Legal requirement Vendor and supply-chain governance European Union Partially applicable

Verify conformity before importing or distributing high-risk AI

Under EU AI Act, Articles 23 and 24

Source-linked Open official source

What does it require?

Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised representative where required, and must indicate their name and contact details on the system. Distributors must verify CE marking, the declaration of conformity and instructions, and refrain from making non-compliant systems available.

Practical action

Build AI Act checks into supplier onboarding and contract clauses.

Who does it apply to?

Importers and distributors of high-risk AI systems.

Applies from:

Evidence examples

  • Supplier due-diligence checklist (record)

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Annex A controls on third parties and suppliersOriginal editorial mapping.medium
NIST AI RMF 1.0GOVERN 6.1, GOVERN 6.2Third-party risk management.high

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.