Most teams building a high-risk AI system under the AI Act assume they will need an external auditor to sign it off. For the great majority of Annex III systems, that is simply wrong — and the wrong assumption costs both money and months.
The AI Act’s conformity assessment machinery is where a lot of budget gets misallocated. Vendors and consultancies have an incentive to make it sound like every high-risk system needs a notified body — an accredited third party — to certify it, because that is a service someone can sell. The regulation says something much narrower. For the majority of Annex III use cases, the provider assesses its own system, declares conformity, and affixes the CE marking without any third party involved at all. Knowing which route your system actually falls under is the difference between a documentation exercise you run internally and a certification engagement with an external timeline you do not control.
The default is self-assessment, not certification
Article 43 sets out two procedures for stand-alone high-risk systems. The first, in Annex VI, is conformity assessment based on internal control: the provider verifies its own compliance, with no notified body involved. The second, in Annex VII, brings in a notified body to assess the quality management system and the technical documentation. The critical point is which systems get which route.
Free · 4 minutes
Do you know where AI is already being used in your business — and what it can see?
Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.
For Annex III points 2 to 8 — that is, critical infrastructure, education, employment and worker management, access to essential services including credit scoring, law enforcement, migration and border control, and administration of justice — the procedure is Annex VI, internal control. No notified body. This is the overwhelming majority of the high-risk systems a typical regulated firm will build or deploy: the recruitment screener, the credit-decision model, the fraud-triage engine. All of them self-assess.
The exception sits in Annex III point 1: biometrics — remote biometric identification, biometric categorisation, and emotion recognition. Here the provider gets a choice, but a conditional one. Where harmonised standards or common specifications exist and the provider has applied them in full, it may still use Annex VI internal control. Where the provider has not applied those standards, has applied only part of them, or the standards do not exist, it must go the Annex VII route through a notified body. In other words, for biometric systems the availability and application of standards is the switch that decides whether you self-assess or get audited.
That switch matters more than it looks, because the harmonised standards underpinning the AI Act are still being developed by CEN-CENELEC and have been running behind schedule. If you are building a biometric system and cannot point to a published standard you have applied in full, plan on the notified body route by default rather than hoping to self-assess.
Product-embedded systems are a different regime entirely
There is a third case that catches people out. Where a high-risk AI system is a safety component of a product already covered by the Union harmonisation legislation listed in Annex I — medical devices, machinery, lifts, radio equipment and the rest — the AI conformity assessment is folded into the conformity assessment that product already has to undergo under its own sectoral law. You do not run a separate AI Act procedure; the AI requirements are checked within the existing notified-body process for that product. These systems also have a later start date: their obligations apply from 2 August 2028, against 2 December 2027 for stand-alone Annex III systems. If your AI is embedded in a regulated product, your conformity path is defined by that product’s directive or regulation, not by Annex VI or VII in isolation.
What the self-assessment audit trail has to contain
Internal control is not lighter-touch in substance; it is lighter-touch only in that nobody external checks it before market. The evidence you have to hold is the same evidence a notified body would demand. Under Annex VI, the provider must be able to show:
- A quality management system meeting Article 17 — documented policies, procedures and instructions covering the whole lifecycle, not an ISO certificate borrowed from elsewhere.
- The technical documentation of Annex IV — the system’s design, its intended purpose, its data governance, its risk management, its performance and its human-oversight measures, kept current as the system changes.
- Evidence that the technical documentation and the design of the system agree — that what is documented is what is deployed.
- A signed EU declaration of conformity under Article 47, retained for ten years and available to authorities on request.
- The CE marking under Article 48, and registration of the system in the EU database under Article 49 before it goes on the market or into service.
The self-assessment does not mean less work. It means you own the assurance. A market surveillance authority can ask for any of the above after the fact, and “we self-assessed” is only a defence if the file behind it is real. The discipline here is close to the one behind deciding when a DPIA is genuinely required: the label is cheap; the documented reasoning is the thing that survives scrutiny.
What the notified body route adds
Where Annex VII applies, a notified body assesses your quality management system against Article 17 and examines the technical documentation, with access to the training, validation and testing datasets, and the right to run its own tests. If satisfied, it issues a Union technical documentation assessment certificate. That certificate is valid for up to four years for Annex III systems and up to five for Annex I products, renewable only on re-assessment, and the notified body runs periodic surveillance audits in between. This is what changes the economics: an external timeline, an accreditation-body queue, dataset access for a third party, and a certificate that has to be maintained rather than earned once. If your system is one that can self-assess, you avoid all of it.
Self-assessment is not one-and-done
Both routes re-trigger on substantial modification. A change that affects the system’s compliance with the requirements, or a change to its intended purpose beyond what the provider originally declared, obliges a fresh conformity assessment. Under internal control that means re-running your own procedure and updating the declaration; under the notified body route it means going back to the body to decide whether a new assessment or a supplement to the certificate is needed. For a model that is retrained, re-tuned or repurposed on a regular cadence, this is not a corner case — it is the operating rhythm. The conformity file has to be a living artefact tied to your release process, not a document produced once for launch.
Which you actually need, and when to decide it
For most Annex III systems the answer is Annex VI: you assess yourself, and the work is building the Article 17 quality management system and the Annex IV documentation to a standard that would survive a supervisor reading them cold. Reserve the notified body assumption for biometric systems without applied harmonised standards, and for AI embedded in Annex I products, where the product’s own regime governs. Decide this at design time, because it determines whether you are resourcing an internal documentation programme or procuring an external assessment with a lead time you cannot compress.
The dates make the timing non-negotiable. Following the Digital Omnibus adopted by the Council in June 2026, stand-alone Annex III obligations apply from 2 December 2027 and product-embedded systems from 2 August 2028. That sounds distant until you count backwards through a build. The deferral is not the reprieve it looks like: a defensible Annex IV file and a working quality management system are not things you assemble in the last quarter before a deadline. And if the honest answer to what you are actually building is a biometric system with no standard to lean on, the notified body queue is a dependency you want to be in before everyone else building high-risk AI arrives at the same door.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming