — drafting

Partial — the process machinery maps well, but Art 9 fixes the risk objects (health, safety, fundamental rights) and demands per-system testing 42001 leaves to you

Art 10 — data and data governance

Training, validation, and test data subject to governance practices: design choices, provenance, bias examination and mitigation, relevant gaps, representativeness for the context of use.

Controls A.7 (data management, acquisition, quality, provenance, preparation); EN ISO/IEC 5259 series operationalises quality

Data governance & quality — EN ISO/IEC 5259 adopted; Act-specific work drafting

Partial — strongest overlap of the table, yet Art 10’s per-dataset bias and representativeness findings exceed a process standard’s reach

Art 11 — technical documentation

Documentation per Annex IV — system description, development process, training methodology, validation results — sufficient for authorities to assess conformity, kept current.

Control A.6.2.7 (technical documentation for the AI system); cl 7.5 documented-information discipline

Covered within the QMS/documentation cluster incl. prEN 18286 (public enquiry) — drafting

Partial — A.6.2.7 creates the habit; Annex IV dictates the exact table of contents, which 42001 nowhere replicates

Art 12 — record-keeping / logging

Automatic event logging over the system’s lifetime enabling traceability of situations creating risk, substantial modifications, and (for some systems) identification of persons involved in verification.

Control A.6.2.8 (event-log recording); overlaps 27001 logging controls in an IMS

Record-keeping EN — drafting

Partial — A.6.2.8 demands logs exist; Art 12 dictates specific logging capabilities and retention behaviours

Art 13 — transparency to deployers

Systems designed so deployers can interpret and use outputs; instructions for use covering capabilities, limitations, accuracy metrics, oversight measures, and maintenance.

Controls A.8 (information for interested parties: documentation, reporting, incident communication) and A.9.3 (intended use)

Transparency EN — drafting

Partial — A.8 builds the communication machinery; Art 13 fixes the mandatory content list for instructions of use

Art 14 — human oversight

Design enabling effective oversight: understand capabilities/limits, stay aware of automation bias, correctly interpret output, decide not to use, intervene or stop.

Controls A.9 (responsible use processes, intended use) and A.6 design objectives; oversight named among Annex C objectives

Human oversight EN — drafting

Partial-to-thin — 42001 governs the deciding and documenting of oversight; Art 14 demands the system be built with oversight capabilities, a design requirement

Art 15 — accuracy, robustness, cybersecurity

Appropriate accuracy levels (declared in instructions), resilience to errors and inconsistencies, and AI-specific security — data poisoning, adversarial evasion, model extraction — across the lifecycle.

Annex C objectives (robustness, security, safety); control A.6.2.4 (verification & validation); ISO/IEC 24029 and TS 4213 inform metrics

Three ENs (accuracy / robustness / cybersecurity) — drafting

Thin — the most technical article, and the one where a management system contributes least: Art 15 wants measured, declared, tested properties of the system itself

Art 17 — quality management system

A documented QMS covering compliance strategy, design and development procedures, testing, data management, risk management, incident reporting, communication with authorities, and more.

The whole clause 4–10 architecture — the closest structural cousin: 42001 is, functionally, an AI QMS with an impact-assessment spine

prEN 18286 — public enquiry since 30 Oct 2025; the deliverable that exists because 42001 alone was judged insufficient

Strong-but-not-presumptive — a mature AIMS delivers most Art 17 substance; alignment with prEN 18286’s Act-specific content still required, and no presumption until citation

Key terms: crosswalk, technical documentation, human oversight, data governance, quality management system (Art 17)

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.