Conformity Assessment Roadmap (Art. 43)
From Compliance Chaos to Smooth EU AI Act Conformity: A Step-by-Step Guide for European SMEs
As a small to medium-sized enterprise (SME) in Europe, navigating the complex landscape of artificial intelligence (AI) regulations can be daunting. The EU AI Act, with its 43 articles and numerous annexes, demands attention to detail and meticulous planning to ensure compliance. In this article, we’ll break down the Conformity Assessment Roadmap (Art. 43), providing you with a clear understanding of the process and practical examples to guide your journey.
Route Selection: The Key to Success
The EU AI Act divides high-risk AI systems into two categories for conformity assessment purposes: those that fall under Annex I, Section A, and all others listed in Annex III. If your system belongs to the former, you’ll need to involve a Notified Body (Route B). For everyone else, the journey begins with Internal Control (Route A).
Route A: Internal Control (Annex VI)
This route involves self-assessment through four phases:
Phase 1 — Preparation (Weeks 1–4)
Gather essential documentation, including your company’s organizational structure, quality management system (QMS), and technical documentation. This groundwork will serve as the foundation for your internal assessment.
Practical Example: Establish a centralized documentation repository using tools like Docebo or similar platforms to ensure easy access and update tracking.
Phase 2 — Evidence Collection and Documentation (Weeks 4–12)
Gather evidence of your system’s compliance with EU AI Act requirements. This includes testing, validation, and certification processes.
Key Takeaway: Ensure that all documentation is accurate, up-to-date, and easily accessible for audit purposes.
Phase 3 — Internal Assessment (Weeks 12–16)
Evaluate your collected evidence against the EU AI Act’s criteria, identifying areas of improvement or compliance gaps. This phase requires meticulous attention to detail and a systematic approach.
Practical Example: Utilize risk management tools to assess potential non-compliance risks and prioritize corrective actions.
Phase 4 — Declaration and Registration (Weeks 16–18)
Submit your declaration of conformity with the EU AI Act, providing detailed documentation of your system’s compliance status. This is a critical step in ensuring transparency and accountability.
Practical Example: Leverage digital platforms to streamline the submission process, reducing administrative burdens.
Route B: Conformity Assessment Involving Notified Body (Annex VII)
In cases where Annex I, Section A applies, you’ll need to engage with a Notified Body for an external audit. This route involves several steps:
When Must You Use a Notified Body?
If your AI system falls under Annex III and meets the criteria for high-risk systems, involving a Notified Body is mandatory.
Practical Example: Identify Notified Bodies in your sector and initiate contact to discuss assessment requirements.
Selecting a Notified Body
Choose a Notified Body based on their expertise in your field and reputation. This decision is crucial for ensuring a smooth and effective conformity assessment process.
Key Takeaway: Research the Notified Body’s experience with similar systems and assess their communication style and approach.
Notified Body Assessment Phases
The external audit will involve several phases, from documentation review to on-site assessments, culminating in a report detailing your system’s compliance status.
Third-Party Assessment Triggers
In some cases, even if you’ve opted for Route A, an external assessment may be triggered due to changes in your system or other factors. Being aware of these triggers will help you prepare and avoid potential non-compliance issues.
Practical Example: Develop a change management process that includes notifications to relevant stakeholders and documentation updates as necessary.
Conformity Assessment Timeline Tracker
To ensure compliance, keep track of the various timelines associated with each phase of your conformity assessment journey. This can be achieved through digital tools or project management software.
Key Takeaway: Regularly review and update your timeline tracker to stay on schedule and address any issues promptly.
Related Templates
To streamline your conformity assessment process, access related templates from VORLUX AI for guidance on documentation, risk management, and more.
Get Started with Your Conformity Assessment Journey Today
Compliance with the EU AI Act demands attention to detail and a structured approach. By following this roadmap and staying informed about regulatory updates, you’ll be well-equipped to navigate the complexities of AI compliance in Europe.
Start your journey now by exploring VORLUX AI’s resources and consulting services for tailored guidance on your conformity assessment needs.