Classifying a system as high-risk under Annex III tells you obligations apply. Conformity assessment is the process that proves you’ve met them before the system goes to market — the AI Act equivalent of the CE-marking process already familiar from EU product-safety law. It’s also one of the least understood steps in the compliance chain, because most guidance stops at “you need a conformity assessment” without explaining which route applies or what actually happens during one.

Two Routes, and How the Choice Gets Made

Article 43 sets out two conformity assessment procedures for high-risk systems:

Route A — Internal control (Annex VI). The provider self-assesses. This is the default route for most high-risk categories, provided the system was developed using harmonised standards or Commission common specifications where they exist.

Route B — Notified body assessment (Annex VII). An accredited third-party notified body assesses the provider’s quality management system and technical documentation. This route is mandatory for the specific Annex III category covering biometric identification systems, and becomes mandatory more broadly whenever harmonised standards or common specifications don’t exist (or the provider hasn’t applied them) for the system in question.

For most mid-market SaaS and internal tooling — HR screening, credit-risk scoring, workforce management — internal control (Route A) is the applicable path once the relevant harmonised standards are published. That’s part of why the Digital Omnibus deferred the high-risk application date: the CEN/CENELEC harmonised standards that Route A depends on aren’t finalized yet, so providers can’t yet demonstrate compliance against a standard that doesn’t exist.

What Internal Control (Route A) Actually Involves

Per Annex VI, the provider must:

  1. Verify the quality management system complies with Article 17 — this covers your documented processes for design control, data governance, risk management, and post-market monitoring, not just the AI system itself.
  2. Examine the technical documentation to confirm the system meets the essential requirements in Chapter III, Section 2 (risk management, data governance, technical robustness, human oversight, and the rest of the high-risk requirement set).
  3. Verify that the design, development, and post-market monitoring process (Article 72) is actually consistent with what the technical documentation claims — not just that the documentation exists, but that it accurately reflects what was built.

In practice, this means your Annex IV documentation isn’t a separate deliverable from the conformity assessment — it’s the primary evidence the assessment is checked against. Get the documentation right first, and the internal-control assessment becomes a verification exercise rather than a scramble.

What Notified Body Assessment (Route B) Adds

When Route B applies, an accredited notified body reviews both your quality management system and your technical documentation independently, rather than relying on your own internal sign-off. This route takes longer, costs more, and requires selecting and engaging an accredited body — but Article 62(2) specifically requires that SME providers’ interests be taken into account when notified bodies set their fees, with fees reduced proportionately to the provider’s size and market position. If you expect to need Route B, it’s worth confirming your SME status is documented, since the fee reduction isn’t automatic — it has to be claimed against the provider’s actual size and market indicators.

After Assessment: CE Marking and EU Database Registration

Passing conformity assessment isn’t the final step. Two things follow:

  • CE marking. The system is affixed with the CE mark, signaling conformity with the Act’s requirements — the same visual signal used across other EU product-safety regulation, now extended to high-risk AI.
  • EU database registration. Before placing the system on the market, providers of most high-risk systems must register in the EU-wide database maintained under the Act, making key information about the system publicly searchable. (A narrower registration obligation also applies to deployers who are public authorities.)

Skipping either step after a successful internal assessment is itself a compliance gap — conformity assessment, CE marking, and database registration are three separate, sequential requirements, not one bundled event.

Substantial Modification Resets the Clock

A high-risk system that undergoes a substantial modification — a change to its intended purpose or a modification that affects compliance with the essential requirements — is treated as a new product for conformity assessment purposes. This is a common blind spot for AI systems specifically, because model updates, retraining on new data, and configuration changes happen far more frequently than they would for a traditional physical product. A system that passed assessment at launch can fall out of conformity through an update that never gets checked against the essential requirements again — which is exactly what ongoing post-market monitoring is designed to catch.

Building This Into Your Compliance Plan

The practical sequence, in order:

  1. Confirm the system is high-risk under Annex III and identify your role as provider or deployer.
  2. Build Annex IV technical documentation as the primary evidence base — not as an afterthought to the assessment.
  3. Determine your route (internal control vs. notified body) based on the specific Annex III category and standards status.
  4. Complete the assessment, apply CE marking, and register in the EU database.
  5. Monitor for substantial modifications that would require reassessment.

Aikraft’s documentation generator is built to produce Annex IV-aligned records from your system inventory, so the technical documentation your conformity assessment depends on is current before you need it — see how it works or start free.