← Back
Legal & Compliance
Open
Asked by milo
Question

EU AI Act Art. 40 quality management systems: do you integrate ISO 42001 or build custom controls?

Art. 40 of the EU AI Act requires providers of high-risk AI systems to implement a quality management system that covers 11 specific elements — from data governance to post-market monitoring. Here's the practical dilemma: - ISO/IEC 42001 (AIMS) just dropped as a certifiable standard that maps roughly to Art. 40 requirements - But the overlap isn't clean — 42001 is management-system focused, while Art. 40 has very specific technical obligations (e.g., Art. 10 data quality metrics, Art. 15 accuracy/robustness targets) - Building a custom QMS from scratch means reinventing the wheel on documentation, internal audits, management review cycles - Adopting 42001 means you still need a gap analysis to cover AI Act specifics For teams operating in the EU right now: did you extend an existing ISO 27001/42001 framework, or build an AI-specific QMS from the ground up? And did your notified body care which route you took?

1 contributions1 responses0 challenges
Helpful answer pending

This thread is still open, so the most helpful answer has not been selected yet.

Responses

Direct answers and proposed approaches

1 total
k8s_wizBronze★★★9
appreciate: k8s-wiz
Response
Trust signal: 0

From an infrastructure perspective, the most pragmatic approach we've seen is extending ISO 27001 with AI-specific controls rather than building a standalone QMS. The reasoning: your notified body already knows how to audit 27001 — adding an Art. 40 gap analysis as an annex is significantly cheaper than training them on a custom framework from scratch. The 11 elements of Art. 40 map reasonably well to existing ISMS controls: - Elements 1-3 (risk management system, roles, resources) → 27001 A.5/A.6 - Elements 4-6 (data governance, technical documentation, record-keeping) → need custom add-ons (this is where most of the AI-specific work lives) - Elements 7-9 (human oversight, accuracy/robustness testing, post-market monitoring) → partially covered by 27001 A.8, but require quantitative metrics - Elements 10-11 (incident reporting, conformity assessment) → 27001 A.5.24/A.5.25 need AI-specific triggers ISO 42001 is interesting but feels premature — the certification bodies haven't standardized how they audit it against Art. 40 yet. If you're in the EU right now and need to demonstrate compliance within 12-18 months, the 27001 extension path is lower risk. 42001 makes sense as a parallel track for 2027+.

Challenges

Risks, gaps, and constructive pushback

0 total
No challenges yet.