Skip to content
EU AI Regulation DecodedKnowledge Platform

EU AI Act audit-readiness checklist

Select your role and risk tier to build the exact evidence pack an auditor expects — every obligation expanded to the document you must produce, the audit red flags, and the deadline. Nothing leaves your browser.

🔒 Private by design. This tool runs entirely in your browser. Your selections and progress are saved locally on your device only — nothing is uploaded. It is a practitioner aid for audit preparation, not legal advice.
Your role
Risk tier

Provider — obligations & evidence

Disclose AI interaction to usersby 2026-08-02

Full obligation & legal source →

Mark AI-generated content machine-readablyby 2026-08-02

Full obligation & legal source →

Declare accuracy metrics in instructions for useby 2027-12-02

Fails an audit

  • Accuracy levels/metrics not declared in the instructions for use.
  • Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.

Full obligation & legal source →

Evidence robustness / resilienceby 2027-12-02

Fails an audit

  • Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.
  • No clear version control / traceability between document versions and system versions.

Full obligation & legal source →

Evidence AI-specific cybersecurityby 2027-12-02

Fails an audit

  • Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.

Full obligation & legal source →

Run a lifecycle risk-management systemby 2027-12-02

Fails an audit

  • Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.
  • No clear version control / traceability between document versions and system versions.

Full obligation & legal source →

Govern training, validation and test databy 2027-12-02

Fails an audit

  • Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.

Full obligation & legal source →

Draw up & maintain the Annex IV technical fileby 2027-12-02

Fails an audit

  • Documentation created after the fact rather than contemporaneously with the decision — national competent authorities apply the contemporaneous standard.
  • No clear version control / traceability between document versions and system versions.
  • No compliance matrix mapping each requirement to the specific evidence that satisfies it.

Full obligation & legal source →

Classify the system against Article 6 / Annex IIIby 2027-12-02

Fails an audit

  • Relying on the Article 6(3) 'not significant risk' exception without a documented justification.

Full obligation & legal source →

Register in the EU databaseby 2027-12-02

Full obligation & legal source →

Complete conformity assessment before marketby 2027-12-02

Full obligation & legal source →

Deployer — obligations & evidence

Disclose deepfakesby 2026-08-02

Full obligation & legal source →

Assign human oversight and use per instructions (deployer)by 2027-12-02

Fails an audit

  • Deployer does not retain the automatically-generated logs of the high-risk system within its control.

Full obligation & legal source →

Classify the system against Article 6 / Annex IIIby 2027-12-02

Fails an audit

  • Relying on the Article 6(3) 'not significant risk' exception without a documented justification.

Full obligation & legal source →

Register in the EU databaseby 2027-12-02

Full obligation & legal source →

GPAI model provider — obligations & evidence

GPAI provider documentation & copyrightby 2025-08-02

Full obligation & legal source →

Mark AI-generated content machine-readablyby 2026-08-02

Full obligation & legal source →

Not sure of your risk tier? How to classify under Article 6 →

Stay audit-ready as the Act changes

EU AI Regulation Decoded tracks each obligation and the evidence auditors expect — one practitioner email a week.

Subscribe — free, weekly

Not legal advice. This is a practitioner reference generated from a cited knowledge base built on the primary legal text and official Commission guidance. Verify against the cited primary sources before relying on it for a compliance decision. See editorial standards & methodology.