AI Governance Institute
All governance templates →← How do we comply with the EU AI Act?

Implementation Kit

EU AI Act Compliance Checklist and Documentation Templates

The working set for EU AI Act compliance: a risk-tier classification worksheet against Annex III, an Annex IV technical documentation template, a conformity self-assessment checklist, and an EU database registration checklist.

Who this is for: The compliance owner taking a system through EU AI Act classification and the high-risk obligations.

Download the kit (Markdown) ↓4 artifacts. Every table also copies as CSV.

1. EU AI Act risk tier classification worksheet

Spreadsheet

Walks a system to a tier: prohibited, high-risk, limited-risk, or minimal.

Template

QuestionAnswerResult
Does the system perform an Article 5 prohibited practice (social scoring, manipulative techniques, untargeted facial scraping, most real-time remote biometric ID)?Y / NY: Prohibited, stop
Is it a safety component of a product covered by Annex I legislation, requiring third-party conformity assessment?Y / NY: High-risk (Annex I route)
Does it fall in an Annex III use case (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice)?Y / NY: High-risk unless an Article 6(3) derogation applies
If Annex III: does it only perform a narrow procedural task, improve a prior human activity, detect patterns without replacing human judgement, or do prep work?Y / NY: may not be high-risk; document the Article 6(3) assessment
Does it interact with people, generate synthetic media, or is it an emotion-recognition system?Y / NY: transparency obligations (Article 50) at minimum
Resulting tier and obligations set:

Worked example

QuestionAnswerResult
Article 5 prohibited practice?Ncontinue
Annex I safety component?Ncontinue
Annex III use case?Yemployment: screening and filtering applications
Article 6(3) narrow-task derogation applies?Nranking materially influences the hiring funnel
Interacts with people / synthetic media / emotion recognition?N-
TierHigh-risk (Annex III, employment)full Chapter III obligations + FRIA + registration

Acceptance criteria

  • ✓The Article 5 check is done first and routes prohibited systems to a stop.
  • ✓Any Article 6(3) derogation claim is documented with reasoning, not asserted.
  • ✓The worksheet output names the exact obligations set the tier triggers.

2. Annex IV technical documentation template

Document

The structure of the technical documentation a high-risk system must maintain.

Template

Maintained current for the life of the system. Sections track Annex IV.

  1. General description: intended purpose, provider, versions, how it interacts with hardware/software, deployment forms
  2. Detailed description: development process, design specifications, system architecture, data requirements, human oversight measures, pre-determined changes
  3. Monitoring, functioning, control: capabilities and limitations, accuracy metrics, foreseeable unintended outcomes, input data specifications
  4. Risk management system: the Article 9 risk management process and its outputs
  5. Lifecycle changes: log of changes made through the system's life
  6. Standards applied: harmonised standards or other solutions used to meet requirements
  7. EU declaration of conformity
  8. Post-market monitoring plan: per Article 72

Worked example

Section 3 excerpt, Resume Screener:

  • Capabilities: ranks applicants 1-5 against a role's structured requirements.
  • Limitations: does not assess portfolio content, video, or references; degrades when a role's requirement mix changes materially.
  • Accuracy: ranking accuracy 0.81 on the 2026-08 holdout; adverse-impact ratio lowest 0.88.
  • Foreseeable unintended outcomes: demographic disparity from historical data skew (mitigated, monitored monthly); over-reliance by recruiters (mitigated by oversight design and override monitoring).
  • Input data specifications: structured fields parsed from the application; free-text CV parsed then discarded for inference.

Acceptance criteria

  • ✓All eight Annex IV areas are present, even if a section is short.
  • ✓Accuracy, robustness, and known limitations are stated with figures and dates.
  • ✓The documentation is updated on every change that the versioning policy records.

3. Conformity assessment checklist

Spreadsheet

The self-assessment most Annex III systems run (internal control, Annex VI) before the declaration of conformity.

Template

Requirement (Chapter III, Section 2)ArticleIn place?Evidence
Risk management system, run across the lifecycle9Y / N
Data governance: relevant, representative, error-checked training/validation/test data10Y / N
Technical documentation (Annex IV)11Y / N
Automatic logging of events over the system's lifetime12Y / N
Transparency and information to deployers (instructions for use)13Y / N
Human oversight measures designed in14Y / N
Accuracy, robustness, and cybersecurity appropriate to the purpose15Y / N
Fundamental Rights Impact Assessment (deployers of certain systems)27Y / N
Quality management system (providers)17Y / N

Worked example

RequirementArticleIn place?Evidence
Risk management system9Yrisk assessment + multi-framework register rows
Data governance10Ytraining data provenance + bias evals
Technical documentation11PartialAnnex IV doc drafted; sections 6 and 7 outstanding
Event logging12Ydecision log schema in production
Instructions for use13Ydeployer guide v2
Human oversight14Partialdesign gap: no low-score review step
Accuracy, robustness, security15Yeval + adversarial test reports
FRIA27Nscheduled 2026-10-31
Quality management system17YISO 42001-aligned QMS

Acceptance criteria

  • ✓Every Chapter III Section 2 requirement is assessed with linked evidence.
  • ✓Partial or missing items have an owner and a date, and the declaration of conformity is not signed while any are open.
  • ✓The fundamental rights impact assessment (FRIA) is completed where the deployer obligation applies.

4. EU database registration checklist

Spreadsheet

The steps to register a high-risk system (and, for deployers that are public bodies, their use) in the EU database.

Template

StepOwnerDoneNote
Confirm the system is in an Annex III category requiring registrationComplianceY / N
Gather the required registration data (provider, system, intended purpose, status, member states, docs)ComplianceY / N
Register before placing on the market or putting into serviceProviderY / Ndate
Public-body deployer: register the use of the systemDeployerY / Nif applicable
Keep the registration entry updated on material change or withdrawalComplianceY / N

Worked example

StepOwnerDoneNote
Annex III category confirmedComplianceYemployment
Registration data gatheredComplianceYpack assembled from Annex IV doc
Registered before serviceProviderNtarget: before the 2027-12-02 applicability date
Public-body deployer useDeployerN/Ano public-body deployers
Keep entry updatedComplianceYtied to the change process

Acceptance criteria

  • ✓Registration happens before the system is placed on the market or put into service.
  • ✓The registration data set is assembled from the Annex IV documentation, not re-created.
  • ✓A process keeps the entry current on material changes.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

CMP-007
EU AI Act Conformity Assessment and FRIA Process

The whole kit is the EU AI Act conformity assessment and FRIA process.

HOC-001
AI System Risk Classification

The risk-tier worksheet is a documented, EU-AI-Act-specific risk classification.

ALC-002
High-Risk AI Audit Trail

The Article 12 logging requirement maps to the high-risk audit trail control.

CMP-006
AI Content Watermarking and Labeling Compliance

Where the system generates synthetic media, the transparency step feeds content labelling compliance.

MGV-001
AI Model Preview and Staged Release Policy

The conformity checklist gates a system before it is placed on the market, part of staged release.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →