Skip to content
Skip article header Engineering

AI Act Conformity Assessment

Which conformity assessment procedure applies to a high-risk AI system under Article 43, why Annex III point 5 credit and insurance systems take the Annex VI internal control route with no notified body involved, and what evidence a self-assessment has to produce and keep.

18 min read 106 views

Technically reviewed by Victor Sineglazov, D.Sc.

A provider's own staff signing the declaration page on a thick conformity file in a small office with no external assessor present, the Annex VI internal control route for credit scoring and insurance pricing under the AI Act
Skip key takeaways
  • For credit scoring and life and health insurance pricing there is no notified body Article 43(2) sends Annex III points 2 to 8 to the internal control procedure in Annex VI, and the Regulation says in terms that this procedure does not provide for the involvement of a notified body.
  • The choice everyone writes about belongs to Annex III point 1, the biometrics block Annex III point 1 covers remote biometric identification, biometric categorization and emotion recognition, and nothing in a lending or underwriting stack sits there. Even inside that block the choice is conditional on having applied harmonised standards under Article 40 or common specifications under Article 41.
  • Internal control is not a lighter standard, it is an unwitnessed one Annex VI point 2 makes the provider verify its own quality management system against Article 17, and with no external assessor the provider's own file is the entire proof. Its first reader is the market surveillance authority, which for financial institutions is the national financial supervisor, but only in so far as the system is in direct connection with the provision of those financial services.
  • Write the retraining envelope into the technical file before launch Changes pre-determined at the initial assessment and documented under Annex IV point 2(f) are not a substantial modification; undocumented ones restart the whole assessment, whether or not the model is redistributed.
  • The deadline is 2 December 2027, not 2 August 2026 Regulation (EU) 2026/1744 moved standalone Annex III high-risk applicability to 2 December 2027 and the Annex I route to 2 August 2028, leaving Article 6(5) on its original 2 February 2026 date.

A bank builds a credit scoring model. It works through high-risk classification under the AI Act, concludes the system is high-risk and then asks the obvious next question: who signs it off? Most published material answers that with a choice, internal control or a notified body, as though the provider gets to pick. For a credit scoring model or an insurance pricing model it is not a choice. The Regulation routes those systems to one procedure and no external body is involved at any point. That is easier and harder than it sounds. Easier, because there is no queue, no fee and no audit calendar. Harder, because nobody will ever tell you your file is good enough.

In short: for creditworthiness evaluation and life and health insurance pricing there is no notified body. Article 43(2) sends those systems to the internal control procedure in Annex VI, and the Regulation says in terms that this procedure does not involve a notified body. After Regulation (EU) 2026/1744, the Digital Omnibus on AI, the obligations apply from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Annex I ones. Material citing 2 August 2026 was written before the amendment, or was not updated after it. The entire compliance burden therefore falls on evidence the provider assembles, holds and can hand over cold.

What conformity assessment is under the AI Act

Conformity assessment is an act the provider performs before the system reaches the market, not a document. It is the procedure by which the provider demonstrates that a high-risk system meets the requirements in Chapter III, Section 2. It consumes the technical documentation assembled under Annex IV, and it produces a conclusion the provider then attests to in the EU declaration of conformity.

The distinction matters commercially because procurement teams routinely conflate the two. A vendor that shows a buyer a thick Annex IV file has shown the input to the procedure. It has not shown that the procedure was run, that its outcome was recorded or that anyone inside the vendor took responsibility for the conclusion.

The two candidate procedures

Only two procedures exist in the Regulation. The first is set out in Annex VI, the "conformity assessment procedure based on internal control", whose point 1 does nothing but forward to points 2, 3 and 4. Annex VI is four points long in total. The second, in Annex VII, is "the conformity assessment procedure based on points 2 to 5", and its point 2 explains what that means in practice: "The approved quality management system for the design, development and testing of AI systems pursuant to Article 17 shall be examined in accordance with point 3 and shall be subject to surveillance as specified in point 5." The same point sends the technical documentation for examination under point 4. Both passages come from Regulation (EU) 2024/1689 as published in the Official Journal. Annexes VI and VII were not amended by the Digital Omnibus, so the base text is still the operative text for both.

