AI Governance Institute
How do we comply with the EU AI Act?

Implementation Kit

EU AI Act Compliance Kit

The working set for EU AI Act compliance: a risk-tier classification worksheet against Annex III, an Annex IV technical documentation template, a conformity self-assessment checklist, and an EU database registration checklist.

Who this is for: The compliance owner taking a system through EU AI Act classification and the high-risk obligations.

Download the kit (Markdown) ↓4 artifacts. Every table also copies as CSV.

1. EU AI Act risk tier classification worksheet

Spreadsheet

Walks a system to a tier: prohibited, high-risk, limited-risk, or minimal.

Template

QuestionAnswerResult
Does the system perform an Article 5 prohibited practice (social scoring, manipulative techniques, untargeted facial scraping, most real-time remote biometric ID)?Y / NY: Prohibited, stop
Is it a safety component of a product covered by Annex I legislation, requiring third-party conformity assessment?Y / NY: High-risk (Annex I route)
Does it fall in an Annex III use case (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice)?Y / NY: High-risk unless an Article 6(3) derogation applies
If Annex III: does it only perform a narrow procedural task, improve a prior human activity, detect patterns without replacing human judgement, or do prep work?Y / NY: may not be high-risk; document the Article 6(3) assessment
Does it interact with people, generate synthetic media, or is it an emotion-recognition system?Y / NY: transparency obligations (Article 50) at minimum
Resulting tier and obligations set:

Worked example

QuestionAnswerResult
Article 5 prohibited practice?Ncontinue
Annex I safety component?Ncontinue
Annex III use case?Yemployment: screening and filtering applications
Article 6(3) narrow-task derogation applies?Nranking materially influences the hiring funnel
Interacts with people / synthetic media / emotion recognition?N-
TierHigh-risk (Annex III, employment)full Chapter III obligations + FRIA + registration

Acceptance criteria

  • The Article 5 check is done first and routes prohibited systems to a stop.
  • Any Article 6(3) derogation claim is documented with reasoning, not asserted.
  • The worksheet output names the exact obligations set the tier triggers.

2. Annex IV technical documentation template

Document

The structure of the technical documentation a high-risk system must maintain.

Template

Maintained current for the life of the system. Sections track Annex IV.

  1. General description: intended purpose, provider, versions, how it interacts with hardware/software, deployment forms
  2. Detailed description: development process, design specifications, system architecture, data requirements, human oversight measures, pre-determined changes
  3. Monitoring, functioning, control: capabilities and limitations, accuracy metrics, foreseeable unintended outcomes, input data specifications
  4. Risk management system: the Article 9 risk management process and its outputs
  5. Lifecycle changes: log of changes made through the system's life
  6. Standards applied: harmonised standards or other solutions used to meet requirements
  7. EU declaration of conformity
  8. Post-market monitoring plan: per Article 72

Worked example

Section 3 excerpt, Resume Screener:

  • Capabilities: ranks applicants 1-5 against a role's structured requirements.
  • Limitations: does not assess portfolio content, video, or references; degrades when a role's requirement mix changes materially.
  • Accuracy: ranking accuracy 0.81 on the 2026-08 holdout; adverse-impact ratio lowest 0.88.
  • Foreseeable unintended outcomes: demographic disparity from historical data skew (mitigated, monitored monthly); over-reliance by recruiters (mitigated by oversight design and override monitoring).
  • Input data specifications: structured fields parsed from the application; free-text CV parsed then discarded for inference.

Acceptance criteria

  • All eight Annex IV areas are present, even if a section is short.
  • Accuracy, robustness, and known limitations are stated with figures and dates.
  • The documentation is updated on every change that the versioning policy records.

3. Conformity assessment checklist

Spreadsheet

The self-assessment most Annex III systems run (internal control, Annex VI) before the declaration of conformity.

Template

Requirement (Chapter III, Section 2)ArticleIn place?Evidence
Risk management system, run across the lifecycle9Y / N
Data governance: relevant, representative, error-checked training/validation/test data10Y / N
Technical documentation (Annex IV)11Y / N
Automatic logging of events over the system's lifetime12Y / N
Transparency and information to deployers (instructions for use)13Y / N
Human oversight measures designed in14Y / N
Accuracy, robustness, and cybersecurity appropriate to the purpose15Y / N
Fundamental Rights Impact Assessment (deployers of certain systems)27Y / N
Quality management system (providers)17Y / N

Worked example

RequirementArticleIn place?Evidence
Risk management system9Yrisk assessment + multi-framework register rows
Data governance10Ytraining data provenance + bias evals
Technical documentation11PartialAnnex IV doc drafted; sections 6 and 7 outstanding
Event logging12Ydecision log schema in production
Instructions for use13Ydeployer guide v2
Human oversight14Partialdesign gap: no low-score review step
Accuracy, robustness, security15Yeval + adversarial test reports
FRIA27Nscheduled 2026-10-31
Quality management system17YISO 42001-aligned QMS

Acceptance criteria

  • Every Chapter III Section 2 requirement is assessed with linked evidence.
  • Partial or missing items have an owner and a date, and the declaration of conformity is not signed while any are open.
  • The FRIA is completed where the deployer obligation applies.

4. EU database registration checklist

Spreadsheet

The steps to register a high-risk system (and, for deployers that are public bodies, their use) in the EU database.

Template

StepOwnerDoneNote
Confirm the system is in an Annex III category requiring registrationComplianceY / N
Gather the required registration data (provider, system, intended purpose, status, member states, docs)ComplianceY / N
Register before placing on the market or putting into serviceProviderY / Ndate
Public-body deployer: register the use of the systemDeployerY / Nif applicable
Keep the registration entry updated on material change or withdrawalComplianceY / N

Worked example

StepOwnerDoneNote
Annex III category confirmedComplianceYemployment
Registration data gatheredComplianceYpack assembled from Annex IV doc
Registered before serviceProviderNtarget: before the 2027-12-02 applicability date
Public-body deployer useDeployerN/Ano public-body deployers
Keep entry updatedComplianceYtied to the change process

Acceptance criteria

  • Registration happens before the system is placed on the market or put into service.
  • The registration data set is assembled from the Annex IV documentation, not re-created.
  • A process keeps the entry current on material changes.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

CMP-007
EU AI Act Conformity Assessment and FRIA Process

The whole kit is the EU AI Act conformity assessment and FRIA process.

HOC-001
AI System Risk Classification

The risk-tier worksheet is a documented, EU-AI-Act-specific risk classification.

ALC-002
High-Risk AI Audit Trail

The Article 12 logging requirement maps to the high-risk audit trail control.

CMP-006
AI Content Watermarking and Labeling Compliance

Where the system generates synthetic media, the transparency step feeds content labelling compliance.

MGV-001
AI Model Preview and Staged Release Policy

The conformity checklist gates a system before it is placed on the market, part of staged release.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.