An accredited third-party organisation recognised by a member state to assess certain high-risk AI systems under the EU AI Act. It reviews evidence, tests, and documentation when self-assessment is not sufficient under the regulation.
Expanded Definition
A Notified Body is a formally designated conformity assessment organisation that a member state recognises to evaluate whether a product or system meets specific legal requirements before market entry. For this glossary term, the most relevant context is the EU AI Act, where a Notified Body may be used when a high-risk AI system cannot rely on self-assessment alone. The role is narrower than a general auditor and more specific than an internal compliance function: it is empowered to review technical documentation, testing evidence, risk controls, and conformity processes against regulatory criteria.
Industry usage can be uneven because the exact scope of a Notified Body depends on the applicable law, sector, and designation regime. In practice, the body does not “approve AI” in a broad sense; it assesses whether the provider has shown compliance with defined obligations for a specific system and use case. That distinction matters because a passing assessment is evidence of regulatory conformity, not a guarantee that the system is safe in every operational context. The most common misapplication is treating a Notified Body like a blanket certification authority, which occurs when organisations assume one assessment covers all deployments, versions, or risk scenarios.
Examples and Use Cases
Implementing Notified Body review rigorously often introduces schedule and evidence-collection overhead, requiring organisations to weigh faster release cycles against the cost of structured compliance testing.
- A provider of a high-risk hiring model assembles technical files, logging evidence, and human oversight procedures for independent review before deployment.
- An AI system used in critical infrastructure is routed through a conformity assessment process because internal self-declaration is not sufficient under the applicable rules.
- A compliance team prepares version-controlled documentation so a designated body can trace risk management decisions, data governance, and test results.
- A procurement function requires confirmation that a supplier’s AI system has completed the appropriate external assessment pathway before contract award.
- A governance group uses the assessment findings to close gaps in NIST Cybersecurity Framework 2.0-aligned controls, especially where system integrity and accountability evidence overlap.
Why It Matters for Security Teams
Security teams need to understand Notified Body requirements because the assessment boundary shapes what evidence must exist, how controls are documented, and when a system can lawfully move toward deployment. For AI governance, this is not just a legal formality. It affects model traceability, data provenance, access controls around training artefacts, change management, and incident response readiness. Where identity, NHI, or agentic AI is involved, the same discipline extends to service accounts, tool permissions, and delegated execution paths that can alter the risk posture of the assessed system.
Misunderstanding the role can leave teams with incomplete documentation, inconsistent control ownership, or a false sense of compliance after a single review cycle. That becomes especially problematic when a system is updated, retrained, or repurposed, because the original assessment may no longer reflect current behaviour. A useful reference point is the governance emphasis in the NIST Cybersecurity Framework 2.0, which reinforces accountability and lifecycle management even though it is not the regulating instrument for the EU AI Act. Organisations typically encounter the real operational cost only after a release is delayed, a supplier cannot produce evidence, or a regulator asks for proof that the designated assessment path was followed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST AI RMF set the technical controls, while EU AI Act define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| EU AI Act | The Act establishes when external conformity assessment by a Notified Body is required. | |
| NIST CSF 2.0 | GV.OV | CSF governance and oversight help organise evidence and accountability around assessments. |
| NIST AI RMF | GOVERN | AI RMF GOVERN supports accountability and documentation that parallel conformity assessment needs. |
Determine whether the AI system needs third-party conformity assessment before placing it on the market.