Exemple de rapport de conformité
Un vrai rapport de conformité au règlement IA UE pour un système IA à haut risque Annexe III, anonymisé.
Most urgent
Per Article 43, complete the conformity assessment procedure which includes: (1) Assessment type - determine if internal assessment is allowed or if a notified body is required (Annex I systems or remote biometric identification require notified body); (2) Technical documentation review - review technical documentation to verify compliance with Articles 8-15; (3) Quality management system - verify QMS is implemented and operational (Article 17); (4) Testing - conduct or review testing and validation results; (5) Declaration - draw up EU Declaration of Conformity upon successful assessment. The assessment must be completed before placing the AI system on the market.Exposition aux sanctions
No Art 99 fine ceiling applies at this risk level
No Art 99 fine ceiling applies at this risk level
Not compliant
Indicative result only. Coverage: 66 of 113 EU AI Act articles. Not a regulatory conformity verdict.
96 finding(s) excluded from this code grade as document/process — INCLUDES HIGH/CRITICAL severity; see obligation_completeness for the real obligation coverage
158
Total des constatations
1
Critical
58
Élevé
37
Moyen
0
Low
62
Info
Yes
Blocking issues
12
Missing artefacts
Overdue 36d
Days to deadline
Compliance Officer View
By Article
Required Artefacts(12)
Other
Quality Management System - Article 16
Article 16
Post-Market Monitoring - Article 72
Article 72
Incident Reporting - Article 73
Article 73
Fundamental Rights Impact Assessment - Article 27
Article 27
Technical documentation - Annex IV completeness
Article 11
Data governance documentation required per Article 10 is missing.
Article 10
Logging documentation required per Article 12 is missing.
Article 12
Instructions for use required per Article 13 are missing.
Article 13
Human oversight documentation required per Article 14 is missing.
Article 14
Accuracy and robustness documentation required per Article 15 is missing.
Article 15
Incident reporting documentation required per Article 20 is missing.
Article 20
Transparency documentation required per Articles 50-52 is missing.
Article 50
Calendrier estimé
Minimum viable
57 days
Conformité totale
217 days
Roadmap
Immediate
30 days
Per Article 43, complete the conformity assessment procedure which includes: (1) Assessment type - determine if internal assessment is allowed or if a notified body is required (Annex I systems or remote biometric identification require notified body); (2) Technical documentation review - review technical documentation to verify compliance with Articles 8-15; (3) Quality management system - verify QMS is implemented and operational (Article 17); (4) Testing - conduct or review testing and validation results; (5) Declaration - draw up EU Declaration of Conformity upon successful assessment. The assessment must be completed before placing the AI system on the market.
Short-term
90 days
Create documentation_retention_policy per Article 18 of the EU AI Act.
Create fundamental_rights_assessment per Article 10 of the EU AI Act.
Create quality_management_system per Article 17 of the EU AI Act.
Per Article 10, create data governance documentation including: (1) Data sources - identify and document all data sources used for training, validation, and testing; (2) Training data - describe data collection, selection, and preparation processes, including data quality measures; (3) Validation data - document validation datasets and their representativeness; (4) Data quality - specify relevance, representativeness, accuracy, completeness, and bias mitigation measures; (5) Data management - describe data collection, labeling, storage, and retention procedures; (6) Privacy and data protection - document compliance with applicable data protection laws. Ensure documentation covers the entire data lifecycle and addresses potential biases.
Per Article 11 and Annex IV, create and maintain technical documentation that includes all 8 required sections: (1) General description - system identification, intended purpose, and version; (2) System design - architecture, components, and technical specifications; (3) Risk management - risk identification, analysis, evaluation, and mitigation (Article 9); (4) Data governance - data sources, training data, and data quality measures (Article 10); (5) Human oversight - human oversight measures and procedures (Article 14); (6) Accuracy, robustness, and cybersecurity - performance metrics, robustness testing, and cybersecurity measures (Article 15); (7) Testing and validation - test procedures, validation results, and performance metrics; (8) Instructions for use - user instructions, limitations, and intended use. Documentation must be kept up-to-date and made available to competent authorities upon request.
Per Article 11 and Annex IV, create technical documentation that includes: (1) General description - system identification, intended purpose, and AI system version; (2) System design - architecture, components, and technical specifications; (3) Risk management - risk identification, analysis, evaluation, and mitigation measures (Article 9); (4) Data governance - data sources, training data, and data quality measures (Article 10); (5) Human oversight - human oversight measures and procedures (Article 14); (6) Accuracy, robustness, and cybersecurity - performance metrics, robustness testing, and cybersecurity measures (Article 15); (7) Testing and validation - test procedures, validation results, and performance metrics; (8) Instructions for use - user instructions, limitations, and intended use. Documentation must be kept up-to-date and made available to competent authorities upon request.
Per Article 12, create logging documentation that includes: (1) Automatic logging - document that automatically generated logs are kept for at least 6 months, or longer if required by Union or national law; (2) Log retention - specify retention periods and procedures for log storage; (3) Audit trail - document audit trail capabilities and access controls; (4) Access controls - document who can access logs and under what circumstances. Logging must be automatic and cover all relevant system operations.
Per Article 14, create human oversight documentation including: (1) Oversight mechanisms - document how human oversight is implemented; (2) Human intervention capabilities - document when and how humans can intervene; (3) Override/stop procedures - document procedures for overriding or stopping AI system operations; (4) Training for human overseers - document training procedures for personnel responsible for oversight; (5) Interpretation guidance - document guidance for interpreting AI outputs. Human oversight must be effective and allow for intervention at any time.
Per Article 15, create accuracy and robustness documentation including: (1) Accuracy metrics - document accuracy levels and how they are measured; (2) Robustness testing - document robustness testing procedures and results; (3) Performance evaluation - document performance evaluation methods and criteria; (4) Cybersecurity measures - document cybersecurity measures implemented to ensure robustness. The system must achieve an appropriate level of accuracy, robustness, and cybersecurity appropriate to the intended purpose.
Per Article 16, establish a QMS that includes: (1) Compliance strategy; (2) Design/development procedures; (3) Testing procedures; (4) Data management; (5) Risk management integration; (6) Post-market monitoring; (7) Incident handling; (8) Communication with authorities.
Per Article 17, establish and document a data retention policy that ensures: (1) Log retention - automatically generated logs are kept for at least 6 months, or longer if required by Union or national law; (2) Documentation availability - all documentation required under the AI Act is kept and made available to market surveillance authorities upon request; (3) Retention period - documentation is retained for at least 10 years after the AI system is placed on the market or put into service; (4) Accessibility - documentation is organized and accessible within required timeframes. The retention policy must be documented and implemented as part of the quality management system.
Per Article 17, implement a quality management system (QMS) that includes: (1) Documented procedures - procedures for design, development, testing, validation, and deployment; (2) Risk management integration - integration with the risk management system (Article 9); (3) Data governance - procedures for data governance (Article 10); (4) Technical documentation - procedures for creating and maintaining technical documentation (Article 11); (5) Conformity assessment - procedures for conformity assessment and ongoing compliance; (6) Post-market monitoring - procedures for post-market monitoring (Article 72); (7) Corrective actions - procedures for corrective actions and incident reporting. The QMS must be documented, implemented, and maintained throughout the AI system lifecycle.
Per Article 18, establish documentation retention procedures that ensure: (1) Log retention - automatically generated logs are kept for at least 6 months, or longer if required by Union or national law; (2) Documentation availability - all documentation required under the AI Act is kept and made available to market surveillance authorities upon request; (3) Retention period - documentation is retained for at least 10 years after the AI system is placed on the market or put into service; (4) Accessibility - documentation is organized and accessible within required timeframes. The retention policy must be documented and implemented as part of the quality management system.
Per Article 20, create incident reporting documentation including: (1) Incident definition - define what constitutes a serious incident (death, serious injury, breach of fundamental rights, etc.); (2) Detection procedures - procedures to detect and identify serious incidents; (3) Reporting timeline - report incidents to competent authorities without undue delay, and immediately for critical incidents (within 15 days); (4) Report content - include all required elements: incident description, system identification, impact assessment, and mitigation measures; (5) Follow-up - procedures for investigating incidents and implementing corrective measures. The procedure must be documented and operational before placing the AI system on the market.
Per Article 27, conduct FRIA including: (1) Risk assessment of fundamental rights impacts; (2) Affected groups identification; (3) Mitigation measures; (4) Monitoring plan; (5) Stakeholder consultation; (6) Documentation. Required for deployers in employment, education, essential services, or law enforcement.
Per Article 47 and Annex V, create EU Declaration of Conformity including: (1) Provider identification; (2) System identification; (3) Intended purpose; (4) Conformity statement; (5) Applicable standards; (6) Notified body details (if applicable); (7) Signature and date.
Per Article 47 and Annex V, create an EU Declaration of Conformity that includes: (1) Provider identification - provider name and address; (2) System identification - AI system name, model, and version; (3) Intended purpose - description of the AI system's intended purpose; (4) Conformity statement - statement that the AI system conforms to the EU AI Act; (5) Applicable standards - list of harmonised standards or other technical specifications applied; (6) Notified body details - if applicable, notified body name and identification number; (7) Signature and date - signature of authorized representative and date. The declaration must be drawn up before placing the system on the market and kept for 10 years after the system is placed on the market.
Per Article 49, register the high-risk AI system in the EU database before placing it on the market. Registration must include: (1) Provider information - provider name and address; (2) System identification - AI system name, model, version, and serial number; (3) Intended purpose - description of the intended purpose; (4) Risk classification - confirmation that the system is classified as high-risk; (5) Conformity assessment - reference to the conformity assessment procedure used; (6) CE marking - confirmation that CE marking has been affixed. Registration is mandatory and must be completed before the system is placed on the market. The registration number must be included in the EU Declaration of Conformity.
Per Article 6, document classification assessment including: (1) Risk classification - determine if the AI system is high-risk based on Annex III categories: (a) biometric identification, (b) critical infrastructure, (c) education, (d) employment, (e) essential services, (f) law enforcement, (g) migration/border control, (h) justice/democratic processes; (2) Classification methodology - document the methodology used to classify the system; (3) Classification result - document whether the system is classified as high-risk and the rationale; (4) Review procedures - document procedures for reviewing and updating classification as system evolves. Classification must be performed before placing the system on the market.
Per Article 72, establish PMM system including: (1) Monitoring plan; (2) Performance metrics tracking; (3) Incident tracking; (4) User feedback collection; (5) Update procedures; (6) Corrective action procedures.
Per Article 72, implement a post-market monitoring (PMM) system that includes: (1) Monitoring plan - establish a plan to systematically collect and analyze data on AI system performance; (2) Data collection - collect data on system performance, incidents, and user feedback; (3) Analysis - analyze collected data to identify potential risks or non-compliance; (4) Reporting - report findings to competent authorities as required; (5) Corrective actions - implement corrective actions when issues are identified; (6) Documentation - maintain records of all PMM activities. The PMM system must be active throughout the AI system lifecycle and integrated with the quality management system.
Per Article 73, establish incident reporting procedures that include: (1) Incident definition - define what constitutes a serious incident (death, serious injury, breach of fundamental rights, etc.); (2) Detection procedures - procedures to detect and identify serious incidents; (3) Reporting timeline - report incidents to competent authorities without undue delay, and immediately for critical incidents (within 15 days); (4) Report content - include all required elements: incident description, system identification, impact assessment, and mitigation measures; (5) Follow-up - procedures for investigating incidents and implementing corrective measures. The procedure must be documented and operational before placing the AI system on the market.
Per Articles 48-49, affix the CE marking so that it is: (1) Visible - clearly visible on the AI system or its packaging; (2) Legible - easily readable and indelible; (3) Accessible - accessible to users and competent authorities; (4) Compliant - in the form specified in Annex VI. The CE marking indicates that the AI system conforms to the EU AI Act. It must be affixed before placing the system on the market. If the marking cannot be affixed to the system itself, it must be affixed to the packaging or accompanying documentation.
Medium-term
Move the document into the expected 'docs/' directory so the scanner and auditors can locate the document of record for this obligation.
Per Article 13, create instructions for use that accompany the high-risk AI system, including: (1) Provider identity; (2) Intended purpose and conditions of use; (3) Characteristics, capabilities, and limitations of performance; (4) Human oversight measures; (5) Expected lifetime and maintenance measures.
Per Articles 50-52, create transparency documentation including: (1) User notification - document how users are notified that they are interacting with an AI system; (2) Disclosure requirements - document what information is disclosed to users; (3) Transparency measures - document measures taken to ensure transparency and explainability. For limited-risk AI systems, users must be informed that they are interacting with an AI system. For high-risk systems, additional transparency requirements apply.
Long-term
Rename the document to the canonical filename 'classification_assessment' (with an appropriate extension) so it is unambiguously identified as the document of record for this obligation.
By Category
Documentation Completeness
Engineer View
Code Findings (by file)
Missing Patterns
Obligations sans code d'implémentation trouvé — lacunes de couverture, et non infractions à une ligne précise.
Exemple de dossiers générés
Il s'agit des documents de conformité réellement générés par Scanara pour ce système IA, pas de maquettes.