Who actually gets to choose a route

The choice everyone writes about is real, but it is narrow. Article 43(1) reaches only high-risk systems listed in point 1 of Annex III, and only where the provider demonstrated compliance with the Section 2 requirements through harmonised standards or common specifications. Where it applies, "the provider shall opt for one of the following conformity assessment procedures based on" either the internal control route in Annex VI or the assessment of the quality management system and of the technical documentation "with the involvement of a notified body, referred to in Annex VII." Those passages are in Regulation (EU) 2024/1689, which the Omnibus left untouched at Article 43(1).

Annex III point 1 is the biometrics block. Its chapeau in Regulation (EU) 2024/1689, which the Digital Omnibus did not amend at that point, reads "Biometrics, in so far as their use is permitted under relevant Union or national law" and it covers remote biometric identification, biometric categorization and emotion recognition. Nothing in a lending or underwriting stack sits there.

The choice is conditional even where it exists

Read Article 43(1) again and the second condition surfaces. The route choice is available only where "the provider has applied harmonised standards referred to in Article 40, or, where applicable, common specifications referred to in Article 41", again from Regulation (EU) 2024/1689. A biometrics provider that has applied no standard at all does not get to choose internal control. It is pushed to Annex VII by the conditions in the next subparagraph. So the two-route framing describes one Annex III point, under one precondition. For everything else in Annex III the procedure is fixed.

Why credit scoring and insurance pricing self-assess

Article 43(2) is the load-bearing sentence of this whole subject. It reads: "For high-risk AI systems referred to in points 2 to 8 of Annex III, providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body." That is from Regulation (EU) 2024/1689 as published in the Official Journal, and the Digital Omnibus left the paragraph verbatim. Regulation (EU) 2026/1744 replaced Article 43(3) in full and left paragraphs 1, 2, 4 and 6 alone.

What Annex III point 5 actually covers

Point 5 sits inside the range 2 to 8, under the chapeau "Access to and enjoyment of essential private services and essential public services and benefits". Two of its limbs are the commercially significant ones. The first: "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud;". The second: "AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance;". Both are quoted from Regulation (EU) 2024/1689, and Annex III point 5 was not amended.

Both carve-outs, the fraud exception on the creditworthiness limb and the life-and-health-only scope of the insurance limb, are developed in full in our note on the AI Act fundamental rights impact assessment.

One escape hatch is largely closed for scoring systems. Article 6(3) lets a provider conclude that an Annex III system is not high-risk, but the same article adds that an Annex III system "shall always be considered to be high-risk where the AI system performs profiling of natural persons." A credit scoring model profiles natural persons by construction. And claiming the derogation is itself a filing: a provider taking that view "shall document its assessment before that system is placed on the market or put into service", and Article 6(3) then attaches the registration obligation in Article 49(2) to it. Both are Article 6 of Regulation (EU) 2024/1689, unamended in the paragraphs quoted.

What the Annex VI internal control route requires

"Internal" is not a synonym for light. The procedure runs on three substantive points, each of which is a verification the provider owes. Point 2: "The provider verifies that the established quality management system is in compliance with the requirements of Article 17." Under point 3, the provider "examines the information contained in the technical documentation in order to assess the compliance of the AI system with the relevant essential requirements set out in Chapter III, Section 2." Point 4: the provider "also verifies that the design and development process of the AI system and its post-market monitoring as referred to in Article 72 is consistent with the technical documentation." All three are in Regulation (EU) 2024/1689, Annex VI.

Point 4 is the one teams underestimate. It is not a documentation check. It asks whether the process that actually ran matches the process the file describes, which means the file has to be true about how the model was built and monitored, not merely internally coherent.

The quality management system a financial institution already has

Article 17(1) lists thirteen elements a provider's quality management system must include. For banks and insurers, Article 17(4) then does most of the work. A provider that is a financial institution already subject to internal governance requirements under Union financial services law has the quality management system obligation "deemed to be fulfilled by complying with the rules on internal governance arrangements or processes pursuant to the relevant Union financial services law", with an exception for paragraph 1 points (g), (h) and (i). Both provisions are in Regulation (EU) 2024/1689, and the Omnibus amended neither of them.

The three excepted points are the risk management system under Article 9, the post-market monitoring system under Article 72 and serious incident reporting under Article 73. A regulated firm therefore inherits ten of the thirteen elements from governance it already runs, and has to build three. Those three are exactly the ones Annex VI point 4 then tests for consistency with the technical file.

The evidence a self-assessment has to produce and hold

A signed declaration page resting on a thick self-assessed conformity file beside a printed marking proof sheet whose number space is left blank, the entire evidence a self-assessment under AI Act Annex VI produces

With no external assessor there is no interim verdict. The file is the entire proof, and its first reader will be someone who was not in the room. That reader is defined. For high-risk systems placed on the market, put into service or used by financial institutions regulated by Union financial services law, Article 74(6) makes the market surveillance authority "the relevant national authority responsible for the financial supervision of those institutions", but only where the system is "in direct connection with the provision of those financial services." The qualifier at the end is not decoration. A system that is not in direct connection with the regulated financial service does not travel with the firm to its prudential supervisor. Article 74(7) adds that in appropriate circumstances, and provided coordination is ensured, "another relevant authority may be identified by the Member State as market surveillance authority for the purposes of this Regulation." Both from Regulation (EU) 2024/1689, Article 74, which the Omnibus did not amend.

What the file has to contain beyond Annex IV

Four artifacts sit on top of the technical documentation, and each has its own retention or publication mechanics. The declaration of conformity is the attestation. Article 47 makes the provider draw one up for each high-risk system, written and either machine readable, physical or electronically signed, and then "keep it at the disposal of the national competent authorities for 10 years after the high-risk AI system has been placed on the market or put into service." Logs are the operational record, kept "for a period appropriate to the intended purpose of the high-risk AI system, of at least six months", and Article 19(2) lets a regulated firm fold them into what it already keeps: a financial institution "shall maintain the logs automatically generated by their high-risk AI systems as part of the documentation kept under the relevant financial services law." Registration is the public entry, since before placing an Annex III system on the market the provider "shall register themselves and their system in the EU database referred to in Article 71". All from Regulation (EU) 2024/1689.

The CE marking is where self-assessment shows on the outside. For software delivered over an interface, "a digital CE marking shall be used, only if it can easily be accessed via the interface from which that system is accessed", or through a machine-readable code or other electronic means. And the identification number that buyers sometimes ask for does not exist here, because Article 48(4) attaches it only to "the notified body responsible for the conformity assessment procedures set out in Article 43". An internal control route produces no notified body, so a credit scoring system carries a CE marking with no four-digit number after it. That is correct, not a gap. Article 48 as quoted is in Regulation (EU) 2024/1689.

One more piece of the file has no template and will not have one soon. Article 72(3), as replaced by the Digital Omnibus, now requires the post-market monitoring system to rest on a plan that forms part of the Annex IV technical documentation, and then defers the template: "The Commission, taking utmost account of the opinion of the Board, shall adopt guidance, including a template, on the post-market monitoring plan by 2 September 2027." The pre-amendment text required a binding implementing act by 2 February 2026. That duty was repealed and replaced by non-binding guidance nineteen months later, so anyone writing a monitoring plan today is writing it without a template and against a deadline that arrives after the plan is needed. Article 72(4) does supply a route for regulated firms, since its second subparagraph extends the integration option to "high-risk AI systems referred to in point 5 of Annex III placed on the market or put into service by financial institutions" that already carry internal governance requirements under Union financial services law. The Article 72(3) wording is quoted from Regulation (EU) 2026/1744, the instrument that enacted it, and Article 72(4) from Regulation (EU) 2024/1689, which the Omnibus left standing.

When internal control is not available to you

Two situations take the choice away. The first applies inside Annex III point 1. Article 43(1) states that the provider "shall follow the conformity assessment procedure set out in Annex VII where" one of four conditions is met: "harmonised standards referred to in Article 40 do not exist, and common specifications referred to in Article 41 are not available;", "the provider has not applied, or has applied only part of, the harmonised standard;", "the common specifications referred to in point (a) exist, but the provider has not applied them;" and where a harmonised standard "has been published with a restriction, and only on the part of the standard that was restricted." Where Annex VII does apply, the provider "may choose any of the notified bodies", except that for law enforcement, immigration or asylum authorities and Union bodies the market surveillance authority acts as the notified body instead. From Regulation (EU) 2024/1689.

The Annex I product route after the Omnibus

The second situation is the Annex I product route, and it is the part of Article 43 the Digital Omnibus rewrote. For a system covered by the Union harmonisation legislation in Section A of Annex I, the current Article 43(3) says "the provider of the system shall follow the relevant conformity assessment procedure as required in accordance with the relevant Union harmonisation legislation." The Chapter III Section 2 requirements ride along inside that assessment, the Article 17 quality management system is assessed too, and a named subset of Annex VII applies: points 3, 4.3, 4.4, 4.5, the fifth paragraph of 4.6 and point 5. A new subparagraph settles the overlap case, where a system sits in both Section A of Annex I and a category in Annex III: it "shall follow the relevant conformity assessment procedure as required pursuant to the relevant Union harmonisation legislation listed in Section A of Annex I." Another confirms that embedding AI does not by itself force a third-party assessment. Manufacturers are "not required to choose a conformity assessment procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component" unless the Annex I Section A legislation already demands it. All quoted from Regulation (EU) 2026/1744, which enacted the replacement paragraph.

None of that reaches a lender or an insurer through its core models. Annex I is a list of product-safety and type-approval instruments. It contains no financial services act, no cybersecurity act and no data-protection act, so a credit scoring or underwriting model has no Annex I limb to fall down.

Substantial modification, and what restarts the assessment

An assessment is not a one-time event. Article 43(4) provides that high-risk systems already assessed "shall undergo a new conformity assessment procedure in the event of a substantial modification, regardless of whether the modified system is intended to be further distributed or continues to be used by the current deployer." The words after the comma close the obvious workaround. A model retrained for internal use only is caught on exactly the same terms as one shipped to a new client. The paragraph is quoted from Regulation (EU) 2024/1689.

Write the retraining envelope into the technical file before launch

The escape is narrow and it has to be built in advance. For systems that continue to learn after being placed on the market, the same article continues: "changes to the high-risk AI system and its performance that have been pre-determined by the provider at the moment of the initial conformity assessment and are part of the information contained in the technical documentation referred to in point 2(f) of Annex IV, shall not constitute a substantial modification." Quoted from Regulation (EU) 2024/1689, Article 43(4).

Two conditions, both temporal. The change has to be pre-determined at the moment of the initial assessment, and it has to be written into Annex IV point 2(f). A retraining policy authored after launch does not qualify retroactively. For a scoring model that is refit quarterly on fresh performance data, that single paragraph is the difference between a routine release and a repeat of the whole procedure, and the decision has to be made before the first release, not after the first refit.

What Regulation (EU) 2026/1744 changed

The Digital Omnibus on AI, Regulation (EU) 2026/1744 of 8 July 2026, entered into force on 27 July 2026 and is the only amendment the AI Act has received. Its most consequential move for this subject is in Article 113. The current point (c) applies "Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5)" from "2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and" and "2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I;". Quoted from Regulation (EU) 2026/1744, which enacted that point.

The pre-amendment point (c) deferred only Article 6(1) to 2 August 2027, which left Annex III systems on the general 2 August 2026 date. Material citing 2 August 2026 was written before the amendment, or was not updated after it. The Article 6(5) carve-out means the Commission's classification guidelines keep their own 2 February 2026 date and are not deferred with the rest. The AI Act compliance timeline maps the remaining dates.

What it did not change

Article 43(1), (2), (4) and (6) all survive verbatim, as do Annex VI, Annex VII and Annex III point 5. So the finance answer is unchanged in substance and only moved in time. Article 43(3) now sets a hard date for existing notified bodies: without prejudice to Article 28, bodies "notified under the Union harmonisation legislation in Section A of Annex I, shall apply for designation in accordance with Section 4 of this Chapter by 28 January 2028." The legacy cut-off in Article 111(2) moved with it, tied to the Article 113 dates above, with public authority deployments still due by 2 August 2030. Quoted from Regulation (EU) 2026/1744, the instrument that enacted the replacements.

One boundary deserves stating plainly, because it is widely compressed. The replaced Article 75 gives the AI Office exclusive competence over certain AI systems, subject to four carve-outs, one of which covers "AI systems provided by law enforcement authorities, border management authorities and financial institutions, insofar as those AI systems fall under Article 74(6)". The final clause is conditional. It reroutes a financial institution's system to its financial supervisor only where Article 74(6) reaches it, and Article 74(6) is itself limited to systems in direct connection with the provision of those financial services. The carve-out is quoted from Regulation (EU) 2026/1744, which replaced Article 75 in full. A financial institution does not simply stay with its sector supervisor for everything it builds.

The route can change under you

Self-assessment is a current state, not a settled one. Article 43(6) empowers the Commission to adopt delegated acts under Article 97 amending paragraphs 1 and 2 of that article, so as "to subject high-risk AI systems referred to in points 2 to 8 of Annex III to the conformity assessment procedure referred to in Annex VII or parts thereof." Quoted from Regulation (EU) 2024/1689. Points 2 to 8 is the range that contains credit scoring and insurance pricing.

What that implies for how the file is built now

A file built to the current minimum and a file built to survive that power are different artifacts. The difference is not volume. It is whether an outsider can follow the reasoning without a guided tour: whether test results tie to named model versions, whether the quality management system evidence points at dated artifacts rather than policy statements, and whether the post-market monitoring plan describes measurements that were actually taken. A team that has to reconstruct that later, under a delegated act, with a notified body waiting, will pay several times over for what it skipped.

How Pharos Production builds AI Act conformity evidence

We build FinTech and insurance systems where the model is part of a regulated product, and treat the conformity file as an engineering output, not an afterthought. That means version-pinned datasets and model artifacts, evaluation runs against those versions, a retraining envelope in Annex IV point 2(f) before first release and logging designed against Article 12, not retrofitted from application logs.

Because the Annex VI route has no external checkpoint, our practical test is a cold read: hand the file to an engineer who did not build the system and see whether they can reconstruct how conformity was concluded. Our AI governance and FinTech development teams work on that file alongside the build, so the evidence exists at launch, not after a request arrives.

Sources: Regulation (EU) 2024/1689 (AI Act), base Official Journal text, Articles 6, 19, 43, 47, 48, 49, 74 and Annexes III, VI and VII, via Regulation (EU) 2024/1689; Regulation (EU) 2026/1744 (Digital Omnibus on AI), Articles 43(3), 72(3), 75, 111(2) and 113, via Regulation (EU) 2026/1744. Read on 25 August 2026. A provision the Digital Omnibus left alone is cited to the base Official Journal text, and a provision whose wording the Digital Omnibus replaced is cited to Regulation (EU) 2026/1744, the instrument that enacted the current wording. Consolidated EUR-Lex texts are not cited here, because they carry no legal value. This article is engineering guidance, not legal advice. Confirm every requirement against the primary text with qualified counsel.

FAQ

Last updated:

Quick answers to common questions about custom software development, pricing, process and technology.

  • Copy link Copies a direct link to this answer to your clipboard.

    No. Article 43(2) routes high-risk systems in Annex III points 2 to 8 to the internal control procedure in Annex VI, and the Regulation states that this procedure does not provide for the involvement of a notified body. Creditworthiness evaluation and credit scoring sit in Annex III point 5, inside that range, so the provider assesses conformity itself.

    There is no external sign-off to obtain and no notified body identification number to affix after the CE marking.

  • Copy link Copies a direct link to this answer to your clipboard.

    The choice in Article 43(1) is written for systems in Annex III point 1, the biometrics block, and it applies only where the provider has used harmonised standards under Article 40 or common specifications under Article 41. Everything in Annex III points 2 to 8 goes to internal control under Annex VI instead, with no choice attached.

  • Copy link Copies a direct link to this answer to your clipboard.

    Article 43(1) forces Annex VII where harmonised standards under Article 40 do not exist and common specifications under Article 41 are not available, where the provider has not applied the harmonised standard or applied only part of it, where common specifications exist but were not applied or where a harmonised standard was published with a restriction, in which case only for the restricted part of the standard.

  • Copy link Copies a direct link to this answer to your clipboard.

    After Regulation (EU) 2026/1744, the Digital Omnibus on AI of 8 July 2026 in force 27 July 2026, Chapter III Sections 1, 2 and 3 apply from 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and from 2 August 2028 for systems classified as high-risk under Article 6(1) and Annex I. Article 6(5) is expressly carved out of that deferral.

    Material citing 2 August 2026 was written before the amendment, or was not updated after it.

  • Copy link Copies a direct link to this answer to your clipboard.

    Yes. Article 43(6) empowers the Commission to adopt delegated acts amending Article 43(1) and (2) so that Annex III points 2 to 8 fall under the Annex VII procedure or parts of it.

    The power is discretionary and unexercised today, but a file built only to the current minimum would need rebuilding if it is used, which is an argument for making the evidence externally readable from the start.

I work with startup founders who need a dedicated software development team but don’t want to gamble on hiring, random outsourcing, or opaque delivery.
Most founders face the same problem sooner or later.
Early technical and team decisions lock the product into tech debt, slow delivery, missed milestones and constant re-hiring. By the time this becomes visible, fixing it is already expensive.

As a CTO and software architect, I help founders design, build and run dedicated development teams that work as a true extension of the startup. Not as a black-box vendor.

My focus is on complex products where mistakes are costly:

  • Web3 and blockchain platforms
  • FinTech and regulated products
  • High-load startup systems
  • MVP → scale transitions

We don’t do body-shopping.
We don’t sell generic outsourcing.

Instead, we help founders:

  • build the right team structure from day one
  • keep technical ownership and transparency
  • scale delivery without losing control
  • avoid vendor lock-in and hidden risks

Teams are aligned with the product roadmap, business goals and long-term architecture. Not just short-term velocity.

Dmytro Nasyrov, Founder and CTO at Pharos Production
Dmytro Nasyrov Founder & CTO Let's work together!

Your business results matter

Achieve them with minimized risk through our bespoke innovation capabilities

Your contact details
Please enter your name
Please enter a valid email address
Please enter your message
* required

We typically reply within 4 hours. Prefer email? hello@pharosproduction.com

What happens next?

  1. Contact us

    Contact us today to discuss your project. We're ready to review your request promptly and guide you on the best next steps for collaboration

    Same day
  2. NDA

    We're committed to keeping your information confidential, so we'll sign a Non-Disclosure Agreement

    1 day
  3. Plan the Goals

    After we chat about your goals and needs, we'll craft a comprehensive proposal detailing the project scope, team, timeline and budget

    3-5 days
  4. Finalize the Details

    Let's connect on Google Meet to go through the proposal and confirm all the details together!

    1-2 days
  5. Sign the Contract

    As soon as the contract is signed, our dedicated team will jump into action on your project!

    Same day