EU AI Act Article 43 Conformity Assessment: an SME Checklist You Can Complete Before December 2027
By the end of this post you will know which conformity assessment route applies to your AI system, you will have a document register with every file the procedure asks for, and you will have a month-by-month plan that finishes before 2 December 2027. You need no lawyer to start, no paid tool, and no hardware beyond the laptop you already have.
What you need
- The list of AI systems you build or sell, one line each. If you only use someone else’s system, your duties sit in Article 26 (deployer), not Article 43. This checklist is for providers.
- The text of Regulation (EU) 2024/1689 on EUR-Lex, open in a tab. Articles 6, 9 to 17, 43 and 47 to 49, plus Annexes III, IV, VI and VII, are the parts you will read.
- A spreadsheet and two hours for the first pass.
- Optional: a local model to draft text you then correct.
ollama run qwen2.5-coder:7bruns on a 16 GB laptop.
The dates, as amended in July 2026
The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026 (EUR-Lex; summary by Gibson Dunn). It moved the high-risk deadlines and left the rest in place.
| Obligation | Applies from | Source |
|---|---|---|
| Prohibited practices (Art. 5) and AI literacy (Art. 4) | 2 February 2025 | Reg. 2024/1689, Art. 113 |
| General-purpose AI models | 2 August 2025 | Reg. 2024/1689, Art. 113 |
| Transparency (Art. 50) | 2 August 2026; grace period to 2 December 2026 for systems already on the market | Reg. 2026/1744 |
| High-risk systems listed in Annex III (this checklist) | 2 December 2027 | Reg. 2026/1744 |
| High-risk AI inside regulated products (Annex I) | 2 August 2028 | Reg. 2026/1744 |
From today, 9 September 2026, that is 15 months. The plan below uses 12 and keeps three in reserve.
Step 1: Confirm you are in scope (20 minutes)
Answer these three questions for each system and write the answers down. The written answer is itself a required document when you claim the exemption.
- Is it an AI system under Article 3(1)? A machine-based system that infers from its input how to generate outputs such as predictions, recommendations or decisions. A rules-only spreadsheet macro is not.
- Is its intended purpose listed in Annex III? The eight areas are biometrics, critical infrastructure, education, employment, essential services (credit, insurance, benefits), law enforcement, migration and justice. Our risk classification guide walks the list with examples.
- Does the Article 6(3) exemption apply? It does when the system only performs a narrow procedural task, improves the result of a human activity, detects patterns without replacing human assessment, or does preparatory work. Profiling of natural persons always stays high-risk. If you rely on the exemption, document the reasoning and register the system under Article 49(2).
If the answer to question 2 is yes and to question 3 is no, continue. Otherwise you are finished with Article 43, and your remaining work is Article 50 transparency, covered in our compliance guide.
Step 2: Pick the route (10 minutes)
Article 43 gives two procedures. Which one applies depends on the Annex III item, not on your company size.
| Your system | Procedure | Who checks |
|---|---|---|
| Annex III, points 2 to 8 (everything except biometrics) | Annex VI, internal control | You |
| Annex III, point 1 (biometrics), harmonised standards fully applied | Annex VI or Annex VII, your choice | You, or a notified body |
| Annex III, point 1, standards not or only partly applied | Annex VII | A notified body listed in NANDO |
| Product covered by Annex I (machinery, medical devices, lifts) | The sectoral procedure, with the AI Act requirements added | The body that already certifies the product |
Most SME systems land in the first row. The rest of this checklist is the Annex VI route.
Step 3: Open the document register (the checklist)
Annex VI asks you to verify three things: that your quality management system meets Article 17, that your technical documentation meets Annex IV, and that the way you actually designed and built the system matches that documentation. Everything you will verify lives in these files.
| # | Document | Article | Free starting point |
|---|---|---|---|
| 1 | Risk classification decision (your Step 1 answers) | Art. 6, Annex III | This post |
| 2 | Intended purpose and instructions for use | Art. 13 | Your product sheet, rewritten |
| 3 | Risk management file | Art. 9 | A register with likelihood, severity, mitigation, owner |
| 4 | Data governance record: sources, labelling, bias checks | Art. 10 | One datasheet per dataset |
| 5 | Technical documentation | Art. 11, Annex IV | The SME simplified form of Art. 11(1) |
| 6 | Logging design: which events, kept how long | Art. 12 | A one-page specification |
| 7 | Human oversight measures | Art. 14 | Our Article 14 guide |
| 8 | Accuracy, robustness and cybersecurity tests | Art. 15 | Your test reports, with numbers |
| 9 | Quality management system | Art. 17 | Policy, process map, competence matrix, audit log |
| 10 | Post-market monitoring plan | Art. 72 | One page until the Commission template is published |
| 11 | Serious incident procedure (15-day reporting) | Art. 73 | One page with names and phone numbers |
| 12 | EU declaration of conformity | Art. 47, Annex V | The nine fields listed below |
| 13 | CE marking and EU database registration | Arts. 48, 49 | Free, done last |
Copy the table into your spreadsheet, add an owner and a status column, and the register exists. Article 11(1) already lets SMEs and start-ups use the simplified technical documentation form; the Omnibus extended it to small mid-caps (Cloud Security Alliance note).
Step 4: Run the three Annex VI checks
Do them in order and keep the evidence of each check in the register.
- Quality management check. Walk Article 17(1)(a) to (m) and point each letter at a document from row 9. Missing letters become tasks. Article 17(2) says the system must be proportionate to your size, so a ten-person company documents ten-person processes.
- Technical documentation check. For every requirement in Articles 9 to 15, name the page in the Annex IV file that shows it is met. If you cannot name a page, the requirement is not met yet.
- Design consistency check. Compare what the documentation says with what the repository, the tickets and the test logs show. Differences are fixed on one side or the other, and the fix is dated.
When all three pass, draw up the declaration of conformity (Annex V: system name and version, provider name and address, statement of sole responsibility, reference to the Regulation, standards applied, notified body if any, place, date, signature), affix the CE marking, and register the system in the EU database before it goes on the market. Check the Official Journal for harmonised standards before you finalise: when one is listed, applying it gives presumption of conformity under Article 40.
The plan, working back from 2 December 2027
| When | What | Register rows |
|---|---|---|
| September to October 2026 | Steps 1 and 2, register opened, owners named | 1, 2 |
| November 2026 to February 2027 | Risk file, data governance, logging spec, oversight measures | 3, 4, 6, 7 |
| March to June 2027 | Annex IV documentation, test campaign, QMS written down | 5, 8, 9 |
| July to August 2027 | Three Annex VI checks, gaps closed | 10, 11 |
| September 2027 | Declaration, CE marking, database registration | 12, 13 |
| October to November 2027 | Reserve |
The first 30 minutes, today
- Minutes 0 to 10: list your systems in the spreadsheet with one sentence of intended purpose each.
- Minutes 10 to 20: run each one through the Commission’s free AI Act compliance checker on the Single Information Platform and note the result in row 1.
- Minutes 20 to 30: ask a local model for a first draft of rows 2 and 3. Prompt: “Here is a description of my AI system: [paste]. Write a 120-word intended purpose statement in the style of EU product documentation, then list ten foreseeable risks to health, safety or fundamental rights, each with a likelihood and a severity from 1 to 5.” Correct everything; the model does not know your system.
Honest limits
- Notified bodies designated for the AI Act are still few. If you are in the biometrics row, contact one this quarter, not next year.
- The register proves nothing by itself. The three checks in Step 4 are the assessment; the files are only what you check.
- This is a procedure, not legal advice. One hour with a lawyer once the register is full is money well spent.
Next steps
- Classify first: AI risk classification under the EU AI Act.
- Design row 7 properly: Human oversight, Article 14.
- The whole picture: EU AI Act compliance guide 2026 and our EU AI Act hub.
- Grab the template: Conformity assessment checklist (Article 43).
- Grab the template: AI literacy training plan (Article 4).
Work with us
We open the document register with clients in two half-day sessions, on their own machines and with their own data, so nothing about the system leaves the building. If you want the second session with us, get in touch or read how our consulting works.