View all articles
EU AI ActConformity AssessmentComplianceSME Checklist

EU AI Act Article 43 Conformity Assessment: an SME Checklist You Can Complete Before December 2027

JG
Jacobo Gonzalez Jaspe
|

By the end of this post you will know which conformity assessment route applies to your AI system, you will have a document register with every file the procedure asks for, and you will have a month-by-month plan that finishes before 2 December 2027. You need no lawyer to start, no paid tool, and no hardware beyond the laptop you already have.

What you need

  • The list of AI systems you build or sell, one line each. If you only use someone else’s system, your duties sit in Article 26 (deployer), not Article 43. This checklist is for providers.
  • The text of Regulation (EU) 2024/1689 on EUR-Lex, open in a tab. Articles 6, 9 to 17, 43 and 47 to 49, plus Annexes III, IV, VI and VII, are the parts you will read.
  • A spreadsheet and two hours for the first pass.
  • Optional: a local model to draft text you then correct. ollama run qwen2.5-coder:7b runs on a 16 GB laptop.

The dates, as amended in July 2026

The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026 (EUR-Lex; summary by Gibson Dunn). It moved the high-risk deadlines and left the rest in place.

ObligationApplies fromSource
Prohibited practices (Art. 5) and AI literacy (Art. 4)2 February 2025Reg. 2024/1689, Art. 113
General-purpose AI models2 August 2025Reg. 2024/1689, Art. 113
Transparency (Art. 50)2 August 2026; grace period to 2 December 2026 for systems already on the marketReg. 2026/1744
High-risk systems listed in Annex III (this checklist)2 December 2027Reg. 2026/1744
High-risk AI inside regulated products (Annex I)2 August 2028Reg. 2026/1744

From today, 9 September 2026, that is 15 months. The plan below uses 12 and keeps three in reserve.

Step 1: Confirm you are in scope (20 minutes)

Answer these three questions for each system and write the answers down. The written answer is itself a required document when you claim the exemption.

  1. Is it an AI system under Article 3(1)? A machine-based system that infers from its input how to generate outputs such as predictions, recommendations or decisions. A rules-only spreadsheet macro is not.
  2. Is its intended purpose listed in Annex III? The eight areas are biometrics, critical infrastructure, education, employment, essential services (credit, insurance, benefits), law enforcement, migration and justice. Our risk classification guide walks the list with examples.
  3. Does the Article 6(3) exemption apply? It does when the system only performs a narrow procedural task, improves the result of a human activity, detects patterns without replacing human assessment, or does preparatory work. Profiling of natural persons always stays high-risk. If you rely on the exemption, document the reasoning and register the system under Article 49(2).

If the answer to question 2 is yes and to question 3 is no, continue. Otherwise you are finished with Article 43, and your remaining work is Article 50 transparency, covered in our compliance guide.

Step 2: Pick the route (10 minutes)

Article 43 gives two procedures. Which one applies depends on the Annex III item, not on your company size.

Your systemProcedureWho checks
Annex III, points 2 to 8 (everything except biometrics)Annex VI, internal controlYou
Annex III, point 1 (biometrics), harmonised standards fully appliedAnnex VI or Annex VII, your choiceYou, or a notified body
Annex III, point 1, standards not or only partly appliedAnnex VIIA notified body listed in NANDO
Product covered by Annex I (machinery, medical devices, lifts)The sectoral procedure, with the AI Act requirements addedThe body that already certifies the product

Most SME systems land in the first row. The rest of this checklist is the Annex VI route.

Step 3: Open the document register (the checklist)

Annex VI asks you to verify three things: that your quality management system meets Article 17, that your technical documentation meets Annex IV, and that the way you actually designed and built the system matches that documentation. Everything you will verify lives in these files.

#DocumentArticleFree starting point
1Risk classification decision (your Step 1 answers)Art. 6, Annex IIIThis post
2Intended purpose and instructions for useArt. 13Your product sheet, rewritten
3Risk management fileArt. 9A register with likelihood, severity, mitigation, owner
4Data governance record: sources, labelling, bias checksArt. 10One datasheet per dataset
5Technical documentationArt. 11, Annex IVThe SME simplified form of Art. 11(1)
6Logging design: which events, kept how longArt. 12A one-page specification
7Human oversight measuresArt. 14Our Article 14 guide
8Accuracy, robustness and cybersecurity testsArt. 15Your test reports, with numbers
9Quality management systemArt. 17Policy, process map, competence matrix, audit log
10Post-market monitoring planArt. 72One page until the Commission template is published
11Serious incident procedure (15-day reporting)Art. 73One page with names and phone numbers
12EU declaration of conformityArt. 47, Annex VThe nine fields listed below
13CE marking and EU database registrationArts. 48, 49Free, done last

Copy the table into your spreadsheet, add an owner and a status column, and the register exists. Article 11(1) already lets SMEs and start-ups use the simplified technical documentation form; the Omnibus extended it to small mid-caps (Cloud Security Alliance note).

Step 4: Run the three Annex VI checks

Do them in order and keep the evidence of each check in the register.

  1. Quality management check. Walk Article 17(1)(a) to (m) and point each letter at a document from row 9. Missing letters become tasks. Article 17(2) says the system must be proportionate to your size, so a ten-person company documents ten-person processes.
  2. Technical documentation check. For every requirement in Articles 9 to 15, name the page in the Annex IV file that shows it is met. If you cannot name a page, the requirement is not met yet.
  3. Design consistency check. Compare what the documentation says with what the repository, the tickets and the test logs show. Differences are fixed on one side or the other, and the fix is dated.

When all three pass, draw up the declaration of conformity (Annex V: system name and version, provider name and address, statement of sole responsibility, reference to the Regulation, standards applied, notified body if any, place, date, signature), affix the CE marking, and register the system in the EU database before it goes on the market. Check the Official Journal for harmonised standards before you finalise: when one is listed, applying it gives presumption of conformity under Article 40.

The plan, working back from 2 December 2027

WhenWhatRegister rows
September to October 2026Steps 1 and 2, register opened, owners named1, 2
November 2026 to February 2027Risk file, data governance, logging spec, oversight measures3, 4, 6, 7
March to June 2027Annex IV documentation, test campaign, QMS written down5, 8, 9
July to August 2027Three Annex VI checks, gaps closed10, 11
September 2027Declaration, CE marking, database registration12, 13
October to November 2027Reserve

The first 30 minutes, today

  • Minutes 0 to 10: list your systems in the spreadsheet with one sentence of intended purpose each.
  • Minutes 10 to 20: run each one through the Commission’s free AI Act compliance checker on the Single Information Platform and note the result in row 1.
  • Minutes 20 to 30: ask a local model for a first draft of rows 2 and 3. Prompt: “Here is a description of my AI system: [paste]. Write a 120-word intended purpose statement in the style of EU product documentation, then list ten foreseeable risks to health, safety or fundamental rights, each with a likelihood and a severity from 1 to 5.” Correct everything; the model does not know your system.

Honest limits

  • Notified bodies designated for the AI Act are still few. If you are in the biometrics row, contact one this quarter, not next year.
  • The register proves nothing by itself. The three checks in Step 4 are the assessment; the files are only what you check.
  • This is a procedure, not legal advice. One hour with a lawyer once the register is full is money well spent.

Next steps

Work with us

We open the document register with clients in two half-day sessions, on their own machines and with their own data, so nothing about the system leaves the building. If you want the second session with us, get in touch or read how our consulting works.

Share: LinkedIn X
Newsletter

Access exclusive resources

Subscribe to unlock 230+ workflows, 43 agents, and 26 professional templates. Weekly insights, no spam.

Bonus: Free EU AI Act checklist when you subscribe
Once a week No spam Unsubscribe anytime
EU AI Act is now in effect — Is your organization compliant?

Tell us what you want to run

Tell us what you want to run and on what budget. We will tell you which hardware you need, which model fits, and what to expect from it — before you spend anything.

Self-service Local-first Open-source toolkits

136 pages of free resources · 26 compliance templates · 22 certified devices