EU AI Act Documentation

EU AI Act Documentation Company: Annex IV Technical Files Drafted for One AI System at a Time

EU AI Act compliance documentation is a file, not an opinion. As a Dhaka-based company, we draft that file from your design and test records for international companies, one system and one file at a time, at a fixed price per file: the technical documentation Article 11 and Annex IV require, the risk management description, the data governance record, instructions for use and the post-market plan. A documentation lead and an engineer work inside your document system; your counsel classifies, your owner approves.

You can stop after every step; none obliges you to buy the next. We start with the one AI system your counsel has placed, or may place, in scope: the hiring screen, the credit model, the safety component, the chatbot that needs a notice. Its role and category as counsel states them are recorded, existing records are collected, the missing Annex IV sections are listed, and the file is priced from your own figures.

You get a written verdict — a scope record first, one system’s technical file, deployer records instead of a provider file, transparency notices only, or a governance inventory before any law-specific work. If nothing is in scope, you stop here and keep the gap review.

30 minutes 01 Scope · free call
2 weeks 02 Diagnose · $1,500 scope review, half credited
4 weeks 03 Pilot · $4,000, one Annex IV file
Per system 04 Production · from $6,000 per file
Quarterly 05 Managed Ops · quarterly file review

What is included in EU AI Act compliance documentation?

EU AI Act compliance documentation covers six records drafted from your own design, data and test records: a scope and applicability record, the Annex IV technical file, the risk management description, the data governance record, instructions for use and transparency notices, and a post-market plan with a change log. Each card below is one deliverable.

On the Article 50 notices, the European Commission’s guidance adds: “Published text that has undergone human review or editorial control – does not need to be labelled.”

Scope and applicability record

Your role as provider or deployer and the risk category are recorded exactly as your counsel states them. The articles that follow, and the records each asks for, are written down before drafting.

Annex IV technical file

The nine Annex IV sections are drafted from your design, development, test and monitoring records. They run from the general description to metrics, risk management, changes and the post-market plan.

Risk management description

The Article 9 risk management system is written as a document. It covers known and foreseeable risks, the measures taken, residual risk, testing against the measures and the review cycle.

Data governance record

The Article 10 record covers training, validation and testing data: origin, collection, annotation, labelling and enrichment, assumptions, gaps and bias examination. Each dataset gets an owner.

Instructions and transparency notices

Article 13 instructions for deployers are drafted in plain language. So are the Article 50 notices users must see when they talk to a machine or view synthetic content.

Post-market plan and file upkeep

The Article 72 post-market monitoring plan comes with a change log that keeps Annex IV section six true as the system evolves. A handover session follows, then optional quarterly reviews.

Not included: Legal advice or deciding your role or risk category · conformity assessment, notified-body work or any declaration · general AI governance packs, which sit on their own page.

Which EU AI Act compliance record do you need first: technical file, risk description, data record or post-market plan?

EU AI Act compliance documentation for a high-risk provider rests on four records; the scope review says which you lack first. The Annex IV technical file is the spine; the Article 9 risk description and the Article 10 data record feed it; the Article 72 post-market plan keeps it true after release. All four sit inside our AI services.

Article 11 of the EU AI Act requires that “the technical documentation of a high-risk AI system shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date”.

Technical file

The nine Annex IV sections in one document, when your counsel has placed a system in Annex III and no file exists yet.

Risk description

The Article 9 risk management system written out with measures and residual risk, when testing exists, but nobody has described it.

Data record

The Article 10 account of training, validation and test data, when a vendor model or scraped data leaves the origin of the data unanswered.

Post-market plan

The Article 72 plan and change log, when the system is already live and the file must stay true as it changes.

How long does EU AI Act compliance documentation take for one AI system?

EU AI Act compliance documentation for one AI system takes four weeks in the pilot, after a two-week scope review. The example is a curriculum vitae (CV) screening tool whose provider role and Annex III category counsel had stated; each item traces to an Annex IV section and an approver.

Sample pilot log · CV-screening tool, Annex III provider

Pilot log · CV-screening tool

The file at that step · its result

Scope signed

The position your counsel states, on record first.

