regulations

Conformity Assessment

The formal process a high-risk AI system goes through to demonstrate it meets the EU AI Act's requirements — internal self-assessment for most Annex III systems, or third-party assessment where a notified body is involved — before the system can be placed on the market or put into service.

Compliance auditor reviewing conformity assessment documentation for a high-risk AI system
Photo: Zulfugar Karimov via Unsplash
Governome Editorial Team2 min readHow we source and review this content.

Conformity assessment is the checkpoint between "we built a high-risk AI system" and "we're legally allowed to place it on the market." It's the process that verifies the system actually satisfies the substantive obligations the Act attaches to high-risk status — risk management, data governance, technical documentation, logging, transparency, and human oversight — before deployment, not an audit that happens after the fact.

Two routes, depending on the system

For most high-risk systems classified under Annex III, the provider carries out the conformity assessment internally, based on internal control — essentially a rigorous, documented self-assessment against the Act's requirements. A smaller set of systems, generally those tied to product-safety legislation already requiring third-party assessment (certain Annex I categories), go through assessment by a notified body — an independent organization authorized to verify conformity, similar to the role notified bodies already play under existing EU product-safety law like the Medical Device Regulation.

What a successful assessment produces

A system that passes conformity assessment gets a declaration of conformity and, where applicable, a CE marking — the same visible signal used across other EU product regulation to indicate a product has been verified against the relevant legal requirements. Conformity assessment isn't a one-time event tied only to first launch, either: a substantial modification to a high-risk system generally triggers a fresh assessment, which is one reason the risk management process required under Article 9 needs to track predetermined changes in advance — an unplanned modification can force an unplanned reassessment. For the full mechanics of both routes, including what triggers notified-body involvement and what a substantial modification actually looks like in practice, see our step-by-step walkthrough of the conformity assessment process.

For the classification step that determines whether a system needs conformity assessment at all, see how Article 6 high-risk classification works.

Executives reviewing an AI governance accountability structure in an office
Photo: Vitaly Gariev via Unsplash

ai governance

AI Governance

The structure of accountability, review, and decision rights a company puts in place to control how it builds, buys, and deploys AI systems.
Governome Editorial Team · 2 min read
Analysts monitoring a high-risk AI system's outputs on screens
Photo: Boitumelo via Unsplash
An AI system subject to heightened legal obligations because of what it's used for — not because of the underlying technology — typically because it materially affects access to employment, credit, healthcare, housing, or legal standing.
Governome Editorial Team · 2 min read
European Union policy officials in discussion at a government building
Photo: Karson via Unsplash

regulations eu

The EU AI Act

The EU AI Act classifies AI systems into risk tiers and phases its obligations in on a multi-year schedule. Here's what's actually in force today, what's still phasing in, and how the risk tiers work.
Governome Editorial Team · 4 min read
Compliance team running a risk management review meeting around a whiteboard
Photo: Fiqih Alfarish via Unsplash
Article 9 requires high-risk AI providers to run a continuous risk management process across the system's entire lifecycle, not produce a one-time document. Here's what the process actually has to include, and the gap auditors flag most.
Governome Editorial Team · 7 min read
Compliance team reviewing conformity assessment documentation for a high-risk AI system
Photo: Zulfugar Karimov via Unsplash
Article 43 conformity assessment has two routes: internal control, which covers most high-risk systems and involves no external reviewer at all, and notified-body assessment, reserved for a narrow slice of biometric systems. Here's how each one actually works, what gets produced, and what forces a redo.
Governome Editorial Team · 7 min read
Compliance and legal professionals reviewing AI system documentation together
Photo: Sherwin Ker via Unsplash
Article 6 of the EU AI Act classifies a system as high-risk through a combination of Annex I product-safety overlap and Annex III use-case categories. Here's how the two-step test actually applies, with the exemption most teams get wrong.
Governome Editorial Team · 3 min read