Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Notified Body Governance

Notified-Body Independence, Confidentiality and Competence

What this control does

Maintain notified-body independence, impartiality, confidentiality, cybersecurity, insurance and qualified personnel.

How to implement

For a notified body, maintain documented safeguards for impartiality, competence, resources, confidentiality, cybersecurity and the applicable liability arrangements. Review conflicts of interest before assigning work, verify staff competence and maintain suitable assessment procedures. Control access to confidential assessment information, including information exchanged with other bodies. Investigate breaches or capacity gaps and take corrective action. Coordinate formal reporting through the Notified-Body Regulatory Reporting and Continuity control; this control does not replace the required information-sharing process.

Suggested timing and triggers

Before relevant assignments; continuously for required safeguards; on staffing, ownership, capacity or security changes; periodic review.

Evidence examples

Independence and conflict declarations Competence matrix, staffing and procedure records Confidentiality agreements and access reviews Security and applicable liability evidence Internal review findings and corrective actions

How to check this control

Sample an assessment assignment for conflicts, competence and adequate resources. Check access to confidential files and follow one deficiency through correction. Verify that information sharing uses the applicable confidentiality controls.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Notified-Body Independence, Confidentiality and Competence | EU AI Act Suggested Control | Tracker Networks