Conformity Assessment
Conformity assessment is the process of checking and demonstrating that something—such as a product, service, process, system, or person—meets a set of specified requirements. Those requirements may come from a voluntary standard or technical specification, or, in some cases, from binding law. Depending on the context, the assessment may be performed by the organization itself, by a customer, or by an independent third party.
Conformity assessment is the demonstration that specified requirements relating to a product, process, service, system, person, or body are fulfilled, typically by verifying that a relevant standard, technical specification, or legal requirement has been applied across activities such as design, manufacturing, and installation. The nature of the underlying requirements determines the legal weight of the exercise: assessment against a voluntary standard (for example an ISO/IEC standard) is contractual or voluntary in character, whereas assessment mandated by legislation—such as the conformity assessment procedure that must be completed before certain products are placed on the EU market, or the assessment required for high-risk AI systems under the EU AI Act—is a legal precondition to market access within that jurisdiction. Conformity assessment is distinct from, though often a component of, formal certification: it denotes the underlying demonstration of fulfilled requirements, which may be conducted as first-party (self-assessment), second-party, or third-party activity. Scope, applicable requirements, and the required level of independence vary by jurisdiction, sector, and risk classification, and the specific procedures and standard versions change over time; readers should verify obligations against the current official text of the relevant standard or legislation. This entry is informational and does not address how conformity assessment applies to any particular product or organization, which requires professional judgment.
Why it matters
Conformity assessment is the mechanism that connects a written requirement to a demonstrable fact: it is how an organization shows that a product, service, process, system, or person actually meets what a standard, technical specification, or law demands. Its practical significance depends heavily on the source of the requirements. When the underlying requirements come from a voluntary standard—such as an ISO/IEC standard—the assessment is contractual or voluntary in character, and its value lies in the assurance it provides to customers, partners, or the organization itself. When the requirements come from binding legislation, the assessment can become a legal precondition to market access rather than an optional exercise.
This distinction matters most where legislation makes conformity assessment mandatory. In the EU single market, a conformity assessment procedure must generally be completed before certain products can be sold, meaning the assessment is not a post-sale formality but a gate to lawful placement on the market. The EU AI Act extends a comparable logic to high-risk AI systems, which are subject to conformity assessment against the Act's requirements before they are placed on the market or put into service within that jurisdiction. For organizations operating in these areas, treating conformity assessment as a checkbox rather than a substantive demonstration of fulfilled requirements can translate directly into inability to lawfully bring a product to market.
Because scope, applicable requirements, and the required level of independence vary by jurisdiction, sector, and risk classification—and because both standard versions and legislative procedures change over time—the practical burden of conformity assessment cannot be assumed to be uniform. What suffices as self-assessment in one context may require third-party involvement in another. Readers should verify the specific obligations against the current official text of the relevant standard or legislation rather than assume a single approach applies across products or regions.
Who it's relevant to
Inside CA
Common questions
Answers to the questions practitioners most commonly ask about CA.

