Skip to main content

Conformity Assessment — EU AI Act Article 43

Complete guide to EU AI Act conformity assessments. When to use Annex VI vs Annex VII, when a notified body is required, and how to generate a Declaration of Conformity.

A conformity assessment is the mandatory procedure under EU AI Act Article 43 through which high-risk AI providers demonstrate their system meets the Act's requirements before placing it on the EU market. Most providers follow Annex VI (internal control) independently. A notified body (Annex VII) is required only for certain biometric systems. Successful completion results in a Declaration of Conformity and the right to affix the CE marking. Enforcement begins August 2, 2026.

Annex VI vs Annex VII: Which Path Applies?

Annex VI — Internal Control

The default path for most high-risk AI systems. The provider conducts the assessment internally — no external body involvement required. You must demonstrate compliance against Articles 9–15, 17, and maintain a complete Annex IV technical file.

  • All Annex III categories except remote biometric ID
  • Provider performs assessment independently
  • No notified body engagement or fees
  • Technical file retained for 10 years post-market

Annex VII — Notified Body Assessment

Required when a high-risk AI system is intended for use in real-time remote biometric identification in publicly accessible spaces by law enforcement (Article 43(1)(b)). An accredited notified body must conduct a third-party review of the technical file and quality management system.

  • !Remote biometric ID in public spaces (law enforcement)
  • !Accredited notified body engagement required
  • !Third-party review of technical file and QMS
  • !EU type-examination certificate issued

6-Step Conformity Assessment Process (Annex VI)

1

Confirm High-Risk Classification

Verify the AI system falls within one or more Annex III categories or is a safety component of an Annex I regulated product. Document the classification rationale in your Annex IV technical file.

2

Compile the Annex IV Technical File

Prepare all 10 elements of the Annex IV technical documentation: system description, design specifications, training data documentation, risk management records, testing results, monitoring plan, instructions for use, and post-market plan.

3

Implement Quality Management System (Art 17)

Establish documented procedures for data management, design and development, testing, conformity assessment, risk management, and post-market monitoring. The QMS is a prerequisite for a valid conformity assessment.

4

Conduct Article 9 AIRA and Article 10 Data Governance Review

Complete your AI Risk Assessment and document training dataset governance, including bias mitigation measures. These are evidenced in the technical file reviewed during assessment.

5

Perform Internal Conformity Review

Review your technical file against every applicable article (9–15, 17, 72) and confirm all requirements are met. Identify and close any gaps. The review must be performed by personnel with appropriate technical expertise.

6

Issue Declaration of Conformity and Affix CE Marking

Sign the EU Declaration of Conformity under Article 47 and register the system in the EU AI Act database (Article 49). Affix the CE marking to the AI system and its documentation, authorising EU market placement.

Declaration of Conformity

Under Article 47, the EU Declaration of Conformity must include: the AI system name and version, provider details, a statement that the system complies with Regulation (EU) 2024/1689, references to any harmonised standards applied, notified body details (if applicable), date of issue, and an authorised signatory. The declaration must be kept for 10 years after the system is placed on the market.

For AI systems embedded in products already regulated under other CE marking directives (Annex I — e.g. medical devices, machinery), the conformity assessment follows the applicable sectoral legislation, with the EU AI Act requirements incorporated into that process.

How Scanara Accelerates Conformity Assessment

Automated Annex IV generation

Scanara generates the complete 10-element Annex IV technical documentation from your scan results — ready for internal review or notified body submission.

Gap analysis against all articles

A compliance scan maps your codebase against Articles 9–15 and 17, surfacing every gap before your internal conformity review, with article-precise findings.

QMS evidence collection

Automated CI/CD scan logs, finding histories, and remediation records feed your Article 17 QMS documentation with continuous, timestamped evidence.

See Scanara conformity assessment automation →

Frequently Asked Questions


How Scanara Helps

Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.