# Conformity assessment, declaration and registration

- **Record type**: Control
- **Kind**: Process
- **Owner**: Regulatory compliance lead
- **Frequency**: Once per AI system
- **Duties served**: 4

## What the control achieves

Takes a regulated system through the applicable pre-market assessment, produces the signed declaration or certificate and completes any registration with authorities before the system is placed on the market.

## How it is typically implemented

Early in the project the compliance lead determines which assessment route applies, whether an outside body must be involved and what registrations follow, and books notified-body capacity if needed. A conformity checklist maps each legal requirement to the evidence in the technical file, and a gap review is completed before the assessment is formally started. On a successful outcome the declaration is signed by an authorised person, markings are applied, registrations are filed and the records are retained for the required period. A re-assessment trigger list defines which changes require the exercise to be repeated.

## Evidence it produces

- Declaration of conformity or certificate (conformity_declaration)
- Registration record in the relevant database (regulatory_filing)
- Conformity evidence pack (technical_file): Requirement-to-evidence map with the supporting documents.

## Legal duties this control serves

- Complete conformity assessment, CE marking and EU database registration — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-conformity-assessment-registration
- Verify conformity before importing or distributing high-risk AI — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-importer-distributor-obligations
- Non-EU providers must appoint an EU authorised representative for high-risk AI — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-22-authorised-representative
- Providers must document and register a conclusion that an Annex III system is not high-risk — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-6-4-non-high-risk-assessment-documentation

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Clause 9.2; Annex A.6.2.7
- NIST AI RMF 1.0: GOVERN 1.1; MAP 4.1

## MIT AI Risk Repository subdomains addressed

6.5, 7.3

## Provenance

- **Record page**: https://aipolicytracker.org/controls/conformity-assessment-and-registration
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: medium
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
