You are on CAQA Consulting
CAQA GROUPSAustralia's compliance & quality assurance consultancy
Home / Services / EU AI Act & ISO 42001
AI Governance & Conformity

Sell AI into Europe. Prove it complies.

The EU AI Act reaches any organisation, anywhere, that places an AI system on the EU market or whose system outputs are used by people in the EU. We build the governance that satisfies it - aligned to ISO/IEC 42001, the certifiable AI management system standard.

Penalties up to €35M / 7% of global turnoverProhibited practices since 2 Feb 2025GPAI obligations since 2 Aug 2025Delivery Worldwide
What we deliver

Conformity, end to end

One team covering both sides of the same coin: the legal obligations of the EU AI Act and the management system - ISO/IEC 42001 - that operationalises them. Delivered with your legal advisers, anywhere you are based.

01
Applicability & risk classification

Are you actually in scope? We map your systems against the Act's risk tiers - including outputs used in the EU by organisations with no EU presence.

02
Gap assessment against the Act and ISO/IEC 42001

One assessment, two lenses: legal obligations and the certifiable management system that evidences them.

03
AI quality management system build

An ISO/IEC 42001-aligned AIMS designed for certification - policies, roles, risk treatment, lifecycle controls.

04
Technical documentation & record-keeping

The Annex-grade documentation packs high-risk systems must maintain - built once, kept current.

05
Conformity assessment preparation & registration

Readiness for the conformity route that applies to you, and support through registration.

06
Authorised representative coordination

Non-EU providers of high-risk systems must appoint an EU-based authorised representative - we coordinate the arrangement and the information flow.

07
GPAI transparency obligations

Documentation, downstream information and copyright measures for general-purpose model providers and deployers.

08
Prohibited-practice screening & staff training

Screen the portfolio against the banned-practice list and train the teams who build and buy AI.

The timeline

Where the Act stands

2 February 2025Prohibited AI practices apply - unacceptable-risk systems are banned in the EU market.
2 August 2025General-purpose AI obligations apply - transparency, documentation and copyright measures for GPAI providers.
High-risk obligationsOriginally set for 2 August 2026; being deferred toward late 2027 under the Digital Omnibus package following the political agreement of 7 May 2026 - formal adoption still pending. We track the timetable so you do not have to.
High-risk requirementsA quality management system, technical documentation, conformity assessment and registration - plus an EU-based authorised representative for non-EU providers.

Regulatory guidance, not legal advice - we work alongside your legal counsel and our Legal & Regulatory Dispute Support practice.

Exposed to the EU market?

A free, confidential scoping call tells you which tier you fall in and what conformity actually requires.

Book a free consultation →

Newsletter Subscription

To Receive Updates And Offers