EU AI Act
EU AI Act - Notified Bodies, Standards and Conformity Assessment

EU AI Act EUAI-Art.43: Conformity assessment

Providers must put each high-risk AI system through the correct conformity assessment procedure before it is placed on the market or put into service. For Annex III point 1 biometrics systems, where harmonised standards or common specifications have been applied, the provider chooses between internal control under Annex VI and assessment of the quality management system and the technical documentation with the involvement of a notified body under Annex VII; where such standards do not exist, were not applied, were applied only in part, or were published with a restriction, the Annex VII procedure must be followed. For Annex III points 2 to 8, internal control under Annex VI applies without notified body involvement. For systems covered by the Union harmonisation legislation in Section A of Annex I, the procedure required by that legislation applies and the Section 2 requirements form part of that assessment. A system already assessed must undergo a new conformity assessment on substantial modification; changes to a continuously learning system that were pre-determined by the provider at the initial assessment and recorded in the technical documentation are not a substantial modification.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 21 controls across 7 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 4 controls

ISO 27001:2022 · 3 controls

  • 5.35 Independent review of information security
  • 8.29 Security testing in development and acceptance
  • 8.32 Change management

ISO/IEC 42001:2023 · 3 controls

  • A.6.2.3 Documentation of AI system design and development
  • A.6.2.4 AI system verification and validation
  • A.6.2.5 AI system deployment

SOC 2 · 3 controls

  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • SOC2-CC4.1 CC4.1 Ongoing and separate evaluations of control (COSO principle 16)
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • AIRMF-MS-1.3 Internal experts who did not serve as front-line developers for the system and independent assessors are involved in regular assessments and updates, and domain experts, users, AI actors external to the team, and affected communities are consulted in support of assessments as necessary per organizational risk tolerance
  • AIRMF-MS-4.2 Measurement results regarding AI system trustworthiness in deployment contexts and across the AI lifecycle are informed by input from domain experts and other relevant AI actors to validate whether the system is performing consistently as intended, and results are documented

NIS2 Directive · 1 control

  • Art.24 Use certified ICT products, services and processes where the Member State requires it

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in EU AI Act - Notified Bodies, Standards and Conformity Assessment

You are reading one control. How much of EU AI Act have you already done?

EU AI Act EUAI-Art.43 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of EU AI Act your existing evidence covers. Hold ISO/IEC 42001:2023 and 17 of 43 EU AI Act controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO/IEC 42001:2023 pair alone.

Query this from an agent

The graph holds this control, the 21 it maps to, and the evidence behind each claim, over MCP and REST.