Implementation Kit
EU AI Act Global Compliance Roadmap and Vendor Questionnaire
The strategic question for a non-EU company: apply EU AI Act standards everywhere, or only to EU-facing systems. A global-vs-tiered decision framework, a vendor EU AI Act questionnaire, and a high-risk compliance roadmap.
Who this is for: The compliance leader at a global company deciding how far the EU AI Act reaches into non-EU operations.
1. Global vs. tiered compliance decision framework
SpreadsheetA structured way to decide whether to hold one global standard or segment by market.
Template
| Factor | Points toward one global standard | Points toward tiered by market |
|---|---|---|
| Share of systems or revenue touching the EU | High | Low and stable |
| Cost of maintaining two system variants | High (shared codebase, hard to fork) | Low (already region-segmented) |
| Other jurisdictions trending toward EU-like rules | Yes | No |
| Customer expectation / competitive positioning | EU-grade is a selling point | Price-sensitive, no demand |
| Internal capacity to run parallel compliance regimes | Limited | Ample |
| Decision: | ||
| Systems in scope for EU-grade treatment: | ||
| Review date for this decision: |
Worked example
| Factor | Assessment |
|---|---|
| EU exposure | ~30% of enterprise revenue; growing |
| Cost of two variants | High: single codebase, forking oversight logic is expensive |
| Other jurisdictions | Several US states and the UK trending toward risk-based rules |
| Customer expectation | EU-grade governance is used in enterprise sales globally |
| Internal capacity | One compliance team; cannot run two regimes well |
| Decision | One global standard at EU-AI-Act high-risk level for all Annex-III-equivalent systems |
| In scope | Resume Screener, Fraud Scoring, any future consequential-decision system |
| Review date | 2027-06-01 |
Acceptance criteria
- ✓The decision is made deliberately with the factors documented, not by default.
- ✓It names exactly which systems get EU-grade treatment.
- ✓It has a review date, since exposure and the regulatory landscape shift.
2. Vendor EU AI Act compliance questionnaire
SpreadsheetWhat to ask an AI vendor whose product is part of an EU high-risk system.
Template
| Question | Vendor response | Evidence | Gap |
|---|---|---|---|
| What is your role under the EU AI Act for this product (provider, GPAI provider, other)? | |||
| For GPAI: do you provide the Article 53 technical documentation and the training-content summary? | |||
| Do you supply the information a downstream provider needs to meet Annex IV and Article 13? | |||
| Do you support our conformity assessment with test results, model cards, and data governance evidence? | |||
| Will you notify us of changes that could affect our compliance, and in what window? | |||
| Do you have an authorised representative in the EU (if established outside)? |
Worked example
| Question | Vendor response | Evidence | Gap |
|---|---|---|---|
| Role under the Act | GPAI model provider | vendor legal statement | none |
| Article 53 docs + training summary | Yes, under NDA | doc portal access | none |
| Downstream provider info for Annex IV / Art. 13 | Partial | model card + eval summary | need input-data specs and known-limitation detail |
| Support for our conformity assessment | Yes | test result pack | none |
| Change notification | Changelog only | public changelog | need contractual notice window; redline sent |
| EU authorised representative | Yes | name + address provided | none |
Acceptance criteria
- ✓The vendor's role under the Act is established and recorded.
- ✓Gaps in the information you need for your own conformity assessment are tracked to closure.
- ✓A change-notification commitment is secured in the contract.
3. High-risk system compliance roadmap
SpreadsheetThe plan to get one system from where it is to conformity, with dates.
Template
| Workstream | Current state | Target | Owner | Due | Dependencies |
|---|---|---|---|---|---|
| Risk management system | Art. 9 process operating | ||||
| Data governance | Art. 10 evidence complete | ||||
| Technical documentation | Annex IV current | ||||
| Logging | Art. 12 in production | ||||
| Human oversight | Art. 14 designed and verified | ||||
| Accuracy / robustness / security | Art. 15 evidence | ||||
| FRIA | completed | ||||
| Conformity assessment + declaration | signed | ||||
| EU database registration | registered |
Worked example
| Workstream | Current | Target | Owner | Due | Dependencies |
|---|---|---|---|---|---|
| Human oversight | override exists; no low-score review | review step for bottom quartile | Talent | 2026-10-10 | UI change |
| FRIA | not started | completed | Legal | 2026-10-31 | oversight design final |
| Technical documentation | drafted | Annex IV current | Compliance | 2026-11-15 | eval refresh |
| Conformity assessment | 6 of 9 requirements met | declaration signed | Compliance | 2027-06-01 | above three |
| EU database registration | not started | registered | Compliance | before 2027-12-02 | conformity done |
Acceptance criteria
- ✓Every Chapter III workstream has an owner, a due date, and its dependencies.
- ✓Dates chain back from the applicability deadline, not forward from today.
- ✓The roadmap is reviewed on the same cadence as the compliance calendar.
Governance controls this kit produces evidence for
Completing the artifacts above gives you a head start on the evidence requirements for these controls.
The roadmap and vendor questionnaire drive the EU AI Act conformity assessment for global systems.
The global-vs-tiered decision is a multi-jurisdiction compliance strategy artifact.
The vendor questionnaire feeds EU-AI-Act-specific clauses into vendor contracts.
Scoping which systems get EU-grade treatment depends on risk classification.
The high-risk roadmap is a governance-program milestone plan.
This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.
Decide what to implement next
Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.
Start the AI governance assessment →