Annex IV: the technical file
This is the document a market surveillance authority asks for. It is not a free-form report — Annex IV is a prescribed contents list with nine headings, and the assessment is against the list. Most organisations already hold seventy percent of the material and none of the structure.
The nine headings
| Heading | What goes in it, and where you already have it | |
|---|---|---|
| 1 | General description of the AI system | Intended purpose, provider, versions, how it interacts with hardware or other software, forms of distribution, hardware it runs on, product photos or illustrations where relevant, instructions for use. |
| 2 | Detailed description of elements and development process | Methods and steps performed, third-party tools and pre-trained systems used, design specifications, system architecture, data requirements and provenance, human oversight measures, pre-determined changes, validation and testing procedures and results. Usually spread across a design doc, a model card and an engineering wiki. |
| 3 | Monitoring, functioning and control | Capabilities and limitations including accuracy for specific persons or groups, foreseeable unintended outcomes and sources of risk, human oversight measures, input data specifications. |
| 4 | Appropriateness of the performance metrics | Not just the metrics: the argument that they are the right ones for this intended purpose. Rarely written anywhere today. |
| 5 | The Article 9 risk management system | The risk file itself. Article 9 → |
| 6 | Relevant changes made through the lifecycle | A change log with regulatory significance, not a git history. |
| 7 | Harmonised standards applied | In full or in part, and where not applied, a description of the solutions adopted instead. Standards status → |
| 8 | Copy of the EU declaration of conformity | Article 47. Conformity assessment → |
| 9 | Post-market monitoring system and plan | The Article 72 plan lives here. Article 72 → |
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
Three things that catch people
- Heading 4 is an argument, not a table. “We report AUC of 0.87” is a metric. Annex IV asks why AUC is the appropriate metric for this intended purpose and this affected population. Teams routinely have the number and not the justification.
- Heading 2 requires third-party components to be named. Pre-trained models, foundation models, open-source libraries, labelling vendors. If you cannot name what is inside your system, you cannot complete the technical file, which makes this a procurement question long before it is a documentation one.
- Heading 6 has to be maintained. Article 11 requires the documentation to be kept up to date. A file frozen at conformity assessment and never touched again is non-compliant by the second release.
Retention: ten years
Article 18 requires providers to keep the technical documentation, the quality management system documentation, any notified body documentation and decisions, and the EU declaration of conformity at the disposal of national competent authorities for ten years after the system is placed on the market or put into service.
Ten years is longer than most engineering teams keep anything. It is longer than typical cloud log retention, longer than most vendor contracts, and considerably longer than the average tenure of the people who built the system. Plan the archive, not just the document.
SME simplification
Article 11(1) allows SMEs including start-ups to provide the Annex IV elements in a simplified manner, and empowers the Commission to establish a simplified form. Simplified means simplified, not optional: the nine headings still have to be addressed. Check the current position on the Commission’s AI Act Service Desk before relying on this.
Status labels on this page
Verified fact: The nine Annex IV headings, the Art. 11 timing and up-to-date duty, the Art. 18 ten-year retention, and the SME simplification power.
Expert analysis: The three failure modes above and the observation that heading 4 is usually missing.
Unsettled: The final content of any Commission simplified form for SMEs.
Build the file as a system, not a document
A technical file that is regenerated from source systems each release stays current. One assembled by hand for an audit is stale the week after. That difference is the whole argument for a management system underneath it.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Questions
What is Annex IV technical documentation under the EU AI Act?
Annex IV sets out the prescribed contents of the technical documentation required by Article 11 for high-risk AI systems. It has nine headings: a general description of the system; a detailed description of its elements and development process; detailed information about monitoring, functioning and control; a description of the appropriateness of the performance metrics; the risk management system under Article 9; a description of relevant changes made through the lifecycle; a list of harmonised standards applied; a copy of the EU declaration of conformity; and a detailed description of the post-market monitoring system and plan.
When must technical documentation be drawn up?
Article 11(1) requires the technical documentation to be drawn up before the high-risk AI system is placed on the market or put into service, and kept up to date. It must demonstrate that the system complies with the Chapter III Section 2 requirements and provide national competent authorities and notified bodies with the information necessary to assess compliance in a clear and comprehensive form.
Do SMEs get simplified technical documentation?
Article 11(1) provides that SMEs including start-ups may provide the elements of the technical documentation specified in Annex IV in a simplified manner, and empowers the Commission to establish a simplified technical documentation form targeted at their needs. The Digital Omnibus package also addressed documentation burden for smaller organisations. Check the current position on the Commission's AI Act Service Desk before relying on simplification.
How long must technical documentation be kept?
Article 18 requires providers to keep the technical documentation, the quality management system documentation, notified body documentation and decisions, and the EU declaration of conformity at the disposal of national competent authorities for ten years after the high-risk AI system has been placed on the market or put into service.
Obligations, article by article
- Art. 5 prohibitions
- Art. 4 AI literacy
- Art. 50 transparency
- Art. 9 risk management
- Art. 10 data governance
- Arts. 12–13 logging
- Art. 14 human oversight
- Art. 15 accuracy & security
- Art. 17 QMS
- Arts. 43–48 conformity
- Art. 49 registration
- Art. 57 sandboxes
- Open source
- Art. 72 monitoring
- Art. 73 incidents
- Arts. 51–56 GPAI
- Art. 99 penalties
- Compliance checklist
- FRIA template (Art. 27)
- When Annex III does not apply →