ai services

EN 18286: The Missing Link Between AI Governance and EU AI Act Compliance

Introduction: Why EN 18286 Matters

The Plan-Do-Check-Act Framework

At first glance, EN 18286 will feel familiar to anyone who has implemented ISO 9001 or ISO 42001. The structure follows a PDCA system model, The Plan-Do-Check-Act model is a continual improvement cycle used in management system standards.

  • Plan: define the AI management objectives, regulatory obligations, risks, controls, responsibilities and documented processes needed to manage AI systems effectively.
  • Do: implement the planned processes and controls across the AI system lifecycle, including design, development, deployment, monitoring and change management.
  • Check: monitor, measure, audit and review whether the AI management system and AI system controls are operating as intended and meeting applicable requirements.
  • Act: take corrective action, address nonconformities, improve controls and update the management system in response to performance results, incidents, regulatory change and lessons learned.

In the context of EN 18286, this means AI governance and compliance are not treated as one-off activities, but as an ongoing cycle of planning, operation, monitoring, review and improvement across the AI system lifecycle.

Alignment with ISO 9001 and ISO/IEC 42001

In fact, the standard includes correspondence tables showing alignment with both ISO 9001 and ISO 42001

  • Like ISO 9001, EN 18286 requires organisations to establish policies, objectives, defined responsibilities, documented processes and management reviews.
  • Like ISO 42001, it adopts a lifecycle-based approach to AI governance, addressing risk management, stakeholder engagement, monitoring and continuous improvement.

Organisations that already operate either of these standards will find many concepts transferable and potentially reusable.

Whether you are exploring AI for the first time, reviewing existing AI use or preparing for future certification, AvISO can help you build a clear and practical approach.

How EN 18286 Differs from Existing Management System Standards

However, EN 18286 is not simply another quality standard. Its purpose is fundamentally different.

ISO 9001 focuses on customer satisfaction and organisational quality. ISO/IEC 42001 focuses on establishing an AI management system that enables responsible governance of AI. EN 18286, by contrast, defines quality in terms of regulatory compliance. Throughout the standard, "quality" is linked directly to meeting regulatory requirements and protecting health, safety and fundamental rights.

Regulatory Compliance Across the AI Lifecycle

This shift in emphasis drives several unique requirements. EN 18286 requires organisations to establish a regulatory compliance strategy, identify applicable legal requirements, implement lifecycle controls for AI systems, maintain technical documentation, manage post-market monitoring, investigate serious incidents, control modifications and continuously assess compliance after deployment. It also places strong emphasis on demonstrating traceability, verification, validation, risk management and oversight throughout the entire AI lifecycle.

Stakeholders, Fundamental Rights and Market Surveillance

The standard also extends beyond traditional governance by introducing specific requirements relating to deployers, affected persons, fundamental rights, regulatory authorities and market surveillance obligations. This reflects the EU AI Act's objective of protecting people from harms arising from AI systems while ensuring accountability from providers.

Presumption of Conformity and Regulatory Limits

For organisations preparing for the EU AI Act, EN 18286 may become one of the most important standards to understand. Annex ZA explicitly maps the standard to EU AI Act requirements and states that, once referenced in the Official Journal of the European Union, conformity with applicable clauses can provide a presumption of conformity with corresponding regulatory requirements. However, the standard is clear that implementing EN 18286 alone does not automatically guarantee compliance with the EU AI Act. Regulatory obligations must still be assessed and addressed individually.

Key Takeaway

ask a question

Get in touch to discuss information security and specialist assurance support
Kent: 01892 800476 | London: 02037 458 476 | info@avisoconsultancy.co.uk

By filling out this form, you agree to the terms laid out in our privacy policy
Thank you!
Your submission has been received, one of our team members will be in touch soon.
Oops! Something went wrong while submitting the form.
ISO consultants kent
ASK our AGENT
By clicking “Continue To Site”, you agree to the storing of cookies on your device to enhance site navigation, analyse site usage, and assist in our marketing efforts. View our Privacy Policy for more information.