Caesar AI Atlas
Regulatory • Intermediate

Harmonised Standard vs Common Specification

A side-by-side comparison of Harmonised Standard and Common Specification. Understand how each supports conformity evidence and when teams should rely on standards or regulator-recognized specifications.

Quick Verdict: Use Harmonised Standard when a referenced European standard is available; use Common Specification when recognized technical criteria fill a gap or clarify compliance expectations.

At a Glance

Harmonised Standard

Harmonised Standard defines European standard adopted under EU standardisation rules and referenced for regulatory conformity purposes.

Key Characteristics
  • • European standard adopted under EU standardisation rules
  • • Referenced for regulatory conformity purposes
  • • Helps providers demonstrate legal requirements have been met
Watch Out For
  • • Not every technical standard is harmonised for the relevant legal requirement
  • • Evidence still needs to show correct implementation, not only citation of the standard

Context: Most relevant when a provider is building conformity evidence for an AI system under an EU regulatory framework.

VS
Common Specification

Common Specification defines technical specification recognized under European Union law as a means of demonstrating compliance with certain regulatory requirements.

Key Characteristics
  • • Technical specification recognized under EU law
  • • Provides criteria for meeting regulatory requirements
  • • Useful where harmonised standards are unavailable or insufficient
Watch Out For
  • • Should not be treated as a generic internal guideline
  • • May apply because of a specific regulatory gap or insufficiency rather than ordinary standard selection

Context: Most relevant when compliance teams need recognized technical criteria but cannot rely fully on an available harmonised standard.

Key Differences

AspectHarmonised StandardCommon Specification
Regulatory purposeA harmonised standard gives a European standardization route for showing conformity with referenced legal requirements.A common specification gives legally recognized technical criteria that can support compliance when standards do not sufficiently cover the requirement.
Trigger pointRelevant when an adopted and referenced standard exists for the AI system or requirement.Relevant where harmonised standards are unavailable, incomplete, or insufficient for the regulatory obligation.
Required evidenceEvidence should show which harmonised standard was applied and how the system implementation follows it.Evidence should show which specification was relied on and how its practical criteria were satisfied.
Responsible actorThe provider normally uses the standard as part of its conformity evidence and technical documentation.The provider or compliance owner uses the specification to document an alternative recognized compliance route.
Audit implicationAuditors will look for traceability between the referenced standard, the requirement, and implementation records.Auditors will examine why the specification was used and whether it properly addresses the missing or insufficient standard coverage.
Caesar AI Note

In practice, the safest approach is to treat both as evidence anchors, not shortcuts. A compliance file should explain why the selected route is applicable and where the implementation proof sits.

Notes

Common Mistakes

1

Treating any industry standard as a harmonised standard.

2

Using a common specification without documenting why a harmonised standard was unavailable or insufficient.

3

Assuming a citation alone proves conformity without implementation evidence.

4

Mixing the two routes in policies without assigning evidence ownership.

When to Use Each

harmonised-standard

Use Harmonised Standard when your AI system can be mapped to a European standard referenced for regulatory conformity. It is strongest when the standard directly covers the relevant EU AI Act requirement and your records show implementation evidence.

common-specification

Use Common Specification when recognized technical criteria are needed because harmonised standards are not available or do not fully address the obligation. Document why this route was chosen and how each specification requirement was implemented.

Compliance Note

Under EU AI Act workflows, this distinction affects how conformity evidence is organized and reviewed. ISO 42001-style management systems can track both routes as controlled external requirements with owners, implementation evidence, and review dates.

FAQ

Is a common specification the same as a harmonised standard?+

No. A harmonised standard is a European standard referenced for conformity purposes, while a common specification is a recognized technical specification that can provide practical compliance criteria in specific circumstances.

Which one should a provider cite in technical documentation?+

The provider should cite the route actually used to demonstrate conformity. If both are relevant, the documentation should explain the role of each and avoid presenting them as interchangeable.

Why does the difference matter for audits?+

The audit question is not only whether a document exists, but whether the chosen evidence route fits the legal requirement. Mislabeling the route can make the conformity file harder to defend.

Recently Viewed

No recently viewed comparisons yet.