AIPolicyTracker
KitFree · sent to your work emailEU AI ActISO/IEC 42001

EU AI Act Conformity Assessment and QMS Workbook

Formats: XLSX and DOCX · Version v2 · Built from dataset 9710140e23e4 · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

In brief

The EU AI Act Conformity Assessment and QMS Workbook is a free XLSX and DOCX kit for EU AI Act and ISO/IEC 42001. For providers of high-risk AI systems: each recorded requirement mapped to the evidence that meets it, the thirteen quality management elements, a re-assessment trigger log and a draft declaration of conformity.

Format
XLSX and DOCX · Kit
Version
v2, built 6 Oct 2026
Duties cited
2 from 1 instruments
Rows from the records
45
Written for
Provider / developer, Deployer / user organisation, Public authority / government body
Price and licence
Free · CC BY 4.0

What's inside

  • Requirement-to-evidence map across nine requirement areas
  • Quality management system elements with owner and approval date
  • Re-assessment trigger log
  • Document: assessment route, standards applied and the declaration of conformity outline

Preview

The sheets and sections of version v2, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Requirement to evidence · 7 columns · 16 rows from the records
First rows of the Requirement to evidence sheet
AreaRequirementReferenceEvidence in the technical fileStatus ▾Checked byRecord
AI risk managementEstablish a risk management system for high-risk AIArticle 9https://aipolicytracker.org/obligations/eu-ai-act-risk-management-system
Data governance and qualityApply data governance and quality criteria to training, validation and testing dataArticle 10https://aipolicytracker.org/obligations/eu-ai-act-data-governance
Technical documentationDraw up technical documentation before placing a high-risk system on the marketArticle 11 and Annex IVhttps://aipolicytracker.org/obligations/eu-ai-act-technical-documentation
Record keeping and loggingDesign high-risk systems to log events automaticallyArticle 12; Article 26(6) for deployershttps://aipolicytracker.org/obligations/eu-ai-act-record-keeping
Human oversightEnable and assign effective human oversightArticle 14; Article 26(2) for deployershttps://aipolicytracker.org/obligations/eu-ai-act-human-oversight
Accuracy, robustness and cybersecurityAchieve appropriate accuracy, robustness and cybersecurityArticle 15https://aipolicytracker.org/obligations/eu-ai-act-accuracy-robustness-cybersecurity

Every recorded EU AI Act requirement a conformity assessment checks, mapped to the evidence that shows it is met.

Sheet: QMS elements · 5 columns · 13 rows from the records
First rows of the QMS elements sheet
Quality management elementDocument or procedureOwnerApprovedStatus ▾
Strategy for regulatory compliance, including change management
Design, design control and design verification
Development, quality control and quality assurance
Examination, test and validation procedures
Technical specifications and standards applied
Data management

The elements a provider's quality management system documents. Link each to the procedure that implements it.

Sheet: Re-assessment triggers · 6 columns · blank, 60 rows ready to fill
First rows of the Re-assessment triggers sheet
DateChange madeSubstantial modification? ▾ReasoningNew assessment needed ▾Decided by
Rows are yours to fill; the dropdowns, formulas and colour rules are already in place.

Every change to the system after its assessment, with the decision on whether it needs a new one.

