Notified Body Governance
Notified-Body Independence, Confidentiality and Competence
What this control does
Maintain notified-body independence, impartiality, confidentiality, cybersecurity, insurance and qualified personnel.
How to implement
For a notified body, maintain documented safeguards for impartiality, competence, resources, confidentiality, cybersecurity and the applicable liability arrangements. Review conflicts of interest before assigning work, verify staff competence and maintain suitable assessment procedures. Control access to confidential assessment information, including information exchanged with other bodies. Investigate breaches or capacity gaps and take corrective action. Coordinate formal reporting through the Notified-Body Regulatory Reporting and Continuity control; this control does not replace the required information-sharing process.
Suggested timing and triggers
Before relevant assignments; continuously for required safeguards; on staffing, ownership, capacity or security changes; periodic review.
Evidence examples
Independence and conflict declarations Competence matrix, staffing and procedure records Confidentiality agreements and access reviews Security and applicable liability evidence Internal review findings and corrective actions
How to check this control
Sample an assessment assignment for conflicts, competence and adequate resources. Check access to confidential files and follow one deficiency through correction. Verify that information sharing uses the applicable confidentiality controls.
Related EU AI Act obligations
Article 31
Maintain the Governance, Independence, Resources and Competence Required of an AI Notified Body
Article 31(1)-(3)
Maintain Appropriate Organisation, Quality Management, Processes and Cybersecurity
Sub-obligation of Article 31: Maintain the Governance, Independence, Resources and Competence Required of an AI Notified Body
Article 31(4)-(6)
Safeguard Independence, Objectivity and Impartiality in AI Conformity Assessment
Sub-obligation of Article 31: Maintain the Governance, Independence, Resources and Competence Required of an AI Notified Body
Article 31(7); Article 78
Protect Confidentiality and Professional Secrecy in Notified-Body Activities
Sub-obligation of Article 31: Maintain the Governance, Independence, Resources and Competence Required of an AI Notified Body
Article 31(8)-(9)
Maintain Proportionate Assessment Procedures and Appropriate Liability Insurance
Sub-obligation of Article 31: Maintain the Governance, Independence, Resources and Competence Required of an AI Notified Body
Article 31(10)-(11)
Maintain Sufficient Professional Competence and Qualified Personnel
Sub-obligation of Article 31: Maintain the Governance, Independence, Resources and Competence Required of an AI Notified Body
Article 31(12); Article 38
Participate in Notified-Body Coordination and Remain Current on Relevant Standards
Sub-obligation of Article 31: Maintain the Governance, Independence, Resources and Competence Required of an AI Notified Body
Article 45(2)-(4)
Share Required Conformity-Assessment Information With Peer Notified Bodies
Sub-obligation of Article 45: Meet Notified-Body Information-Sharing and Reporting Obligations