Article 11 + Annex IV
EU AI Act Article 11 Step-by-Step — How to Build the Annex IV File
A step-by-step build for the EU AI Act Article 11 / Annex IV technical documentation file. Eight sections, eight weeks, evidence pack, and what to do over a weekend if you start late.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Hand-edited 2026-04-28
How to actually build an Annex IV file
Article 11 of Regulation (EU) 2024/1689 says you must have a technical file. Annex IV lists the eight sections it must contain. This pillar is the build.
We give two paths:
- Eight-week production build. What you do if you have time and want a defensible-on-inspection file.
- Weekend draft (v0.1). What you do if you have less than two weeks and just need something that exists.
Use the production build if you are >12 weeks from the system going live; use the weekend draft as a stop-gap if you are short of time.
The eight sections in one screen
- §1 — General description. Intended purpose, provider, version, integrations, IFU. → Annex IV §1
- §2 — Detailed development description. Methodology, architecture, data, hyperparameters, validation, cybersecurity. → Annex IV §2 data
- §3 — Monitoring, functioning and control. Accuracy, foreseeable unintended outcomes, human oversight measures, input-data specs. → Annex IV §3 human oversight + §3 accuracy
- §4 — Risk management system. Description of the Article 9 system. → Annex IV §4
- §5 — Lifecycle changes. Change log of every material modification. → Annex IV §5
- §6 — Standards and specifications applied. Harmonised standards under Article 40, common specs under Article 41.
- §7 — EU declaration of conformity (Article 47). Signed copy of the declaration.
- §8 — Post-market monitoring plan. Article 72 plan for in-deployment evaluation. → Annex IV §8
Plus a related artefact, Annex IV / conformity assessment under Article 43.
Eight-week production build
Week 1 — §1 general description and §6 standards
Write the intended purpose sentence. Excluded uses included. Show it to a lawyer; iterate. Lock the version number and bind it to the EU Database registration draft (Article 49). Choose the harmonised standards you will cite — at minimum, ISO/IEC 42001:2023 (AI management), 23894:2023 (AI risk), 24029-2:2023 (robustness). Cite explicitly.
Output: §1 final draft (~3 pages), §6 final draft (~1 page).
Week 2 — §2 data documentation
Write the data sheets (one per training/validation/test set). Document data lineage: source → ingestion → cleaning → labelling → split. State the legal basis for personal-data processing under GDPR. If you process special-category data under Article 10(5), produce the strict-necessity dossier — the Commission DPAs read this paragraph carefully.
Output: §2 data subsection (~5–10 pages), data sheets as appendices.
Week 3 — §2 architecture, hyperparameters, training process
Document the model architecture, training infrastructure (compute hours, GPU class, total wall-time), hyperparameters, random seeds, reproducibility commit hashes. State the "general logic of the AI system" (Annex IV §2(b)) — feature-importance plots for tree models, attention visualisations for transformers, whatever is honest.
Output: §2 architecture subsection (~4–6 pages).
Week 4 — §2 validation, §2 cybersecurity (Article 15)
Run the validation. Disaggregate metrics by demographic group (Article 15(3)). Run adversarial tests against poisoning, extraction, evasion and (for LLM-based features) prompt injection. Document the test plan, the test results, the residual risks. Tie the residual risks back into the Article 9 register.
Output: §2 validation subsection (~3–5 pages), §2 cybersecurity subsection (~2–3 pages).
Week 5 — §3 monitoring and human oversight
Write the in-deployment monitoring section: accuracy targets, drift monitoring, anomaly detection, alerting. Document the Article 14 human oversight measures the system supports: who sees what in the UI, what controls they have, what training they need. Tie to the Article 13 instructions for use.
Output: §3 final draft (~4–6 pages).
Week 6 — §4 risk management
Describe the Article 9 system: methodology, scope, mitigation hierarchy, review cadence, integration with §3 / §5 / §8 / Article 79. Include vulnerable-groups paragraph under Article 9(9) where applicable. Reference the live register's stable identifier. Make sure the register is actually live — Annex IV §4 is the abstract; without the live register it is fiction.
Output: §4 final draft (~2–3 pages), live register linked.
Week 7 — §5 changelog, §8 post-market monitoring plan
Build the §5 changelog as an append-only table (date, change description, code commit, risk-management verdict). Pull from your git log, filter to material changes, format. Write the §8 post-market monitoring plan: in-deployment performance review cadence, drift report cadence, complaint channel, incident triage tied to Article 79. Use the Commission template (published Q1 2026) if you have it.
Output: §5 starting changelog (~1–3 pages), §8 final draft (~3–5 pages).
Week 8 — §7 declaration of conformity, conformity-assessment route
Run the Article 43 conformity assessment. For most Annex III high-risk systems, this is internal self-assessment (Article 43(2)). For Annex III §1 biometric identification (real-time), notified-body assessment is required.
Sign the Article 47 declaration of conformity. Named accountable person; not a generic "CEO." File the EU Database registration under Article 49.
Output: §7 declaration (~1 page), file complete.
End-of-week-8 file size: 30–80 pages. Defensible to inspection.
Weekend draft (v0.1)
Saturday morning: §1, §6, §7. Use the Annex V template verbatim for §7.
Saturday afternoon: §5. Pull the git log; filter to material changes; format as a table.
Sunday morning: §2. Write architecture, data sheets, hyperparameters. Two to three pages.
Sunday afternoon: §3, §4, §8. Reference the Article 9, Article 14 and Article 72 artefacts — if you don't have them yet, write stub paragraphs naming the artefact and the date you'll have it complete. That's fine for v0.1.
End of weekend: 15–25 pages. Not your final file. But good enough for an internal review and 80% of the work.
Evidence pack — the artefacts behind the file
The Annex IV file references; it is not the full evidence. The full evidence pack you need ready for an Article 21 / Article 74 request:
- The risk register under Article 9 (live, version-controlled).
- The data sheets under Article 10 (one per dataset).
- The bias examination report under Article 10(2)(f)–(g).
- The validation report with disaggregated metrics under Article 15(3).
- The adversarial-test reports under Article 15(5) cybersecurity.
- The human-oversight SOP under Article 14.
- The operator training records for every overseer.
- The post-market monitoring data under Article 72.
- The incident register under Article 73.
- The changelog under Annex IV §5.
- The EU Database registration entry under Article 49.
- The declaration of conformity under Article 47.
Lining up 12 artefacts is the actual work. The Annex IV file is the cover sheet that points to them.
What about non-EU SaaS providers
If you are based outside the EU and your system's outputs are used in the Union (Article 2(1)(c)), you owe the full Article 11 file plus an Article 22 authorised representative established in the Union by written mandate. The representative receives the file on your behalf and cooperates with authorities. Designate them early — non-EU providers without a representative cannot lawfully place the system on the EU market.
Pre-inspection rehearsal
Once the file is written, run a 30-minute internal rehearsal. Have a colleague who hasn't worked on the file open it cold and try to:
- Read §1 and state, in their own words, what the system does and what it is excluded from.
- Locate the latest entry in §5 and confirm the date is recent.
- Find the disaggregated metrics in §3 and explain whether any sub-group is materially under-served.
- Find the post-market monitoring cadence in §8.
- Locate the Article 47 declaration of conformity and confirm the signatory and date.
If your colleague can do all five in 15 minutes, the file is in shape. If they can't, the file isn't.
Generate Article 11 documentation with AI
Governancer Pro's LLM-assisted Article 11 drafting tool produces a v0.1 draft from a structured intake. Output is a Word file with all eight sections pre-filled with system-specific content. The expected post-edit time per section is 30–90 minutes. The full v0.1 from intake to file: half a day.
The tool does not replace the Article 9 register or the validation runs. It writes the prose around them.
What we ship for the build
- Free. The 30-question quiz and gap-report email. Maps your current state against the eight sections.
- Starter (€99/mo). The Article 11 .docx template (15-page substantive draft with all eight sections), 12-item checklist, magic-link account, dashboard.
- Pro (€199/mo). LLM-assisted drafting tool (5 drafts/month), 30-item extended checklist, FRIA template, ISO 42001 / NIST AI RMF crosswalks, per-system gap reports, regulatory digest, audit trail, exportable compliance file.
Disclaimer. This pillar is a reference build for the EU AI Act Article 11 file. It is not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Article 11 · Starter tier · critical
Draft technical documentation (system purpose, design, risk)
Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.
Article 11 · Starter tier · critical
Document training data sources and quality controls
Article 10 data governance must be traceable in the technical file. Where did the data come from, who vetted it, what validation ran.
Annex IV · Pro tier · high
Adversarial-testing results against common attack vectors
Annex IV(2)(g) requires documentation of cybersecurity measures. Cover data poisoning, model extraction, evasion, and prompt injection with real test results.
Annex IV · Pro tier · critical
Disaggregated performance metrics by demographic group
Article 15(3) + Annex IV(2)(b) require accuracy metrics reported across the groups on which the system is intended to be used — not just overall averages.
Annex IV · Pro tier · low
Changelog of every model retrain and architecture change
Annex IV(2)(f) requires any pre-determined changes to system performance and information about how continuous compliance is ensured.
Annex IV · Pro tier · medium
List ISO/IEC 42001 + 23894 + 24029 alignment
Annex IV(2)(h) requires a list of harmonised standards applied in full or in part. ISO 42001 (AIMS), 23894 (risk), 24029 (robustness) are the core trio.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
art11-tech-docs | ISO/IEC 42001:2023 Clause 7.5 — Documented information | Article 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions. |
art11-tech-docs | ISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentation | Annex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation. |
art11-training-data | ISO/IEC 42001:2023 Annex A.7.4 — Quality of data for AI systems | Article 10 training-data documentation directly evidences the data-quality control objective in Annex A.7. |
annexiv-cybersecurity | ISO/IEC 42001:2023 Annex A.6.2.5 — Security of AI systems | Adversarial-testing results against poisoning, extraction, evasion and prompt injection evidence the AI-security control of Annex A.6.2.5. |
annexiv-performance-groups | ISO/IEC 42001:2023 Annex A.6.2.4 — Verification and validation | Disaggregated metrics by demographic group are the validation-across-intended-population evidence required by Annex A.6.2.4. |
annexiv-changes-log | ISO/IEC 42001:2023 Clause 8.1 — Operational planning and control | Change-log of retrains and architecture changes is the operational change-control evidence required by Clause 8.1. |
annexiv-harmonised-standards | ISO/IEC 42001:2023 Clause 4.4 — AI management system | Listing harmonised-standard alignment (ISO 42001/23894/24029) is the AIMS-establishment evidence of Clause 4.4. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
art11-tech-docs | NIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitations | Article 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1. |
art11-tech-docs | NIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewed | Maintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4. |
art11-training-data | NIST AI RMF MAP 2.3 — Scientific integrity and TEVV considerations are identified and documented, including data and modeling approach | Documenting training-data sources, quality controls and TEVV is the substance of MAP 2.3. |
annexiv-cybersecurity | NIST AI RMF MEASURE 2.7 — AI system security and resilience are evaluated and documented | Adversarial-testing results across attack vectors are the documented security/resilience evaluation MEASURE 2.7 calls for. |
annexiv-performance-groups | NIST AI RMF MEASURE 2.11 — Fairness and bias — as identified in the MAP function — are evaluated and results are documented | Disaggregated performance metrics by demographic group are the fairness measurement MEASURE 2.11 demands. |
annexiv-changes-log | NIST AI RMF MANAGE 4.2 — Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties | Retrain and architecture changelogs are the measurable continual-improvement activity MANAGE 4.2 expects. |
annexiv-harmonised-standards | NIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documented | Listing harmonised-standard alignment (ISO 42001/23894/24029) is the documented standards landscape GOVERN 1.1 expects. |
Related
Article 11
EU AI Act Article 11 — Technical Documentation Requirements
Annex IV §1
Annex IV §1 — General Description of the AI System (EU AI Act)
Annex IV §2(d)
Annex IV §2(d) — Data Documentation (EU AI Act)
Annex IV §4
Annex IV §4 — Risk Management System Description (EU AI Act)
Annex IV §2(b) + §3
Annex IV — Accuracy Documentation (EU AI Act)
Annex IV §3 (oversight)
Annex IV — Human Oversight Documentation (EU AI Act)
Annex IV §5
Annex IV §5 — Lifecycle Changes Log (EU AI Act)
Annex IV §8 (Article 72 plan)
Annex IV §8 — Post-Market Monitoring Plan (EU AI Act)
Article 43 + Annex VI/VII
Conformity Assessment for High-Risk AI (Article 43 + Annex IV)
Articles 6 / 16 / 25 / 53
EU AI Act for SaaS — Are You a Provider, Deployer, or Both?
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.