AI Assurance & Audit advanced 8 min read 7 flashcards

Conformity Assessment and Third-Party Certification

Who is allowed to declare an AI system compliant under the EU AI Act, why most high-risk systems are self-assessed while biometrics can need a notified body, how harmonised standards create a presumption of conformity that did not yet exist as of September 2026, and how this differs from ISO/IEC 42001 certification audited under ISO/IEC 42006.

A company selling a CV-screening model into the EU and a company selling remote biometric identification both build high-risk AI systems under the AI Act. The first will almost certainly assess its own system, sign an EU declaration of conformity and affix the CE marking with no outsider involved. The second may need a notified body to examine its quality management system and technical documentation first. What separates them is one paragraph of Article 43 and the state of European standardisation.

This concept covers who may say a system conforms and what the certificate means; what an AI audit can establish covers audit epistemics and ISO 42001 and certifiable management systems the voluntary standard.

The routes in Article 43

The AI Act follows the EU's New Legislative Framework for product safety: the law sets essential requirements, and conformity assessment checks a product against them before it reaches the market (Regulation (EU) 2024/1689, Article 43).

System Procedure Third party
Annex III points 2-8 (employment, credit, education, essential services, law enforcement and others) Internal control, Annex VI None
Annex III point 1 (biometrics), harmonised standards or common specifications fully applied Provider chooses Annex VI or Annex VII Optional
Annex III point 1, standards absent or not fully applied Annex VII: QMS and technical documentation assessed Notified body required
Products under Annex I Section A (medical devices, machinery and others) The sectoral procedure, extended to the AI requirements The sector's notified body, where that regime uses one

Certificates issued by notified bodies last at most four years for Annex III systems and five years for Annex I systems, renewable on re-assessment (Article 44(2)). A substantial modification triggers a fresh assessment (Article 43(4)), but changes to a continuously learning system that were pre-determined and documented at the initial assessment do not count as substantial. For a model retrained monthly, that clause decides whether reassessment is occasional or constant.

Harmonised standards and the presumption of conformity

Under Article 40, a system that follows harmonised standards whose references are published in the Official Journal is presumed to meet the requirements those standards cover. The argument becomes "we applied EN X" rather than a bespoke case per requirement. Where standards fail to arrive or are inadequate, Article 41 lets the Commission adopt common specifications with the same effect.

As of September 2026, that presumption was not yet available for any requirement. CEN-CENELEC's JTC 21 drafts them under the Commission's request M/613. EN 18286, the quality management system standard for Article 17, was approved on 12 July 2026, the first of the set to finish (CEN-CENELEC, 2026, EN 18286 in the Spotlight). Risk management, logging and cybersecurity drafts were at or past public enquiry by mid-2026, and bias and data governance were still in drafting. Publication by CEN-CENELEC is not citation: the Commission must first assess each standard, and the Commission's standardisation page, last updated in August 2026, listed none as cited (European Commission, Standardisation of the AI Act).

The lag reshaped the timetable. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and moved the application of the high-risk obligations from 2 August 2026 to 2 December 2027 for Annex III systems and to 2 August 2028 for Annex I products, explicitly because standards would not be ready (Regulation (EU) 2026/1744). It also lets a body already designated under Annex I sectoral legislation make a single application and undergo a single assessment to be designated under both regimes.

A notified body is not a certification body

A notified body is designated by a Member State's notifying authority against the Act's requirements (Articles 28-31), listed by the Commission, and performs a legally required assessment of a specific product. An ISO/IEC 42001 certification body is accredited by a national accreditation body under ISO/IEC 17021-1 and certifies an organisation's management system, which is voluntary and says nothing directly about any one model. ISO/IEC 42006:2025 adds AI-specific requirements for those certification bodies, covering auditor competence, audit time calculation and access to the organisation's documentation (ISO/IEC 42006:2025, Requirements for bodies providing audit and certification of artificial intelligence management systems). A 42001 certificate is not a presumption of conformity with the AI Act, and JTC 21 wrote EN 18286 rather than citing 42001 unchanged.

When it breaks

Self-assessment dominates, and the critics say that is the design flaw. Veale and Zuiderveen Borgesius argued, of the draft Act, that there are almost no situations where AI-specific notified bodies are required, and that once standards exist even biometric systems can self-assess (Veale & Zuiderveen Borgesius, 2021, Demystifying the Draft EU Artificial Intelligence Act, Computer Law Review International 22(4), arXiv:2107.03721). The final text kept that structure. The framework's defence is that it scales and places responsibility on the party that knows the product best; either way, the standards carry most of the real rule-making.

Standards encode value choices made by private bodies. Thresholds for acceptable bias or residual risk are normative; delegating them to CEN-CENELEC, where civil-society participation is thin and Parliament has no binding veto, is a legitimacy question that product safety rarely had to face.

Point-in-time assessment fits poorly with systems that change. A four-year certificate on a model retrained monthly certifies a process for change, not a model, and its value depends on how tightly the pre-determined change plan was written.

Capacity is a hard constraint. Designation of AI Act notified bodies has been possible since August 2025, yet assessors competent in both conformity assessment and machine learning are scarce, and providers needing Annex VII assessment will compete for them.

Check yourself

7 flashcards for this concept

Click a card to reveal the answer.

Drill the whole track