Skip to main content
The state of ai impact assessment
Category: Audit & Certification

Conformity Assessment

Also known as: CA, conformity assessment procedure
Simply put

Conformity assessment is the process of checking and demonstrating that something—such as a product, service, process, system, or person—meets a set of specified requirements. Those requirements may come from a voluntary standard or technical specification, or, in some cases, from binding law. Depending on the context, the assessment may be performed by the organization itself, by a customer, or by an independent third party.

Formal definition

Conformity assessment is the demonstration that specified requirements relating to a product, process, service, system, person, or body are fulfilled, typically by verifying that a relevant standard, technical specification, or legal requirement has been applied across activities such as design, manufacturing, and installation. The nature of the underlying requirements determines the legal weight of the exercise: assessment against a voluntary standard (for example an ISO/IEC standard) is contractual or voluntary in character, whereas assessment mandated by legislation—such as the conformity assessment procedure that must be completed before certain products are placed on the EU market, or the assessment required for high-risk AI systems under the EU AI Act—is a legal precondition to market access within that jurisdiction. Conformity assessment is distinct from, though often a component of, formal certification: it denotes the underlying demonstration of fulfilled requirements, which may be conducted as first-party (self-assessment), second-party, or third-party activity. Scope, applicable requirements, and the required level of independence vary by jurisdiction, sector, and risk classification, and the specific procedures and standard versions change over time; readers should verify obligations against the current official text of the relevant standard or legislation. This entry is informational and does not address how conformity assessment applies to any particular product or organization, which requires professional judgment.

Why it matters

Conformity assessment is the mechanism that connects a written requirement to a demonstrable fact: it is how an organization shows that a product, service, process, system, or person actually meets what a standard, technical specification, or law demands. Its practical significance depends heavily on the source of the requirements. When the underlying requirements come from a voluntary standard—such as an ISO/IEC standard—the assessment is contractual or voluntary in character, and its value lies in the assurance it provides to customers, partners, or the organization itself. When the requirements come from binding legislation, the assessment can become a legal precondition to market access rather than an optional exercise.

This distinction matters most where legislation makes conformity assessment mandatory. In the EU single market, a conformity assessment procedure must generally be completed before certain products can be sold, meaning the assessment is not a post-sale formality but a gate to lawful placement on the market. The EU AI Act extends a comparable logic to high-risk AI systems, which are subject to conformity assessment against the Act's requirements before they are placed on the market or put into service within that jurisdiction. For organizations operating in these areas, treating conformity assessment as a checkbox rather than a substantive demonstration of fulfilled requirements can translate directly into inability to lawfully bring a product to market.

Because scope, applicable requirements, and the required level of independence vary by jurisdiction, sector, and risk classification—and because both standard versions and legislative procedures change over time—the practical burden of conformity assessment cannot be assumed to be uniform. What suffices as self-assessment in one context may require third-party involvement in another. Readers should verify the specific obligations against the current official text of the relevant standard or legislation rather than assume a single approach applies across products or regions.

Who it's relevant to

Product and manufacturing compliance teams
Teams responsible for placing physical products on the market—particularly in the EU, where a conformity assessment procedure must generally be completed before a product can be sold—need to identify which requirements apply, whether self-assessment suffices, and when an independent body must be involved. Because procedures and standard versions change, these teams should verify obligations against the current official legislative and standard text for each product category.
AI governance and product teams
Organizations developing or deploying AI systems that may fall within the EU AI Act's high-risk category should understand that conformity assessment against the Act's requirements can be a legal precondition before such a system is placed on the market or put into service. How the Act applies to a specific system depends on its classification and requires professional judgment against the current text.
Auditors and assessment professionals
Those performing or overseeing conformity assessment activities need to keep first-party, second-party, and third-party arrangements distinct, and to recognize that conformity assessment is the underlying demonstration of fulfilled requirements rather than certification itself. The required level of independence varies by jurisdiction, sector, and risk classification.
Compliance officers and legal counsel
Professionals advising on market access must distinguish assessment against voluntary standards, which is contractual or voluntary in character, from legally mandated assessment, which is a precondition to lawful market entry within a jurisdiction. Application to any particular product or organization is fact-specific and should be confirmed against the relevant current official source.

Inside CA

Conformity Assessment Procedure
The defined process by which a product, system, process, or service is evaluated against specified requirements. Depending on the applicable regime, this may involve self-assessment by the provider or involvement of an external body. The specific procedure required generally depends on the risk category or nature of the item being assessed.
Applicable Requirements
The benchmark against which conformity is measured. These may derive from binding law (for example, requirements imposed under the EU AI Act for certain high-risk systems) or from voluntary standards and technical specifications. The source of the requirement determines whether the assessment is legally mandated or contractually or voluntarily undertaken.
Self-Assessment (Internal Control)
A route in which the provider or manufacturer itself evaluates conformity and attests to it, typically maintaining supporting technical documentation. This is generally permitted for lower-risk categories under certain regimes but should be verified against the specific applicable framework.
Third-Party Assessment
Involvement of an independent body (such as a notified or accredited body, where the regime provides for one) to evaluate conformity. This route is generally reserved for higher-risk items or where the applicable law or scheme requires external verification. It should not be conflated with self-assessment.
Technical Documentation and Evidence
The records demonstrating how the item meets the applicable requirements. The nature and retention of this documentation vary by regime and are often a precondition for both self-assessment and third-party routes.
Declaration or Attestation of Conformity
A formal statement, where required by the applicable regime, that the item conforms to specified requirements. The form, legal weight, and any accompanying marking or certificate depend on the specific framework and jurisdiction and should be verified against the current official text.

