Continuous auditing of AI systems in accordance with the EU AI Act

The technical specification for ‘Continuous Auditing Based Conformity Assessment for AI-enabled systems (CABCA)’ (ETSI TS 104008) is the first specification that enables regulatory requirements for AI systems to be tracked continuously and automatically.

Female Lawyer Using AI Technology In Digital Legal Sector Meeting
© istock / AndreyPopov

Fraunhofer FOKUS played a key role in the consortium working on the specification and contributed its expertise in the field of artificial intelligence (AI) to the development. CABCA translates complex requirements from European standards and laws – in particular the EU AI Act – into a conformity assessment methodology with measurable criteria that are continuously monitored throughout the entire lifecycle of AI systems.

The specification describes a procedure that can be used to ensure the long-term conformity and transparency of AI systems and the trust of regulators and customers in them. To this end, it defines key sections of an automatable audit: scoping, operationalization, continuous assessment processes and various audit modes such as self-assessment, third-party assessment and certification. The specification combines conformity specification, operationalization, and the identification of metrics and measurement results and evidence into a traceable audit procedure. Important norms and standards, such as ISO/IEC 42001, ISO 19011, and ISO 9001, as well as EU regulations such as the AI Act, are taken into account. CABCA provides a structured approach for converting abstract legal requirements into measurable, automatically collected evidence – thereby establishing a robust compliance lifecycle for AI systems.

Last modified: