ETSI TS 104 008 V1.1.1 (2026-01)
Methods for Testing & Specification (MTS); Continuous Auditing Based Conformity Assessment for AI-enabled systems
Methods for Testing & Specification (MTS); Continuous Auditing Based Conformity Assessment for AI-enabled systems
DTS/MTS-AI-00104008_ContAudit
General Information
- Status
- Not Published
- Technical Committee
- MTS AI - Methods of Testing and Specification Artificial Intelligence
- Current Stage
- 12 - Citation in the OJ (auto-insert)
- Due Date
- 28-Nov-2025
- Completion Date
- 07-Jan-2026
Frequently Asked Questions
ETSI TS 104 008 V1.1.1 (2026-01) is a standard published by the European Telecommunications Standards Institute (ETSI). Its full title is "Methods for Testing & Specification (MTS); Continuous Auditing Based Conformity Assessment for AI-enabled systems". This standard covers: DTS/MTS-AI-00104008_ContAudit
DTS/MTS-AI-00104008_ContAudit
ETSI TS 104 008 V1.1.1 (2026-01) is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
TECHNICAL SPECIFICATION
Methods for Testing & Specification (MTS);
Continuous Auditing Based Conformity Assessment
for AI-enabled systems
2 ETSI TS 104 008 V1.1.1 (2026-01)
Reference
DTS/MTS-AI-00104008_ContAudit
Keywords
AI, assessment, conformity, testing
ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE
Tel.: +33 4 92 94 42 00 Fax: +33 4 93 65 47 16
Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° w061004871
Important notice
The present document can be downloaded from the
ETSI Search & Browse Standards application.
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format on ETSI deliver repository.
Users should be aware that the present document may be revised or have its status changed,
this information is available in the Milestones listing.
If you find errors in the present document, please send your comments to
the relevant service listed under Committee Support Staff.
If you find a security vulnerability in the present document, please report it through our
Coordinated Vulnerability Disclosure (CVD) program.
Notice of disclaimer & limitation of liability
The information provided in the present deliverable is directed solely to professionals who have the appropriate degree of
experience to understand and interpret its content in accordance with generally accepted engineering or
other professional standard and applicable regulations.
No recommendation as to products and services or vendors is made or should be implied.
No representation or warranty is made that this deliverable is technically accurate or sufficient or conforms to any law
and/or governmental rule and/or regulation and further, no representation or warranty is made of merchantability or fitness
for any particular purpose or against infringement of intellectual property rights.
In no event shall ETSI be held liable for loss of profits or any other incidental or consequential damages.
Any software contained in this deliverable is provided "AS IS" with no warranties, express or implied, including but not
limited to, the warranties of merchantability, fitness for a particular purpose and non-infringement of intellectual property
rights and ETSI shall not be held liable in any event for any damages whatsoever (including, without limitation, damages
for loss of profits, business interruption, loss of information, or any other pecuniary loss) arising out of or related to the use
of or inability to use the software.
Copyright Notification
No part may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and
microfilm except as authorized by written permission of ETSI.
The content of the PDF version shall not be modified without the written authorization of ETSI.
The copyright and the foregoing restriction extend to reproduction in all media.
© ETSI 2025.
All rights reserved.
ETSI
3 ETSI TS 104 008 V1.1.1 (2026-01)
Contents
Intellectual Property Rights . 5
Foreword . 5
Modal verbs terminology . 5
Executive summary . 5
Introduction . 6
1 Scope . 7
2 References . 7
2.1 Normative references . 7
2.2 Informative references . 7
3 Definition of terms, symbols and abbreviations . 8
3.1 Terms . 8
3.2 Symbols . 9
3.3 Abbreviations . 9
4 CABCA Motivation and Overview . 10
4.1 Imperative of CABCA in AI System Assurance . 10
4.2 Comparison of CABCA with Traditional Audit Processes . 12
5 Fundamentals of CABCA . 13
5.1 General . 13
5.2 Mandatory Prerequisites for Implementing CABCA . 15
5.2.1 General . 15
5.2.2 Comprehensive Knowledge Base . 15
5.2.3 Technical and Operational Expertise . 16
5.2.4 Infrastructure and Methodological Framework . 16
5.2.5 Risk Management and Stakeholder Engagement . 16
5.3 Basic Assumptions of CABCA . 16
5.3.1 General . 16
5.3.2 AI System Heterogeneity and Dynamism . 17
5.3.3 Universal Applicability and Transparency . 17
5.3.4 Independence and Objectivity in Auditing . 17
5.4 Principles of CABCA . 17
5.4.1 General . 17
5.4.2 Ongoing confor mity . 18
5.4.3 Stakeholder trust . 18
5.4.4 Adaptability . 18
6 Description of the CABCA Process Execution . 18
6.1 General . 18
6.2 Process Variations Based on CABCA Modes . 20
6.2.1 Self-Assessment Path . 20
6.2.2 Third-Party Assessment Path . 20
6.2.3 Certification Path . 21
6.3 Roles in Process Execution . 21
6.3.1 General . 21
6.3.2 Auditee . 21
6.3.3 Auditing Party . 22
6.3.4 Entity for Attestation of Conformity . 23
7 Scoping (Identification of Conformity Specifications) . 23
7.1 General . 23
7.2 Sources and Integration Criteria for Conformity Specifications . 23
7.2.1 Sources of Conformity Specifications . 23
7.2.2 Criteria for Integrating Conformity Specifications in CABCA . 24
8 Operationalization (Planning & Risk Assessment, Automation Setup) . 25
ETSI
4 ETSI TS 104 008 V1.1.1 (2026-01)
8.1 Process of Operationalization . 25
8.1.1 General . 25
8.1.2 Identification of Quality Dime nsio ns . 26
8.1.2.1 Requirements for Defining Quality Dimensions . 26
8.1.2.2 Criteria for Defining Quality Dimensions . 26
8.1.3 Identification of Risks . 26
8.1.3.1 Requirements for Defining Risks . 26
8.1.3.2 Criteria for Identifying Risks . 26
8.1.4 Deriving Measurable Compliance Requirements and Metrics . 27
8.1.4.1 Requirements for Deriving Measurable Compliance Requirements and Metrics . 27
8.1.4.2 Criteria for Deriving Measurable Compliance Requirements . 27
8.1.4.3 Criteria for Deriving Metrics. 27
8.1.5 Implementing Measurements . 28
8.1.5.1 Requirements for Implementing Measurements . 28
8.1.5.2 Criteria for Implementing Measurements . 28
8.2 The Operationalization Specification . 28
8.2.1 General . 28
8.2.2 Requirements for the Operationalization Specification . 29
8.2.3 Criteria for the Operationalization Specification . 29
9 Continuous Assessment Process . 30
9.1 Continuous Evidence Gathering & Measurement . 30
9.2 Assessment Evidence . 31
9.2.1 General . 31
9.2.2 Sources of Evidence During Development and Training. 31
9.2.3 Sources of Evidence During Operation . 32
9.3 Persistence of Assessment Results . 32
9.4 Updating Conformity Status . 33
9.4.1 Conformity Status Updates . 33
9.4.2 Transparency in Reporting and Updates . 33
9.4.3 Effective Communication with Stakeholders . 33
9.4.4 Building and Maintaining Stakeholder Trust . 34
10 Documentation of the CABCA Process and its Outcome . 34
10.1 General . 34
10.2 CABCA Documentation Items . 34
10.2.1 General . 34
10.2.2 Conformity Specification . 35
10.2.3 Operationalization Specification . 35
10.2.4 Measurement Results and Evidence . 35
10.3 Traceability and Consistency . 35
10.4 Stakeholder Documentation Profiles . 36
Annex A (informative): Examples . 37
A.1 General . 37
A.2 PII Leakage Control for a Support Ticket Assistant . 37
A.2.1 Use Case Description . 37
A.2.2 CABCA Implementation Example . 37
A.2.2.1 General . 37
A.2.2.2 Scoping and Operationalization Specification . 37
A.2.2.3 Continuous Assessment Report . 39
A.3 Use Case: Data Drift Monitoring for Demand Forecasting . 40
A.3.1 Use Case Description . 40
A.3.2 CABCA Implementation Example . 40
A.3.2.1 General . 40
A.3.2.2 Scoping and Operationalization Specification . 40
A.3.2.3 Continuous Assessment Report . 42
History . 44
ETSI
5 ETSI TS 104 008 V1.1.1 (2026-01)
Intellectual Property Rights
Essential patents
IPRs essential or potentially essential to normative deliverables may have been declared to ETSI. The declarations
pertaining to these essential IPRs, if any, are publicly available for ETSI members and non-members, and can be
found in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to
ETSI in respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the
ETSI IPR online database.
Pursuant to the ETSI Directives including the ETSI IPR Policy, no investigation regarding the essentiality of IPRs,
including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not
referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become,
essential to the present document.
Trademarks
The present document may include trademarks and/or tradenames which are asserted and/or registered by their owners.
ETSI claims no ownership of these except for any which are indicated as being the property of ETSI, and conveys no
right to use or reproduce any trademark and/or tradename. Mention of those trademarks in the present document does
not constitute an endorsement by ETSI of products, services or organizations associated with those trademarks.
DECT™, PLUGTESTS™, UMTS™ and the ETSI logo are trademarks of ETSI registered for the benefit of its
Members. 3GPP™, LTE™ and 5G™ logo are trademarks of ETSI registered for the benefit of its Members and of the
3GPP Organizational Partners. oneM2M™ logo is a trademark of ETSI registered for the benefit of its Members and of ®
the oneM2M Partners. GSM and the GSM logo are trademarks registered and owned by the GSM Association.
Foreword
This Technical Specification (TS) has been produced by ETSI Technical Committee Methods for Testing and
Specification (MTS).
Modal verbs terminology
In the present document "shall", "shall not", "should", "should not", "may", "need not", "will", "will not", "can" and
"cannot" are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of
provisions).
"must" and "must not" are NOT allowed in ETSI deliverables except when used in direct citation.
Executive summary
The present document specifies the key aspects of Continuous Auditing-Based Conformity Assessment (CABCA) to
ensure that AI-enabled systems maintain conformity with evolving standards and regulations throughout their lifecycle.
CABCA enables automated, continuous assessment and reporting of AI system compliance, addressing the limitations
of traditional point-in-time audits.
ETSI
6 ETSI TS 104 008 V1.1.1 (2026-01)
Introduction
Artificial Intelligence (AI) systems are increasingly deployed in critical domains, where their compliance with
regulations, standards, and ethical guidelines should be continuously assured. The dynamic and adaptive nature of AI,
coupled with stringent requirements under frameworks like the EU Artificial Intelligence Act, creates a need for robust,
continuous assessment methodologies. CABCA addresses this need by introducing a structured approach to ongoing
auditing, replacing static, periodic evaluations with automated, real-time conformity checks. The present document
outlines the principles, prerequisites, processes and documentation practices for implementing CABCA within
organizations. It emphasizes stakeholder trust, adaptability, and transparency as core principles for sustainable AI
assurance. By operationalizing high-level requirements into measurable metrics and continuous evidence collection,
CABCA enables organizations to demonstrate reliable and verifiable AI system conformity throughout the entire
lifecycle.
ETSI
7 ETSI TS 104 008 V1.1.1 (2026-01)
1 Scope
The present document specifies the key aspects of Continuous Auditing-Based Conformity Assessment (CABCA) as an
audit methodology to evaluate and assess an AI system's conformity to relevant standards and regulations in a
continuous manner. The present document applies to all types of organizations involved in the quality management of
any of the lifecycle stages of AI systems as well as to any AI stakeholder roles.
The present document specifies:
• Principles underlying CABCA, including independence, reliability, stakeholder trust and transparency.
• CABCA assessment process, covering architecture, roles and procedures.
• Outcome of the assessments, including the issuance or revocation of conformity status.
2 References
2.1 Normative references
References are either specific (identified by date of publication and/or edition number or version number) or
non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the
referenced document (including any amendments) applies.
Referenced documents which are not found to be publicly available in the expected location might be found in the
ETSI docbox.
NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee
their long-term validity.
The following referenced documents are necessary for the application of the present document.
[1] ISO/IEC 42001:2023: "Information technology — Artificial intelligence — Management system".
[2] ISO 19011:2018: "Guidelines for auditing management systems" (Edition 3, 2018).
[3] ISO 9001:2015: "Quality management systems — Requirements" (Edition 5, 2015).
2.2 Informative references
References are either specific (identified by date of publication and/or edition number or version number) or
non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the
referenced document (including any amendments) applies.
NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee
their long-term validity.
The following referenced documents may be useful in implementing an ETSI deliverable or add to the reader's
understanding, but are not required for conformance to the present document.
[i.1] P. Pfeiffer et al.: "Towards a Standard Process enabling AI-support for Safety and Conformity of
Medical Devices", 2022.
[i.2] J. Mökander et al.: "Conformity Assessments and Post-market Monitoring: A Guide to the Role of
Auditing in the Proposed European AI Regulation", Minds and Machines, vol. 32, pp. 241-268,
2022.
[i.3] L. Floridi et al.: "capAI - A Procedure for Conducting Conformity Assessment of AI Systems in
Line with the EU Artificial Intelligence Act", SSRN Electronic Journal, 2022.
ETSI
8 ETSI TS 104 008 V1.1.1 (2026-01)
[i.4] C. A. Sánchez: "Role of Measurement in Conformity Assessment", in Handbook of Quality
System, Accreditation and Conformity Assessment, Springer, 2024.
[i.5] T. Granlund et al.: "On Medical Device Software CE Compliance and Conformity Assessment",
arXiv preprint arXiv:2103.06815, 2021.
[i.6] ETSI TR 103 910: "Methods for Testing and Specification (MTS); AI Testing; Test Methodology
and Test Specification for ML-based Systems".
[i.7] K. Lam et al.: "A Framework for Assurance Audits of Algorithmic Systems", in Proc. ACM
FAccT '24, 2024.
[i.8] National Institute of Standards and Technology (NIST): "Artificial Intelligence Risk Management
Framework (AI RMF 1.0)", NIST AI 100-1, 2023.
[i.9] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying
down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008,
(EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and
Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act).
[i.10] High-Level Expert Group on AI: "Ethics guidelines for trustworthy AI", European Commission,
Apr. 8, 2019.
[i.11] ETSI TR 104 119: "Methods for Testing & Specification (MTS); AI Testing; Guidelines for
Documentation of AI-enabled Systems".
3 Definition of terms, symbols and abbreviations
3.1 Terms
For the purposes of the present document, the following terms apply:
AI - risk management frameworks: guidelines and best practices for identifying, assessing, and mitigating risks
associated with Artificial Intelligence (AI) systems, such as machine learning models, to ensure their safe and
responsible use
AI system: machine-based system that is designed to operate with varying levels of autonomy and that may exhibit
adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to
generate outputs such as predictions, content, recommendations or decisions
AI system lifecycle: entire sequence of activities relating to an AI system, from its initial ideation, requirements
gathering, and design, through its development, deployment, operation, monitoring and eventual decommissioning
assessment engine: software component that automates the evaluation of collected artifacts against predefined quality
criteria to generate quality assessment outcomes
assessment report: document providing detailed information on the AI System's compliance status
NOTE: The assessment report involves regularly updating stakeholders by mapping measurement results to
specific requirements categorized under relevant quality dimensions, ensuring transparency and building
trust in the adherence to relevant standards and regulations.
conformity assessment: process of evaluating and determining whether a product, service, or system complies with
specified requirements, such as standards or regulations
conformity specification: foundational document outlining the required standards and guidelines, originating from
sources like international bodies, national standards, industry guidelines, internal policies, and legislative requirements,
to ensure systems meet the necessary compliance criteria
continuous assessment: automated collection and evaluation of measurement results against predefined metric
thresholds operating in a continuous manner
ETSI
9 ETSI TS 104 008 V1.1.1 (2026-01)
continuous auditing: ongoing process of collecting, analysing, and reporting audit-related information, typically
conducted in real-time or near-real-time, to provide stakeholders with timely insights into an organization's operations
and compliance status
metrics and measurements: set of defined parameters and established quantification methods assigned to requirements
in CABCA
NOTE: These are crucial for the auditable and applicable framework provided by CABCA for continuous
assessment.
ML life cycle: technical process that is a subset of the broader AI System Lifecycle, comprising the stages of data
preparation, model engineering, evaluation, and deployment, which culminate in the creation and operationalization of a
model
MLOps: set of practices and methodologies for managing the lifecycle of Machine Learning (ML) models, including
development, deployment and maintenance
model: technical component or representation of learned knowledge within an AI system, such as a neural network or a
foundation model, derived from a machine learning process
operationalization: process in CABCA of translating high-level Conformity Specifications into actionable steps and
machine-readable metrics
NOTE: This process includes the documentation of operational decisions and the setup of automated assessments.
operationalization specification: specification that ensures the proper instantiation of the CABCA measurement and
evidence collection system
quality dimensions: fundamental aspects in CABCA used to assess AI compliance, including accuracy, robustness,
avoidance of unwanted bias, accountability, privacy and security
NOTE: Each dimension is broken down into specific, manageable components for precise auditing.
risk traceability: capability in CABCA ensuring that each risk mitigation action is linked back to its original risk and
source specification, maintaining clarity and accountability
stakeholder: individual, group, or organization that has an interest or concern in an AI system
NOTE: Stakeholders can affect or be affected by the AI system's actions, objectives, and policies.
3.2 Symbols
Void.
3.3 Abbreviations
For the purposes of the present document, the following abbreviations apply:
AI Artificial Intelligence
API Application Programming Interface
CABCA Continuous Auditing-Based Conformity Assessment
CE Conformité Européenne
ER Entity-Relationship
ESO European Standardization Organization
GDPR General Data Protection Regulation
HEN Harmonised European Standard
HIPAA Health Insurance Portability and Accountability Act
IEC International Electrotechnical Commission
ISO International Organization for Standardization
MIL Military
ML Machine Learning
MLOp Machine Learning Operations
NER Named Entity Recognition
ETSI
10 ETSI TS 104 008 V1.1.1 (2026-01)
NIST National Institute of Standards and Technology
QMS Quality Management System
STD Standard
TD Technical Documentation
UL Underwriters Laboratories
4 CABCA Motivation and Overview
4.1 Imperative of CABCA in AI System Assurance
The European Union's Artificial Intelligence Act (EU AI Act) [i.9] establishes comprehensive obligations for providers
of high-risk AI systems, encompassing critical areas such as risk management (Art. 9), technical documentation
(Art. 11), quality management (Art. 17), conformity assessment (Art. 43), the EU Declaration of Conformity (Art. 47),
and post-market monitoring (Art. 72) [1], [i.2], [i.3]. These requirements form a tightly interlinked compliance
framework demanding sustained conformity throughout the AI system's lifecycle. Satisfying these legal obligations
effectively, especially at scale and given the dynamic nature of AI, necessitates an operational framework capable of
translating legal specifications into verifiable, continuously monitored processes. This regulatory imperative creates a
distinct demand for methodologies that can manage this complexity and ensure ongoing compliance, moving beyond
traditional static assessments.
This need is driven significantly by regulations like the EU AI Act, which places organizations, including stakeholders
like manufacturers, vendors, and providers, under increasing pressure to ensure their AI systems meet stringent quality
and compliance standards. This necessity stems from a broad spectrum of stakeholders, including regulators, customers,
and society at large, who demand assurance that AI systems are accurate, robust, fair, secure, and respect privacy [i.2],
[i.3]. The challenge, however, lies in translating these high-level, often abstract, requirements into tangible and
measurable attributes that can be assessed continuously throughout the AI system's lifecycle [i.1], [i.4]. Such
assessment criteria are required by the European Standardisation Request on AI to underpin the European legislation on
AI.
