Conformity Assessment 

A conformity assessment is a formal process used to confirm that an AI system meets applicable regulatory requirements before entering the EU market or being put into service.

What Is a Conformity Assessment?

Under the EU AI Act, conformity assessments are particularly relevant to high-risk AI systems, with Article 43 setting out the assessment routes for systems covered by Annex III. Responsibility for an AI conformity assessment generally falls on the AI system provider, although other parties may take on these obligations if they place the system on the market under their own name or make substantial modifications. Depending on the system and circumstances, the process may be completed internally or involve an independent notified body. 

A conformity assessment is different from an AI risk assessment or Fundamental Rights Impact Assessment (FRIA), which focus on identifying and evaluating potential risks and impacts. Instead, it verifies that required measures have been implemented and documented, making it an important part of managing AI in compliance with regulatory requirements. The assessment may also need to be repeated when substantial changes are made to the AI system, making conformity an ongoing consideration throughout its lifecycle.

Internal Control vs. Third-Party Assessment

The EU AI Act provides different conformity assessment routes depending on the type of high-risk AI system and whether applicable harmonized standards or common specifications have been followed. Some assessments can be completed through internal control, while others require an independent conformity assessment body, designated as a notified body, to review the system and supporting documentation.

For certain biometric systems under Annex III, point 1, specific rules also apply when public authorities are involved. In specific cases involving law enforcement, immigration, asylum authorities, or EU institutions, the relevant market surveillance authority may perform the role of the notified body. A successful third-party assessment can result in an EU technical documentation assessment certificate.

Assessment routeHow it worksWhen it applies
Internal controlThe provider assesses and documents whether the AI system meets applicable EU AI Act requirements.Available for Annex III point 1 systems when applicable harmonized standards or common specifications have been followed.
Third-party assessmentA notified body reviews the provider’s quality management system and technical documentation.Required for certain Annex III point 1 systems when relevant standards or specifications are unavailable, not applied, or only partly applied.
Internal control for other Annex III systemsThe provider follows the Annex VI internal control procedure without notified-body involvement.Applies to Annex III points 2–8, including areas such as critical infrastructure, education, employment, essential services, law enforcement, migration, and justice.
EU AI Act assessment routes 

What Does a Conformity Assessment Cover?

A conformity assessment looks beyond the AI model itself to examine the systems, processes, documentation, and controls that support it. Organizations may conduct a gap analysis before the formal assessment to identify missing requirements and address potential compliance gaps. Here are the key areas a conformity assessment typically covers:

Technical documentation

Organizations need clear documentation describing the AI system’s intended purpose, design, development, capabilities, limitations, and performance. These records provide evidence of how the system works and how relevant requirements have been addressed.

Risk management

A documented risk management process should identify, assess, mitigate, and monitor potential risks throughout the AI lifecycle. This connects the conformity assessment with the organization’s broader AI risk management program.

Data governance

The assessment reviews how training, validation, and testing data is selected, managed, and maintained. Organizations should be able to demonstrate that appropriate data governance practices are in place to support the system’s intended purpose and performance.

Quality management

Organizations need processes for managing AI development, testing, documentation, compliance responsibilities, and ongoing monitoring. A structured quality management system helps establish clear processes, responsibilities, and oversight. 

Human oversight

High-risk AI systems must include appropriate measures for human oversight. The assessment considers whether people can effectively supervise the system, understand relevant outputs, intervene when necessary, and prevent or address harmful outcomes.

Accuracy, robustness, and cybersecurity

Organizations must demonstrate that the AI system meets appropriate levels of accuracy and performs reliably under expected conditions. The assessment also considers cybersecurity safeguards designed to protect the system against vulnerabilities, manipulation, and other security threats.

Post-market monitoring

Organizations need processes for monitoring AI system performance, identifying new risks or compliance issues, and taking corrective action when necessary. This includes reviewing relevant data and incidents over time to detect changes that could affect the system’s performance or compliance status.

AI-native GRC for how teams work today.

Scytale G2 badge

Documentation, CE Marking, and Ongoing Obligations

Completing a conformity assessment is not the final step in EU AI Act compliance. Once conformity has been established, the provider must complete the EU declaration of conformity and affix the CE marking to the high-risk AI system where applicable. Compliance must then be maintained throughout the AI system’s lifecycle, as substantial modifications may trigger a new assessment. Where a notified body is involved, certificates are generally valid for four years and may need to be renewed.

Organizations should determine their system’s EU AI Act risk category and applicable assessment route early, while also considering the updated compliance timeline for an EU AI Act conformity assessment. Under Regulation (EU) 2026/1744, the relevant high-risk AI requirements apply from:

  • December 2, 2027: High-risk AI systems classified under Article 6(2) and Annex III.
  • August 2, 2028: High-risk AI systems classified under Article 6(1) and Annex I.

How Scytale Helps with Conformity Assessment

Scytale helps organizations manage conformity assessment requirements as part of their wider AI governance and compliance program. Its AI GRC platform centralizes controls, evidence, risks, and documentation, helping teams identify gaps and prepare the records needed to demonstrate compliance before an internal or notified-body assessment.

Scytale also helps organizations manage overlapping AI requirements from one place, including the EU AI Act and frameworks such as ISO 42001 and NIST AI RMF. By continuously monitoring compliance activities, teams can reduce repetitive work, maintain clearer audit trails, and stay prepared as AI systems and regulatory requirements change.