Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Chapter III · Articles 43–48

Conformity assessment, and why you cannot automate it

People search for "automated EU AI Act conformity assessment" because they are hoping it is a scan. It is not. It is a legal procedure with a named responsible party, a signed declaration, and a ten-year document retention duty. What can be systematised is the evidence, and that is most of the work.

Arts. 43, 47, 48Annexes VI & VIIReg. (EU) 2024/1689

The two routes

Article 43 sets out which procedure applies to which system. For stand-alone Annex III high-risk systems the default is internal control.

Most Annex III systems

Internal control — Annex VI

The provider verifies that its quality management system meets Article 17, examines the technical documentation, and checks the design and development process and post-market monitoring plan against the documentation. No third party is involved. The provider signs and carries the liability.

Biometrics, and Annex I products

Notified body — Annex VII

Applies to Annex III point 1 biometric systems where the provider has not applied harmonised standards or common specifications. Also reached through the underlying product legislation for Annex I embedded AI, where a notified body is often already in the picture.

Internal control is not "self-certification lite"

The absence of a third party does not reduce the evidentiary burden. It moves it entirely onto you. A market surveillance authority can require the full technical documentation, and Article 18 requires you to keep it for ten years after the system is placed on the market. Internal control means you build the file to a standard someone else could audit, because eventually someone might.

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

What you produce at the end

  1. Technical documentation to Annex IV: a prescribed contents list, not a free-form document. General description, development process, monitoring and control, risk management records, validation and testing, and the post-market monitoring plan. Art. 11
  2. EU declaration of conformity: drawn up by the provider, kept for ten years, naming the system and stating that it meets the Chapter III Section 2 requirements. Art. 47
  3. CE marking: affixed visibly, legibly and indelibly, or digitally where the system is provided digitally, accessible through the interface or a machine-readable code. Art. 48
  4. EU database registration: before placing on the market. Art. 49

The SaaS-specific parts people get wrong

  • Continuous deployment is not exempt. Article 43(4) treats a substantial modification as triggering a fresh assessment. Changes pre-determined by the provider and included in the technical documentation at the time of the initial assessment are not substantial modifications, which makes your documented change envelope a design decision, not a paperwork decision.
  • You may be a provider without building a model. Article 25 turns a deployer into a provider if they put their name or trade mark on a high-risk system, make a substantial modification, or change the intended purpose of a system in a way that makes it high-risk.
  • CE marking on software is real. Digital affixing is expressly contemplated. "We are a web app, CE marking doesn't apply to us" is not a position the Regulation supports for a high-risk system.

Status labels

Verified: the routes, the Annexes, the article numbers, the ten-year retention and the December 2027 / August 2028 application dates. Expert analysis: our reading of how the substantial-modification test interacts with continuous deployment. Unsettled: the availability of harmonised standards, which shapes whether the biometric notified-body route bites.

So what can actually be systematised?

Nearly all of the preparation. The assessment is a decision; the file behind it is a system.

WorkCan it be systematised?
AI system inventory and classificationYes, and should be
Annex IV documentation assembly and version controlYes
Risk management records (Art. 9)Yes
Data governance evidence (Art. 10)Largely
Logging and traceability (Art. 12)Yes: engineering
Post-market monitoring plan (Art. 72)Yes
The Annex VI verification itselfNo: a human decision
Signing the declaration of conformityNo: a named person

If a vendor offers you "automated conformity assessment", ask which of the last two rows they are performing. The honest answer is neither.

Next step

Build the file before you need it

December 2027 sounds far away. Annex IV documentation, a working risk management system and a post-market monitoring plan are not a quarter of work. Organisations that already run an ISO/IEC 42001 management system start this with the organisational layer done.

Are you even high-risk?

Conformity assessment only applies to high-risk systems. Check before you spend a quarter on it.

Annex III quick check →

Questions

Can conformity assessment be automated?

No. It is a legal procedure with a responsible party and a signed declaration. Evidence assembly can and should be systematised; the assessment and the declaration cannot be delegated to software.

Do SaaS vendors need CE marking?

If you are the provider of a high-risk AI system placed on the EU market, yes. Article 48 allows digital affixing for digitally supplied systems.

When must it be complete?

Before placing on the market or putting into service. That obligation applies from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for Annex I embedded systems.

Does a notified body have to be involved?

Usually not for Annex III. The main exception is biometric systems under Annex III point 1 where harmonised standards or common specifications have not been applied.