DEV Community

Char-Z AI
Char-Z AI

Posted on Originally published at charz.ai AI-assisted

Conformity Assessment: What It Is and Do You Need One?

What Is an EU AI Act Conformity Assessment?

A conformity assessment under the EU AI Act is the formal process by which providers demonstrate that a high-risk AI system meets all applicable requirements before placing it on the European market (European Commission, 2024). It is analogous to the CE marking process for physical products — the AI system cannot be legally sold in the EU without completed conformity assessment and a declaration of conformity.

The assessment verifies that the system satisfies requirements across eight categories: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, and cybersecurity. Assessments must be completed for each high-risk AI system individually before it is placed on the market.

Do You Need a Conformity Assessment?

The requirement applies to high-risk AI systems under the EU AI Act. To determine whether conformity assessment is required, evaluate your systems against the Annex III categories (and Annex I product components) as set out in the Act.

  • Biometric identification — conformity assessment Required (Annex III) — route: third-party notified body.

  • Critical infrastructure AI — Required (Annex III) — route: third-party notified body.

  • Education and vocational AI — Required (Annex III) — route: third-party notified body.

  • Employment and worker management AI — Required (Annex III) — route: third-party notified body.

  • Access to essential services AI — Required (Annex III) — route: third-party notified body.

  • Law enforcement AI — Required (Annex III) — route: third-party notified body.

  • Migration and border control AI — Required (Annex III) — route: third-party notified body.

  • Justice and democratic processes AI — Required (Annex III) — route: third-party notified body.

  • Safety component of regulated products (Annex I) — Required — route: product-specific notified body.

  • Limited-risk AI systems — No — route: self-assessment only.

  • Minimal-risk AI systems — No — route: no assessment required.

Internal vs Third-Party Assessment

The AI Act provides two assessment routes depending on system type:

Internal conformity assessment

Providers conduct the assessment themselves. This route is available for high-risk AI systems that are not listed in Annex III and do not involve safety components of regulated products. The provider must maintain technical documentation, implement a quality management system, and prepare a declaration of conformity (European Commission, 2024).

Third-party conformity assessment

Required for Annex III high-risk systems. An accredited notified body reviews the system's technical documentation, tests compliance with specific requirements, and issues a certificate of conformity. The notified body assessment is mandatory for systems in biometric identification, critical infrastructure, law enforcement, and justice domains (European Commission, 2024).

Conformity Assessment Process

The conformity assessment process follows a structured sequence:

Step 1: System classification

Confirm that the AI system qualifies as high-risk under Annex III or Annex I. If uncertain, consult the AI Office's classification guidance or seek a preliminary opinion from a notified body.

Step 2: Requirements mapping

Identify all applicable requirements from Articles 8-15 of the AI Act. Requirements cover risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, and cybersecurity. Map each requirement to specific evidence in your system documentation (European Commission, 2024).

Step 3: Gap analysis

Compare current system documentation and controls against the mapped requirements. Identify gaps and implement corrective measures. In practice, initial gap analyses typically find a meaningful share of requirements only partially addressed.

Step 4: Documentation preparation

Compile the technical documentation required under Article 11. Documentation must be detailed enough for a notified body to assess compliance without additional information from the provider (European Commission, 2024).

Step 5: Declaration of conformity

Prepare the declaration of conformity under Article 47. The declaration identifies the provider, the AI system, the applicable requirements, and the conformity assessment route. It must be signed by an authorized representative of the provider (European Commission, 2024).

Step 6: CE marking and market placement

Apply the CE marking to the AI system or its documentation. The system may then be placed on the EU market subject to ongoing monitoring obligations (European Commission, 2024).

Technical Documentation Requirements

  • Article 11 of the AI Act specifies the minimum technical documentation requirements for high-risk AI systems:

  • System description: intended purpose, provider identity, version history.

  • Design specifications: architecture, development methodology, hardware requirements.

  • Training data: sources, scope, characteristics, known limitations.

  • Performance metrics: accuracy, robustness, cybersecurity benchmarks.

  • Risk management: known risks, mitigation measures, residual risk assessment.

  • Testing methodology: validation procedures, test data, results analysis.

  • Human oversight: design measures for human intervention and override.

  • Cybersecurity measures: protections against manipulation, data poisoning, adversarial attacks.

Timeline and Deadlines

The conformity assessment timeline is tied to the EU AI Act's phased enforcement schedule:

  • GPAI transparency obligations — August 2, 2026: first enforcement date — no conformity assessment required for GPAI.

  • High-risk transition (Annex III) — December 2, 2027: conformity assessment required for all new Annex III high-risk systems — moved back from August 2, 2026 by the Digital Omnibus on AI (Regulation (EU) 2026/1744).

  • High-risk transition (Annex I) — August 2, 2028: conformity assessment required for AI safety components in regulated products under Annex I product-safety law.

  • Public-sector deployments — August 2, 2030: high-risk systems deployed by public authorities must have completed conformity assessment.

Costs and Preparation

The cost of conformity assessment varies significantly based on system complexity and assessment route:

  • Internal self-assessment: €15,000–€50,000 — typical timeline 2–4 months.

  • Third-party notified body (simple system): €50,000–€150,000 — 4–8 months.

  • Third-party notified body (complex system): €150,000–€500,000 — 8–14 months.

  • Ongoing annual compliance maintenance: €20,000–€100,000 — continuous.

Organizations that begin conformity assessment preparation well before the deadline — rather than starting only months out — are significantly more likely to achieve compliance on time. Early start also leaves room for the inevitable back-and-forth with notified bodies.

Frequently Asked Questions

Can I use an internal assessment for all high-risk systems?

No. Annex III high-risk systems — including biometric identification, critical infrastructure, law enforcement, and justice applications — require third-party assessment by an accredited notified body. Internal assessment is available only for high-risk systems outside Annex III, such as those that are safety components of regulated products not listed in Annex III (European Commission, 2024).

How long does a notified body assessment take?

The AI Act specifies that notified bodies must complete their assessment within defined timeframes, typically 3-6 months from application. However, the actual timeline depends on the complexity of the system, the completeness of documentation submitted, and the notified body's current workload.

What happens if my system fails the conformity assessment?

If a notified body determines that a system does not meet requirements, it issues a non-conformity report specifying the deficiencies. The provider must address the deficiencies and resubmit for assessment. During the remediation period, the system cannot be placed on the EU market. If the non-conformity poses an immediate risk to health, safety, or fundamental rights, the AI Office may issue a corrective action order (European Commission, 2024).

Do I need separate conformity assessments for each AI system?

Yes. The AI Act requires conformity assessment for each high-risk AI system individually. If your organization deploys multiple high-risk systems, each must undergo its own assessment. Shared components (e.g., a common model architecture) may be assessed once, but each deployment context requires separate evaluation (European Commission, 2024).

Sources

European Commission. (2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council. Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2024/1689

Top comments (0)