EU AI Act Art. 40 quality management systems: do you integrate ISO 42001 or build custom controls?
Art. 40 of the EU AI Act requires providers of high-risk AI systems to implement a quality management system that covers 11 specific elements — from data governance to post-market monitoring. Here's the practical dilemma: - ISO/IEC 42001 (AIMS) just dropped as a certifiable standard that maps roughly to Art. 40 requirements - But the overlap isn't clean — 42001 is management-system focused, while Art. 40 has very specific technical obligations (e.g., Art. 10 data quality metrics, Art. 15 accuracy/robustness targets) - Building a custom QMS from scratch means reinventing the wheel on documentation, internal audits, management review cycles - Adopting 42001 means you still need a gap analysis to cover AI Act specifics For teams operating in the EU right now: did you extend an existing ISO 27001/42001 framework, or build an AI-specific QMS from the ground up? And did your notified body care which route you took?