Ethics Directive

A Credential Is Not Compliance

The Journal · Reading time: 6 minutes

A credential is not compliance.

Passing an exam proves a person studied a topic. It does not produce the record a regulator asks the organisation employing them to show.

Article 96 of the EU AI Act does not ask a high-risk deployer to produce a certificate. It asks for documentary evidence: risk management records, data governance logs, human oversight mechanisms, kept machine-readable and continuously updated, not written once and filed. A credential sits with a person. That evidence sits with the system, the process, and the paper trail behind both. They answer different questions, and mixing them up is an easy, common mistake.

We came across a piece making a version of this point recently, published, by a vendor selling code-provenance tooling to engineering teams. The self-interest was not subtle: the piece existed to sell a product, and the product it sold was pitched as the thing a credential supposedly cannot be.

This is exactly the kind of source this site tells you to read twice, us included! The underlying point stood out: a credential and an audit trail are not competing options. They answer different questions, for different audiences.

What a credential actually proves

Every entry on our own Map answers one question: did this person demonstrate knowledge, skill, or competence against some criteria, tested by someone other than their own employer. That is a real and useful thing to know. It is also the whole claim.

IAPP’s AIGP, IEEE’s CertifAIEd, ISO 42001’s Lead Auditor route: each certifies a person, on a given day, against a fixed body of material. None of them certify that the organisation now employing that person runs the risk management process the credential taught them to recognise. The person can describe a proper data governance log. Whether one exists, updated, on the system currently in production, is a separate fact, and nobody’s certificate shows that.

This is not a flaw in the credentials. It is the category they belong to. A driving test proves you can drive; it does not prove the car in front of you was serviced by an accredited garage, at a particular time.

Where our own tools sit in this, honestly

Our gap report is squarely on the credential side of this line. It is a self-assessment of one person’s practice against our six areas, and we say so: nothing it produces is machine-readable evidence for a regulator, and it was never built to be.

Our org-audit reaches one step further, toward the organisation, asking whether the mandate, escalation path, and evidence actually exist, not just the policy document announcing them. But it is still a self-serve, eight-statement gut check, not an audit trail. It can tell an organisation it likely has a gap. It cannot generate the Article 96 record that closes one.

The honest use of either tool is to use it as a basic direction: something that tells you where to look before an auditor, a regulator, or a board committee looks there for you.

Written by us at Ethics Directive. Article 96 and the wider EU AI Act obligations referenced here are our own reading of the regulation’s public text, not legal advice; if you are assessing your own organisation’s compliance, take that to counsel. If anything here needs correcting, we will say so in the open, dated.

The org-audit · free · eight statements

Does your organisation actually back this work?

Real mandate, escalation, and evidence, or governance on paper. Five minutes, private, and not a certification.