Article 34 requires assessments by the applicable date for the designated service, at least annually thereafter, and before deploying functionalities likely to have a critical impact on the identified risks. It also requires supporting documents to be preserved for at least three years after each assessment.
A useful evidence file should let an auditor trace each conclusion from risk signal to mitigation choice: service map, feature inventory, algorithmic-system descriptions, content moderation metrics, advertising-system review, recommender testing, complaint and notice data, consultation inputs, data-governance records, severity and probability rationale, and management approval. DSA recital 90 says providers should, where appropriate, involve representatives of recipients, potentially affected groups, independent experts, and civil-society organisations in risk assessments and mitigation design. Article 42(4) requires publication of information about those consultations where applicable.