Skip to main content
The state of ai impact assessment
Category: AI Governance

Conformity Assessment for AI

Also known as: CA, Conformity Assessment under the EU AI Act, AI Conformity Assessment, Conformity Assessment for High-Risk AI Systems
Simply put

A conformity assessment for AI is the process of checking and demonstrating that an AI system meets the requirements set out for it before it can be placed on the market or put into use. Under the EU AI Act, this process applies primarily to systems classified as high-risk and is intended to show that they are safe and compliant with mandatory rules. It is a formal evaluation step rather than a general quality review, and its precise application depends on how the system is classified.

Formal definition

Under the EU AI Act, a conformity assessment is the formal process of verifying and/or demonstrating that a high-risk AI system satisfies the mandatory requirements laid down in the Regulation before that system is placed on the market or put into service. The assessment procedure generally applies to high-risk AI systems and, per Article 43, may take the form of an internal control (self-assessment by the provider) or involve a notified body, depending on the category of system and whether the provider has applied relevant harmonised standards; where such standards are applied, this can affect the assessment route available. Because the EU AI Act is binding law with extraterritorial reach, conformity assessment obligations can apply to providers established outside the EU whose systems are placed on the EU market or whose outputs are used within the EU, though the specific triggers and procedures are fact-specific. This entry does not cover conformity assessment regimes outside the EU AI Act context, and readers should note that the AI Act's provisions, phased application timelines, and implementing details are still developing; verify against the current official text and any harmonised standards or guidance issued by the relevant authorities. This is an informational definition and not legal advice; application to a particular AI system requires professional judgment.

Why it matters

Conformity assessment is the gatekeeping mechanism through which the EU AI Act operationalizes its requirements for high-risk AI systems. Rather than treating compliance as a matter of good faith, the Regulation ties market access to a formal demonstration that a system meets mandatory requirements before it is placed on the market or put into service. For organizations that develop or deploy AI systems falling within the high-risk category, the conformity assessment is therefore not an optional quality exercise but a precondition to lawful operation within the EU market.

The practical significance is heightened by the Regulation's extraterritorial reach. Because obligations can attach to providers established outside the EU whose systems are placed on the EU market or whose outputs are used within the EU, conformity assessment is a concern well beyond European borders. Providers who misjudge whether their system is high-risk, or who fail to complete the applicable assessment route, may find that their system cannot lawfully be offered in the EU. This makes early and accurate classification, and an understanding of which assessment procedure applies, a material business and legal consideration.

Readers should note that the EU AI Act's provisions, phased application timelines, and implementing details are still developing, and that harmonised standards which affect the available assessment route are evolving. The precise triggers, procedures, and deadlines are fact-specific and subject to change. This entry describes the concept qualitatively; it does not constitute legal advice, and application to any particular system requires professional judgment against the current official text.

Who it's relevant to

Providers of high-risk AI systems
Organizations that develop AI systems classified as high-risk under the EU AI Act carry primary responsibility for ensuring a conformity assessment is completed before the system is placed on the market or put into service. This includes determining whether an internal control (self-assessment) route is available or whether a notified body must be involved, a determination that can depend on the harmonised standards applied. The precise obligations are fact-specific and should be assessed against the current text of the Regulation.
Non-EU providers with EU market exposure
Because the EU AI Act has extraterritorial reach, providers established outside the EU may be subject to conformity assessment obligations where their systems are placed on the EU market or where their outputs are used within the EU. The specific triggers are fact-specific, so organizations outside Europe should not assume they fall outside scope without verifying against the Regulation and applicable guidance.
Compliance and legal teams
Compliance officers and legal counsel supporting AI development need to understand where conformity assessment fits within an organization's broader obligations, including how classification as high-risk triggers the requirement and how the choice of assessment route may be affected by the standards applied. Given that timelines and implementing details are still developing, these teams play a central role in tracking evolving requirements against the official text.
Notified bodies and assessors
Where the applicable procedure requires third-party involvement rather than internal control, notified bodies conduct or verify the assessment of high-risk AI systems. Their role and the circumstances under which they are engaged depend on the system category and the harmonised standards in play, both of which are subject to ongoing development.

Inside CA

Conformity Assessment (definition)
The process by which a provider of an AI system demonstrates, before placing the system on the market or putting it into service, that the system meets the applicable requirements. Under the EU AI Act it is a legal obligation for certain categories of AI, most notably high-risk AI systems, rather than a voluntary exercise. Application to a specific system depends on that system's classification and requires professional judgment.
Risk-based scope
Conformity assessment obligations are tied to the risk tier of the AI system. High-risk systems are generally the ones subject to formal assessment, while lower-risk systems face lighter or no assessment obligations. Whether a given system falls within scope is fact-specific and should be checked against the current classification rules in the official text.
Internal control vs. third-party assessment
The EU AI Act contemplates different assessment routes: assessment based on internal controls carried out by the provider, and assessment involving a notified body (a third party). Which route applies depends on the type of high-risk system and any applicable harmonised standards. The two routes are distinct and should not be treated as interchangeable.
Relationship to harmonised standards
Technical standards (for example those developed by European standardisation bodies) can support conformity assessment. Standards are, in general, voluntary instruments, but conformity with certain harmonised standards may confer a presumption of conformity with corresponding legal requirements. The standard itself remains distinct from the regulation that gives it legal effect.
Documentation and technical file
Conformity assessment typically rests on documentary evidence such as technical documentation, records of the risk management and quality management processes, and records demonstrating that legal requirements have been addressed. This documentation supports, but is not a substitute for, ongoing compliance.
Declaration and marking (where applicable)
Successful conformity assessment for in-scope systems is generally followed by a formal declaration by the provider and, where the framework requires it, appropriate marking. The precise procedural and marking requirements should be verified against the current official text rather than assumed.
Ongoing and post-market obligations
Conformity assessment is not a one-time event that permanently settles compliance. Substantial modifications to a system may trigger re-assessment, and providers generally remain subject to post-market monitoring and record-keeping duties. The scope and triggers for re-assessment depend on the nature of the change.

