Skip to main content
Category: Compliance & Audit

Declaration of Conformity

Also known as: DoC, EU Declaration of Conformity, Supplier's Declaration of Conformity
Simply put

A Declaration of Conformity is a formal statement, typically issued by a manufacturer or its authorized representative, asserting that a product meets the relevant regulatory or standards-based requirements that apply to it. It is often a self-issued document, meaning the party placing the product on the market takes responsibility for the claim, sometimes supported by test results or other evidence. The specific form, legal status, and requirements vary by jurisdiction and by the regulatory framework involved.

Formal definition

A Declaration of Conformity (DoC) is a declaration by which a manufacturer, or the manufacturer's representative, attests that a product meets all relevant applicable requirements. In some regimes it functions as a supplier's (first-party) attestation of conformity, as described in ISO conformity assessment materials, where the supplier declares compliance provided supporting test results exist. In the EU context, an EU declaration of conformity is described as a mandatory legal document that the responsible party must sign to declare that products comply with applicable EU requirements, identifying the relevant regulations and directives; the legal weight and mandatory nature are therefore jurisdiction- and framework-specific and should not be assumed to apply outside the regime in which they are defined. This entry does not resolve how DoC requirements may map onto AI systems under specific frameworks such as the EU AI Act, and readers should consult the governing instrument for scope, required content, and effective dates rather than treating any single national or regional formulation as universal.

Why it matters

A Declaration of Conformity is one of the primary mechanisms by which regulators shift responsibility for compliance onto the party placing a product on the market. Because a DoC is often self-issued, the manufacturer or its authorized representative is the one attesting that the product meets applicable requirements, which means the document is both a compliance artifact and an accountability record. For compliance officers and auditors, this makes the DoC a focal point: it identifies which regulations and directives the responsible party claims to have satisfied, and it typically presupposes that supporting evidence, such as test results, exists to back the claim.

The legal weight of a DoC varies by jurisdiction and framework, and this variability is itself a source of risk. In the EU context, an EU declaration of conformity is described as a mandatory legal document that the responsible party must sign, whereas in other regimes—such as the U.S. FCC's supplier's Declaration of Conformity process referenced in ISO conformity assessment materials—the document functions as a first-party attestation subject to that regime's specific rules. Treating one jurisdiction's formulation as universal is a common error that can leave products non-compliant in markets where different content, signatures, or supporting evidence are required.

For those working on AI systems, it is important not to assume that DoC requirements defined for physical products or under general product safety regimes translate directly onto AI systems under any particular framework. This entry does not resolve how DoC obligations may map onto AI systems under specific instruments, and the governing instrument should be consulted for scope, required content, and effective dates. The practical significance of a DoC lies in its role as a documented, signed assertion of compliance; it manages and evidences compliance responsibility but does not by itself guarantee that a product is free of defects or risk.

Who it's relevant to

Compliance officers and regulatory specialists
These professionals are often responsible for ensuring a Declaration of Conformity is prepared, identifies the correct applicable regulations and directives, and is signed by the appropriate responsible party. Because the DoC is frequently self-issued, they must confirm that the underlying compliance claim is supportable and that the document meets the content and legal-status requirements of the specific jurisdiction and framework involved.
Auditors and assurance professionals
Auditors treat the DoC as a documented, signed assertion of compliance and typically examine whether supporting evidence—such as test results—exists behind the declaration. The DoC serves as a reference point for tracing which requirements the responsible party claims to have met, though its evidentiary value depends on the framework under which it was issued.
Manufacturers and their authorized representatives
As the parties who typically issue and sign a Declaration of Conformity, manufacturers and their authorized representatives take on responsibility for the compliance claim when they place a product on the market. They should confirm the required form, content, and legal status applicable in each target jurisdiction rather than assuming one region's formulation applies universally.
Legal and policy professionals
Legal specialists assess the binding nature and consequences of a DoC, which vary by regime—for example, an EU declaration of conformity is described as a mandatory legal document, whereas other regimes may treat a supplier's declaration differently. They are also positioned to evaluate how, or whether, DoC obligations extend to AI systems under a given governing instrument, a mapping this entry does not resolve.

Inside DoC

Manufacturer or provider identification
Details identifying the entity issuing the declaration and, where applicable, its authorized representative. In the EU AI Act context, this is typically the provider of the AI system taking responsibility for the declared conformity.
Product or system identification
Information sufficient to identify the specific AI system or product to which the declaration applies, so the declaration can be traced to the exact item placed on the market or put into service.
Statement of conformity
An explicit assertion that the identified system meets the applicable requirements. This is a claim made under the responsibility of the issuer rather than an independent certification, and its exact scope depends on the framework invoked.
Reference to applicable requirements
Citation of the legal instrument, harmonized standards, or specifications against which conformity is declared. Under the EU AI Act, this commonly references the relevant requirements for the system's risk classification, though the specific obligations vary by system type.
Reference to conformity assessment procedure
Where relevant, an indication of the assessment route followed, which in some cases is an internal self-assessment by the provider and in others may involve a third-party body. The applicable route depends on the system and framework.
Signature and accountability
Identification of the person signing on behalf of the issuer, establishing who bears responsibility for the declaration's accuracy. Issuing a declaration is typically the act by which the provider assumes legal responsibility for stated conformity.

Common questions

Answers to the questions practitioners most commonly ask about DoC.

Does issuing a Declaration of Conformity mean an independent regulator has certified or approved the product?
No. As commonly used in EU product legislation contexts, a Declaration of Conformity is typically a self-declaration by the manufacturer (or its authorized representative) asserting that a product meets applicable requirements. It should not be read as a regulator's certification or approval. In some regimes a third-party conformity assessment body may be involved in earlier steps, but the declaration itself is generally the responsibility of the party placing the product on the market, not an endorsement by a supervisory authority.
Is a Declaration of Conformity the same thing as ongoing proof that a system remains compliant?
Not exactly. A Declaration of Conformity typically attests to conformity at a particular point, generally when the product is placed on the market or put into service. It should not be conflated with continuous or ongoing assurance of compliance. Where obligations extend over a product's lifecycle, separate monitoring, updating, and record-keeping measures are usually needed, and the declaration may require review or reissuance if the product or the applicable requirements change. This entry does not address the specific triggers for reissuance, which are framework-dependent.
Who is responsible for drawing up and signing a Declaration of Conformity?
Responsibility typically rests with the party that places the product on the market or puts it into service, commonly the manufacturer or its authorized representative, depending on the applicable framework. The declaration is generally signed by someone with authority to bind that party. Organizations should confirm the specific responsible role under the particular legal instrument they are subject to, as allocations of responsibility differ across regimes and this entry does not resolve those jurisdiction-specific details.
What information does a Declaration of Conformity generally need to contain?
The precise required contents depend on the applicable legal instrument, so organizations should consult the governing framework rather than relying on a single template. In many product-conformity regimes, such declarations commonly identify the product, the responsible party, the relevant requirements or standards relied upon, and a statement of conformity, together with a signature and date. Because required elements vary and can change, treat any generic checklist as a starting point rather than an authoritative list.
How should an organization retain and make available a Declaration of Conformity?
In many frameworks the responsible party is expected to keep the declaration and its supporting technical documentation available for a defined period and to provide it to authorities on request. The specific retention period, format, and availability obligations are framework-dependent and are out of scope for this entry, so organizations should verify them against the instrument that applies to them. As a practical matter, maintaining traceable links between the declaration and the underlying evidence supports later inquiries.
How does a Declaration of Conformity fit within broader AI governance and model risk management activities?
A Declaration of Conformity is generally a compliance artifact tied to placing a product on the market, and it can serve as an output that governance and risk processes feed into. It does not, on its own, constitute an AI governance program or a model risk management framework, nor does it eliminate risk. Organizations typically use governance structures and risk controls to generate and substantiate the evidence behind such a declaration, while treating the declaration as one control among many rather than a substitute for ongoing oversight.

Common misconceptions

A Declaration of Conformity is an independent certification that the system is safe or compliant.
In many frameworks a declaration is a statement made by the provider under its own responsibility, not verification by an external authority. Some conformity assessment routes involve self-assessment without a third party. It attests to a claim of conformity; it does not by itself constitute independent proof and does not eliminate residual risk.
A Declaration of Conformity has the same meaning and scope across all jurisdictions and regulatory regimes.
The specific contents, legal weight, and required assessment procedures depend on the instrument invoked and its jurisdiction. A declaration issued under the EU AI Act is scoped to that regime's requirements and should not be assumed interchangeable with declarations under other regulations or voluntary standards.
Once a Declaration of Conformity is issued, the provider's compliance obligations are complete.
A declaration typically reflects conformity at the point of issuance. It does not remove ongoing obligations such as monitoring, and model performance can degrade over time. The declaration is one control within a broader governance and risk management process, not a terminal event.

Best practices

Identify precisely which legal instrument or standard the declaration is issued under, and confirm its jurisdiction and scope before drafting, rather than assuming a single universal format applies.
Ensure the specific AI system, its version, and its intended purpose are unambiguously identified so the declaration is traceable to the exact item placed on the market or put into service.
Confirm the applicable conformity assessment route before issuing, distinguishing self-assessment routes from those requiring third-party involvement, and document which was followed.
Maintain supporting technical documentation and evidence that substantiate the declared conformity, since the declaration is a claim made under the issuer's own responsibility.
Establish a clear line of accountability by assigning a specific authorized signatory who understands that signing assumes legal responsibility for the stated conformity.
Treat the declaration as a point-in-time statement and pair it with ongoing monitoring and change-management processes, recognizing that it does not eliminate residual risk or cover later modifications.