How to Use This Checklist
This 55-point checklist covers the requirements for high-risk AI systems under the EU AI Act. The main compliance deadline is 2 December 2027, postponed from the original 2 August 2026 date by the EU's 2026 Digital Omnibus. Score each item: 0 (Not started), 1 (In progress), 2 (Implemented). Focus on risk classification first — if your system isn't high-risk, many requirements don't apply.
Phase 0: Risk Classification (5 items)
Determine Your Obligations
- Complete AI system inventory — all AI systems deployed or in development are catalogued
- Each AI system classified against Annex III risk categories (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice)
- Prohibited AI practices reviewed — confirm no systems fall under Article 5 prohibitions
- Role determined for each system — are you provider, deployer, importer, or distributor?
- GPAI model obligations assessed — do any systems use or provide general-purpose AI models?
Phase 0 Score: ___ / 10
Phase 1: Risk Management System (Article 9) — 8 items
- Risk management system established as a continuous, iterative process throughout the AI system lifecycle
- Known and reasonably foreseeable risks identified and documented
- Risks estimated and evaluated, including risks from reasonably foreseeable misuse
- Risk mitigation measures adopted — technical, organisational, or both
- Residual risks documented and communicated to deployers
- Testing procedures defined to ensure risk management measures are effective
- Risk management system reviewed and updated when significant changes occur
- Risk management documentation maintained for regulatory inspection
Phase 1 Score: ___ / 16
Kubernetes Recipes
Practical guide for container orchestration and deployment — hands-on patterns you can use today.
View on Amazon →Phase 2: Data Governance (Article 10) — 7 items
- Training, validation, and testing datasets are subject to appropriate data governance practices
- Data relevance, representativeness, and accuracy assessed and documented
- Possible biases in datasets identified and addressed
- Data gaps or shortcomings identified with mitigation measures
- Special category data processing (Article 10(5)) justified and documented where used for bias detection
- Statistical properties of datasets documented, including intended purpose and limitations
- Data retention policies defined and implemented for training data
Phase 2 Score: ___ / 14
Phase 3: Technical Documentation (Article 11) — 7 items
- General description of the AI system including intended purpose, developer identity, and system version
- Detailed description of system elements: algorithms, data, training methodologies, key design choices
- Information on monitoring, functioning, and control of the system
- Description of the computational resources used (hardware, compute, training time)
- Validation and testing procedures documented with results
- Cybersecurity measures documented
- Technical documentation kept up-to-date throughout the system lifecycle
Phase 3 Score: ___ / 14
Automating Azure DevTest Labs
Automate lab management and integrate with CI/CD pipelines.
Start on Pluralsight →Phase 4: Record-Keeping & Logging (Article 12) — 5 items
- Automatic logging of events enabled throughout the AI system's operation
- Logging captures: operating period, reference database, input data, identity of persons involved in verification
- Log retention period defined (appropriate to intended purpose, at least 6 months unless regulated otherwise)
- Logs accessible to deployers for monitoring and post-market surveillance
- Logging design enables traceability of AI system decisions
Phase 4 Score: ___ / 10
Phase 5: Transparency & Information (Article 13) — 5 items
- Instructions for use provided to deployers — clear, accessible, and comprehensive
- Intended purpose and foreseeable misuse scenarios documented
- Level of accuracy, robustness, and cybersecurity declared with metrics
- Known limitations communicated, including conditions where system may not perform as intended
- Human oversight measures documented in instructions for use
Phase 5 Score: ___ / 10
AI Readiness Checklist
50-point interactive checklist covering strategy, data, infrastructure, governance, and people. Score your organisation's AI readiness.
Get Free Checklist →Phase 6: Human Oversight (Article 14) — 5 items
- Human oversight measures designed into the system (human-in-the-loop, human-on-the-loop, or human-in-command)
- Oversight persons can fully understand the AI system's capabilities and limitations
- Oversight persons can correctly interpret outputs and decide not to use the system
- Ability to override or reverse AI system decisions is implemented
- Ability to interrupt or stop the AI system via a "stop" button or similar procedure
Phase 6 Score: ___ / 10
Phase 7: Accuracy, Robustness & Cybersecurity (Article 15) — 5 items
- Accuracy levels declared and tested with appropriate metrics and benchmarks
- System is resilient to errors, faults, and inconsistencies in the environment
- Technical redundancy solutions implemented (including backup and fail-safe plans)
- Cybersecurity measures protect against vulnerabilities, manipulation of training data, model poisoning, and adversarial examples
- System resilient to attempts to alter use or performance by exploiting vulnerabilities
Phase 7 Score: ___ / 10
Phase 8: Conformity Assessment & Market Placement (Articles 16-17, 43-49) — 8 items
- Conformity assessment procedure identified (self-assessment for most, third-party for biometric and critical infrastructure)
- Quality management system established covering compliance strategy, design control, testing, and post-market monitoring
- EU declaration of conformity drawn up
- CE marking affixed to the AI system
- Registration in the EU database for high-risk AI systems completed
- Post-market monitoring system established and documented
- Serious incident reporting procedure established (reporting to market surveillance authorities)
- All documentation retained for 10 years after the AI system is placed on the market
Phase 8 Score: ___ / 16
Scoring Guide
- 90-110: Compliance-ready. Proceed to conformity assessment.
- 70-89: Strong foundation. Address gaps in Phases 3-4 (documentation, logging) and Phase 8 (conformity).
- 50-69: Significant work needed. Prioritise Phase 1 (risk management) and Phase 2 (data governance) — they underpin everything else.
- 30-49: Early stage. Focus on Phase 0 (classification) first — you may have fewer obligations than you think.
- 0-29: Pre-compliance. The December 2027 deadline still requires immediate programme mobilisation — the extension buys time, not room for complacency.
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
