AI Governance Institute logo
AI Governance Institute

Practical Governance for Enterprise AI

· CMP-007High effort

EU AI Act Conformity Assessment and FRIA Process

Implement the EU AI Act's conformity assessment pathway for high-risk AI systems, including technical documentation, notified body engagement where required, and fundamental rights impact assessment.

Objective

Ensure high-risk AI systems deployed in the EU meet the EU AI Act's conformity obligations before going to market, including technical documentation standards, human oversight requirements, and fundamental rights impact assessment.

Maturity Levels

1

Initial

The organization is aware of EU AI Act obligations but has not assessed which systems are high-risk or begun conformity preparation.

2

Developing

High-risk systems have been identified. Technical documentation drafting is in progress but the conformity assessment process has not been defined.

3

Defined

A conformity assessment process is documented. Technical documentation exists for each high-risk system. The FRIA process is defined and has been run for at least one system.

4

Managed

All high-risk systems have completed technical documentation and FRIA. Notified body relationships are established for systems requiring third-party assessment. Post-market monitoring plans are operational.

5

Optimizing

Technical documentation is maintained continuously as systems change. FRIA findings feed into system design. The organization participates in EU AI Office stakeholder consultations.

Evidence Requirements

What an auditor or assessor would expect to see for this control.

  • High-risk system register identifying each system subject to EU AI Act high-risk classification, with classification rationale.
  • Technical documentation meeting Annex IV requirements for each high-risk system, with version date and sign-off.
  • Completed FRIA for each high-risk system deployed by a public authority or in a sensitive domain, with documented findings and mitigation plan.

Implementation Notes

Key steps

  • Classify AI systems against the EU AI Act Annex III high-risk categories. Systems in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and administration of justice require conformity assessment.
  • For each high-risk system, produce technical documentation meeting Article 11 and Annex IV requirements: system description, design specifications, training data governance, performance metrics, robustness and accuracy testing results, human oversight measures, and post-market monitoring plan.
  • Determine the conformity assessment pathway:
    • Most high-risk systems: internal conformity assessment with technical documentation lodged in an EU-accessible register.
    • Biometric identification and law enforcement systems: third-party notified body assessment required.
  • Select a notified body if required. The EU AI Act's list of notified bodies was published from 2025. Engage early — notified bodies have limited capacity.
  • Conduct a Fundamental Rights Impact Assessment (FRIA) for public authority deployers and private operators deploying high-risk systems with significant impact on individuals. The FRIA must assess impacts on dignity, non-discrimination, privacy, and data protection.
  • Register the system in the EU AI Act database where required (all high-risk systems from 2026).
  • Implement post-market monitoring as required by Article 72.

FRIA process steps

  1. Define the system scope and the affected population.
  2. Identify fundamental rights that could be affected: non-discrimination, privacy, dignity, freedom of expression, right to explanation.
  3. For each identified risk, assess severity and likelihood, and document existing mitigations.
  4. Where residual risks remain, define additional mitigations or human oversight requirements.
  5. Document the FRIA output and make it available to deployer compliance teams.

Example Implementation

EU AI Act Conformity Assessment Tracker

SystemAnnex III CategoryAssessment PathwayTechnical Doc StatusFRIA RequiredFRIA StatusNotified BodyReg. Database
Automated CV screeningEmployment (8a)InternalComplete — v2.1YesCompleteN/ARegistered
Credit risk scoringEssential services (5b)InternalIn progressYesNot startedN/APending
Remote biometric IDBiometrics (1b)Third-partyCompleteYesComplete[Notified Body X]Registered
Benefits eligibility AIAdministration (8e)InternalCompleteYesIn progressN/APending

Control Details

Control ID
CMP-007
Domain
Typical owner
Legal / Compliance / AI Engineering
Implementation effort
High effort
Agent-relevant
No

Tags

EU AI Actconformity assessmentFRIAhigh-risk AInotified bodyCE marking

Related Playbook

How do we document AI decision-making for auditability?How do we disclose AI governance maturity to investors and regulators?Who owns AI governance within the organization?How do we build an AI governance program from scratch?What do we do when an AI system causes harm or fails?How do we govern AI models from preview release through retirement?How do we build and maintain an AI model registry?Is our AI red-teaming rigorous enough?How do we inventory and classify AI systems by risk level?How do we detect and mitigate algorithmic bias?What does audit-ready AI documentation look like in practice?How do we report AI risk to the board and audit committee?How do we comply with China's AI regulations?How do we maintain data privacy compliance when using AI?How do we build director-level AI literacy for effective board oversight?How do we ensure human-in-the-loop review is actually effective?How do we govern AI agents that take autonomous actions?How do we perform an AI risk assessment?What does meaningful human oversight look like for high-risk AI decisions?How are we managing third-party AI risks?What is our process for model drift monitoring?How do we build and maintain a multi-framework AI risk register?How do we map AI compliance obligations across multiple jurisdictions?How do we prepare for AI regulation over the next 12 months?What are our obligations under emerging AI regulations?How do we ensure third-party AI vendors meet our standards?How do we apply a three lines of defense model to AI risk?