KitFree · no accountEU AI ActISO/IEC 42001
AI System Technical Documentation
The technical file a high-risk system needs: one section per element the recorded documentation duties name, with placeholders, plus a document register.
What's inside
- Document: general description, development process, data, monitoring, risk management, changes, standards, with placeholders
- Register sheet: documents, versions, owners, last review
- Duties sheet: every recorded documentation and record-keeping duty
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Document register
| Doc ID | Document | Section of the technical file ▾ | Version | Owner | Last review | Next review ƒ | Location / link |
|---|---|---|---|---|---|---|---|
| Rows are yours to fill; the dropdowns, formulas and colour rules are already in place. | |||||||
Sheet: Documentation duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Developers must document high-risk systems and disclose known risks | Technical documentation | Colorado AI Act | Colorado (United States) | Provider / developer | Legal requirement | C.R.S. 6-1-1702 | 2026-06-30 | Developers must make available to deployers a general statement of intended uses, documentation of known or reasonably foreseeable risks of algorithmic discrimi | Deployer documentation pack; Public statement on high-risk systems | GOVERN 1.4, MAP 3.x | Source-linked | https://aipolicytracker.org/obligations/us-colorado-developer-documentation-and-disclosure | |
| Draw up technical documentation before placing a high-risk system on the market | Technical documentation | EU AI Act | European Union | Provider / developer | Legal requirement | Article 11 and Annex IV | 2026-08-02 | Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate complian | Annex IV technical file | Clause 7.5 Documented information; Annex A control on system documentation | GOVERN 1.4, MAP 3.x | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-technical-documentation |
| Design high-risk systems to log events automatically | Record keeping and logging | EU AI Act | European Union | Provider / developer, Deployer / user organisation | Legal requirement | Article 12; Article 26(6) for deployers | 2026-08-02 | High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operati | Logging specification and retention policy | Annex A control on event logging | MEASURE 2.x, MANAGE 4.1 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-record-keeping |
| Achieve appropriate accuracy, robustness and cybersecurity | Accuracy, robustness and cybersecurity | EU AI Act | European Union | Provider / developer | Legal requirement | Article 15 | 2026-08-02 | High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy l | Accuracy metrics and test evidence; AI security assessment | Annex A controls on AI system verification and validation | MEASURE 2.5, 2.6, 2.7 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-accuracy-robustness-cybersecurity |
| Providers must keep high-risk AI documentation for ten years | Record keeping and logging | EU AI Act | European Union | Provider / developer | Legal requirement | Article 18 | 2026-08-02 | For ten years after a high-risk AI system is placed on the market or put into service, the provider must keep at the disposal of national competent authorities | Retention schedule for AI conformity records; Technical file archive index | Clause 7.5.3; Annex A.6.2.7 | GOVERN 1.4 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-18-documentation-keeping |
| Providers must retain automatically generated logs under their control | Record keeping and logging | EU AI Act | European Union | Provider / developer | Legal requirement | Article 19 | 2026-08-02 | Providers must keep the event logs that a high-risk AI system generates under Article 12, to the extent those logs are within their control, for a period approp | Log retention configuration and policy; Sample log export demonstrating retention period | Annex A.6.2.8 | MEASURE 2.4, MANAGE 4.1 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-19-provider-log-retention |
Document outline (DOCX)
- Purpose of the technical file
- General description
- Development process
- Data and data governance
- Monitoring and control
- Risk management
- Changes over the lifecycle
- Standards applied
- Post-market monitoring
- Duties this file serves
- Developers must document high-risk systems and disclose known risks
- Draw up technical documentation before placing a high-risk system on the market
- Design high-risk systems to log events automatically
- Achieve appropriate accuracy, robustness and cybersecurity
- Providers must keep high-risk AI documentation for ten years
- Providers must retain automatically generated logs under their control
- Providers must document and register a conclusion that an Annex III system is not high-risk
- Providers of GPAI models must maintain technical documentation and inform downstream providers
- Providers of systemic-risk GPAI models must secure the model and its infrastructure
- Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool
Duties this template covers (11)
Each is cited in the file with its source reference and a link back to the record.
- Keep records of consequential decisions influenced by the technology for three years
- Developers must supply deployers with documentation of the technology
- Draw up technical documentation before placing a high-risk system on the market
- Design high-risk systems to log events automatically
- Achieve appropriate accuracy, robustness and cybersecurity
- Providers must keep high-risk AI documentation for ten years
- Providers must retain automatically generated logs under their control
- Providers must document and register a conclusion that an Annex III system is not high-risk
- Providers of GPAI models must maintain technical documentation and inform downstream providers
- Providers of systemic-risk GPAI models must secure the model and its infrastructure
- Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | 914895c3103e | First version, built from dataset 914895c3103e. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
- Is the AI System Technical Documentation free?
- Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 20 recorded duties are cited in it, drawn from 3 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is the AI System Technical Documentation free?
- Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 20 recorded duties are cited in it, drawn from 3 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.