Skip to main content
SME Conformity Assessment Checklist for the EU AI ActEU AI Act & GPAI
6 min readFor AI Governance Leaders

SME Conformity Assessment Checklist for the EU AI Act

If you're a small or medium-sized enterprise (SME) preparing for the EU AI Act conformity assessment, you need a structured way to track your progress. This checklist provides that structure.

Purpose of the Template

This checklist helps SME teams prepare for conformity assessment under the EU AI Act's high-risk AI system requirements. It covers Technical Documentation (Annex IV), quality management obligations, and specific simplifications available to small and microenterprises.

Use this to:

  • Track your readiness across all required elements
  • Identify gaps before engaging a notified body or submitting for self-assessment
  • Utilize the simplified documentation forms the European Commission will develop for SMEs
  • Document which simplifications you're claiming under the Act's proportionality provisions

This isn't a replacement for legal review. It's a working document for your technical and compliance teams to coordinate preparation.

Prerequisites

Before using this checklist, confirm:

  1. Your system qualifies as high-risk under Annex III or meets the criteria in Article 6. If you're building on a general-purpose AI model, your downstream application's risk category determines your obligations, not the model's classification.

  2. You've determined your enterprise size under EU definitions: microenterprise (fewer than 10 employees, turnover/balance sheet under €2 million), small enterprise (fewer than 50 employees, under €10 million), or medium-sized (fewer than 250 employees, under €50 million turnover or €43 million balance sheet).

  3. You know which simplifications apply to you. Microenterprises can comply with certain quality management elements in a simplified manner. Small and microenterprises will use the Commission's simplified technical documentation forms once published.

  4. You've identified your conformity assessment route: self-assessment with internal controls, or third-party notified body assessment. Most high-risk systems require notified body involvement unless you're using harmonized standards for safety components.

Checklist Template

Copy this into your project management system or maintain it as a living spreadsheet. Assign owners and target dates for each section.

Section 1: Technical Documentation (Annex IV)

Status codes: Not Started / In Progress / Complete / N/A (with justification)

  • General description of the AI system: Intended purpose, instructions for use, version information, integration architecture
  • Detailed description of system elements: Data governance measures, computational resources, design specifications, monitoring mechanisms
  • Development process documentation: Design choices, assumptions, data requirements, human oversight provisions
  • Risk management system description: Risk identification methodology, risk mitigation measures, residual risk assessment
  • Training, validation, and testing datasets: Data provenance, representativeness analysis, annotation quality procedures, bias assessment
  • Training methodology: Computational resources used, training duration, optimization methods, performance metrics
  • Validation and testing procedures: Validation evidence including test protocols, performance benchmarks, edge case testing, reproducibility measures
  • Cybersecurity measures: Protection against unauthorized access, data poisoning safeguards, model limitations and use restrictions
  • Change management process: Version control, update procedures, post-market monitoring integration

SME-specific note: If you're a small or microenterprise, mark which sections you're completing using the Commission's simplified forms. As of now, those forms are still in development, but your documentation structure should align with Annex IV requirements in anticipation.

Section 2: Quality Management System

  • Compliance strategy and regulatory compliance procedures: How you ensure ongoing AI Act conformity
  • Techniques and procedures for design, control, and verification: Your development lifecycle controls
  • Post-market monitoring system: Incident tracking, performance drift detection, user feedback loops
  • Reporting procedures: Serious incident reporting to market surveillance authorities, documentation of corrective actions
  • Record-keeping system: Automatically generated logs (minimum 6 months or as required by sector law), manual records of decisions and actions

Microenterprise simplification: If you qualify as a microenterprise, document which quality management elements you're addressing in simplified form. You still need the substance, but you can streamline the formality.

Section 3: Conformity Assessment Preparation

  • Harmonized standards applied: List specific standard numbers (e.g., EN standards once published) and which requirements they cover
  • Common specifications applied: If harmonized standards don't exist or don't fully cover your system, document which common specifications you're following
  • Gaps and alternative measures: For any requirements not covered by standards or specifications, describe your alternative compliance approach
  • Declaration of conformity draft: Prepare the declaration structure even if you can't finalize it yet
  • CE marking plan: Where and how you'll affix the marking, including digital placement if applicable

Section 4: SME-Specific Support Utilization

  • Regulatory sandbox participation: If applicable, document your sandbox plan, testing results, and compliance demonstrations from sandbox activity
  • Fee proportionality request: If you're engaging a notified body, document your enterprise size and request proportional fee structure
  • Member State guidance accessed: List which dedicated communication channels you've used, queries submitted, guidance received
  • Training activities completed: Document any Member State awareness-raising or training programs your team has attended

Section 5: Vendor and Supply Chain

  • Foundation model provider documentation: If you're building on a general-purpose AI model, collect the provider's transparency documentation and instructions for use
  • Third-party component inventory: List all outsourced models, APIs, or AI components, with vendor due diligence records
  • Data source documentation: For training and testing data from external sources, document provenance and licensing
  • Subcontractor quality controls: If you're outsourcing development or validation work, document oversight measures

Customization

Adjust for your system's complexity: If you're building a straightforward classification system with a well-understood use case, you'll complete some sections quickly. If you're integrating multiple AI components or operating in a heavily regulated sector (medical devices, critical infrastructure), you'll need deeper documentation in Sections 1 and 2.

Map to your existing processes: Don't create parallel documentation. If you already maintain design decision logs, test reports, or incident tracking systems, reference those systems in the checklist and note where AI Act-specific elements need to be added.

Align with sector-specific requirements: If you're in financial services, healthcare, or another regulated domain, cross-reference this checklist with your existing compliance frameworks (e.g., SR 11-7 for model risk management in banking). The AI Act's requirements often overlap with existing validation and documentation obligations.

Track sandbox benefits: If you're participating in a regulatory sandbox, use Section 4 to document how sandbox testing reduces your assessment burden. The documentation you produce in the sandbox can directly support your conformity assessment, and sandbox participation provides protection from administrative fines if you follow the agreed plan in good faith.

Scale your quality management system: Microenterprises should focus on demonstrating that the substance of quality management is present, even if you don't have the formal processes a larger organization would maintain. For example, you might have a shared spreadsheet for post-market monitoring instead of an enterprise monitoring platform. That's acceptable under the proportionality principle.

Validation Steps

Before you consider this checklist complete:

  1. Cross-check against Annex IV: Open the AI Act text and verify you've addressed every element in Annex IV, even if your answer is "not applicable" with justification.

  2. Review your instructions for use: Can a deployer understand your system's intended purpose, limitations, and human oversight requirements from your documentation? If not, Section 1 isn't complete.

  3. Test your incident reporting process: Walk through a hypothetical serious incident. Can you identify it, document it, and determine whether it requires reporting to authorities within the required timeframes?

  4. Verify your log retention: Check that your system automatically generates and retains logs for at least six months (or longer if sector-specific law requires it). Spot-check that logs are accessible and interpretable.

  5. Confirm your SME status documentation: Make sure you can prove your enterprise size with financial records or employee counts. You'll need this to claim fee proportionality and simplified procedures.

  6. Engage early with your Member State's dedicated channel: Before you finalize your conformity assessment approach, submit key questions through your Member State's SME communication channel. Their guidance can help you avoid rework.

The AI Act mentions SMEs 38 times because the drafters recognized that small teams can't carry the same compliance overhead as large organizations. This checklist helps you take advantage of those provisions while still meeting the substance of high-risk AI system requirements. Use it as a living document, update it as the Commission publishes simplified forms and as Member States clarify their implementation approaches, and treat it as a coordination tool for your entire team, not just a compliance exercise.

You Might Also Like