Conformity assessment of a high-risk AI system under the EU AI Act

AI ACT · CONFORMITY

High-Risk AI Conformity Assessment: How It Works

A high-risk artificial intelligence system should not reach the market merely because it works.

It must be possible to demonstrate that it meets the requirements that apply to it.

That is the role of conformity assessment: the process through which a provider checks and documents compliance with the AI Act before placing the system on the market or putting it into service.

A common misconception is that every conformity assessment means an external body audits the system.

The procedure depends on the type and classification of the system, applicable legislation, the harmonised standards used and the route established by Article 43.

Conformity assessment does not always mean following the same procedure. It means demonstrating that the system meets the requirements that apply to it.

What a conformity assessment is

Conformity assessment is the process used to determine whether a high-risk AI system meets applicable requirements.

It is not simply an audit, certification or document review. It may combine technical documentation, controls, testing, risk management, a quality management system, internal review and, where required, a notified body.

Which systems must undergo it

High-risk systems must follow the relevant route before being placed on the market or put into service.

Routes differ between Annex III systems and systems embedded in products regulated under Annex I legislation. Correct AI Act classification therefore comes first.

What requirements are assessed

The assessment covers applicable Chapter III, Section 2 requirements, including risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity.

Conformity depends on a complete system of controls and evidence, not one document.

The difference between Annex VI and Annex VII

Annex VI

Internal control: the provider assesses conformity internally and no notified body participates.

Annex VII

Assessment based on the quality management system and technical documentation, with a notified body.

They are different procedures, not interchangeable labels.

When internal control can be used

Article 43 provides internal control under Annex VI for certain Annex III systems. In particular, systems listed in points 2 to 8 currently follow this route without a notified body.

Internal control is not an unsupported self-declaration. The provider must demonstrate compliance through controls, results and AI evidence.

When a notified body is involved

Annex VII may apply in specified cases concerning point 1 of Annex III.

It also applies in Article 43 circumstances involving unavailable harmonised standards or common specifications, standards that are not applied or only partly applied, unapplied common specifications, or relevant restrictions on a published standard.

The notified body reviews the quality management system, technical documentation and applicable requirements. Not every high-risk system requires one.

AI systems linked to regulated products

Where a high-risk AI system forms part of a product covered by Annex I Union harmonisation legislation, the provider follows the applicable sectoral conformity procedure and integrates AI Act requirements into it.

A needless parallel process should not be created.

How the assessment works step by step

Step 1. Classify the system

Confirm that it is high-risk.

Step 2. Determine the route

Choose Annex VI, Annex VII or the Annex I sectoral procedure.

Step 3. Identify requirements

Define what must be demonstrated.

Step 4. Prepare technical documentation

Consolidate architecture, purpose, data, risk, testing and controls in the technical file.

Step 5. Review the management system

Assess the quality management system where relevant.

Step 6. Perform testing

Verify accuracy, robustness, security, operation and controls.

Step 7. Review evidence

Ensure each requirement can be demonstrated.

Step 8. Involve a notified body

Do so only when the procedure requires it.

Step 9. Resolve non-conformities

Close identified gaps.

Step 10. Complete the assessment

Formalise the outcome.

Step 11. Complete subsequent obligations

Where applicable, prepare the EU declaration of conformity, CE marking and registration.

Team reviewing conformity requirements for a high-risk artificial intelligence system

Technical documentation

The technical documentation should show how the system was designed, developed, tested and controlled, including purpose, architecture, data, tests, risk, controls, oversight, logs and changes.

It must be complete, coherent, current and traceable.

Quality management system

Article 17 requires providers of high-risk systems to maintain a quality management system covering compliance strategy, design, development, testing, validation, data, risk management, monitoring, incidents, documentation and responsibilities.

Under Annex VII, it forms part of the notified body assessment.

Risk, data, logs and human oversight

These elements should connect as risk → control → test → log → oversight → evidence.

The assessment should show that risks are identified, data governed, controls effective, traceability available, human oversight genuine, and required accuracy, robustness and cybersecurity achieved.

What happens after the assessment

Passing the assessment does not end the work. Providers must monitor, manage incidents, maintain documentation, update records, review risk and control change.

Conformity is part of the lifecycle and the wider AI governance framework.

What happens when the system changes

Article 43 requires a new assessment after a substantial modification, whether the modified system is redistributed or remains in use by the current deployer.

For continuously learning systems, changes predetermined by the provider and assessed during the original assessment may not constitute a substantial modification.

This makes AI system change management essential.

The relationship with CE marking and registration

Once conformity is demonstrated, the EU declaration of conformity, CE marking and registration may follow where applicable.

They do not replace the assessment. CE marking is not a standalone certification detached from the process.

Common mistakes

Assuming every system needs a notified body

That is incorrect.

Treating internal control as no control

It still requires evidence.

Choosing Annex VI or VII before classification

The system type must come first.

Treating the process as an ISO audit

They are not equivalent, and ISO/IEC 42001 does not replace Article 43.

Preparing documentation at the end

Evidence should follow the lifecycle.

Ignoring sectoral legislation

An integrated procedure may apply.

Failing to manage change

A substantial modification may trigger reassessment.

Confusing CE marking with assessment

The marking follows the relevant process.

Conformity is not demonstrated by one audit

Assessment connects classification → requirements → controls → evidence → assessment → market placement.

The route may vary, but the central question remains: can the provider demonstrate that the system meets the requirements that apply to it?

That requires coherence across risk, data, controls, tests, people and evidence.

References

  • Regulation (EU) 2024/1689 — Artificial Intelligence Act.
  • Article 16 — Obligations of providers of high-risk AI systems.
  • Article 17 — Quality management system.
  • Article 43 — Conformity assessment.
  • Article 47 — EU declaration of conformity.
  • Article 48 — CE marking.
  • Article 49 — Registration.
  • Annex VI — Conformity assessment procedure based on internal control.
  • Annex VII — Conformity assessment based on quality management system and assessment of technical documentation.
  • Annex I — Union harmonisation legislation.
  • Annex III — High-risk AI systems.

Do you know which conformity route applies to your AI system?

Before considering a notified body, CE marking or technical documentation, the organisation must correctly determine classification, applicable procedure and required evidence.

Start the diagnostic →
Céntrika’s diagnostic can help identify that starting point.