AI Governance Institute
All governance templates →How does the EU AI Act affect our global operations?

Implementation Kit

EU AI Act Global Compliance Roadmap and Vendor Questionnaire

The strategic question for a non-EU company: apply EU AI Act standards everywhere, or only to EU-facing systems. A global-vs-tiered decision framework, a vendor EU AI Act questionnaire, and a high-risk compliance roadmap.

Who this is for: The compliance leader at a global company deciding how far the EU AI Act reaches into non-EU operations.

Download the kit (Markdown) ↓3 artifacts. Every table also copies as CSV.

1. Global vs. tiered compliance decision framework

Spreadsheet

A structured way to decide whether to hold one global standard or segment by market.

Template

FactorPoints toward one global standardPoints toward tiered by market
Share of systems or revenue touching the EUHighLow and stable
Cost of maintaining two system variantsHigh (shared codebase, hard to fork)Low (already region-segmented)
Other jurisdictions trending toward EU-like rulesYesNo
Customer expectation / competitive positioningEU-grade is a selling pointPrice-sensitive, no demand
Internal capacity to run parallel compliance regimesLimitedAmple
Decision:
Systems in scope for EU-grade treatment:
Review date for this decision:

Worked example

FactorAssessment
EU exposure~30% of enterprise revenue; growing
Cost of two variantsHigh: single codebase, forking oversight logic is expensive
Other jurisdictionsSeveral US states and the UK trending toward risk-based rules
Customer expectationEU-grade governance is used in enterprise sales globally
Internal capacityOne compliance team; cannot run two regimes well
DecisionOne global standard at EU-AI-Act high-risk level for all Annex-III-equivalent systems
In scopeResume Screener, Fraud Scoring, any future consequential-decision system
Review date2027-06-01

Acceptance criteria

  • The decision is made deliberately with the factors documented, not by default.
  • It names exactly which systems get EU-grade treatment.
  • It has a review date, since exposure and the regulatory landscape shift.

2. Vendor EU AI Act compliance questionnaire

Spreadsheet

What to ask an AI vendor whose product is part of an EU high-risk system.

Template

QuestionVendor responseEvidenceGap
What is your role under the EU AI Act for this product (provider, GPAI provider, other)?
For GPAI: do you provide the Article 53 technical documentation and the training-content summary?
Do you supply the information a downstream provider needs to meet Annex IV and Article 13?
Do you support our conformity assessment with test results, model cards, and data governance evidence?
Will you notify us of changes that could affect our compliance, and in what window?
Do you have an authorised representative in the EU (if established outside)?

Worked example

QuestionVendor responseEvidenceGap
Role under the ActGPAI model providervendor legal statementnone
Article 53 docs + training summaryYes, under NDAdoc portal accessnone
Downstream provider info for Annex IV / Art. 13Partialmodel card + eval summaryneed input-data specs and known-limitation detail
Support for our conformity assessmentYestest result packnone
Change notificationChangelog onlypublic changelogneed contractual notice window; redline sent
EU authorised representativeYesname + address providednone

Acceptance criteria

  • The vendor's role under the Act is established and recorded.
  • Gaps in the information you need for your own conformity assessment are tracked to closure.
  • A change-notification commitment is secured in the contract.

3. High-risk system compliance roadmap

Spreadsheet

The plan to get one system from where it is to conformity, with dates.

Template

WorkstreamCurrent stateTargetOwnerDueDependencies
Risk management systemArt. 9 process operating
Data governanceArt. 10 evidence complete
Technical documentationAnnex IV current
LoggingArt. 12 in production
Human oversightArt. 14 designed and verified
Accuracy / robustness / securityArt. 15 evidence
FRIAcompleted
Conformity assessment + declarationsigned
EU database registrationregistered

Worked example

WorkstreamCurrentTargetOwnerDueDependencies
Human oversightoverride exists; no low-score reviewreview step for bottom quartileTalent2026-10-10UI change
FRIAnot startedcompletedLegal2026-10-31oversight design final
Technical documentationdraftedAnnex IV currentCompliance2026-11-15eval refresh
Conformity assessment6 of 9 requirements metdeclaration signedCompliance2027-06-01above three
EU database registrationnot startedregisteredCompliancebefore 2027-12-02conformity done

Acceptance criteria

  • Every Chapter III workstream has an owner, a due date, and its dependencies.
  • Dates chain back from the applicability deadline, not forward from today.
  • The roadmap is reviewed on the same cadence as the compliance calendar.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

CMP-007
CMP-007

The roadmap and vendor questionnaire drive the EU AI Act conformity assessment for global systems.

CMP-001
CMP-001

The global-vs-tiered decision is a multi-jurisdiction compliance strategy artifact.

PRC-002
PRC-002

The vendor questionnaire feeds EU-AI-Act-specific clauses into vendor contracts.

HOC-001
HOC-001

Scoping which systems get EU-grade treatment depends on risk classification.

MGV-003
MGV-003

The high-risk roadmap is a governance-program milestone plan.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →