EU AI Act

EU AI Act Conformity Assessment: The Step-by-Step Process

A conformity assessment is how high-risk AI system providers prove their systems meet EU AI Act requirements before going to market. For most Annex III systems, self-assessment is permitted. For biometric and some safety-critical systems, a third-party notified body is required. Here's the full process, step by step.

← Back to EU AI Act Complete Guide

The EU AI Act conformity assessment is the formal process by which a high-risk AI system provider demonstrates compliance before placing a system on the EU market. It's not a one-off audit. It's a structured process involving risk classification, documentation, quality management, testing, EU database registration, and ongoing post-market monitoring. This article walks through each step in sequence, explains who needs to complete it, and covers what happens if you skip or fail the assessment.

What a conformity assessment is (and who needs one)

A conformity assessment is only required for providers of high-risk AI systems. The two categories of high-risk AI are:

If your AI system doesn't fall into either of these categories, you don't need a conformity assessment. Deployers of high-risk AI systems (companies that use a high-risk system built by someone else) also don't complete a conformity assessment, though they do have their own obligations around appropriate use and human oversight.

Step 1: Determine your risk classification

Before you can begin a conformity assessment, you need to be confident about your system's risk classification. This is more than a checkbox; a wrong classification in either direction carries real risk. Over-classifying wastes resources on unnecessary conformity work. Under-classifying creates enforcement exposure.

The classification process involves:

Document your classification rationale in writing. This documentation becomes part of your Annex IV technical file and will be reviewed by any authority that investigates your compliance.

Step 2: Build your Annex IV technical documentation file

Annex IV of the Act sets out the minimum content of the technical documentation that high-risk AI system providers must prepare and maintain. Building this file is typically the most time-consuming part of the conformity assessment process, especially for companies without existing model cards or AI system documentation.

The Annex IV file must include:

The technical file doesn't have a prescribed format, but it must be comprehensive, accurate, and kept up to date. National market surveillance authorities can request it at any time, and they typically do so at the start of any investigation.

2 August 2026 is the deadline for GPAI, Article 50 transparency, and enforcement provisions. High-risk Annex III conformity requirements may follow, with a proposed deferral to December 2027 under the Digital Omnibus. Don't wait for legal certainty to start your documentation work. Better Societies builds Annex IV technical files as part of the compliance engagement. Start your assessment.

Step 3: Implement the required quality management system

Article 17 requires providers of high-risk AI systems to establish a quality management system (QMS) before placing the system on the market. The QMS must cover the full AI lifecycle, from design through deployment and post-market monitoring.

The QMS must include documented policies and procedures for:

Companies with an existing ISO 9001 or ISO 27001 quality management system can adapt their existing documentation significantly. The AI Act's QMS requirements are compatible with ISO 42001 (the AI management system standard), and some companies are pursuing dual certification. You don't need ISO certification to comply with the Act, but having a documented QMS of any kind makes the compliance path substantially shorter.

Step 4: Run the conformity assessment (internal vs third-party notified body)

With documentation and a QMS in place, the formal conformity assessment can begin. The Act provides two pathways:

The internal assessment is not a rubber stamp. It requires a systematic review of every requirement in Articles 9 through 15 of the Act against your technical file and QMS documentation, with evidence of compliance for each. The output is a formal declaration of conformity, which is a legal document stating that the system meets the requirements of the Act, signed by an authorised representative of the provider.

Step 5: Affix the CE mark and register in the EU AI database

After a successful conformity assessment (whether internal or by a notified body), two actions are required before the system can be placed on the EU market:

Registration in the EU database is public and searchable. It enables users, deployers, and competent authorities to look up registered systems and verify their compliance status. For companies operating multiple high-risk systems, each system requires a separate registration entry.

Step 6: Set up post-market monitoring

Conformity assessment doesn't end at deployment. Article 72 requires providers to implement a post-market monitoring system that actively collects and reviews data about the system's performance in real-world use throughout its operational life.

The post-market monitoring system must include:

The timeline: what needs to be done before 2 Aug 2026

The 2 August 2026 deadline applies to transparency (Article 50), GPAI obligations, and the enforcement and market surveillance framework. High-risk Annex III conformity requirements are potentially deferred to 2 December 2027 under the Digital Omnibus proposal, but this is not yet settled law.

What companies should have completed by 2 August 2026 regardless:

Starting the conformity assessment process now avoids a cost and resource spike as the deadline approaches. Assessment work done before December 2027 (if the deferral passes) is not wasted; it's documentation and controls your business needs regardless.

What happens if you skip or fail the assessment

Failing to conduct a required conformity assessment, or placing a high-risk AI system on the EU market without completing the assessment, is a violation of the Act subject to penalties under Article 99. Specifically:

There's no provision for a lighter-touch "first warning" in lieu of fines for serious violations. The Act's enforcement is modelled on the EU's product safety framework, which has decades of precedent for real enforcement action, not just warnings.

Related reading

Frequently asked questions

What is an EU AI Act conformity assessment?

A conformity assessment is the process by which a provider of a high-risk AI system demonstrates that the system complies with the requirements of the EU AI Act before placing it on the EU market. For most Annex III high-risk systems, self-assessment using the Annex VI procedure is permitted. For biometric identification systems and some law enforcement AI, a third-party notified body assessment is required.

Who needs to complete a conformity assessment?

Only providers of high-risk AI systems under Annex III (or AI components in safety-critical products under Annex II) are required to complete a conformity assessment. Deployers of high-risk AI systems, and providers of limited-risk or minimal-risk AI systems, do not need a conformity assessment, though deployers must implement appropriate oversight measures.

What is Annex IV technical documentation?

Annex IV specifies the minimum content of the technical documentation that high-risk AI system providers must prepare and maintain. It includes a general description of the AI system, design and development information, training data details, performance metrics and test results, risk management measures, human oversight design, and cybersecurity measures.

Do you need a third party to conduct an EU AI Act conformity assessment?

For most high-risk AI systems under Annex III, self-assessment is permitted using the procedure in Annex VI. Third-party notified body involvement is required for AI systems used in real-time biometric identification, and AI components in certain safety-critical products under Annex II where the relevant product regulation requires third-party assessment.

What is the EU AI database and who must register?

The EU AI database is a public registration system managed by the European Commission. Providers of high-risk AI systems must register their systems before placing them on the EU market. GPAI model providers must also register their models. The database includes basic information about each system, its intended purpose, risk classification, and conformity assessment status.

What happens if you skip the conformity assessment?

Skipping a required conformity assessment is a violation of the Act subject to fines under Article 99 of up to EUR 15 million or 3% of global annual turnover. National market surveillance authorities can also require the system to be withdrawn from the EU market until compliance is demonstrated.

When do conformity assessment obligations apply?

For most high-risk Annex III systems, full conformity assessment requirements apply from 2 August 2026, though a Digital Omnibus proposal to defer this to 2 December 2027 is under consideration and not yet settled law. GPAI model registration requirements applied from 2 August 2025.

How long does a conformity assessment take?

An internal self-assessment for a single high-risk AI system with good existing documentation typically takes 8 to 16 weeks end to end, including documentation drafting, quality management system setup, testing, and EU database registration. Third-party notified body assessments add 4 to 12 weeks on top of internal preparation.

Don't face the assessment alone

Better Societies delivers EU AI Act conformity assessment support including Annex IV technical documentation, quality management setup, and EU database registration. Article 99 fines reach EUR 35M or 7% of global turnover for the most serious violations. Start before the 2 August 2026 deadline.