Start with Maditon
← Back to Resource Center
EU AI Act · Article 43 7 min read

Conformity assessment for high-risk AI systems

Article 43 conformity assessment: internal control vs notified body, what gets assessed, and the practical timeline before a high-risk system goes to market.


For every high-risk AI system placed on the EU market from 2 December 2027 (postponed from 2 August 2026 to 2 December 2027 under the Digital Omnibus, agreed May 2026 and pending formal adoption), the provider must complete a conformity assessment before it goes live. Article 43 sets out the procedure; Annex VI covers internal-control assessment; Annex VII covers third-party notified-body assessment. This guide walks through what the assessment is, which procedure applies to which system, and how to time it.

What a conformity assessment is

A conformity assessment is a structured demonstration that your AI system meets the requirements of Chapter III, Section 2 of the Act — Articles 8 through 15:

  • Article 9: risk management system
  • Article 10: data governance (training, validation, test data)
  • Article 11: technical documentation per Annex IV
  • Article 12: record-keeping (logging)
  • Article 13: transparency and information for deployers
  • Article 14: human oversight
  • Article 15: accuracy, robustness, cybersecurity

The output is a declaration of conformity (Annex V) signed by you, evidence supporting it (the technical documentation), and the right to affix the CE marking to your AI system.

Two procedures — pick the right one

Article 43 specifies two paths, depending on the type of high-risk system:

| Procedure | Used for | Performed by | |---|---|---| | Annex VI — internal control | Annex III high-risk systems (most of them) | The provider, internally, with documented evidence | | Annex VII — third-party assessment | Annex III biometric systems where harmonised standards don’t fully apply, and high-risk systems embedded in Annex II products | A notified body |

For most SaaS providers building Annex III systems (HR-tech, credit scoring, education-tech), Annex VI internal control applies. You assess your own conformity, sign your own declaration, retain the documentation for 10 years.

For providers of biometric ID systems, medical-device-embedded AI, machinery-embedded AI, and similar Annex II safety components, a notified body conducts the assessment. The list of designated notified bodies for the AI Act is maintained by the European Commission.

The Annex VI internal-control procedure (most common)

For an SME running Annex VI, the practical steps are:

  1. Verify the quality management system is in place per Article 17 — covering design, development, quality control, post-market monitoring, and reporting procedures
  2. Examine the technical documentation drafted per Annex IV — confirming it covers all the requirements
  3. Verify the risk-management process under Article 9 — confirming risks are identified, evaluated, and mitigated
  4. Confirm the system performs as documented — testing against the declared specifications
  5. Draft and sign the EU declaration of conformity per Annex V
  6. Affix the CE marking to the AI system (digital or physical, depending on the system form)
  7. Retain the documentation for 10 years for supervisory authority inspection

No external auditor is required. But “internal control” doesn’t mean “rubber stamp” — supervisory authorities can demand the documentation at any time, and gaps in the underlying evidence will lead to enforcement action.

The Annex VII third-party procedure

For systems requiring notified-body assessment, the path is longer:

  1. Apply to a notified body designated for the relevant product category
  2. Submit the technical documentation per Annex IV for the body’s review
  3. Quality management system assessment — the notified body audits your QMS per Article 17
  4. Assessment of conformity with Section 2 — including potentially on-site testing
  5. Notified body issues the EU technical documentation assessment certificate if conformity is demonstrated
  6. You sign the EU declaration of conformity referencing the certificate
  7. CE marking can then be affixed

Notified-body assessment can take 3–6 months depending on complexity and the notified body’s workload. Book early.

What the harmonised standards do

When the European Commission designates harmonised standards under Article 41 (these are being developed by CEN-CENELEC JTC 21 through 2025–2026), conformity with the harmonised standards gives a presumption of conformity with the corresponding Act requirements.

In practice: once standards exist for risk management, data governance, technical documentation, etc., a provider following those standards is presumed compliant. The notified body’s job becomes verifying you followed the standard, rather than assessing each requirement from scratch.

As of mid-2026, the harmonised standards are not yet finalised. Until they are, both providers and notified bodies must assess conformity directly against the Act’s text — a higher-effort process.

Substantial modification — when re-assessment is required

Article 43(4): if the system undergoes a “substantial modification” that materially changes its compliance posture or intended purpose, a new conformity assessment is required.

Substantial modification includes:

  • Changes to the intended purpose
  • Changes to the system’s architecture that affect its performance properties
  • Changes to the data on which the system was trained that materially affect accuracy or robustness
  • Adding new categories of users or affected persons

Cosmetic changes, UI tweaks, infrastructure migrations, and routine model retraining within the documented evaluation envelope are typically not substantial. Document the boundary you draw.

The declaration of conformity (Annex V)

The declaration of conformity is a one-page legal document signed by the provider. It must include:

  • Provider name and address (plus authorised representative if non-EU)
  • AI system identifier (trade name, version, etc.)
  • A statement that the AI system meets the requirements of Chapter III Section 2
  • References to relevant harmonised standards or common specifications applied
  • The conformity assessment procedure used (Annex VI or VII)
  • Notified body identity, if applicable
  • Date, place, and signature of the responsible party

The declaration must be drawn up in one of the official languages of the Member States where the system is placed on the market.

CE marking — placement and format

The CE marking must be affixed to the AI system before it is placed on the market. For physical systems, the marking goes on the product. For SaaS or software-only AI systems, the marking is displayed digitally — typically in the about screen, the instructions for use, or the product’s packaging documentation.

The marking must be visible, legible, and indelible. For digital displays, it must be present at every entry point or first interaction with the system.

Practical timeline before 2 December 2027

Backwards-plan from your launch date:

  • 6+ months before — start technical documentation (Annex IV); design risk-management system (Art. 9); design QMS (Art. 17)
  • 4–6 months before — complete data governance documentation (Art. 10); conduct internal evaluation; book notified body if Annex VII applies
  • 2–4 months before — internal conformity assessment OR notified-body review; finalise instructions for use
  • 1–2 months before — sign declaration of conformity; affix CE marking; register in EU database (Art. 49)
  • Day of — system goes live

If you’re targeting 2 December 2027, work backwards from that date and build in slack — most SMEs underestimate the lead time. Most SMEs underestimate the time required for Annex IV technical documentation — it’s a substantive engineering deliverable, not a marketing exercise.

How software helps

Maditon is built for the provider conformity assessment workflow. Each AI system carries its risk classification, its data governance record, its technical documentation evidence, its reviewer notes, its audit log — all in one place. The dossier export at any moment is the basis of the conformity assessment evidence package. The Article 49 registration tab tracks the EU database submission. The compliance checklist tracks the Article 9–15 obligations.