Annex IV, the declaration, the mark, and the database

Lesson 4 of 5 in Conformity Assessment, Standards, CE Marking, and Post-Market Duties.

Every route through Article 43 runs on the same fuel: the technical documentation required by Article 11 and specified section by section in Annex IV. Drawn up before market placement and kept current for ten years, it is simultaneously the input to conformity assessment, the file a notified body examines, and the evidence pack a market surveillance authority will demand years later. Treat it as the single source of truth about the system — because legally, it is.

Walk the nine sections. Each one answers a question an inspector will eventually ask.

1 — General description of the system

Intended purpose, provider identity, version and how versions relate, interactions with hardware and other software, forms of market placement, and the instructions for use. What good looks like: an inspector can tell exactly which system, which version, doing what, for whom — ambiguity here poisons every later section.

2 — Detailed description of elements and development

The deep section: development methods and any third-party tools or pre-trained models; design specifications and architecture; data requirements — datasheets describing training methodologies, datasets, their provenance, scope, labelling and cleaning; the human-oversight assessment against Art 14; pre-determined changes for learning systems; validation and testing — procedures, data used, metrics for accuracy, robustness and compliance, test logs and reports, dated and signed; and cybersecurity measures. What good looks like: a competent third party could reconstruct how the system was built and how you know it works.

3 — Monitoring, functioning and control

The system’s capabilities and limitations, expected accuracy levels for specific persons or groups, foreseeable unintended outcomes and risk sources, and the human-oversight measures plus technical means for interpreting outputs. What good looks like: honest limitation statements — “performs worse on X” written down before an authority discovers it.

4 — Performance appropriateness

A description of the appropriateness of the performance metrics chosen for this specific system. What good looks like: an argued justification — why F1 rather than raw accuracy, why these subgroups, why these thresholds — not a metrics dump.

5 — Risk management description

A detailed account of the Art 9 risk management system: hazards identified, estimation and evaluation, mitigations, residual-risk judgments. What good looks like: a living document with iteration history, not a one-off spreadsheet dated the week before launch.

6 — Lifecycle changes

A description of relevant changes made through the system’s lifecycle. What good looks like: a change log that maps cleanly onto the pre-determined-change envelope from conformity assessment — anything outside it should show a re-assessment trail.

7 — Standards applied

A list of harmonized standards applied in full or in part; where none were applied, a detailed description of the solutions adopted to meet the requirements instead. What good looks like: while OJEU-cited standards remain scarce, this section carries the alternative-solutions argument — expect it to be the most scrutinised page in the file.

8 — Copy of the EU declaration of conformity

The Annex V declaration itself, bound into the file. What good looks like: version-controlled and consistent with section 1 — mismatched system identifiers between declaration and documentation are a classic formal non-compliance finding.

9 — Post-market monitoring plan

A detailed description of the Art 72 system for evaluating performance in the post-market phase, including the monitoring plan. What good looks like: named data sources, review cadence, drift thresholds, and an explicit trigger path into corrective action and Art 73 incident reporting.

With the assessment passed, three formal acts remain. The EU declaration of conformity (Art 47, content in Annex V): one declaration per system, in which the provider assumes responsibility for compliance, kept for ten years and translated as national authorities require. The CE marking (Art 48): affixed visibly, legibly and indelibly — or, for digital-only systems, as a digital marking accessible via the interface or machine-readable code — with the notified body’s identification number added where one was involved. Affixing the mark without grounds is itself a sanctionable act.

Finally, registration (Art 49): before placing an Annex III system on the market, the provider registers it in the EU database established under Article 71 — a public, searchable register. Two details are routinely missed. First, systems the provider filtered out of high-risk via the Article 6(3) derogation must be registered too, with the self-assessment available on demand — the filter leaves a public footprint precisely so authorities can second-guess it. Second, public-body deployers register their use of high-risk systems, and a restricted non-public section holds law-enforcement, migration and border systems.

Key terms: technical documentation, EU declaration of conformity, CE marking, EU database for high-risk AI systems, notified body

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.