EU AI Act Conformity Assessment and Notified Bodies
Decide whether a high-risk AI system can use internal control, needs notified body involvement, or must follow a sectoral product-law assessment route.
Use the page to line up provider obligations, technical documentation, quality management evidence, declaration, CE marking, registration, and notified body records before market release.
Classify the high-risk system before selecting a route or assessor. Annex III points 2 to 8 use internal control, Annex III point 1 biometrics uses internal control only when the standards or common-specification conditions in Article 43 are met, and product-linked systems follow the applicable Annex I Section A product-law procedure. A notified body is not required for every high-risk AI system.
1
Section 1
Route selection starts with the high-risk basis
Start by recording why the AI system is high-risk. Article 6 separates product-linked high-risk AI from Annex III use cases. That split controls the conformity route, the evidence package, and whether an existing product-law notified body may become part of the assessment.
For product-linked systems under Article 6(1), the AI system is high-risk when it is a safety component, or is itself a product, covered by Annex I Union harmonisation legislation and that product is already subject to third-party under that legislation. For Annex III systems, Article 43 generally points to internal control, with a narrower notified body route for point 1 Annex III systems in the conditions listed in Article 43(1).
Check the application date separately from the route. Regulation (EU) 2026/1744 was published on 24 July 2026 and enters into force on 27 July 2026. It applies Chapter III Sections 1-3 from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Article 6(1) systems. For Article 6(1) systems related to products under Annex I Section B, the amendment limits direct AI Act application to Article 6(1), Article 60a, and Articles 102-112; Articles 57-59 apply only where the high-risk requirements have been integrated into the sector law. Record the exact Annex I instrument before selecting an AI Act conformity route.
Record the high-risk legal basis: Article 6(1) product route or Article 6(2) Annex III route.
For Annex III, identify the exact Annex III point and whether Article 6(3) non-high-risk reasoning is being used; if so, document the assessment before market release and register under Article 49(2).
For Annex III point 1 systems, check whether harmonised standards or common specifications fully cover the relevant Section 2 requirements and whether they have been applied without restriction.
For Annex I product systems, integrate the AI Act Section 2 requirements into the product-law rather than running a disconnected AI-only exercise.
Annex VI internal control still requires the provider to verify that the quality management system complies with Article 17, examine the technical documentation against the high-risk requirements in Chapter III Section 2, and verify that the design, development process, and post-market monitoring match the technical documentation.
The minimum evidence package should therefore connect the Section 2 requirements to system design and operating controls: risk management, data governance, technical documentation, logging, deployer information, human oversight, accuracy, robustness, and cybersecurity. A self-assessment that only stores a policy or vendor attestation does not answer Annex VI.
Keep an Article 17 quality management file covering regulatory strategy, design control, validation, data management, risk management, post-market monitoring, serious incident reporting, communications, record keeping, resources, and accountability.
Keep Article 11 and Annex IV technical documentation with intended purpose, versions, interfaces, architecture, datasets, validation and testing reports, human oversight measures, cybersecurity measures, standards or common specifications, declaration of conformity, and post-market monitoring plan.
Keep the internal-control conclusion as a traceable sign-off that names the applied standards or common specifications and explains any alternative technical solution.
Store provider logs where under provider control and align the log design with post-market monitoring and substantial-modification detection.
A notified body is required under Article 43(1) for high-risk AI systems listed in point 1 of Annex III when the provider cannot rely fully on the relevant harmonised standards or common specifications, including where no such standards or specifications exist, only part of a standard is applied, a common specification is not applied, or a standard is published with a restriction for the relevant part.
For high-risk AI systems covered by Annex I Section A product legislation, Article 43(3) sends the provider to the procedure required by that product law. Notified bodies notified under those product laws may control conformity with AI Act Section 2 requirements if their compliance with specified AI Act notified-body requirements has been assessed in the relevant notification procedure.
When Annex VII applies to a system intended for use by law-enforcement, immigration, or asylum authorities, or by Union institutions, bodies, offices, or agencies, the relevant market surveillance authority acts as the notified body. Do not route those systems to an ordinary commercial notified body.
Prepare a notified-body application package with the provider details, covered AI systems, Article 17 quality management documentation, Annex IV technical documentation, and a declaration that the same application has not been lodged with another notified body.
Expect the notified body to examine the quality management system, examine technical documentation, request evidence or tests, and, where necessary and proportionate to its task, access training, validation, and testing datasets.
Treat model or system changes that could affect compliance or intended purpose as notified-body change events when a Union technical documentation assessment certificate has been issued.
Keep refusals, restrictions, suspensions, withdrawals, certificates, supplements, audit reports, and reasoned assessment decisions with the product release evidence.
Provider obligations around declaration, CE marking, and registration
Article 16 makes the provider responsible for the complete pre-market chain: comply with Section 2 requirements, operate a quality management system, keep documentation, run the Article 43 before placement or putting into service, draw up the EU declaration of conformity, affix CE marking, and register where Article 49 applies.
Article 47 and Annex V require a declaration for each high-risk AI system, issued under the provider's sole responsibility. It must identify the system, the provider or authorised representative, applicable Union law, relevant standards or common specifications, and, where applicable, the notified body, procedure, and certificate.
