AI Act Conformity Assessment: Internal Control vs Notified Body
Ready 4 AI Act · April 9, 2026 · Last updated July 31, 2026

What a conformity assessment is
An EU AI Act conformity assessment is the procedure by which a provider demonstrates that a high-risk AI system meets all applicable requirements in Chapter III, Section 2. The result is a Declaration of Conformity and a CE marking.
Two routes: internal control (Annex VI) and notified body involvement (Annex VII).
The default rule
For most Annex III high-risk systems — those high-risk because of their use case (HR, education, credit, essential services) — the default is internal control under Annex VI. No third party required.
When a notified body is required
- Biometric systems under Annex III(1) where harmonised standards are not fully applied.
- Annex I products — AI as a safety component of products already regulated by harmonised EU legislation (medical devices, machinery, toys). The sectoral conformity route applies.
- Biometric systems without harmonised standards.
The decision path
- Annex I regulated product? → Sectoral route integrating AI Act obligations.
- Annex III(1) biometric? → Notified body unless harmonised standards fully applied.
- Other Annex III? → Internal control.
- Substantial modification? → Redo the assessment.
What internal control involves
- Confirm the quality management system (Article 17) is in place.
- Verify the technical documentation (Article 11 and Annex IV) is complete.
- Verify the design and development process matches the documentation.
- Sign the EU Declaration of Conformity and affix CE marking.
- Register the system in the EU database (Article 71).
What notified body involvement adds
- Independent assessment of the QMS and technical documentation.
- A certificate valid up to five years, subject to surveillance.
- Higher direct cost, smoother path in regulated verticals.
Substantial modification
Article 43(4): a substantial modification after placing on the market triggers a new assessment. Continuous learning within a pre-defined and documented performance range does not count.
Common mistakes
- Assuming a notified body is always required.
- Skipping EU database registration — a hard prerequisite.
- Forgetting Article 49 deployer registration duties for public authorities.
- Treating the Declaration of Conformity as a one-time document.
Related: High-risk AI systems guide · EU AI Act overview · Free readiness assessment
Reviewed by Ready 4 AI Act EU - Editorial team. This article is journalistic information, not legal advice.
Not sure where you stand?
Take the free readiness assessment and get a personalised report.
Start free assessment