This article is about the structure of assurance obligations, not a survey of jurisdictions. The only regime read at source here is the EU AI Act, quoted from the European Commission's own pages on 31 August 2026. Where a jurisdiction is not mentioned, that is not a statement about that jurisdiction, by implication or otherwise. Nothing here is legal advice in any jurisdiction, and the operative wording must be read in the original before any decision is taken on it.
- Two questions get merged. Who is obliged to check an AI system, and who is able to. Almost everywhere the answer to the first is nobody, and the answer to the second is a growing market.
- In the EU, third-party assessment is genuinely required only in a narrow case. Article 43 offers Annex III point 1 providers a notified body route and makes it obligatory where harmonised standards are absent or partly applied. For Annex III points 2 to 8 the Act directs providers to internal control under Annex VI, which does not provide for the involvement of a notified body.
- A required check has a floor set by somebody other than the buyer, a recognised meaning, a route of challenge, and no differentiating power. An available check inverts all four.
- Available assurance is not weaker. It is often more specific and more current. It simply cannot discharge a legal obligation, and presenting it as though it could is the failure mode.
- Where nothing is required, build the evidence base anyway and decide about certificates separately. The artefacts are the same either way, and assembling them after a demand costs several times what assembling them before one does.
Section 1. The two questions
The first question is regulatory. Before this system may be placed on a market or put into service, does the law oblige a party other than us to examine it and say so. That question has a yes or no answer in each jurisdiction, and the answer is a fact about the statute rather than about the system.
The second question is commercial. If we wanted somebody outside this organisation to examine the system and produce a report, could we buy that, from whom, against what benchmark, and how often. That question has an answer that changes month by month as a market develops, and it is entirely independent of the first.
The reason the merge is so common is that in most regulated fields the two answers coincide. Where a check is required, an industry exists to perform it, and where an industry exists it is usually because a check is required. AI has separated them, because the demand for external examination arrived from buyers and insurers several years before any legislature was ready to compel it. That separation is temporary in some jurisdictions and may be permanent in others, and either way an operator planning today has to hold both answers at once.
Section 2. Where a check is actually required
The EU AI Act is the most detailed AI statute this desk has read at source, so it is the natural place to test the assumption that a detailed statute produces a mandatory audit. It mostly does not.
Article 43 divides the Annex III high-risk population. For Annex III point 1, biometrics, the provider opts either for internal control under Annex VI or for an assessment of the quality management system and the technical documentation with the involvement of a notified body under Annex VII. That choice is constrained: where harmonised standards do not exist, where the provider has applied them only in part, or where common specifications are unavailable, the notified body route becomes obligatory rather than optional. That is the one place in the Annex III regime where an outside examination is genuinely compelled.
For Annex III points 2 to 8, which is critical infrastructure, education, employment, essential services including credit, law enforcement, migration and the administration of justice, the Act provides that providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body. Annex VI is three verifications, all performed by the provider on its own work: the quality management system against Article 17, the technical documentation against the essential requirements, and the consistency of design, development and post-market monitoring with that documentation.
A separate route exists for Annex I, AI embedded in products already regulated by existing sectoral legislation. There, third-party involvement can arrive through the product legislation that already applies, which is a different mechanism from anything the AI Act creates. The full reading of that architecture, including what the Act asks of a notified body under Article 31 when it does want one, is on the European desk at most high-risk AI needs no outside auditor under the Act.
No other jurisdiction is characterised in this article. This desk has not verified the assurance position outside the EU in this pass, and the discipline that governs these pages is that an unverified regime is left unmentioned rather than described approximately. The map of where AI statutes exist at all is at the global AI regulation status tracker.
Section 3. Where a check is merely available
Meanwhile, the answer to the second question has changed materially during 2026, and it changed without any legislature acting.
Schellman published on 3 February 2026 that it had become the first accredited auditor for AIUC-1, describing a structure in which it provides independent audit evidence collection, detailed reporting and certification guidance while the Artificial Intelligence Underwriting Company conducts technical evaluations and issues certification, with agent behaviour tested quarterly to ensure ongoing compliance. KPMG published on 27 August 2026 that KPMG LLP is the first of the Big Four to achieve AIUC-1 certification, for a platform it states underwent more than 900 technical tests including hallucinations, high-risk domain interactions, content safety and prompt injection attacks. Alongside that sits the older and more conventional management system route, where Schellman describes itself as the first ISO 42001 ANAB accredited certification body.
None of that is required by any statute this desk has read. All of it is purchasable today. The certification desk's reading of what that structure is and how its accreditation chain compares with the classical one is at the audit layer arrived, and it is private.
Section 4. Four differences that decide what each is worth
These are the properties that make a required check and an available check behave differently, and none of them is about rigour. An available check can be considerably more rigorous than a required one.
The floor. A required check has a scope set by somebody other than the party paying for it. That is its central property. An available check has a scope negotiated between the buyer and the assessor, which means a narrow scope is always purchasable, and which is why the first question to ask about any voluntary certificate is what was in it.
The meaning. A required check has a meaning recognised by supervisors and, eventually, by courts. Passing it establishes something specific in a later dispute. An available check means what its standard says it means, which may be a great deal to a counterparty who understands the standard and nothing at all to a tribunal that has never encountered it.
The remedy. Where a mandated assessor gets it wrong, there is usually a designation regime, a supervisory relationship and an insurance requirement standing behind them. The EU AI Act, for instance, requires a notified body to obtain appropriate liability insurance for its conformity assessment activities. Where a voluntary assessor gets it wrong, your remedy is your contract with them, and you should read the limitation of liability clause in it before you rely on the report.
The signal. This one runs the other way and is consistently underrated. A required check applies to everybody in the category, so holding one tells a counterparty nothing about you relative to your competitors. A voluntary check is held by a minority, so it differentiates precisely because it is not required. An operator buying assurance for commercial reasons is buying the second property, and should be clear that is what they are buying.
Section 5. What follows for a global operator
Do not answer a regulator with a private certificate. It is not responsive, and offering it can read as an attempt to substitute one thing for another. Answer with the evidence the regime asks for. The certificate may sit alongside as context.
Do not read the absence of a required check as the absence of an obligation. This is the most expensive error available here. The EU AI Act's substantive duties on providers and deployers apply regardless of who verifies them, backed by documentation requirements, market surveillance and penalties. And in most jurisdictions the ordinary law of contract, negligence and product liability applies to what an AI system does whether or not an AI statute exists at all, which we set out at where strict liability already reaches AI deployers.
Do not assume a certificate travels. A voluntary certificate is recognised where its standard is recognised, which is a commercial fact rather than a legal one and differs by market and by sector. This is the same structural point we made about compliance programmes generally at why you cannot over-comply your way into compliance: some things transfer between regimes and some things must be performed locally, and knowing which is which is most of the work.
Do expect the requirement question to change under you. The EU's own answer has a date attached: Annex III obligations apply from 2 December 2027 and Annex I from 2 August 2028 under the AI Omnibus. Any operator building a plan on today's answer should know when today's answer expires in each market it sells into.
Section 6. What to do where nothing is required
The practical answer is to stop treating this as a certification decision and treat it as an evidence decision, because the evidence is useful in every branch and the certificate is useful in only some.
Six artefacts serve every assurance regime this desk has examined, and they also serve a claim, a regulator's request and an insurer's proposal form. An inventory of AI systems in production with a named owner for each. A risk record per system, dated. Test results with dates, methods and outcomes. A change log covering the surfaces that alter behaviour without a code change, meaning model version, system prompt, retrieval corpus, tool permissions and guardrail configuration. An oversight arrangement naming who can intervene and how. And an incident procedure that has been read by the people who would have to use it.
Build those and the certificate question becomes cheap, because the assessment is largely a matter of handing over records that already exist. Skip them and the certificate question becomes expensive in every direction at once, since the same absence blocks the audit, the insurance submission and the regulatory answer simultaneously. Which of those artefacts can be reused across frameworks without regeneration is at what evidence transfers between frameworks, and the management system route that formalises them is at ISO 42001 for global operators.
For a smaller operator being asked about a supplier's certificate rather than about its own, the buyer-side version of this question is at what it means when your AI vendor says it is certified. For the insurance dimension, where the distinction between what an underwriter requires and what a marketing page offers has the same shape, see what the panel behind an AI policy tells you.
Section 7. The point in one sentence
Almost nowhere obliges an outside party to examine your AI system, plenty of parties will do it if you ask, and the difference between those two facts determines what a certificate proves, who is bound by it and what it is worth in the room where you produce it.
Questions
Is an independent audit of an AI system legally required anywhere?
Rarely, and in the EU it is narrower than most operators assume. Article 43 of the EU AI Act gives providers of Annex III point 1 systems, which is biometrics, a choice between internal control under Annex VI and an assessment involving a notified body under Annex VII, with the notified body route becoming obligatory where harmonised standards do not exist, are applied only in part, or common specifications are unavailable. For Annex III points 2 to 8 the Act directs providers to internal control, a procedure it describes as one which does not provide for the involvement of a notified body. This article does not characterise any other jurisdiction, because this desk has not verified the position in one.
What is the difference between a required check and an available one?
Four differences that matter operationally. A required check has a floor set by somebody other than the buyer, so it cannot be scoped down to what is convenient. It has a recognised meaning, so a supervisor or a court knows what passing it implies. It usually carries a route of challenge if the assessor is wrong. And it applies to everybody in the category, so it tells you nothing about the holder relative to their peers. An available check inverts all four: the buyer sets the scope, the meaning is whatever the standard says it is, the remedy is contractual, and holding one is a differentiator precisely because most peers do not.
Is an available check worth less than a required one?
Not less, differently. Voluntary assurance is often more useful to a counterparty than a mandatory one, because it is specific to the system rather than generic to the category, it can be retested on a short cycle, and the fact that somebody chose to buy it is itself information. What it cannot do is discharge a legal obligation. The failure mode is not buying voluntary assurance; it is presenting it to a board, a regulator or an insurer as though it were the mandatory kind.
If nothing is required, why would an operator pay for assurance at all?
Because the pressure is arriving from counterparties rather than from regulators. Enterprise procurement questionnaires ask, insurers ask at proposal stage, and large customers increasingly make it a condition of contract. Those parties are not waiting for a legislature. An operator that can produce dated, external evidence about a named system is answering a commercial question that is already being asked, and the cost of assembling that evidence after a demand is materially higher than the cost of assembling it before one.
What should a global operator do where no jurisdiction requires a check?
Build the evidence base once and decide about certificates separately. The artefacts that any assurance regime asks for are broadly the same: an inventory of systems with named owners, a risk record, dated test results, a change log covering model version, prompts, retrieval corpus and tool permissions, an oversight arrangement and an incident procedure. Those are useful whether or not anybody ever audits you, because they are also what a claim, a regulator's request or an insurer's proposal form will demand. Certificates are a decision about which market signal to buy, and that decision is cheap once the evidence exists and expensive before.
Does the absence of a requirement mean the absence of an obligation?
No, and conflating the two is the most expensive error in this area. The EU AI Act imposes substantial obligations on providers and deployers of high-risk systems regardless of who verifies compliance, backed by documentation duties, market surveillance and penalties. Ordinary law of contract, negligence and product liability applies to AI outcomes in most jurisdictions whether or not any AI-specific statute exists. What varies between regimes is who checks and when, not whether anybody is answerable.