Area 1: AI System Inventory and Classification
- Catalogue all AI systems used or provided across the organisation, including third-party tools and embedded AI
- Identify the intended purpose, operational context, and primary users of each system
- Apply the Article 5 prohibited practice checklist to every system, if any falls within a prohibition, halt deployment immediately
- Apply the Annex III classification criteria to each system to determine high-risk status
- Apply the Article 6(3) exception test where Annex III classification is uncertain
- Identify GPAI models in your AI portfolio (provided or integrated)
- Document all classification decisions with supporting reasoning
Area 2: Risk Management System (Article 9)
- Establish a documented risk management system covering the full AI system lifecycle
- Identify and catalogue risks to health, safety, and fundamental rights posed by each high-risk system
- Perform risk estimation and evaluation with documented methodology
- Define and implement risk mitigation measures proportionate to identified risks
- Assess residual risks after mitigation and document conclusions
- Establish a process for updating the risk management system as the system evolves
- Assign named responsibility for risk management system maintenance
Area 3: Technical Documentation (Article 11 + Annex IV)
- General description of the AI system including intended purpose and version history
- Detailed description of system elements, design process, and design specifications
- Description of monitoring, functioning, and control of the system
- Description of changes made to the system through its lifecycle
- Technical capabilities, limitations, and known risks to health, safety, or fundamental rights
- Training methodology and training data characteristics documentation
- Testing and validation procedures and results including performance benchmarks
- Cybersecurity measures implemented
- EU Declaration of Conformity (signed by authorised representative)
- Post-market monitoring plan
Area 4: Data Governance (Article 10)
- Document training, validation, and testing dataset sources, collection methodology, and governance
- Assess datasets for relevance, representativeness, and completeness relative to intended purpose
- Identify and document known biases or limitations in training data
- Establish data governance policies for ongoing data management
- Where personal data is used, coordinate GDPR compliance with AI Act data requirements
- Document data annotation methodologies and quality controls
Area 5: Human Oversight (Article 14)
- Design human oversight into the AI system architecture, not just as a procedural overlay
- Identify specific oversight functions: monitoring, understanding output, intervention, override, shutdown
- Designate named roles with documented authority to intervene in system operation
- Implement measures preventing automation bias in oversight personnel
- Test and validate that oversight mechanisms function as designed under production conditions
- Document human oversight provisions in instructions for use
Area 6: Transparency and Instructions for Use (Article 13)
- Prepare instructions for use for deployers in accessible, clear language
- Instructions must cover: provider identity; capabilities and limitations; performance metrics; intended purpose; foreseeable misuse; monitoring requirements; human oversight requirements; maintenance requirements
- Ensure limited-risk transparency obligations are met for chatbots, deepfakes, and emotion recognition tools
Area 7: Logging and Record-Keeping (Article 12)
- Implement automatic logging capabilities in the AI system (must function without manual activation)
- Ensure logs capture sufficient information to enable traceability of decisions
- Define log retention periods (minimum 6 months; check sector-specific requirements)
- Implement log access controls and integrity protections
Area 8: Conformity Assessment and Registration (Article 43)
- Conduct conformity assessment against Chapter III requirements (self-assessment for most Annex III; notified body for biometric systems)
- Prepare EU Declaration of Conformity
- Apply CE marking where applicable (Annex I regulated product AI)
- Register the system in the EU AI public database before deployment
Area 9: Post-Market Monitoring (Article 72)
- Establish a post-market monitoring system with defined metrics and review frequency
- Establish incident reporting procedures to national competent authorities (Art. 73)
- Implement processes for updating documentation and technical measures when issues are identified
- Assign named responsibility for ongoing post-market monitoring
Area 10: GPAI Compliance (Articles 51–56)
- Determine whether any AI models you provide qualify as GPAI
- Prepare GPAI technical documentation covering model architecture, training, and data sources
- Prepare information package for downstream providers enabling their compliance
- Establish and publish copyright compliance policy covering training data and TDM practices
- Publish training data summary per Article 53(1)(d)
- Assess whether any model exceeds the 10²⁵ FLOPs systemic risk threshold
- If systemic risk: adversarial testing, AI Office incident reporting, cybersecurity measures
Get the Complete 58-Point Checklist
The full 58-point compliance checklist, in the Checklist Pack ($149), maps every obligation to its legal basis, includes completion checkboxes and evidence guidance, and is formatted for audit and regulatory submissions.