Annex IV §3 (oversight)

Annex IV — Human Oversight Documentation (EU AI Act)

How to document human oversight measures in the EU AI Act technical file. Operator profile, training, authority, override monitoring, and the link to Article 14.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review

What the oversight paragraphs require

Annex IV §3 requires documentation of the human oversight measures built into the system in line with Article 14. These measures must enable the four oversight outcomes in Article 14(4): understand capabilities and limits; remain aware of automation bias; correctly interpret outputs; and decide not to use, override, or stop the system.

What to include

A defensible §3 oversight subsection contains:

  • Operator profile. Job title, qualifications, hours-per-week dedicated, reporting line.
  • UI walkthrough. What the operator sees, what controls they have, where the stop button lives.
  • Interpretation tools. Confidence scores, calibration curves, attention maps, SHAP values, "out-of-distribution" warnings.
  • Automation-bias mitigations. Forced-disagreement prompts, A/B switches, periodic recalibration.
  • Stop-control specification. Where in the UI, who can reach it, what happens when invoked.
  • Two-person rule for Annex III §1 biometric law-enforcement systems under Article 14(5).
  • Operator training requirements that the Article 13 instructions for use communicate to deployers.
  • Override-rate monitoring — what is logged, how it is monitored, what thresholds trigger re-validation.

The deployer-side implementation belongs to Article 26(2) and the Article 27 FRIA (where applicable). The Annex IV §3 section documents the provider design — the substrate the deployer operates on top of.

Inline crosswalk

  • ISO/IEC 42001:2023 Annex A.9.2 — Human oversight of AI systems.
  • NIST AI RMF GOVERN 3.2 — Roles and responsibilities for human-AI configurations.
  • NIST AI RMF MEASURE 2.8 — Risks of transparency and accountability are examined.

Common mistakes

  • "Human in the loop" claimed without specifying the loop's geometry.
  • No stop-control documentation in §3.
  • No automation-bias mitigation paragraph.
  • Override-rate monitoring described as future tense.
  • Skipping the two-person rule for biometric law-enforcement.

Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 14 · Starter tier · high

    Document human oversight measures and operator training

    Operators must be able to interpret outputs, decide to override, and stop the system when needed. Write it down.

  • Article 26 · Pro tier · high

    Assign human oversight to competent, trained, and authorised persons

    Article 26(2) requires deployers to assign human oversight to natural persons with the necessary competence, training, authority, and support.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art14-oversightISO/IEC 42001:2023 Annex A.9.2 — Human oversight of AI systemsArticle 14 oversight measures + operator competence map directly to Annex A.9.2 human-oversight controls.
art26-deployer-human-oversightISO/IEC 42001:2023 Annex A.9.2 — Human oversight of AI systemsArticle 26(2) competent and trained oversight by deployers is the human-oversight control of Annex A.9.2.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art14-oversightNIST AI RMF GOVERN 3.2 — Policies and procedures define and differentiate roles and responsibilities for human-AI configurationsArticle 14 documented oversight measures and operator roles map directly to GOVERN 3.2 human-AI role definition.
art14-oversightNIST AI RMF MEASURE 2.8 — Risks associated with transparency and accountability are examined and documentedOperator override paths and stop-controls are the accountability mechanisms MEASURE 2.8 examines.
art26-deployer-human-oversightNIST AI RMF GOVERN 3.2 — Policies and procedures define and differentiate roles and responsibilities for human-AI configurationsAssigning competent and trained oversight personnel is the human-AI role differentiation GOVERN 3.2 mandates.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.