Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Role guide · Internal auditor

EU AI Act for internal audit

Everything in the high-risk regime produces an artefact, which makes it auditable well before it is enforceable. The useful question in 2026 is not “are we compliant?” — the obligations mostly apply in December 2027, but “will the evidence exist when it has to?”

Arts. 6(4), 17, 18, 72Annex IV

What lands on you, and what does not

Ownership boundaries are the most useful thing to settle early. Expert analysis: the Regulation names organisations, not job titles.

ObligationYours?Note
Assurance over classification decisionsYesArt. 6(4) requires them documented before market placement
Assurance over the Annex IV fileYesNine prescribed headings, kept up to date
Assurance over Art. 17 QMS operationYesThirteen enumerated elements
Assurance over Art. 72 monitoring evidenceYesIs the loop back into Art. 9 actually turning?
Assurance over Art. 18 retentionYesTen years, which outlasts most systems
Performing the classificationNoManagement decision; you test it
Signing the declaration of conformityNoProvider function

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

Sample the classification decisions first

Every other test depends on this one. If a system is misclassified as out of scope, there is nothing else to audit, and a wrong answer here means the organisation has been placing a non-conforming high-risk system on the market with no technical file, no assessment and no registration.

What a defensible Article 6(4) assessment contains: the system and its intended purpose; which Annex III sub-point was considered; the threshold gate addressed, does it pose a significant risk of harm, does it materially influence decision-making; which of the four conditions is relied on; an explicit profiling analysis, because profiling makes the derogation unavailable outright; who decided; and the date, which must precede market placement.

In our experience the profiling analysis is the element most often missing, and it is the one that most often reverses the conclusion. The derogation →

Five assertions likely to fail testing

  1. “A human reviews every decision.” Test the override rate, the time per review, and whether the reviewer has authority to overrule. A rate near zero is a finding, not a comfort. Article 14 →
  2. “Our accuracy is X.” Ask when it was last measured on production data, against the figure declared in the instructions for use.
  3. “The technical file is complete.” Test heading 4: the appropriateness of the performance metrics. Teams usually have the number and not the justification.
  4. “We monitor post-market.” Ask for a dated risk-file update triggered by a monitoring finding. If none exists, the loop is not turning.
  5. “ISO 42001 covers it.” It does not satisfy Article 17. JTC 21 assessed exactly that and wrote a separate standard. Mapping →

Your first 30 days

  1. Obtain the AI inventory and reconcile it to systems you know exist. Completeness is the first finding.
  2. Sample five classification decisions against the Article 6(4) standard above.
  3. Test one Annex IV file against the nine headings, and specifically heading 4.
  4. Trace one monitoring finding through to a risk-file update and a corrective action.
  5. Check retention design against Article 18's ten years, including where the archive lives and who can retrieve it.

Questions worth asking

  • Who maintains the AI inventory, and how do new systems get added?
  • Show me a classification assessment dated before market placement.
  • Show me an override that changed an outcome.
  • Where will the technical file be in nine years?

Status labels on this page

Verified fact: Article references, dates and penalty tiers cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.

Expert analysis: The ownership allocation, the failure modes, and the 30-day sequence — all our practice rather than the text.

Unsettled: Harmonised standards remain in development, and the Commission's Annex III guidelines are in draft. Both affect how these obligations will be evidenced.

Next step

Auditable is a design property

Organisations that pass this testing built a management system that produces the evidence as a by-product of operating. The ones that fail assembled documents for an audit.

Start with the inventory

Every role guide on this site converges on the same first step: a list of the AI systems, their intended purpose, their role and their tier.

Run the classifier →

Frequently asked

How do you audit EU AI Act compliance?

By testing the artefacts each obligation produces: the AI system inventory for completeness, Article 6(4) classification assessments for adequacy and timing, the Annex IV technical documentation against its nine prescribed headings, the Article 17 quality management system against its thirteen enumerated elements, the Article 9 risk file including foreseeable misuse and residual risk acceptance, and Article 72 post-market monitoring evidence for whether findings feed back into the risk file.

What evidence should an EU AI Act classification decision contain?

The system and its intended purpose, the Annex III sub-point considered, the Article 6(3) threshold gate addressed, which of the four conditions is relied on, an explicit analysis of whether the system performs profiling of natural persons, the identity of the decision maker, and a date preceding placing on the market or putting into service as required by Article 6(4).

How long must EU AI Act records be kept?

Article 18 requires providers to keep the technical documentation, the quality management system documentation, any notified body documentation and decisions, and the EU declaration of conformity at the disposal of national competent authorities for ten years after the high-risk AI system is placed on the market or put into service. Logs carry a separate minimum of six months under Articles 19 and 26(6).