This is where CABCA emerges as a methodology, directly addressing the unique needs required by regulations like the
EU AI Act and the inherent challenges of AI system assurance. CABCA addresses the specific needs of AI system
operators in terms of quality management by operationalizing conformity in a manner distinct from traditional
process-oriented management systems while also providing assurance for regulators, customers, and society. Whereas
quality management systems that ensure compliance of AI systems address the broad processes of AI development,
deployment, upkeep, and governance, CABCA targets the specificities of AI systems themselves. For this, CABCA
defines how to translate high-level requirements (like those in the AI Act and related standards) into actionable metrics,
ensuring that abstract standards become tangible and assessable [i.1], [i.5]. Moreover, the inherent dynamic nature of AI
systems, characterized by frequent updates to models and changes in data sources - aspects directly relevant to the Act's
post-market monitoring requirements (Art. 72) - demands a continuous conformity assessment methodology [i.3], [i.4].
CABCA rises to this challenge by supporting ongoing reassessment, thus ensuring that AI systems consistently align
with evolving standards and regulations like the EU AI Act, enhancing their compliance and reliability over time for the
benefit of all stakeholders. It is important to state that CABCA's specific continuous assessment approach is proposed as
a method to effectively meet the Act's intent, particularly given the dynamic nature of AI, rather than being an explicitly
mandated mechanism itself. However, this approach is forward-looking, anticipating that future harmonised standards
will likely require continuous assessment to ensure ongoing compliance.
ETSI
11 ETSI TS 104 008 V1.1.1 (2026-01)
Figure 4.1‑1: EU-AI Acts mapping to CABCA
The interrelationship between these key articles and CABCA's supporting role is illustrated in Figure 4.1-1, which
details the interconnected compliance workflow for high-risk AI systems under the EU AI Act. The figure explains how
foundational obligations are translated into operational evidence for formal assessment and declaration. The process
begins with the core provider obligations of establishing a Risk Management (Art. 9) system and a Post-Market
Monitoring (Art. 72) plan. These are not standalone activities; they should be integrated into the provider's operational
framework. The arrows show this operationalization:
• The procedures, plans and results of these activities should be formally 'Documented in TD
(Annex IV.5/IV.9)'. The Technical Documentation (TD) serves as the central repository of evidence about the
AI system itself, detailing its design, capabilities, and the specific risk and monitoring measures applied to it.
• Simultaneously, the processes for conducting risk management and post-market monitoring should be
'Included in QMS (Art. 17(1)(g/h))'. This ensures these activities are embedded within the provider's
organizational Quality Management System (QMS), demonstrating a systematic, repeatable and managed
approach to compliance.
Together, the Technical Documentation (Art. 11, Annex IV) and the Quality Management System (Art. 17) form the
comprehensive body of proof that serves as 'Evidence For' the Conformity Assessment (Art. 43 / Annex VII). During
this assessment, an auditor evaluates this evidence to verify that the provider's claims of compliance are substantiated.
Following a successful assessment, the provider 'Generates (47.1)' the formal EU Declaration of Conformity (Art 47).
To close the evidence loop, a 'Copy kept in TD (Annex IV.8)' ensures this final declaration is included in the system's
official documentation.
CABCA is designed to directly support the 'Operationalization' (blue) and 'Assessment & Declaration' (green) phases. It
provides the structured methodology to translate abstract legal requirements into measurable controls and to
continuously generate the verifiable, up-to-date evidence that populates the TD and QMS, thereby enabling a robust and
manageable compliance lifecycle.
