Questions & Answers
What is Joint Statement and Common Approach?▼
A Joint Statement and Common Approach (JSCA) is a policy-level document issued by EU agencies (such as ENISA) to align multiple stakeholders on specific emerging risks, like AI safety or cloud security. Unlike hard law, it functions as 'soft law'—providing a unified interpretation of regulatory expectations. For enterprises, it serves as the bridge between the EU AI Act's requirements and the technical controls needed for compliance. It is not a substitute for ISO/IEC 27701 or GDPR but acts as a critical interpretive layer. Companies must treat JSCA as a primary input for their risk-adjusted control-selection process, particularly when operating across multiple EU member states where local interpretations of the AI Act may vary. Failure to align with JSCA-identified risks can lead to regulatory scrutiny during EU AI Act compliance audits.
How is Joint Statement and Common Approach applied in enterprise risk management?▼
Implementation typically follows three phases. Phase 1: Risk Scenario Mapping—companies map JSCA-identified risks against the ISO 31000 risk management framework to identify gaps in existing controls. Phase 2: Control Integration—technical controls are integrated into the AI development lifecycle, specifically addressing EU AI Act Article 9 (Risk Management System) and Article 13 (Transparency). Phase 3: Performance Monitoring—KPIs are established, such as 'Model Bias Variance < 0.05' or 'Data-Centric Risk-Adjusted-Score > 80'. A practical example is a European fintech firm that adopted the ENISA Joint Statement on AI security; they reported a 35% reduction in AI-related security incidents within 12 months and achieved 100% compliance with the EU AI Act's technical documentation requirements during the first audit cycle.
What challenges do Taiwan enterprises face when implementing Joint Statement and Common Approach? How to overcome them?▼
Taiwan enterprises face three primary challenges. First, 'Regulatory Interpretation Gap': Local teams often struggle with the EU's unique regulatory language. The solution is to partner with EU-specialized consultants to 'translate' JSCA into actionable technical requirements. Second, 'Resource Constraints': Small and medium enterprises (SMEs) often lack the expertise to implement complex AI controls. A phased approach—prioritizing high-risk AI applications first—is recommended. Third, 'Supply Chain Transparency': Many Taiwan companies are upstream suppliers, not direct EU entities. They must be closely monitored for compliance by their EU customers. The recommended action is to be closely closely aligned with the EU AI Act's supplier obligations (Article 25). The initial investment is typically 0.5-1.5% of annual revenue, but the cost of non-compliance—up to €30M or 6% of global turnover—far outweighs the implementation cost.
Why choose Winners Consulting for Joint Statement and Common Approach?▼
Winners Consulting Services Co., Ltd. specializes in Joint Statement and Common Approach for Taiwan enterprises, delivering compliant management systems within 90 days. Free consultation: https://winners.com.tw/contact
Need help with compliance implementation?
Request Free Assessment