Article 11 + Annex IV

EU AI Act Article 11 Step-by-Step — How to Build the Annex IV File

A step-by-step build for the EU AI Act Article 11 / Annex IV technical documentation file. Eight sections, eight weeks, evidence pack, and what to do over a weekend if you start late.

Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Hand-edited 2026-04-28

How to actually build an Annex IV file

Article 11 of Regulation (EU) 2024/1689 says you must have a technical file. Annex IV lists the eight sections it must contain. This pillar is the build.

We give two paths:

  • Eight-week production build. What you do if you have time and want a defensible-on-inspection file.
  • Weekend draft (v0.1). What you do if you have less than two weeks and just need something that exists.

Use the production build if you are >12 weeks from the system going live; use the weekend draft as a stop-gap if you are short of time.

The eight sections in one screen

  1. §1 — General description. Intended purpose, provider, version, integrations, IFU. → Annex IV §1
  2. §2 — Detailed development description. Methodology, architecture, data, hyperparameters, validation, cybersecurity. → Annex IV §2 data
  3. §3 — Monitoring, functioning and control. Accuracy, foreseeable unintended outcomes, human oversight measures, input-data specs. → Annex IV §3 human oversight + §3 accuracy
  4. §4 — Risk management system. Description of the Article 9 system. → Annex IV §4
  5. §5 — Lifecycle changes. Change log of every material modification. → Annex IV §5
  6. §6 — Standards and specifications applied. Harmonised standards under Article 40, common specs under Article 41.
  7. §7 — EU declaration of conformity (Article 47). Signed copy of the declaration.
  8. §8 — Post-market monitoring plan. Article 72 plan for in-deployment evaluation. → Annex IV §8

Plus a related artefact, Annex IV / conformity assessment under Article 43.

Eight-week production build

Week 1 — §1 general description and §6 standards

Write the intended purpose sentence. Excluded uses included. Show it to a lawyer; iterate. Lock the version number and bind it to the EU Database registration draft (Article 49). Choose the harmonised standards you will cite — at minimum, ISO/IEC 42001:2023 (AI management), 23894:2023 (AI risk), 24029-2:2023 (robustness). Cite explicitly.

Output: §1 final draft (~3 pages), §6 final draft (~1 page).

Week 2 — §2 data documentation

Write the data sheets (one per training/validation/test set). Document data lineage: source → ingestion → cleaning → labelling → split. State the legal basis for personal-data processing under GDPR. If you process special-category data under Article 10(5), produce the strict-necessity dossier — the Commission DPAs read this paragraph carefully.

Output: §2 data subsection (~5–10 pages), data sheets as appendices.

Week 3 — §2 architecture, hyperparameters, training process

Document the model architecture, training infrastructure (compute hours, GPU class, total wall-time), hyperparameters, random seeds, reproducibility commit hashes. State the "general logic of the AI system" (Annex IV §2(b)) — feature-importance plots for tree models, attention visualisations for transformers, whatever is honest.

Output: §2 architecture subsection (~4–6 pages).

Week 4 — §2 validation, §2 cybersecurity (Article 15)

Run the validation. Disaggregate metrics by demographic group (Article 15(3)). Run adversarial tests against poisoning, extraction, evasion and (for LLM-based features) prompt injection. Document the test plan, the test results, the residual risks. Tie the residual risks back into the Article 9 register.

Output: §2 validation subsection (~3–5 pages), §2 cybersecurity subsection (~2–3 pages).

Week 5 — §3 monitoring and human oversight

Write the in-deployment monitoring section: accuracy targets, drift monitoring, anomaly detection, alerting. Document the Article 14 human oversight measures the system supports: who sees what in the UI, what controls they have, what training they need. Tie to the Article 13 instructions for use.

Output: §3 final draft (~4–6 pages).

Week 6 — §4 risk management

Describe the Article 9 system: methodology, scope, mitigation hierarchy, review cadence, integration with §3 / §5 / §8 / Article 79. Include vulnerable-groups paragraph under Article 9(9) where applicable. Reference the live register's stable identifier. Make sure the register is actually live — Annex IV §4 is the abstract; without the live register it is fiction.

Output: §4 final draft (~2–3 pages), live register linked.

Week 7 — §5 changelog, §8 post-market monitoring plan

Build the §5 changelog as an append-only table (date, change description, code commit, risk-management verdict). Pull from your git log, filter to material changes, format. Write the §8 post-market monitoring plan: in-deployment performance review cadence, drift report cadence, complaint channel, incident triage tied to Article 79. Use the Commission template (published Q1 2026) if you have it.

Output: §5 starting changelog (~1–3 pages), §8 final draft (~3–5 pages).

Week 8 — §7 declaration of conformity, conformity-assessment route

Run the Article 43 conformity assessment. For most Annex III high-risk systems, this is internal self-assessment (Article 43(2)). For Annex III §1 biometric identification (real-time), notified-body assessment is required.

Sign the Article 47 declaration of conformity. Named accountable person; not a generic "CEO." File the EU Database registration under Article 49.

Output: §7 declaration (~1 page), file complete.

End-of-week-8 file size: 30–80 pages. Defensible to inspection.

Weekend draft (v0.1)

Saturday morning: §1, §6, §7. Use the Annex V template verbatim for §7.

Saturday afternoon: §5. Pull the git log; filter to material changes; format as a table.

Sunday morning: §2. Write architecture, data sheets, hyperparameters. Two to three pages.

Sunday afternoon: §3, §4, §8. Reference the Article 9, Article 14 and Article 72 artefacts — if you don't have them yet, write stub paragraphs naming the artefact and the date you'll have it complete. That's fine for v0.1.

End of weekend: 15–25 pages. Not your final file. But good enough for an internal review and 80% of the work.

Evidence pack — the artefacts behind the file

The Annex IV file references; it is not the full evidence. The full evidence pack you need ready for an Article 21 / Article 74 request:

  • The risk register under Article 9 (live, version-controlled).
  • The data sheets under Article 10 (one per dataset).
  • The bias examination report under Article 10(2)(f)–(g).
  • The validation report with disaggregated metrics under Article 15(3).
  • The adversarial-test reports under Article 15(5) cybersecurity.
  • The human-oversight SOP under Article 14.
  • The operator training records for every overseer.
  • The post-market monitoring data under Article 72.
  • The incident register under Article 73.
  • The changelog under Annex IV §5.
  • The EU Database registration entry under Article 49.
  • The declaration of conformity under Article 47.

Lining up 12 artefacts is the actual work. The Annex IV file is the cover sheet that points to them.

What about non-EU SaaS providers

If you are based outside the EU and your system's outputs are used in the Union (Article 2(1)(c)), you owe the full Article 11 file plus an Article 22 authorised representative established in the Union by written mandate. The representative receives the file on your behalf and cooperates with authorities. Designate them early — non-EU providers without a representative cannot lawfully place the system on the EU market.

Pre-inspection rehearsal

Once the file is written, run a 30-minute internal rehearsal. Have a colleague who hasn't worked on the file open it cold and try to:

  1. Read §1 and state, in their own words, what the system does and what it is excluded from.
  2. Locate the latest entry in §5 and confirm the date is recent.
  3. Find the disaggregated metrics in §3 and explain whether any sub-group is materially under-served.
  4. Find the post-market monitoring cadence in §8.
  5. Locate the Article 47 declaration of conformity and confirm the signatory and date.

If your colleague can do all five in 15 minutes, the file is in shape. If they can't, the file isn't.

Generate Article 11 documentation with AI

Governancer Pro's LLM-assisted Article 11 drafting tool produces a v0.1 draft from a structured intake. Output is a Word file with all eight sections pre-filled with system-specific content. The expected post-edit time per section is 30–90 minutes. The full v0.1 from intake to file: half a day.

The tool does not replace the Article 9 register or the validation runs. It writes the prose around them.

What we ship for the build

  • Free. The 30-question quiz and gap-report email. Maps your current state against the eight sections.
  • Starter (€99/mo). The Article 11 .docx template (15-page substantive draft with all eight sections), 12-item checklist, magic-link account, dashboard.
  • Pro (€199/mo). LLM-assisted drafting tool (5 drafts/month), 30-item extended checklist, FRIA template, ISO 42001 / NIST AI RMF crosswalks, per-system gap reports, regulatory digest, audit trail, exportable compliance file.

See full pricing.


Disclaimer. This pillar is a reference build for the EU AI Act Article 11 file. It is not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text from Regulation (EU) 2024/1689.

Reference checklist

From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.

  • Article 11 · Starter tier · critical

    Draft technical documentation (system purpose, design, risk)

    Required for all high-risk AI systems before market placement. Our template covers the eight mandatory sections in one .docx.

  • Article 11 · Starter tier · critical

    Document training data sources and quality controls

    Article 10 data governance must be traceable in the technical file. Where did the data come from, who vetted it, what validation ran.

  • Annex IV · Pro tier · high

    Adversarial-testing results against common attack vectors

    Annex IV(2)(g) requires documentation of cybersecurity measures. Cover data poisoning, model extraction, evasion, and prompt injection with real test results.

  • Annex IV · Pro tier · critical

    Disaggregated performance metrics by demographic group

    Article 15(3) + Annex IV(2)(b) require accuracy metrics reported across the groups on which the system is intended to be used — not just overall averages.

  • Annex IV · Pro tier · low

    Changelog of every model retrain and architecture change

    Annex IV(2)(f) requires any pre-determined changes to system performance and information about how continuous compliance is ensured.

  • Annex IV · Pro tier · medium

    List ISO/IEC 42001 + 23894 + 24029 alignment

    Annex IV(2)(h) requires a list of harmonised standards applied in full or in part. ISO 42001 (AIMS), 23894 (risk), 24029 (robustness) are the core trio.

ISO 42001 + NIST AI RMF crosswalk

Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.

ISO/IEC 42001:2023

Checklist itemISO 42001 controlRationale
art11-tech-docsISO/IEC 42001:2023 Clause 7.5 — Documented informationArticle 11 technical file is the AIMS-required documented information evidencing AI system design, purpose, and risk decisions.
art11-tech-docsISO/IEC 42001:2023 Annex A.6.2 — AI system life cycle documentationAnnex A.6.2 requires lifecycle documentation; the Article 11 technical file is its EU AI Act manifestation.
art11-training-dataISO/IEC 42001:2023 Annex A.7.4 — Quality of data for AI systemsArticle 10 training-data documentation directly evidences the data-quality control objective in Annex A.7.
annexiv-cybersecurityISO/IEC 42001:2023 Annex A.6.2.5 — Security of AI systemsAdversarial-testing results against poisoning, extraction, evasion and prompt injection evidence the AI-security control of Annex A.6.2.5.
annexiv-performance-groupsISO/IEC 42001:2023 Annex A.6.2.4 — Verification and validationDisaggregated metrics by demographic group are the validation-across-intended-population evidence required by Annex A.6.2.4.
annexiv-changes-logISO/IEC 42001:2023 Clause 8.1 — Operational planning and controlChange-log of retrains and architecture changes is the operational change-control evidence required by Clause 8.1.
annexiv-harmonised-standardsISO/IEC 42001:2023 Clause 4.4 — AI management systemListing harmonised-standard alignment (ISO 42001/23894/24029) is the AIMS-establishment evidence of Clause 4.4.

NIST AI RMF 1.0

Checklist itemNIST AI RMF subcategoryRationale
art11-tech-docsNIST AI RMF MAP 4.1 — Approaches and metrics for measurement of AI risks are followed; documentation includes purpose, intended use, users, and limitationsArticle 11 technical file documents purpose, design and limitations — the system-context output expected by MAP 4.1.
art11-tech-docsNIST AI RMF GOVERN 1.4 — The risk management process is documented and is regularly reviewedMaintaining a living technical file is the documented and regularly reviewed risk-management evidence under GOVERN 1.4.
art11-training-dataNIST AI RMF MAP 2.3 — Scientific integrity and TEVV considerations are identified and documented, including data and modeling approachDocumenting training-data sources, quality controls and TEVV is the substance of MAP 2.3.
annexiv-cybersecurityNIST AI RMF MEASURE 2.7 — AI system security and resilience are evaluated and documentedAdversarial-testing results across attack vectors are the documented security/resilience evaluation MEASURE 2.7 calls for.
annexiv-performance-groupsNIST AI RMF MEASURE 2.11 — Fairness and bias — as identified in the MAP function — are evaluated and results are documentedDisaggregated performance metrics by demographic group are the fairness measurement MEASURE 2.11 demands.
annexiv-changes-logNIST AI RMF MANAGE 4.2 — Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested partiesRetrain and architecture changelogs are the measurable continual-improvement activity MANAGE 4.2 expects.
annexiv-harmonised-standardsNIST AI RMF GOVERN 1.1 — Legal and regulatory requirements involving AI are understood, managed, and documentedListing harmonised-standard alignment (ISO 42001/23894/24029) is the documented standards landscape GOVERN 1.1 expects.

Pro feature

Generate Article 11 with AI

LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.

Pro template

Download FRIA template

15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.

Get the 30-item EU AI Act compliance checklist

Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.


Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.