ETSI
12 ETSI TS 104 008 V1.1.1 (2026-01)
4.2 Comparison of CABCA with Traditional Audit Processes
Figure 4.2‑1: CABCA comparison to a traditional audit
While CABCA serves the fundamental audit objective of evaluating conformity against requirements, its operational
structure differs significantly from a traditional generic audit process, such as one guided by ISO 19011:2018 [2]. The
simplified process flows illustrated in Figure 4.2‑1 highlights these key distinctions. In the CABCA framework, A0
Scoping is a standing organizational activity that produces a formal Conformity Specification prior to any CABCA run,
whereas B0 Identification of Requirements belongs to a single traditional audit engagement and is performed once per
audit as part of audit planning. The CABCA process is color-coded: the 'Scoping' phase (A0) is highlighted in yellow,
the 'Operationalization' phase (A1) is highlighted in blue, while the continuous 'Assessment' cycle (A2-A5) is
highlighted in green. The differences between the classic process and CABCA are described below, based on the
structure of the classic process:
1) Identifications of Requirements: Both processes begin with determining the applicable requirements. In a
traditional audit, this is the 'Identification of Requirements' (B0), a foundational activity performed as part of
the initial audit planning to establish the audit criteria. In contrast, 'Scoping' (A0) is treated as a prerequisite
governance activity that occurs within an organization before the CABCA methodology is implemented. The
explicit output of this scoping phase - a formal Conformity Specification - is then used as the mandatory input
for the first active CABCA phase, Operationalization (A1), thereby establishing a clear and traceable
foundation for automation.
ETSI
13 ETSI TS 104 008 V1.1.1 (2026-01)
2) Planning & Risk Assessment: In a traditional audit, this is typically a distinct upfront phase (B1), involving
defining objectives, scope, criteria, and applying a risk-based approach to determine the audit strategy and plan
(ISO 19011:2018 [2], clause 6.3 Preparing audit activities, clause 6.3.2 Audit planning, clause 6.3.3 Assigning
work to audit team, clause 6.3.4 Preparing documented information for audit)). For CABCA,
"Operationalization" (A1) incorporates this phase. It includes the essential Planning & Risk Assessment steps
but extends them to translate requirements into detailed, machine-readable metrics and set up the automation
framework (clause 5). This phase effectively configures the continuous assessment engine, integrating
planning directly into the mechanism for execution.
3) Fieldwork / Evidence Gathering: The traditional audit involves "Fieldwork / Evidence Gathering" (B2),
where auditors manually collect and verify information through interviews, observations, and document
review during a specific period (ISO 19011:2018 [2], clause 6.4 Conducting audit activities, clause 6.4.2
Collecting and verifying information). CABCA's "Continuous Evidence Gathering & Measurement" (A2) is
fundamentally different. It is an automated, ongoing process that collects data from system artifacts
(clause 6.2) using programmed measurements, replacing periodic manual collection with continuous
monitoring. Both approaches adhere to the principle of obtaining sufficient, appropriate audit evidence
(ISO 19011:2018 [2], clause 4 Principles of auditing - Evidence-based approach).
4) Analysis & Findings: Traditional audits involve analysing collected evidence against audit criteria to generate
Analysis & Findings (B3), often requiring auditor judgment (ISO 19011:2018 [2], clause 6.5 Generating audit
findings, clause 6.5.1 Evaluating audit evidence, clause 6.5.2 Identifying and recording audit findings). In
CABCA, the "Automated Analysis & Findings Mapping" (A3) performs this step programmatically.
Measurement results are automatically compared against predefined thresholds from the operationalization
phase (clause 6.1), and deviations are identified as findings, enabling rapid identification of nonconformity.
5) Reporting: Reporting (B4) in a traditional audit typically involves issuing a formal Assessment Report upon
completion of the engagement (ISO 19011:2018 [2], clause 6.6 Completing audit, clause 6.6.1 Assessment
Report). CABCA's "Continuous Reporting & Status Updates" (A4) provides more frequent communication. It
focuses on providing dynamic conformity status updates and reports based on the continuous analysis
(clause 6.1 and 6.4), reflecting the real-time nature of the assessment.
6) Follow-up & Monitoring: The traditional audit process includes a distinct " Follow-up & Monitoring"
phase (B5) where actions taken to address findings are verified (ISO 19011:2018 [2], clause 6.7 Completing
audit, implicitly part of programme management to verify action effectiveness). In CABCA, "Iterative
Follow-
...




Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.
Loading comments...