Third-Party Audit
Independent evaluation of AI system compliance by an accredited external body rather than the provider itself.
Definition
Third-Party Audit refers to independent evaluation of an AI system's compliance with regulatory requirements conducted by an external body (typically a notified body) rather than the provider. It provides higher assurance than self-assessment.
EU AI Act Requirements: Third-party conformity assessment is mandatory for:
- Remote biometric identification (Article 43(1)): Always requires notified body involvement
- Non-harmonized areas: When provider doesn't follow harmonized standards or common specifications
- Sectoral requirements: When underlying product legislation mandates third-party assessment
Notified Body Role (Articles 28-39):
- Designated by EU Member States after accreditation
- Must demonstrate technical competence, independence, impartiality
- Reviews technical documentation and quality management system
- May conduct testing and on-site inspections
- Issues conformity assessment certificates
Assessment Procedures:
- Type examination (Annex VII): Notified body examines technical design
- Quality management (Annex VII): Notified body assesses and monitors QMS
- Combination: Often both procedures are required
Related concepts: Notified Body, Conformity Assessment, Self-Assessment, Certification Body
Sources
- •EU AI Act Article 43(1)
- •NYC Local Law 144
Related Terms
Notified Body
Independent organization designated to assess conformity of certain high-risk AI systems....
Conformity Assessment
Process to verify that high-risk AI systems meet regulatory requirements before market placement....
Self-Assessment
Conformity assessment procedure where the AI provider independently evaluates compliance without third-party audit....