A side-by-side comparison of Harmonised Standard and Common Specification. Understand how each supports conformity evidence and when teams should rely on standards or regulator-recognized specifications.
Quick Verdict: Use Harmonised Standard when a referenced European standard is available; use Common Specification when recognized technical criteria fill a gap or clarify compliance expectations.
Harmonised Standard defines European standard adopted under EU standardisation rules and referenced for regulatory conformity purposes.
Context: Most relevant when a provider is building conformity evidence for an AI system under an EU regulatory framework.
Common Specification defines technical specification recognized under European Union law as a means of demonstrating compliance with certain regulatory requirements.
Context: Most relevant when compliance teams need recognized technical criteria but cannot rely fully on an available harmonised standard.
| Aspect | Harmonised Standard | Common Specification |
|---|---|---|
| Regulatory purpose | A harmonised standard gives a European standardization route for showing conformity with referenced legal requirements. | A common specification gives legally recognized technical criteria that can support compliance when standards do not sufficiently cover the requirement. |
| Trigger point | Relevant when an adopted and referenced standard exists for the AI system or requirement. | Relevant where harmonised standards are unavailable, incomplete, or insufficient for the regulatory obligation. |
| Required evidence | Evidence should show which harmonised standard was applied and how the system implementation follows it. | Evidence should show which specification was relied on and how its practical criteria were satisfied. |
| Responsible actor | The provider normally uses the standard as part of its conformity evidence and technical documentation. | The provider or compliance owner uses the specification to document an alternative recognized compliance route. |
| Audit implication | Auditors will look for traceability between the referenced standard, the requirement, and implementation records. | Auditors will examine why the specification was used and whether it properly addresses the missing or insufficient standard coverage. |
In practice, the safest approach is to treat both as evidence anchors, not shortcuts. A compliance file should explain why the selected route is applicable and where the implementation proof sits.
Treating any industry standard as a harmonised standard.
Using a common specification without documenting why a harmonised standard was unavailable or insufficient.
Assuming a citation alone proves conformity without implementation evidence.
Mixing the two routes in policies without assigning evidence ownership.
Use Harmonised Standard when your AI system can be mapped to a European standard referenced for regulatory conformity. It is strongest when the standard directly covers the relevant EU AI Act requirement and your records show implementation evidence.
Use Common Specification when recognized technical criteria are needed because harmonised standards are not available or do not fully address the obligation. Document why this route was chosen and how each specification requirement was implemented.
Under EU AI Act workflows, this distinction affects how conformity evidence is organized and reviewed. ISO 42001-style management systems can track both routes as controlled external requirements with owners, implementation evidence, and review dates.
No. A harmonised standard is a European standard referenced for conformity purposes, while a common specification is a recognized technical specification that can provide practical compliance criteria in specific circumstances.
The provider should cite the route actually used to demonstrate conformity. If both are relevant, the documentation should explain the role of each and avoid presenting them as interchangeable.
The audit question is not only whether a document exists, but whether the chosen evidence route fits the legal requirement. Mislabeling the route can make the conformity file harder to defend.
No recently viewed comparisons yet.