EU AI Act for internal audit
Everything in the high-risk regime produces an artefact, which makes it auditable well before it is enforceable. The useful question in 2026 is not “are we compliant?” — the obligations mostly apply in December 2027, but “will the evidence exist when it has to?”
What lands on you, and what does not
Ownership boundaries are the most useful thing to settle early. Expert analysis: the Regulation names organisations, not job titles.
| Obligation | Yours? | Note |
|---|---|---|
| Assurance over classification decisions | Yes | Art. 6(4) requires them documented before market placement |
| Assurance over the Annex IV file | Yes | Nine prescribed headings, kept up to date |
| Assurance over Art. 17 QMS operation | Yes | Thirteen enumerated elements |
| Assurance over Art. 72 monitoring evidence | Yes | Is the loop back into Art. 9 actually turning? |
| Assurance over Art. 18 retention | Yes | Ten years, which outlasts most systems |
| Performing the classification | No | Management decision; you test it |
| Signing the declaration of conformity | No | Provider function |
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
Sample the classification decisions first
Every other test depends on this one. If a system is misclassified as out of scope, there is nothing else to audit, and a wrong answer here means the organisation has been placing a non-conforming high-risk system on the market with no technical file, no assessment and no registration.
What a defensible Article 6(4) assessment contains: the system and its intended purpose; which Annex III sub-point was considered; the threshold gate addressed, does it pose a significant risk of harm, does it materially influence decision-making; which of the four conditions is relied on; an explicit profiling analysis, because profiling makes the derogation unavailable outright; who decided; and the date, which must precede market placement.
In our experience the profiling analysis is the element most often missing, and it is the one that most often reverses the conclusion. The derogation →
Five assertions likely to fail testing
- “A human reviews every decision.” Test the override rate, the time per review, and whether the reviewer has authority to overrule. A rate near zero is a finding, not a comfort. Article 14 →
- “Our accuracy is X.” Ask when it was last measured on production data, against the figure declared in the instructions for use.
- “The technical file is complete.” Test heading 4: the appropriateness of the performance metrics. Teams usually have the number and not the justification.
- “We monitor post-market.” Ask for a dated risk-file update triggered by a monitoring finding. If none exists, the loop is not turning.
- “ISO 42001 covers it.” It does not satisfy Article 17. JTC 21 assessed exactly that and wrote a separate standard. Mapping →
Your first 30 days
- Obtain the AI inventory and reconcile it to systems you know exist. Completeness is the first finding.
- Sample five classification decisions against the Article 6(4) standard above.
- Test one Annex IV file against the nine headings, and specifically heading 4.
- Trace one monitoring finding through to a risk-file update and a corrective action.
- Check retention design against Article 18's ten years, including where the archive lives and who can retrieve it.
Questions worth asking
- Who maintains the AI inventory, and how do new systems get added?
- Show me a classification assessment dated before market placement.
- Show me an override that changed an outcome.
- Where will the technical file be in nine years?
Status labels on this page
Verified fact: Article references, dates and penalty tiers cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.
Expert analysis: The ownership allocation, the failure modes, and the 30-day sequence — all our practice rather than the text.
Unsettled: Harmonised standards remain in development, and the Commission's Annex III guidelines are in draft. Both affect how these obligations will be evidenced.
Auditable is a design property
Organisations that pass this testing built a management system that produces the evidence as a by-product of operating. The ones that fail assembled documents for an audit.
Start with the inventory
Every role guide on this site converges on the same first step: a list of the AI systems, their intended purpose, their role and their tier.
Frequently asked
How do you audit EU AI Act compliance?
By testing the artefacts each obligation produces: the AI system inventory for completeness, Article 6(4) classification assessments for adequacy and timing, the Annex IV technical documentation against its nine prescribed headings, the Article 17 quality management system against its thirteen enumerated elements, the Article 9 risk file including foreseeable misuse and residual risk acceptance, and Article 72 post-market monitoring evidence for whether findings feed back into the risk file.
What evidence should an EU AI Act classification decision contain?
The system and its intended purpose, the Annex III sub-point considered, the Article 6(3) threshold gate addressed, which of the four conditions is relied on, an explicit analysis of whether the system performs profiling of natural persons, the identity of the decision maker, and a date preceding placing on the market or putting into service as required by Article 6(4).
How long must EU AI Act records be kept?
Article 18 requires providers to keep the technical documentation, the quality management system documentation, any notified body documentation and decisions, and the EU declaration of conformity at the disposal of national competent authorities for ten years after the high-risk AI system is placed on the market or put into service. Logs carry a separate minimum of six months under Articles 19 and 26(6).