Before release, confirm the EU declaration of conformity exists, is up to date, and can be provided to national competent authorities on request.
Affix CE marking visibly, legibly, and indelibly; for digital high-risk AI systems, use a digital CE marking only if it is easily accessible through the interface or another accessible electronic means.
Where a notified body was involved, include the notified body's identification number after the CE marking and in promotional material that refers to CE conformity.
Register providers and relevant high-risk AI systems in the EU database before placement on the market or putting into service where Article 49 requires registration.
Notifying authorities and notified bodies are separate roles
Notifying authorities are Member State authorities responsible for the assessment, designation, notification, and monitoring of bodies. They must be organised to avoid conflicts of interest and to safeguard objectivity and impartiality. A notifying authority is not the provider's assessor in the same way as a notified body; it controls which conformity assessment bodies can become notified bodies and monitors them.
A notified body is the body that has been notified and may perform the notified-body assessment tasks within the scope of its notification. Article 31 requires notified bodies to be independent of providers and other economically interested operators, to avoid consultancy conflicts, to maintain confidentiality, and to have sufficient administrative, technical, legal, and scientific personnel for the relevant AI systems, data, computing, and AI Act requirements.
Use the notifying authority route for questions about designation, notification scope, monitoring, objections, or competence of a body.
Use the notified body route for assessment of the provider's quality management system, technical documentation, certificates, supplements, surveillance audits, and certificate changes.
Check the notified body's notification scope against the AI system type and conformity module before treating a certificate as applicable.
Use the Commission Single Market Compliance Space/NANDO-style listing to locate notified bodies by legislation as designations become available.
Separate harmonised standards, common specifications, and voluntary guidance
A technical standard supports conformity only to the extent that it covers an applicable AI Act requirement. A harmonised standard creates a presumption of conformity only after its reference is published in the Official Journal and only for the requirements covered by that reference. A draft standard, an ISO or ETSI publication, or a standard used elsewhere in the organisation does not receive that legal effect automatically.
Common specifications are Commission acts used under the conditions in Article 41. Providers can use other technical solutions, but they must justify how those solutions meet an equivalent level of compliance. Codes of practice and Commission or standards-body guidance can organise evidence without replacing the binding requirement or the conformity route.
For each cited standard, record the edition, clause, AI Act requirement supported, Official Journal reference if any, date checked, applicable system version, test evidence, and uncovered residual requirement.
Treat ISO/IEC 42001 as management-system evidence and ISO/IEC 23894 as risk-management guidance unless a specific legal mechanism gives a provision a different effect.
Use ETSI AI security, data-supply-chain, privacy, transparency, and explicability material as technical input where it fits the system; label it as supporting evidence unless the relevant provision has acquired a formal presumption of conformity.
Recheck the standards register before and after a new Official Journal citation, common specification, system change, or certificate update.
Treat this checklist as a release gate for a high-risk AI system. It focuses on whether the conformity file would let a competent authority, notified body, importer, distributor, or enterprise customer understand the route chosen and verify the evidence without rebuilding the history from memory.
Escalate the file for legal and regulatory review when the route depends on Annex I product law, Annex III point 1 conditions, partial standards coverage, a restricted harmonised standard, non-application of common specifications, a substantial modification, or a notified-body refusal or restriction.
Article 46 permits a market surveillance authority, on a duly justified request and for a limited period, to authorise a specific high-risk system before is complete for exceptional public-security, life and health, environmental, or key industrial and infrastructure reasons. This is an authority-controlled derogation, not an alternative provider route; the conformity procedure must still be completed without undue delay.
Does every high-risk AI system need a notified body under the EU AI Act?
No. Article 43 uses internal control for high-risk AI systems in Annex III points 2 to 8. Notified body involvement is triggered for Annex III point 1 systems in the conditions listed in Article 43(1), and Annex I product systems follow the relevant product-law route.
What evidence should a provider keep after ?
Article 18 requires providers to keep, for 10 years after placement on the market or putting into service, technical documentation, quality management documentation, approved notified-body change records where applicable, notified-body decisions and documents where applicable, and the EU declaration of conformity.
What changes can reopen ?
Article 43 requires a new after a substantial modification. For systems with a Union technical documentation assessment certificate, Annex VII also requires provider notice to the issuing notified body for changes that could affect compliance or intended purpose.
High-risk basis is recorded with Article 6 reasoning and, where relevant, the exact Annex III point or Annex I product legislation.
Article 43 route decision is written: Annex VI internal control, Annex VII notified-body assessment, or product-law conformity route.
Article 17 quality management documentation and Article 11/Annex IV technical documentation are complete enough to demonstrate Section 2 compliance.
EU declaration of conformity, CE marking decision, notified body certificate details where applicable, and Article 49 registration evidence are stored together.
Change-control rules identify when a new , notified-body supplement, or updated declaration is needed.
Sorena can help map the high-risk basis, select the Article 43 route, assemble provider evidence, and prepare notified-body or internal-control records for EU AI Act work.
Commission explanation of harmonised standards, Official Journal citation, presumption of conformity, international standards, and the distinction from codes of practice.
Binding amendment supporting the revised Chapter III application dates and the limited direct AI Act provisions for Article 6(1) systems related to Annex I Section B products.