The formal, legally mandated evaluation process required to verify that a high-risk AI system complies with all applicable regulatory requirements before it can be deployed or placed on the market.
The official checklist and testing process an AI system must pass to prove it follows the law before it can be used in high-risk situations, similar to a vehicle passing a rigorous safety inspection before it can be sold to the public.
A conformity assessment involves rigorous internal or third-party audits, technical testing, and documentation to ensure the system meets strict standards for data governance, transparency, accuracy, robustness, and human oversight. Depending on the risk level, this may be a self-assessment or require an independent third-party auditor (known as a “Notified Body” in the EU). Successful completion typically results in a CE mark or equivalent regulatory clearance (e.g., FDA 510(k) or De Novo).
Companies building high-risk AI must budget significant time (often 6–18 months) and resources for internal documentation, QMS implementation, and potential third-party auditor fees before launching products in regulated markets. Failure to obtain conformity assessment results in the inability to legally sell or deploy the product.
Before a hospital can deploy an AI tool that automatically detects tumors in X-rays (a high-risk medical device), the developer must undergo a conformity assessment by a notified body. The auditors review the clinical validation data, the quality management system, and the risk management file to ensure the AI is safe and effective before granting CE marking.