Sheet: Requirements on record · 14 columns · 16 rows from the records
First rows of the Requirements on record sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Establish a risk management system for high-risk AIAI risk managementEU AI ActEuropean UnionProvider / developerLegal requirementArticle 92027-12-02Providers of high-risk AI systems must establish, implement, document and maintain a continuous, iterative risk-management system across the system's lifecycle:Risk register and treatment plan; Pre-market test reportsClauses 6.1.2, 6.1.3, 8.2, 8.3 and Annex A controls on AI riskMAP, MEASURE and MANAGE functionsSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-risk-management-system
Apply data governance and quality criteria to training, validation and testing dataData governance and qualityEU AI ActEuropean UnionProvider / developerLegal requirementArticle 102027-12-02High-risk AI systems that use data-driven techniques must be developed on training, validation and testing data sets meeting quality criteria: appropriate goverDataset documentation (datasheet); Bias examination reportAnnex A controls on data for AI systemsMAP 2.3, MEASURE 2.1, MEASURE 2.11Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-data-governance
Draw up technical documentation before placing a high-risk system on the marketTechnical documentationEU AI ActEuropean UnionProvider / developerLegal requirementArticle 11 and Annex IV2027-12-02Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate complianAnnex IV technical fileClause 7.5 Documented information; Annex A control on system documentationGOVERN 1.4, MAP 3.xSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-technical-documentation
Design high-risk systems to log events automaticallyRecord keeping and loggingEU AI ActEuropean UnionProvider / developer, Deployer / user organisationLegal requirementArticle 12; Article 26(6) for deployers2027-12-02High-risk AI systems must technically allow automatic recording of events (logs) over their lifetime to support traceability, post-market monitoring and operatiLogging specification and retention policyAnnex A control on event loggingMEASURE 2.x, MANAGE 4.1Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-record-keeping
Enable and assign effective human oversightHuman oversightEU AI ActEuropean UnionProvider / developer, Deployer / user organisationLegal requirementArticle 14; Article 26(2) for deployers2027-12-02High-risk systems must be designed with human-machine interface tools so natural persons can effectively oversee them, understand capacities and limitations, avHuman oversight procedure and role assignmentAnnex A control on human oversightGOVERN 3.2, MANAGE 2.xSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-human-oversight
Achieve appropriate accuracy, robustness and cybersecurityAccuracy, robustness and cybersecurityEU AI ActEuropean UnionProvider / developerLegal requirementArticle 152027-12-02High-risk AI systems must achieve an appropriate level of accuracy, robustness and cybersecurity and perform consistently throughout their lifecycle. Accuracy lAccuracy metrics and test evidence; AI security assessmentAnnex A controls on AI system verification and validationMEASURE 2.5, 2.6, 2.7Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-accuracy-robustness-cybersecurity

Document outline (DOCX)

  1. EU AI Act conformity assessment and quality management
  2. Assessment route
  3. Harmonised standards and specifications applied
  4. Draft EU declaration of conformity
  5. Requirements, one by one
  6. Establish a risk management system for high-risk AI
  7. Apply data governance and quality criteria to training, validation and testing data
  8. Draw up technical documentation before placing a high-risk system on the market
  9. Design high-risk systems to log events automatically
  10. Enable and assign effective human oversight
  11. Achieve appropriate accuracy, robustness and cybersecurity
  12. Operate a quality management system
  13. Complete conformity assessment, CE marking and EU database registration
  14. Operate a post-market monitoring system
  15. Providers must keep high-risk AI documentation for ten years
  16. Providers must retain automatically generated logs under their control
  17. Providers must document and register a conclusion that an Annex III system is not high-risk
  18. Deployers must ensure input data they control is relevant and representative
  19. Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
  20. Providers of GPAI models must maintain technical documentation and inform downstream providers
  21. Providers of systemic-risk GPAI models must secure the model and its infrastructure

How to use it

  1. 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
  2. 2Read the README page. It states the version (v2), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
  3. 3Fill in your rows. Complete the "Re-assessment triggers" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
  4. 4Check the duties against your situation. The "Requirement to evidence", "QMS elements" and "Requirements on record" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
  5. 5Complete the document. Work through the DOCX sections (EU AI Act conformity assessment and quality management, Requirements, one by one) and replace each placeholder with your organisation's answer.
  6. 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.

Duties this template covers (2)

Each is cited in the file with its source reference and a link back to the record.

Legal basis

  • EU AI Act European Union · Partially applicable

Version history

Versions of EU AI Act Conformity Assessment and QMS Workbook
VersionBuiltDatasetWhat changed
v29710140e23e4Dataset c6967b988bb5 → 9710140e23e4.
v1c6967b988bb5First version, built from dataset c6967b988bb5.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

What is in the EU AI Act Conformity Assessment and QMS Workbook?

Requirement-to-evidence map across nine requirement areas. Quality management system elements with owner and approval date. Re-assessment trigger log. Document: assessment route, standards applied and the declaration of conformity outline.

Which duties does it cite?

2 recorded duties from EU AI Act, including Article 17 and Articles 43, 47, 48 and 49; Annex VIII. Each row links to the record, and the record to the official source.

Who is it for?

The duties it cites fall on provider / developer, deployer / user organisation and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.

Is it free?

Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

How will I know when it changes?

Version v2 was built on 6 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.

Does completing it make us compliant?

No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.