European Union
EU AI Act Conformity Assessment: The Process, Step by Step
For most high-risk systems, nobody outside your own company reviews anything before launch. Here's how the two conformity assessment routes actually work, and which one you're on.
Ask most compliance teams what "conformity assessment" means and you'll get some version of: an outside auditor reviews the system and hands over a certificate. For the large majority of high-risk AI systems under the EU AI Act, that's not what happens. Conformity assessment for most systems is internal control — the provider reviews its own work, against its own documentation, and self-declares. No external reviewer touches it before the system reaches the market.
That's not a loophole. It's the deliberate default Article 43 sets, and it matters because it changes what your team actually has to build toward. If you're picturing a submission-and-approval process with an external gatekeeper, you're planning for the wrong thing for most systems — and building for the wrong thing for the narrow set that genuinely does need one.
The two routes, and which one applies to your system
Article 43 splits high-risk systems into two tracks, and which one you're on depends entirely on which Annex III category your system falls into — not on how risky you personally judge it to be.
Annex VI: internal control (the default for most systems)
For high-risk systems under Annex III points 2 through 8 — this covers most of the categories that show up in practice: employment and worker management, access to essential public and private services (credit, insurance, benefits eligibility), education, migration, and administration of justice — the conformity assessment procedure is Annex VI internal control, and Article 43 doesn't give providers a choice about it. There's no notified body involved, period, regardless of how sensitive the use case feels.
Annex VII: notified-body assessment (a narrow biometric exception)
Annex III point 1 — biometric identification and categorization systems — is the one category where a notified body can enter the picture. Providers of these systems get a conditional choice: if the system was built applying harmonised standards or common specifications in full, internal control under Annex VI is still available. If those standards weren't fully applied, the provider must go through Annex VII instead, which brings in a notified body to independently assess the quality management system and technical documentation.
There's a further carve-out worth knowing even if it rarely applies to you directly: where a high-risk system is intended for use by law enforcement, immigration or asylum authorities, or an EU institution, the relevant market surveillance authority itself steps into the notified-body role, rather than the provider selecting one from the open market.
What Annex VI internal control actually requires you to produce
Internal control isn't "skip the paperwork" — it's "no one outside your organization checks the paperwork before launch," which is a very different thing. Under Annex VI, the provider has to verify two things and be able to defend both if a market surveillance authority ever asks: that the quality management system satisfies Article 17, and that the technical documentation required under Article 11 genuinely evidences conformity with the Chapter III Section 2 obligations — the substance built up through Article 9's risk management system and the other high-risk requirements. Once that verification is done, the provider itself signs off. No submission, no waiting period, no external approval gate.
Take a hypothetical vendor, Verity Screen, building an AI tool that ranks job applicants' résumés for hiring managers — a system that falls under Annex III point 4 (employment). Verity Screen doesn't submit anything to Brussels or to a national authority before shipping. Its compliance team runs internal control: confirms the QMS meets Article 17, confirms the technical file backs up every Chapter III Section 2 obligation the tool is subject to, and once that's done internally, issues its own declaration. The first time an external party is likely to scrutinize any of it is if a regulator opens an inquiry or a customer's procurement team asks pointed questions — which is exactly why the documentation has to genuinely hold up, not just exist.
What Annex VII notified-body assessment actually involves
For the biometric systems that land in Annex VII, the process gains a real external checkpoint. A notified body assesses the quality management system against Article 17 and separately reviews the technical documentation, and if both hold up, it issues a certificate. That's not the end of the relationship, either — the notified body runs periodic surveillance audits for as long as the system stays on the market, reviewing whether the provider is still maintaining and applying the QMS it certified, and it retains the ability to run additional tests on the AI system itself during those audits. Annex VII is meaningfully more expensive and slower than internal control, which is exactly why the Act reserves it for one narrow, higher-sensitivity category rather than applying it broadly.
Contrast that with Verity Screen's résumé tool. A biometric vendor building a remote identity-verification system that matches a live selfie against an ID document — squarely Annex III point 1 — doesn't get to plan around a single internal sign-off the way Verity Screen does. If that vendor hasn't fully applied the relevant harmonised standards, it has to budget for a notified body's assessment timeline before it can ship at all, and for recurring surveillance audits afterward. Two companies building high-risk AI systems in the same regulatory framework can face structurally different launch processes purely because of which Annex III category they fall into — which is exactly why confirming your category correctly, before you plan the rest of your compliance timeline, matters more than debating how risky your system feels in the abstract.
