
Conformity Assessment for AI: What "Ready" Looks Like Before the Audit
A conformity assessment checks that a high-risk AI system meets its requirements before it goes to market. Most of the pain is producing the evidence. Here's what 'ready' looks like — and how to be in that state before the assessor arrives.
- Katya SavenkovaDirector of Operations
In this article
For high-risk AI systems, the EU AI Act expects a conformity assessment — a check that the system meets its requirements before it's placed on the market or put into service. The assessment itself is a procedure; the reason it's dreaded is the evidence it demands. Being 'ready' means having that evidence already assembled and verifiable, so the assessment is a review rather than a scramble.
What a conformity assessment checks
At its core, a conformity assessment asks whether the system genuinely meets the requirements that apply to it — the risk management, data governance, record-keeping, transparency, human oversight, accuracy, and robustness obligations — and whether you can show it. Depending on the system, the assessment may be one you conduct internally or one involving a third party. Either way, the assessor isn't taking your word; they're looking for evidence.
Why the evidence is the hard part
The requirements are knowable. What makes assessment expensive is proving each one is met — for a system that's been running and changing, often with the evidence scattered or never captured in the first place. Teams end up reconstructing, under time pressure, proof of controls that operated months ago. The assessment doesn't fail on the requirements; it stalls on the evidence.
You don't get 'ready' the week before the assessment. You get ready by operating controls that record their own evidence all along.
What "ready" actually looks like
- Controls that operate and record — risk, security, access, and oversight controls running and writing evidence to the ledger as they fire.
- Performance you can show — evaluation results demonstrating the system meets its accuracy and robustness bar, over time.
- Documentation assembled from evidence — the technical file drawn from what happened, not authored from memory.
- A verifiable record — evidence an assessor can check independently, so 'prove it' is a query.
A system in this state isn't scrambling to become assessable; it already is.
Internal readiness vs the formal step
Being ready and being assessed are different. A platform can put you in a state of readiness — controls operating, evidence assembled, documentation current — but the conformity assessment itself is a procedure you undertake, sometimes with a third party, and the determination is theirs and your compliance team's. Confusing 'we have the evidence ready' with 'we are certified' is a mistake worth avoiding; the first is what makes the second achievable, not a substitute for it.
Readiness as a standing state
The goal is to make readiness continuous rather than a pre-audit push. When controls record their operation as they run, you can ask 'are we assessment-ready' any day and get an honest answer from the record — and when the system changes, the evidence updates with it. Readiness stops being an event you brace for and becomes a property you maintain.
Frequently asked questions
Be ready before the assessor arrives. See how continuously recorded controls, evaluation results, and assembled documentation put you in a standing state of assessment-readiness. Book a walkthrough.
Part of