Article 43 + Annex VI/VII
Conformity Assessment for High-Risk AI (Article 43 + Annex IV)
How to run the Article 43 conformity assessment under Regulation (EU) 2024/1689. Internal control (Annex VI) vs notified-body (Annex VII), substantial modification, and the link to the Annex IV file.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review
What Article 43 actually requires
Article 43 of Regulation (EU) 2024/1689 sets the conformity assessment procedure that providers must complete before placing a high-risk AI system on the market or putting it into service.
The route depends on the system class:
- Annex III §1 biometric identification (real-time RBI and post-RBI in law enforcement): the provider chooses between the Annex VI internal-control procedure (where harmonised standards or common specifications are applied in full) or the Annex VII notified-body assessment (otherwise).
- All other Annex III systems: the Annex VI internal control (self-assessment) procedure.
- Annex I (safety-component / Union harmonisation): the procedure under the relevant sectoral legislation (e.g., MDR notified-body assessment for medical devices).
Annex VI — internal control (self-assessment)
For most Annex III high-risk systems, the provider self-assesses against the Section 2 requirements (Articles 8–15). The provider must:
- Ensure the quality management system under Article 17 is established and maintained.
- Examine the Article 11 / Annex IV technical documentation.
- Ensure the design and development process and the post-market monitoring conform to the technical file.
The self-assessment is documented as part of the QMS, and the Article 47 EU declaration of conformity is then drawn up and signed.
Annex VII — notified-body assessment
For Annex III §1 biometric identification systems where harmonised standards or common specifications are not applied in full, the provider must engage a notified body designated under Article 31 for AI-Act conformity. The notified body assesses the QMS and the technical documentation, and issues an EU technical-documentation assessment certificate valid for up to five years.
Substantial modifications — Article 43(4)
A substantial modification within the meaning of Article 3(23) requires a new conformity assessment under Article 43(4). The §5 lifecycle-changes log is the front-line evidence of what triggers this.
What to do
- Identify your system class (Annex III §X) and the applicable conformity-assessment route.
- Build the QMS under Article 17.
- Complete the Annex IV technical file.
- Run the self-assessment (Annex VI) or engage a notified body (Annex VII).
- Sign the Article 47 declaration.
- Affix the CE marking under Article 48.
- Register in the EU Database under Article 49.
- Re-assess on substantial modification under Article 43(4).
Inline crosswalk
- ISO/IEC 42001:2023 Clause 9.2 — Internal audit.
- NIST AI RMF GOVERN 4.1 — Effective challenge for AI deployment is in place.
Common mistakes
- Late conformity assessment. Article 16(f) is before placement on the market.
- Missing CE marking on systems where Article 48 requires it.
- No re-assessment after substantial modification.
- Choosing Annex VI when full harmonised-standard alignment is missing for Annex III §1 systems.
Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 43 · Starter tier · critical
Complete conformity assessment procedure
Required before placing a high-risk system on the market. Internal self-assessment for most Annex III; notified body for §1 biometrics.
Article 49 · Starter tier · medium
Register high-risk system in EU database
Public transparency register. Must be updated annually. Filing is online via the EU AI Office portal.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art43-conformity | ISO/IEC 42001:2023 Clause 9.2 — Internal audit | Internal self-assessment (Article 43 §1 path) and independent review map onto the internal-audit programme of Clause 9.2. |
art49-eudb | ISO/IEC 42001:2023 Annex A.8.3 — External reporting | Filing in the EU AI Office public register evidences Annex A.8 external transparency to interested parties. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art43-conformity | NIST AI RMF GOVERN 4.1 — Organizational practices are in place to foster a critical thinking and safety-first mindset; effective challenge for AI deployment is in place | Conformity assessment is the documented effective-challenge step before deployment that GOVERN 4.1 mandates. |
art49-eudb | NIST AI RMF GOVERN 5.1 — Organizational policies and practices are in place to collect, consider, prioritize, and integrate external feedback | Public registration enables the external-feedback intake GOVERN 5.1 expects organisations to operationalise. |
Related
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.