The crosswalk: Articles 9–15 against 42001 and the JTC 21 pipeline
Lesson 4 of 5 in The EU AI Act Interface: Harmonized Standards and the 42001 Playbook.
Now the working tool of this module: a three-way map between what the law demands (Arts 9–15, plus the Art 17 QMS), what your AIMS already gives you (42001 clauses and Annex A controls), and what the standards pipeline will eventually certify against (JTC 21 deliverables). Used honestly, the crosswalk does two jobs at once — it shows how much Art 8–15 groundwork a real 42001 implementation buys you, and it shows exactly where the coverage runs out.
Read the verdicts with a cold eye. ‘Partial’ is the honest rating almost everywhere, for one structural reason you already know: 42001 makes you build organisational processes; the Act demands per-system technical outcomes. Your A.7 data-management process is real Art 10 groundwork — but Art 10 also wants this system’s training data examined for biases, relevant gaps, and representativeness in its specific context of use, to a depth no management-system clause specifies.
| AI Act article | What the Act demands | Closest 42001 anchor | JTC 21 deliverable & status | Coverage verdict |
|---|---|---|---|---|
Art 9 — risk management system | A continuous, iterative risk process across the system’s entire lifecycle: identify, estimate, evaluate, and treat risks to health, safety, and fundamental rights; test against defined metrics; consider vulnerable groups. | Cl 6.1.2 / 8.2 (AI risk assessment), 6.1.3 / 8.3 (treatment), 6.1.4 / 8.4 impact assessment and control A.5 supply the affected-party lens; ISO/IEC 23894 gives method | AI risk management EN — drafting | Partial — the process machinery maps well, but Art 9 fixes the risk objects (health, safety, fundamental rights) and demands per-system testing 42001 leaves to you |
Art 10 — data and data governance | Training, validation, and test data subject to governance practices: design choices, provenance, bias examination and mitigation, relevant gaps, representativeness for the context of use. | Controls A.7 (data management, acquisition, quality, provenance, preparation); EN ISO/IEC 5259 series operationalises quality | Data governance & quality — EN ISO/IEC 5259 adopted; Act-specific work drafting | Partial — strongest overlap of the table, yet Art 10’s per-dataset bias and representativeness findings exceed a process standard’s reach |
Art 11 — technical documentation | Documentation per Annex IV — system description, development process, training methodology, validation results — sufficient for authorities to assess conformity, kept current. | Control A.6.2.7 (technical documentation for the AI system); cl 7.5 documented-information discipline | Covered within the QMS/documentation cluster incl. prEN 18286 (public enquiry) — drafting | Partial — A.6.2.7 creates the habit; Annex IV dictates the exact table of contents, which 42001 nowhere replicates |
Art 12 — record-keeping / logging | Automatic event logging over the system’s lifetime enabling traceability of situations creating risk, substantial modifications, and (for some systems) identification of persons involved in verification. | Control A.6.2.8 (event-log recording); overlaps 27001 logging controls in an IMS | Record-keeping EN — drafting | Partial — A.6.2.8 demands logs exist; Art 12 dictates specific logging capabilities and retention behaviours |
Art 13 — transparency to deployers | Systems designed so deployers can interpret and use outputs; instructions for use covering capabilities, limitations, accuracy metrics, oversight measures, and maintenance. | Controls A.8 (information for interested parties: documentation, reporting, incident communication) and A.9.3 (intended use) | Transparency EN — drafting | Partial — A.8 builds the communication machinery; Art 13 fixes the mandatory content list for instructions of use |
Art 14 — human oversight | Design enabling effective oversight: understand capabilities/limits, stay aware of automation bias, correctly interpret output, decide not to use, intervene or stop. | Controls A.9 (responsible use processes, intended use) and A.6 design objectives; oversight named among Annex C objectives | Human oversight EN — drafting | Partial-to-thin — 42001 governs the deciding and documenting of oversight; Art 14 demands the system be built with oversight capabilities, a design requirement |
Art 15 — accuracy, robustness, cybersecurity | Appropriate accuracy levels (declared in instructions), resilience to errors and inconsistencies, and AI-specific security — data poisoning, adversarial evasion, model extraction — across the lifecycle. | Annex C objectives (robustness, security, safety); control A.6.2.4 (verification & validation); ISO/IEC 24029 and TS 4213 inform metrics | Three ENs (accuracy / robustness / cybersecurity) — drafting | Thin — the most technical article, and the one where a management system contributes least: Art 15 wants measured, declared, tested properties of the system itself |
Art 17 — quality management system | A documented QMS covering compliance strategy, design and development procedures, testing, data management, risk management, incident reporting, communication with authorities, and more. | The whole clause 4–10 architecture — the closest structural cousin: 42001 is, functionally, an AI QMS with an impact-assessment spine | prEN 18286 — public enquiry since 30 Oct 2025; the deliverable that exists because 42001 alone was judged insufficient | Strong-but-not-presumptive — a mature AIMS delivers most Art 17 substance; alignment with prEN 18286’s Act-specific content still required, and no presumption until citation |
Key terms: crosswalk, technical documentation, human oversight, data governance, quality management system (Art 17)
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.