Article 43 + Annex VI/VII

Conformity Assessment for High-Risk AI (Article 43 + Annex IV)

How to run the Article 43 conformity assessment under Regulation (EU) 2024/1689. Internal control (Annex VI) vs notified-body (Annex VII), substantial modification, and the link to the Annex IV file.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review

What Article 43 actually requires

Article 43 of Regulation (EU) 2024/1689 sets the conformity assessment procedure that providers must complete before placing a high-risk AI system on the market or putting it into service.

The route depends on the system class:

  • Annex III §1 biometric identification (real-time RBI and post-RBI in law enforcement): the provider chooses between the Annex VI internal-control procedure (where harmonised standards or common specifications are applied in full) or the Annex VII notified-body assessment (otherwise).
  • All other Annex III systems: the Annex VI internal control (self-assessment) procedure.
  • Annex I (safety-component / Union harmonisation): the procedure under the relevant sectoral legislation (e.g., MDR notified-body assessment for medical devices).

Annex VI — internal control (self-assessment)

For most Annex III high-risk systems, the provider self-assesses against the Section 2 requirements (Articles 8–15). The provider must:

The self-assessment is documented as part of the QMS, and the Article 47 EU declaration of conformity is then drawn up and signed.

Annex VII — notified-body assessment

For Annex III §1 biometric identification systems where harmonised standards or common specifications are not applied in full, the provider must engage a notified body designated under Article 31 for AI-Act conformity. The notified body assesses the QMS and the technical documentation, and issues an EU technical-documentation assessment certificate valid for up to five years.

Substantial modifications — Article 43(4)

A substantial modification within the meaning of Article 3(23) requires a new conformity assessment under Article 43(4). The §5 lifecycle-changes log is the front-line evidence of what triggers this.

What to do

  1. Identify your system class (Annex III §X) and the applicable conformity-assessment route.
  2. Build the QMS under Article 17.
  3. Complete the Annex IV technical file.
  4. Run the self-assessment (Annex VI) or engage a notified body (Annex VII).
  5. Sign the Article 47 declaration.
  6. Affix the CE marking under Article 48.
  7. Register in the EU Database under Article 49.
  8. Re-assess on substantial modification under Article 43(4).

Inline crosswalk

  • ISO/IEC 42001:2023 Clause 9.2 — Internal audit.
  • NIST AI RMF GOVERN 4.1 — Effective challenge for AI deployment is in place.

Common mistakes

  • Late conformity assessment. Article 16(f) is before placement on the market.
  • Missing CE marking on systems where Article 48 requires it.
  • No re-assessment after substantial modification.
  • Choosing Annex VI when full harmonised-standard alignment is missing for Annex III §1 systems.

Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 43 · Starter tier · critical

    Complete conformity assessment procedure

    Required before placing a high-risk system on the market. Internal self-assessment for most Annex III; notified body for §1 biometrics.

  • Article 49 · Starter tier · medium

    Register high-risk system in EU database

    Public transparency register. Must be updated annually. Filing is online via the EU AI Office portal.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art43-conformityISO/IEC 42001:2023 Clause 9.2 — Internal auditInternal self-assessment (Article 43 §1 path) and independent review map onto the internal-audit programme of Clause 9.2.
art49-eudbISO/IEC 42001:2023 Annex A.8.3 — External reportingFiling in the EU AI Office public register evidences Annex A.8 external transparency to interested parties.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art43-conformityNIST AI RMF GOVERN 4.1 — Organizational practices are in place to foster a critical thinking and safety-first mindset; effective challenge for AI deployment is in placeConformity assessment is the documented effective-challenge step before deployment that GOVERN 4.1 mandates.
art49-eudbNIST AI RMF GOVERN 5.1 — Organizational policies and practices are in place to collect, consider, prioritize, and integrate external feedbackPublic registration enables the external-feedback intake GOVERN 5.1 expects organisations to operationalise.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.