Common questions

Answers to the questions practitioners most commonly ask about CA.

Does conformity assessment for AI always require an independent third-party auditor?
No. Under the EU AI Act, conformity assessment can take the form of an internal (self-assessment) procedure based on internal controls, or a procedure involving a notified body, depending on the type of high-risk AI system and the applicable route set out in the Regulation. Many high-risk systems are addressed through provider self-assessment against the relevant requirements, while third-party involvement is required in specific cases. The correct route is fact-specific, so readers should verify the applicable procedure against the current official text and any harmonised standards referenced.
Is passing a conformity assessment the same as being certified to a standard like ISO/IEC 27001?
No, these are distinct concepts. Conformity assessment under the EU AI Act is a regulatory procedure demonstrating that a system meets legally binding requirements before it is placed on the market or put into service. Certification to a voluntary standard such as ISO/IEC 27001 is a contractual or market-facing attestation against a standard that is not itself law unless incorporated by regulation or agreement. Conformance with a harmonised standard may support a presumption of conformity with certain legal requirements, but the standard and the legal obligation remain separate. Certification alone does not establish regulatory conformity, and conformity assessment is not a certification against any single standard.
Who is responsible for carrying out the conformity assessment?
Responsibility generally rests with the provider of the AI system—the entity that develops it or has it developed and places it on the market or puts it into service under its own name or trademark. This differs from the roles of deployers and other actors in the value chain, whose obligations are distinct. Where a third-party procedure applies, a notified body is involved, but the provider retains primary responsibility for ensuring and demonstrating conformity. Precise role allocation depends on the facts and should be verified against the current legal text.
When in the lifecycle does conformity assessment need to be completed?
As a general matter, conformity assessment is intended to be completed before a high-risk AI system is placed on the market or put into service, so that the required documentation and, where applicable, declarations and markings are in place at that point. In addition, substantial modifications to a system may trigger a renewed assessment. The precise triggers and timing are defined in the Regulation, and readers should confirm the applicable requirements and any transitional periods against the latest authoritative source.
What documentation typically needs to be in place to support a conformity assessment?
In most cases the process relies on technical documentation demonstrating how the system meets the applicable requirements, together with records associated with the provider's quality and risk management, and outputs such as a declaration of conformity where required. Where harmonised standards are used, evidence of conformance to those standards can support the demonstration. The specific documentation set is determined by the applicable requirements and assessment route, so the exact contents should be confirmed against the current official text and referenced standards rather than assumed.
How does the choice of assessment route affect implementation planning?
The applicable route—internal control versus a procedure involving a notified body—affects timelines, resourcing, and evidence-gathering. A route relying on internal controls places the demonstration burden on the provider's own processes and documentation, while involvement of a notified body introduces external scheduling and review considerations. Because the correct route depends on the system type and the requirements in force, organizations generally plan by first confirming the applicable procedure, then aligning documentation, risk management, and any standards conformance accordingly. This entry is informational only; applying these considerations to a particular system requires professional judgment and verification against the current Regulation.

Common misconceptions

Conformity assessment under the AI Act is a voluntary certification, like ISO/IEC 27001 or SOC 2.
For in-scope high-risk AI systems, conformity assessment is a legal obligation arising from the EU AI Act, not a voluntary or purely contractual scheme. Voluntary standards and certifications may support the process, but they are conceptually distinct from a regulatory conformity assessment and do not by themselves discharge the legal duty.
Every AI system must undergo a full third-party conformity assessment.
Obligations are risk-based and route-dependent. Many systems fall outside the high-risk category and face no formal assessment, and several in-scope systems may be assessed through internal controls rather than a notified body. Whether third-party involvement is required depends on the specific system type and applicable standards.
Passing conformity assessment once means the system is permanently compliant.
Conformity assessment reflects a point-in-time demonstration. Substantial modifications can trigger re-assessment, and providers generally remain subject to post-market monitoring and ongoing record-keeping. Continued compliance requires maintaining the underlying processes over the system's lifecycle.

Best practices

Determine and document the system's risk classification early, since it drives whether conformity assessment applies and which route (internal control or notified body) is available; verify the classification against the current official text.
Maintain a complete and current technical file, including risk management and quality management records, so that evidence of conformity is available before the system is placed on the market or put into service.
Track the development and status of relevant harmonised standards, and treat a presumption of conformity as a supporting aid rather than a substitute for meeting the underlying legal requirements.
Establish change-control procedures that flag substantial modifications, so that re-assessment obligations are identified and addressed rather than overlooked.
Implement post-market monitoring and record-keeping processes to sustain compliance over the system's lifecycle, not just at the point of initial assessment.
Confirm current procedural, declaration, and marking requirements against the latest authoritative source, and seek professional judgment for application to a specific system, since these entries are informational and not legal advice.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide