Annex IV §5
Annex IV §5 — Lifecycle Changes Log (EU AI Act)
How to maintain the Annex IV §5 lifecycle-changes log under Regulation (EU) 2024/1689. Append-only design, what counts as a material change, and the link to Article 43 substantial modification.
Source: Regulation (EU) 2024/1689 on EUR-Lex · Last published 2026-04-28 · Draft pending human review
What §5 actually requires
Annex IV §5 of Regulation (EU) 2024/1689 requires:
"A description of any relevant change made by the provider to the system through its lifecycle."
This is where version control meets regulation. Every material change — retraining on new data, hyperparameter changes, feature additions, architecture changes — must be captured. Not every bug fix; not every cosmetic tweak. But anything that could plausibly alter the risk profile under Article 9, the performance under Article 15, or the intended purpose under §1(a).
Substantial modification — Article 3(23)
Article 3(23) defines a substantial modification as a change to the AI system after its placing on the market or putting into service which is not foreseen or planned in the initial conformity assessment by the provider, and as a result of which compliance with the requirements is affected, or the intended purpose for which the AI system has been assessed is modified.
A substantial modification triggers a new conformity assessment under Article 43(4). The §5 changelog is the front-line evidence of what counts as substantial.
Recommended structure — append-only table
| Date | Version | Change description | Code commit / artefact | Risk-mgmt verdict |
|---|---|---|---|---|
| 2026-02-04 | v2.4.0 | Initial production release | a4f21c8 | Article 9 register baseline established |
| 2026-03-12 | v2.4.1 | Re-weighted loss function to address age sub-group gap | b1c8e22 | Closes Article 15 parity target; no re-classification |
| 2026-04-08 | v2.4.2 | Added language coverage: PT and SE | c93ad11 | Triggers Article 10(4) context analysis; not substantial under Art 3(23); no new CA |
| 2026-05-15 | v3.0.0 | Architecture change: tree ensemble → transformer | d56fc40 | Substantial modification under Art 3(23); new conformity assessment under Art 43(4); EU Database entry updated under Art 49 |
What to do
- Bind documentation events to engineering events. A 30-line GitHub Action that opens a §5 PR for every model-retrain or release tag is the cleanest pattern.
- Triage every change against Article 3(23). Document the verdict, even when "not substantial."
- Cross-reference §4 for risk-register updates that the change triggered.
- Update the EU Database (Article 49) entry on substantial modifications.
Inline crosswalk
- ISO/IEC 42001:2023 Clause 8.1 — Operational planning and control.
- NIST AI RMF MANAGE 4.2 — Continual improvements integrated into AI system updates.
Common mistakes
- §5 entries too regular — looks back-filled.
- §5 entries too sparse — looks unmaintained.
- No substantial-modification verdict per row.
- Substantial modification without a fresh Article 43 conformity assessment.
Disclaimer. Reference; not legal advice. Verify with counsel. Reg text from Regulation (EU) 2024/1689.
Reference checklist
From the Governancer 30-item EU AI Act checklist. Each item joins to the ISO 42001 + NIST AI RMF crosswalk table below.
Annex IV · Pro tier · low
Changelog of every model retrain and architecture change
Annex IV(2)(f) requires any pre-determined changes to system performance and information about how continuous compliance is ensured.
ISO 42001 + NIST AI RMF crosswalk
Pulled live from the Governancer crosswalk module. Mapping reference; not a substitute for ISO 42001 certification audit or NIST AI RMF self-attestation.
ISO/IEC 42001:2023
| Checklist item | ISO 42001 control | Rationale |
|---|---|---|
annexiv-changes-log | ISO/IEC 42001:2023 Clause 8.1 — Operational planning and control | Change-log of retrains and architecture changes is the operational change-control evidence required by Clause 8.1. |
NIST AI RMF 1.0
| Checklist item | NIST AI RMF subcategory | Rationale |
|---|---|---|
annexiv-changes-log | NIST AI RMF MANAGE 4.2 — Measurable activities for continual improvements are integrated into AI system updates and include regular engagement with interested parties | Retrain and architecture changelogs are the measurable continual-improvement activity MANAGE 4.2 expects. |
Related
Pro feature
Generate Article 11 with AI
LLM-assisted draft of all eight Annex IV sections, pre-filled from your system intake. 5 drafts/month on Pro.
Pro template
Download FRIA template
15-page Article 27 FRIA template (.docx) with the six elements pre-structured and a worked example.
Get the 30-item EU AI Act compliance checklist
Free PDF. No spam. Maps every Article and Annex IV section we ship to a ready-to-action checklist row.
Reference; not legal advice. Verify with qualified counsel before relying on it for compliance decisions. Reg text quoted from the Official Journal version of Regulation (EU) 2024/1689. Published by Agonist Development AB.