Free Download
AI Compliance & Governance

EU AI Act
High-Risk AI Readiness Checklist

EU Regulation 2024/1689 | Articles 5, 9–15, 43, 49, 53–55, 72 | High-Risk & GPAI Systems
Organisation
Organisation Name
Document Reference
XXX
Assessment Date
2026
Lead Assessor
Regulation Version
EU 2024/1689 (AI Act)
System / Use Case
AI System Description
Role (Provider / Deployer)
Provider / Deployer
Report Status
Draft: In Review
This checklist covers prohibited AI practices (Article 5), high-risk scope screening (Annex III), the eight mandatory conformity obligations for high-risk AI systems (Articles 9–15), conformity assessment and registration requirements (Articles 43, 49), GPAI model compliance (Articles 53–55), and post-market monitoring (Article 72). The August 2026 enforcement deadline applies to high-risk AI systems listed in Annex III. Click any status badge to cycle through YES / PARTIAL / NO / N/A. Evidence and Notes columns are editable in-browser. Use Ctrl+P to print or save as PDF.
Important Notice: Guidance Document Only This document is prepared by Cyvra as an internal working tool to support AI compliance readiness activities. It is a structured guidance aid, not an official regulatory instrument, and does not constitute legal, regulatory, or professional advice. Cyvra is not a conformity assessment body, notified body, accreditation authority, or regulator. Completing or scoring this checklist does not constitute a CE marking, conformity declaration, official audit sign-off, or confirmation of regulatory compliance under EU Regulation 2024/1689. The content reflects Cyvra’s interpretation of publicly available regulatory requirements at the time of preparation. Organisations must seek independent legal and regulatory advice appropriate to their specific circumstances.
EU AI Act Readiness Checklist: Scope Assessment
Page 2 of 5

Section 1: Prohibited AI Practices (Article 5)

8 items — if any apply, system is prohibited
These uses are banned under the EU AI Act regardless of risk level. If your system falls into any category, it cannot be deployed in the EU. Mark YES if the practice applies to your system.
Art. RefProhibited PracticeApplies?Evidence / ReferenceNotes
Art. 5(1)(a)Subliminal or manipulative AI
› Uses techniques beyond conscious awareness to materially distort behaviour
› Exploits psychological weaknesses to cause harm to that person or others
Art. 5(1)(b)Exploiting vulnerabilities of specific groups
› Targets age, disability, or socio-economic situation to distort behaviour
› Causes or is likely to cause significant harm to those persons or others
Art. 5(1)(c)Social scoring by public authorities
› Evaluates or classifies people based on social behaviour or personal characteristics
› Leads to detrimental treatment in unrelated contexts or disproportionate harm
Art. 5(1)(d)Criminal risk assessment solely by profiling
› Predicts or assesses risk of a natural person committing a criminal offence based solely on profiling or personality traits
› Exception: AI systems used to support human assessment based on objective, verifiable facts
Art. 5(1)(e)Untargeted facial image scraping for recognition databases
› Scrapes facial images from the internet or CCTV footage to create or expand databases
› Applies regardless of whether images are subsequently used for law enforcement purposes
Art. 5(1)(f)Emotion recognition in workplace or educational institutions
› Infers emotions of natural persons in those settings
› Exception: safety purposes or medical and research use only
Art. 5(1)(g)Biometric categorisation by sensitive characteristics
› Categorises individuals to infer race, political opinions, religion, sex life, or sexual orientation from biometric data
› Exception: lawfully collected biometrics for law enforcement labelling or filtering
Art. 5(1)(h)Real-time remote biometric ID in public spaces (law enforcement)
› No Article 5(2) exemption applies (targeted search, preventing imminent threat, prosecuting serious crime)
› Exemptions require prior judicial or independent administrative authorisation

Section 2: High-Risk Scope Check (Annex III)

8 categories — if any apply, full obligations apply
Annex III lists eight categories of high-risk AI systems subject to the full conformity obligations in Pages 3–5. Mark YES if your system falls within any category. If none apply, you are subject only to general transparency obligations (Art. 50).
CategoryHigh-Risk Use Case (Annex III)In Scope?System DescriptionNotes
1. BiometricsBiometric identification or categorisation
› Remote biometric identification; biometric categorisation; emotion recognition (safety/medical exceptions apply)
2. InfrastructureCritical infrastructure management
› Safety components of: road transport, water, gas, heating, electricity, digital infrastructure
3. EducationEducational and vocational training
› Determines access/admission; evaluates learning outcomes; detects prohibited student behaviour
4. EmploymentEmployment, HR, and worker management
› Recruitment/CV screening; promotion; task allocation; performance monitoring; termination decisions
5. ServicesEssential private and public services
› Credit scoring; life/health insurance risk; emergency services dispatch; social benefits eligibility
6. Law enforcementLaw enforcement uses
› Assessing risk of offending; polygraph-type tools; crime analytics; evidence reliability assessment
7. MigrationMigration, asylum, and border control
› Verifying document authenticity; risk assessment; processing asylum or visa applications
8. Justice/DemocracyAdministration of justice and democratic processes
› Assists judicial authorities in researching or applying law; influences elections or voting
If in scope: Complete Pages 3–5 (Articles 9–15, 43, 49). Register in EU AI Act database before 2 August 2026. If out of scope: General transparency obligations (Article 50) may still apply to chatbots and deepfake-generating systems.
EU AI Act Readiness Checklist: Risk Management, Data Governance & Technical Documentation
Page 3 of 5
Click any status badge to cycle: YES (compliant) → PARTIAL (in progress) → NO (gap) → N/A (not applicable) → reset. Evidence and Notes fields are editable. These obligations apply primarily to providers of high-risk AI systems.
RefObligationStatusEvidence / ReferenceNotes
Section 3: Risk Management System (Article 9)
9.1Risk management system established and documented
› Continuous iterative process covering the entire system lifecycle
› Updated regularly and each time the system is substantially modified
9.2Known and reasonably foreseeable risks identified
› Risks to health, safety, and fundamental rights assessed for each lifecycle phase
› Includes risks from foreseeable misuse and reasonably foreseeable adverse impacts
9.3Risk estimation and evaluation conducted
› Risks evaluated for intended purpose and foreseeable misuse scenarios
› Post-market data feeds back into ongoing risk evaluation
9.4Risk mitigation and control measures adopted
› Design and development measures applied first; then training, information, instructions
› Technical measures include explainability features, accuracy thresholds, fallback options
9.5Residual risks communicated and judged acceptable
› Residual risks documented and communicated to deployers in instructions for use
› Judged acceptable when weighed against benefits of the intended purpose
9.6System testing for risk conducted before market placement
› Testing against pre-defined metrics and probability thresholds
› Test results documented in technical documentation (Annex IV)
9.7Special consideration for vulnerable groups
› Children and persons with disabilities considered where use foreseeable involves them
› Additional safeguards documented where applicable
Section 4: Data and Data Governance (Article 10)
10.1Data governance practices established
› Covers training, validation, and testing datasets
› Examines design choices, data collection, labelling, and storage
10.2Data relevance, representativeness, and accuracy assessed
› Training data relevant, sufficiently representative, and complete for intended purpose
› Known data gaps and shortcomings identified and documented
10.3Statistical properties of datasets documented
› Characteristics and distributions documented at individual and aggregate level
› Applied across all three dataset splits (train / validation / test)
10.4Bias detection and correction measures in place
› Biases that may affect fundamental rights or produce discriminatory outcomes identified
› Appropriate measures to detect and correct bias implemented and documented
10.5Special category personal data handled appropriately
› Art. 9 GDPR categories used only where strictly necessary for bias detection (Art. 10(5))
› Appropriate safeguards documented; DPA or legal basis confirmed
10.6Third-party and synthetic data sources assessed
› Provenance of all data sources documented
› Synthetic data generation methods and quality controls documented where used
10.7Pre-processing and labelling procedures documented
› Annotation guidelines and labelling processes described
› Quality assurance on labelling applied and evidenced
10.8Validation and testing datasets separate from training data
› Distinct validation set used for tuning; separate test set for final evaluation
› Test set reflects real-world deployment distribution
Section 5: Technical Documentation (Article 11 & Annex IV)
Annex IV specifies minimum content. Documentation must be maintained for 10 years after the system is placed on the market or put into service.
11.1General description of AI system prepared
› Intended purpose, persons responsible, version information
› Interactions with other hardware or software if applicable
11.2Design and development process documented
› General logic, algorithms, key design choices
› Architecture and computational infrastructure described
11.3Training methodology and techniques documented
› Training process, techniques, parameters, and hyperparameter settings
› Optimisation methods and loss functions described
11.4Validation and testing results documented
› Protocols, procedures, and results for validation and testing
› Test environments and conditions described
11.5Performance metrics established and documented
› Accuracy, robustness, and cybersecurity metrics specified
› Benchmark results and minimum thresholds documented
11.6Known limitations and foreseeable misuse documented
› Limitations of the system identified and communicated
› Foreseeable misuse scenarios considered and mitigated or documented
11.7Instructions for use (IFU) for deployers prepared
› Provider identity, intended purpose, performance metrics, maintenance requirements
› Human oversight measures and operator competence requirements specified
11.8Post-market monitoring plan included in documentation
› Describes how performance will be monitored after deployment
› Includes data collection mechanisms and reporting triggers
11.9Substantial modifications tracked and re-documented
› Version control system maintained for all changes to the system
› Substantial modifications trigger a new conformity assessment
EU AI Act Readiness Checklist: Record-Keeping, Transparency, Human Oversight & Technical Performance
Page 4 of 5
RefObligationStatusEvidence / ReferenceNotes
Section 6: Record-Keeping and Logging (Article 12)
12.1Automatic logging capabilities built into the system
› System automatically records events throughout its operational lifetime
› Logging is commensurate with the intended purpose of the system
12.2Logs capture sufficient detail to identify risks
› Events that could constitute a risk or lead to a substantial modification are captured
› Facilitates post-market monitoring and investigation of serious incidents
12.3Log retention periods established and documented
› Retained for minimum period set in technical documentation
› For biometric systems: minimum 6 months unless otherwise required by law
12.4Log access controls and integrity protection implemented
› Access restricted to authorised persons; deployers have access they need for their obligations
› Logs cannot be altered or deleted by unauthorised parties
12.5Deployers have access to relevant logs (Art. 12(3))
› Deployers can retrieve logs necessary to meet their own Article 26 obligations
› Log access mechanism documented in instructions for use
Section 7: Transparency and Information (Article 13)
13.1System designed to enable deployer understanding
› Sufficient transparency to enable deployers to interpret outputs and use them appropriately
› Explainability features built in where technically feasible
13.2Instructions for use provided to deployers
› Provider identity; intended purpose; performance level and accuracy metrics
› Circumstances where system may fail or produce errors; maintenance requirements
13.3Capabilities, limitations, and known risks communicated
› Technical capabilities, accuracy thresholds, and performance limitations stated
› Circumstances under which the system should not be used specified
13.4Hardware and IT environment requirements specified
› Characteristics of required input data described where relevant
› Technical infrastructure, computing, and network requirements specified
13.5AI identity disclosed to end users where required (Art. 50)
› Chatbots, emotion recognition, and deepfake systems disclose AI nature to users
› Applies regardless of high-risk classification when Article 50 is triggered
Section 8: Human Oversight (Article 14)
14.1Human-machine interface suitable for oversight built in
› Measures enable natural persons to understand capabilities and limitations
› Interface designed to prevent automation bias and over-reliance on outputs
14.2Operators can detect anomalies, biases, and failures
› Outputs are interpretable and anomalies surfaced to operators
› Confidence indicators or uncertainty measures provided where appropriate
14.3Override / stop mechanism exists for operators
› Operators can interrupt, override, or stop the system in real time
› Automatic safe state capability built in where technically feasible
14.4Operator training and competency requirements defined
› IFU specifies human oversight competence and technical knowledge requirements
› Training materials or qualifications for oversight roles specified
14.5Human review of high-impact decisions mandated
› For decisions with significant individual effect, human review required before effect taken
› Particularly required in employment, credit, and public services contexts
14.6Oversight roles and escalation procedures assigned
› Named individuals or roles assigned responsibility for human oversight
› Escalation procedures for edge cases and out-of-distribution inputs documented
Section 9: Accuracy, Robustness & Cybersecurity (Article 15)
15.1Accuracy levels established, documented, and achieved
› Accuracy metrics appropriate to intended purpose defined and tested
› Level communicated in IFU and on EU AI database entry
15.2System robust against errors, faults, and inconsistencies
› Resilience to errors and faults during operation demonstrated through testing
› Fallback plan or safe state activated on system failure
15.3Cybersecurity measures proportionate to risk implemented
› Protection against adversarial manipulation, data poisoning, and model inversion attacks
› Security by design applied throughout the development lifecycle
15.4Adversarial robustness assessed and documented
› Adversarial robustness testing conducted
› Known vulnerabilities documented and mitigated
15.5Performance consistent across demographic groups
› Accuracy validated across sub-populations and demographic groups
› Disparate performance identified and mitigated or documented
EU AI Act Readiness Checklist: Conformity Assessment, GPAI Compliance & Post-Market Monitoring
Page 5 of 5
RefObligationStatusEvidence / ReferenceNotes
Section 10: Conformity Assessment & Registration (Articles 43, 49)
Most Annex III systems use self-assessment (Art. 43(2)). Systems involving remote biometric identification require a notified body (Art. 43(1) + Annex VII).
43.1Conformity assessment route identified
› Self-assessment (Art. 43(2)) or notified body assessment (Art. 43(1)) confirmed as applicable
› Notified body required for remote biometric ID and real-time biometric ID in public spaces
43.2Internal control procedure completed (Annex VI)
› Provider checks system against all requirements of Articles 9–15
› Documented procedure on file before market placement
43.3EU declaration of conformity (DoC) signed
› Contains Annex V information: provider, system description, applicable standards
› Signed by authorised person; retained for 10 years from market placement
43.4CE marking affixed where required
› Applied before market placement for systems that require it
› If embedded in a product, sectoral CE marking rules also apply
49.1System registered in EU AI database before market placement
› Registration at ai-prd.ec.europa.eu required before 2 August 2026
› Includes system name, intended purpose, performance metrics, conformity status
49.2Technical documentation retained for 10 years
› All documentation kept from date of market placement for minimum 10 years
› Available to market surveillance authorities and AI Office on request
Section 11: Post-Market Monitoring (Article 72)
72.1Post-market monitoring plan established and active
› Plan proportionate to nature and risk of the system
› Data collected on real-world performance throughout the system lifetime
72.2Serious incidents reported to market surveillance authority
› Reported within 15 days (or 72 hours for critical or widespread risks)
› Near-misses that could have caused a serious incident are also reportable
72.3Malfunctions communicated to deployers and importers
› Providers inform deployers of malfunctions affecting safety or performance
› Corrective action procedures defined and communicated
72.4Market withdrawal and corrective action process established
› Process to withdraw, disable, or recall system if non-conformity identified
› Communication plan to notify affected deployers and authorities
Section 12: General-Purpose AI Model Compliance (Articles 53–55)
Articles 53–55 apply to providers of GPAI models (foundation models, LLMs) made available in the EU. Additional obligations apply if the model poses systemic risk (cumulative training compute >10²⁵ FLOPs or AI Office designation).
53.1Technical documentation for GPAI model prepared (Annex XI/XII)
› Training data, compute used, architecture, capabilities, limitations, evaluation results
› Kept up to date; available to AI Office and national authorities on request
53.2Copyright compliance policy implemented
› Policy to respect EU copyright law in place (Art. 53(1)(c))
› Summary of training data published publicly (Art. 53(1)(d))
53.3Sufficient information provided to downstream providers
› Downstream providers integrating GPAI receive information on capabilities, limitations, safeguards
› Enables downstream providers to meet their own AI Act obligations
Systemic Risk GPAI only (Art. 55) — applies if compute >10²⁵ FLOPs or designated by AI Office
55.1Adversarial testing (red-teaming) conducted
› Model evaluated for serious risks identified in AI Office guidelines
› Results documented and reported to AI Office in annual report
55.2Serious incident reporting to AI Office established
› Incidents related to systemic risks reported to AI Office without undue delay
› Cybersecurity measures adequate for identified risks implemented (Art. 55(1)(d))
Overall Compliance Summary
YES
PARTIAL
GAP
N/A
0%