Common questions

Answers to the questions practitioners most commonly ask about CA.

Is conformity assessment the same as certification?
No. Conformity assessment is the broader process of demonstrating that a product, process, service, or system meets specified requirements, and it can take several forms. Certification is only one possible outcome, typically involving attestation by an accredited third party. Conformity assessment may also be carried out by the organization itself (self-assessment or first-party assessment) or by a customer or other party (second-party assessment), depending on what the applicable requirements permit. Treating certification as synonymous with conformity assessment overlooks these other routes, which may be acceptable or even required in particular contexts.
Does conformity assessment always require an independent third party?
Not necessarily. The party that performs the assessment depends on the applicable regime. Some requirements allow first-party (self) assessment, others contemplate second-party assessment, and others mandate third-party assessment by an independent or accredited body. Which route applies is generally determined by the relevant regulation, standard, or contract, and in some regulatory contexts the required level of independence may vary with the risk level or category of the product or activity. Readers should verify the permitted assessment routes against the applicable authoritative text rather than assuming independence is always required.
How do we determine which conformity assessment route applies to our situation?
The applicable route is generally driven by the requirement being assessed against. Where conformity assessment is mandated by regulation, the legal text or its implementing measures usually specify who may perform it and under what conditions, sometimes varying by risk level or product category. Where it arises from a voluntary standard or a contract, the standard's own provisions or the contract terms govern. Because these details differ across jurisdictions and evolve over time, the applicable route should be confirmed against the current official source relevant to your sector and territory, and its application to your specific circumstances calls for professional judgment.
What is the difference between conformity assessment against a regulation and against a voluntary standard?
The distinction turns on the source of the obligation. Assessment against a regulation addresses requirements that carry legal force within a given jurisdiction, and the assessment method may itself be prescribed by that law. Assessment against a voluntary standard addresses requirements that are not legally binding in themselves unless incorporated by law or agreed by contract. The same technical process may look similar in practice, but the consequences differ: failing a regulatory conformity assessment may expose an organization to legal enforcement, while a voluntary assessment result primarily affects contractual or market positioning unless the standard has been made mandatory by reference.
Does a successful conformity assessment establish permanent conformity?
Generally no. A conformity assessment reflects a determination made at a point in time and under defined conditions. Requirements are periodically amended or superseded, standards are revised into new versions, and the product, process, or system under assessment may change. Many regimes therefore contemplate ongoing obligations such as surveillance, periodic reassessment, or re-evaluation following significant changes. Organizations should treat a favorable result as a snapshot rather than a lasting guarantee and monitor for changes in the applicable requirements or in the subject of the assessment.
What limitations should we keep in mind when relying on a conformity assessment result?
A conformity assessment is bounded by its stated scope, the version of the requirement it was conducted against, and the conditions in place at the time. It does not necessarily cover requirements outside that scope, later versions of the applicable standard or regulation, or changes made after the assessment. Enforcement practice and interpretation may also diverge from the literal text of a requirement, and some assessment regimes are still evolving. For these reasons, a result should be read together with its scope and date, verified against the current authoritative source, and applied to specific circumstances only with appropriate professional judgment.

Common misconceptions

Passing a conformity assessment is the same as being certified.
Conformity assessment is the evaluation process, while certification is a specific outcome issued by an accredited or authorized body under a defined scheme. Some conformity assessments are completed through self-assessment and produce a declaration rather than a certificate. Whether certification results depends on the applicable regime, and the two concepts should be kept distinct.
Conformity assessment always requires an independent third party.
Many regimes permit self-assessment (internal control) for lower-risk items, requiring third-party involvement only for higher-risk categories or where the law or scheme mandates it. The required route is fact-specific and depends on the applicable framework.
A single conformity assessment demonstrates compliance everywhere.
Requirements differ across jurisdictions such as the EU, the United States, and the United Kingdom, and an assessment against one regime's requirements does not automatically satisfy another's. Scope, recognition of assessment bodies, and marking or declaration requirements vary and should be verified per jurisdiction.

Best practices

Identify at the outset whether the applicable requirements derive from binding law or from voluntary standards, since this determines whether conformity assessment is mandatory and what route applies.
Determine the correct assessment route (self-assessment versus third-party) based on the risk category or nature of the item, and verify this against the current official text of the applicable regime rather than assuming.
Maintain complete, current technical documentation and supporting evidence throughout the lifecycle, since it typically underpins both self-assessment and third-party routes.
Confirm the jurisdictional scope of any assessment and do not assume that conformity established under one regime satisfies obligations in another territory or sector.
Where third-party involvement is required, confirm that the body is appropriately accredited or authorized under the relevant scheme, and check the scheme's current version, as these change over time.
Treat the assessment outcome as fact-specific and seek professional judgment for application to particular circumstances rather than relying on a general conformity determination.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps