EU AI Act Conformity Assessment and QMS Workbook
In brief
The EU AI Act Conformity Assessment and QMS Workbook is a free XLSX and DOCX kit for EU AI Act and ISO/IEC 42001. For providers of high-risk AI systems: each recorded requirement mapped to the evidence that meets it, the thirteen quality management elements, a re-assessment trigger log and a draft declaration of conformity.
- Format
- XLSX and DOCX · Kit
- Version
- v2, built 6 Oct 2026
- Duties cited
- 2 from 1 instruments
- Rows from the records
- 45
- Frameworks
- EU AI Act, ISO/IEC 42001
- Written for
- Provider / developer, Deployer / user organisation, Public authority / government body
- Price and licence
- Free · CC BY 4.0
What's inside
- Requirement-to-evidence map across nine requirement areas
- Quality management system elements with owner and approval date
- Re-assessment trigger log
- Document: assessment route, standards applied and the declaration of conformity outline
Preview
The sheets and sections of version v2, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Requirement to evidence
| Area | Requirement | Reference | Evidence in the technical file | Status ▾ | Checked by | Record |
|---|---|---|---|---|---|---|
| AI risk management | Establish a risk management system for high-risk AI | Article 9 | https://aipolicytracker.org/obligations/eu-ai-act-risk-management-system | |||
| Data governance and quality | Apply data governance and quality criteria to training, validation and testing data | Article 10 | https://aipolicytracker.org/obligations/eu-ai-act-data-governance | |||
| Technical documentation | Draw up technical documentation before placing a high-risk system on the market | Article 11 and Annex IV | https://aipolicytracker.org/obligations/eu-ai-act-technical-documentation | |||
| Record keeping and logging | Design high-risk systems to log events automatically | Article 12; Article 26(6) for deployers | https://aipolicytracker.org/obligations/eu-ai-act-record-keeping | |||
| Human oversight | Enable and assign effective human oversight | Article 14; Article 26(2) for deployers | https://aipolicytracker.org/obligations/eu-ai-act-human-oversight | |||
| Accuracy, robustness and cybersecurity | Achieve appropriate accuracy, robustness and cybersecurity | Article 15 | https://aipolicytracker.org/obligations/eu-ai-act-accuracy-robustness-cybersecurity |
Every recorded EU AI Act requirement a conformity assessment checks, mapped to the evidence that shows it is met.
Sheet: QMS elements
| Quality management element | Document or procedure | Owner | Approved | Status ▾ |
|---|---|---|---|---|
| Strategy for regulatory compliance, including change management | ||||
| Design, design control and design verification | ||||
| Development, quality control and quality assurance | ||||
| Examination, test and validation procedures | ||||
| Technical specifications and standards applied | ||||
| Data management |
The elements a provider's quality management system documents. Link each to the procedure that implements it.
Sheet: Re-assessment triggers
| Date | Change made | Substantial modification? ▾ | Reasoning | New assessment needed ▾ | Decided by |
|---|---|---|---|---|---|
| Rows are yours to fill; the dropdowns, formulas and colour rules are already in place. | |||||
Every change to the system after its assessment, with the decision on whether it needs a new one.
Sheet: Requirements on record
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Establish a risk management system for high-risk AI | AI risk management | EU AI Act | European Union | Provider / developer | Legal requirement | Article 9 | 2027-12-02 | Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle: | Risk register and treatment plan; Pre-market test reports | Clauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI risk | MAP, MEASURE and MANAGE functions | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-risk-management-system |
| Apply data governance and quality criteria to training, validation and testing data | Data governance and quality | EU AI Act | European Union | Provider / developer | Legal requirement | Article 10 | 2027-12-02 | High-risk AI systems that use data-driven techniques must be developed on training, validation and testing data sets meeting quality criteria: appropriate gover | Dataset documentation (datasheet); Bias examination report | Annex A controls on data for AI systems | MAP 2.3, MEASURE 2.1, MEASURE 2.11 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-data-governance |
| Draw up technical documentation before placing a high-risk system on the market | Technical documentation | EU AI Act | European Union | Provider / developer | Legal requirement | Article 11 and Annex IV | 2027-12-02 | Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate complian | Annex IV technical file | Clause 7.5 Documented information; Annex A control on system documentation | GOVERN 1.4, MAP 3.x | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-technical-documentation |
| Design high-risk systems to log events automatically | Record keeping and logging | EU AI Act | European Union | Provider / developer, Deployer / user organisation | Legal requirement | Article 12; Article 26(6) for deployers | 2027-12-02 | High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operati | Logging specification and retention policy | Annex A control on event logging | MEASURE 2.x, MANAGE 4.1 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-record-keeping |
| Enable and assign effective human oversight | Human oversight | EU AI Act | European Union | Provider / developer, Deployer / user organisation | Legal requirement | Article 14; Article 26(2) for deployers | 2027-12-02 | High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, av | Human oversight procedure and role assignment | Annex A control on human oversight | GOVERN 3.2, MANAGE 2.x | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-human-oversight |
| Achieve appropriate accuracy, robustness and cybersecurity | Accuracy, robustness and cybersecurity | EU AI Act | European Union | Provider / developer | Legal requirement | Article 15 | 2027-12-02 | High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy l | Accuracy metrics and test evidence; AI security assessment | Annex A controls on AI system verification and validation | MEASURE 2.5, 2.6, 2.7 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-accuracy-robustness-cybersecurity |
Document outline (DOCX)
- EU AI Act conformity assessment and quality management
- Assessment route
- Harmonised standards and specifications applied
- Draft EU declaration of conformity
- Requirements, one by one
- Establish a risk management system for high-risk AI
- Apply data governance and quality criteria to training, validation and testing data
- Draw up technical documentation before placing a high-risk system on the market
- Design high-risk systems to log events automatically
- Enable and assign effective human oversight
- Achieve appropriate accuracy, robustness and cybersecurity
- Operate a quality management system
- Complete conformity assessment, CE marking and EU database registration
- Operate a post-market monitoring system
- Providers must keep high-risk AI documentation for ten years
- Providers must retain automatically generated logs under their control
- Providers must document and register a conclusion that an Annex III system is not high-risk
- Deployers must ensure input data they control is relevant and representative
- Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
- Providers of GPAI models must maintain technical documentation and inform downstream providers
- Providers of systemic-risk GPAI models must secure the model and its infrastructure
How to use it
- 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
- 2Read the README page. It states the version (v2), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
- 3Fill in your rows. Complete the "Re-assessment triggers" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
- 4Check the duties against your situation. The "Requirement to evidence", "QMS elements" and "Requirements on record" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
- 5Complete the document. Work through the DOCX sections (EU AI Act conformity assessment and quality management, Requirements, one by one) and replace each placeholder with your organisation's answer.
- 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.
Duties this template covers (2)
Each is cited in the file with its source reference and a link back to the record.
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v2 | 9710140e23e4 | Dataset c6967b988bb5 → 9710140e23e4. | |
| v1 | c6967b988bb5 | First version, built from dataset c6967b988bb5. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
What is in the EU AI Act Conformity Assessment and QMS Workbook?
Requirement-to-evidence map across nine requirement areas. Quality management system elements with owner and approval date. Re-assessment trigger log. Document: assessment route, standards applied and the declaration of conformity outline.
Which duties does it cite?
2 recorded duties from EU AI Act, including Article 17 and Articles 43, 47, 48 and 49; Annex VIII. Each row links to the record, and the record to the official source.
Who is it for?
The duties it cites fall on provider / developer, deployer / user organisation and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.
Is it free?
Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
How will I know when it changes?
Version v2 was built on 6 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.