Skip to main content

Conformity Assessment

The official checklist and testing process an AI system must pass to prove it follows the law before it can be used in high-risk situations, similar to a vehicle passing a rigorous safety inspection before it can be sold to the public.

The Simple Version

The official checklist and testing process an AI system must pass to prove it follows the law before it can be used in high-risk situations, similar to a vehicle passing a rigorous safety inspection before it can be sold to the public.

Detailed Explanation

A conformity assessment involves rigorous internal or third-party audits, technical testing, and documentation to ensure the system meets strict standards for data governance, transparency, accuracy, robustness, and human oversight. Depending on the risk level, this may be a self-assessment or require an independent third-party auditor (known as a "Notified Body" in the EU). Successful completion typically results in a CE mark or equivalent regulatory clearance (e.g., FDA 510(k) or De Novo).

Key Characteristics

  • Mandatory Gate: A non-negotiable requirement for market access for high-risk AI.
  • Comprehensive Scope: Covers the entire AI lifecycle, not just the final model, including the Quality Management System (QMS) and post-market monitoring plans.
  • Documentation Heavy: Requires detailed technical files, risk management reports, and data governance records.

Why It Matters

Companies building high-risk AI must budget significant time (often 6–18 months) and resources for internal documentation, QMS implementation, and potential third-party auditor fees before launching products in regulated markets. Failure to obtain conformity assessment results in the inability to legally sell or deploy the product.

Common Misconceptions

  • Myth: A conformity assessment is just a one-time IT security audit.
  • Myth: Once you pass, you never have to do it again.

Related Terms

Sources & Further Reading