What comes out the other end: declaration of conformity and CE marking
Whichever route a system goes through, the mechanism that actually authorizes market placement is the same: the provider issues an EU declaration of conformity under Article 47 and affixes CE marking under Article 48. That's true even on the Annex VII route — a notified body's certificate feeds into the provider's declaration, but it's the provider who issues the declaration and takes on the legal responsibility for it, not the notified body. CE marking itself can be physical or, for systems provided digitally, a digital mark accessible through the interface or a machine-readable code; where a notified body was involved, its identification number gets appended to the marking. This is the moment — not the assessment itself — when the system is legally allowed onto the market.
When you have to do it again: substantial modification
Conformity assessment isn't a one-time event tied only to first launch. A substantial modification — a change made after the system is already on the market that wasn't foreseen in the original assessment and that either affects the system's compliance with the Act's requirements or changes its intended purpose — triggers a brand-new conformity assessment. The modified system is treated as a new AI system for this purpose, not an update to the old one, regardless of whether it's being redistributed or the current deployer is just continuing to run it in place.
There's one deliberate exception, and it's worth planning around rather than discovering after the fact: for systems that keep learning after deployment, changes to the system and its performance don't count as substantial modifications if they were pre-determined by the provider at the time of the original assessment and disclosed in the technical documentation. That's precisely why the risk management process required under Article 9 needs to anticipate future changes in advance — a change your technical file already described is routine maintenance, while the same change showing up unannounced is a compliance event that forces you back through the entire assessment.
Where this sits in the compliance sequence
Conformity assessment is the last checkpoint in the sequence, not an independent process you can run in isolation. It comes after a system has cleared Article 5's prohibited-practices screen, been classified high-risk, and built out the substantive obligations — risk management, data governance, technical documentation, logging, transparency, human oversight. Conformity assessment doesn't create any of that substance; it verifies it exists and holds up, then produces the declaration and marking that let the system legally reach the market. Get the sequencing wrong — treating assessment as a final formality bolted on at the end rather than a genuine verification step — and internal control stops protecting you the moment anyone looks closely at the file it's supposed to defend.
Frequently asked questions
- Does every high-risk AI system need a notified body to review it?
- No. Annex III points 2 through 8 — the large majority of high-risk categories, covering things like employment, credit, and access to essential services — go through Annex VI internal control only, with no notified body involved at all. Only Annex III point 1, biometric systems, can require notified-body assessment under Annex VII, and even then only when harmonised standards or common specifications aren't fully applied.
- What's the actual difference between Annex VI and Annex VII?
- Annex VI is internal control: the provider verifies its own quality management system and technical documentation and self-declares conformity, with no external review before the system reaches the market. Annex VII adds a notified body, which independently assesses the quality management system and technical documentation, issues a certificate, and then runs periodic surveillance audits — including additional testing — for as long as the system stays on the market.
- Is there such a thing as an 'EU AI Act certificate'?
- Only inside the notified-body route, and even then it isn't the whole story. A notified body issues a certificate covering the quality management system and technical documentation it reviewed, but the provider is still the one who issues the EU declaration of conformity under Article 47. For the internal-control route that covers most high-risk systems, there's no external certificate at all — the provider's own declaration and CE marking are the entire compliance signal a buyer or regulator sees.
- What triggers a new conformity assessment after a system is already on the market?
- A substantial modification — a post-market change that wasn't foreseen in the original assessment and that affects the system's compliance with the Act's requirements, or changes its intended purpose — forces a brand-new conformity assessment, with the modified system treated as a new AI system entirely. There's one carve-out: for systems that keep learning after deployment, changes that were pre-determined and disclosed in the technical documentation at the time of the original assessment don't count as substantial modifications.
- Who picks the notified body if one is required?
- The provider can choose any notified body it wants, with one exception: where the system is intended for use by law enforcement, immigration or asylum authorities, or EU institutions, bodies, offices, or agencies, the relevant market surveillance authority performs the notified-body role itself rather than letting the provider shop for one.
Sources & references
Suggested next reading
regulations eu
The EU AI Act
regulations
Conformity Assessment
regulatory checklists