Scope itemSample system
SystemCV-screening tool
RoleProvider, as counsel states
CategoryAnnex III, as counsel states
Annex IV sections9
OwnerNamed
9
Annex IV sections in scoperole and category recorded before drafting

Records collected

What your existing records already cover.

General descriptionDevelopment processMonitoring and controlPerformance metricsRisk managementLifecycle changesStandards appliedDeclaration copyPost-market plan
6 of 9
Sections draftable from existing recordsdesign documents, 3 test reports and data sheets

Gaps closed

Missing evidence requested from named owners.

Risk descriptionwritten
Data recordcompleted
Test records3 missing, requested and received
3
Missing test records receivedrisk description and data record done

Owner sign-off · a person signs

Your owner reviews every section.

General descriptionDevelopment processMonitoring and controlPerformance metricsRisk managementLifecycle changesStandards appliedDeclaration copyPost-market plan
9 of 9
Sections reviewed by your ownercounsel confirms the scope record · approval logged

Handed over

The file stays in your own system.

File approvedYour document systemChange log openedPost-market plan dated
Handed overchange log opened · post-market plan dated

Open a step, or a number below, to see the file at that stage

Every quarter the change log is reconciled with what shipped, and Annex IV section six is updated.

Illustrative example. Yellow is where your owner signs; your counsel classifies the system, and we draft to that position.

How does EU AI Act technical documentation get written, from scope to Managed Ops?

EU AI Act technical documentation gets written in five steps, each an exit, because documentation fails when it starts from a template and ends in a legal opinion: a free scoping call, a two-week scope and gap review, a four-week pilot drafting one system’s file, production for further systems, then quarterly Managed Ops; every stage ends in a signed document.

01 30 min · free
Scope We discuss the system, the role your counsel assigns you, the category they have stated or are still deciding, and which records exist. A diagnostic quote follows.
02 2 weeks · credited
Diagnose Role and category recorded as counsel states them; design, data, test and monitoring records collected; each Annex IV section marked present, partial or missing; the pilot priced in writing.
03 4 weeks · fixed price
Pilot One system’s Annex IV file drafted section by section from your records, the risk management description and data governance record written, missing evidence requested, and your owner signs off at the end.
04 Per system · quoted after pilot
Production The remaining systems follow the scope review’s order, each with its own file, plus instructions for use, transparency notices, the post-market plan, a change log and a handover session.
05 Quarterly · optional
Managed Ops A quarterly review: the change log reconciled with what shipped, section six updated, new guidance, standards and Commission templates reflected, with a documentation lead who knows your files.

Who drafts your EU AI Act documentation, and with what?

A documentation lead who owns the file and the section list, an engineer who reads the architecture, data and tests, and a reviewer who checks each section against Annex IV.

Communication One review call a week and a shared Slack or Microsoft Teams channel

Delivery Files stay in your document system and ticketing tool

Quality assurance (QA) Every section reviewed by a second person, with versioning and a named approver

References The EU AI Act as amended, which every section follows

Boundary Your counsel classifies; we draft to that position

Ownership Every file, record and template in your name

Which EU AI Act compliance documentation do you need first: a scope record, a technical file, deployer records, notices or an inventory?

The first piece of EU AI Act documentation you need depends on your situation; five questions show which fits. Role and category unstated means a scope record first; a provider of an Annex III system, one system’s technical file; a deployer, deployer records; a chatbot or synthetic content, transparency notices; no list of AI systems, AI governance documentation first.

1. Has your counsel stated your role?

2. Has your counsel stated the risk category?

3. Is there a list of your AI systems?

4. Which records exist for the system?

5. Does the system talk to people or generate content?

Which one do you need? Answer five questions.

A scope and applicability record first

Nothing in this law can be drafted before the role and the category are on record: your counsel’s position is written down with the articles that follow from it, existing records are collected, and each required document is marked present, partial or missing.

Book a Diagnostic

A first estimate; the scope review confirms it.

How the verdict is decided

No list of systems → the governance inventory first
Role or category not stated → a scope record first
Deployer → deployer records
Provider of a high-risk system → the technical file
A chatbot or synthetic content only → transparency notices

Why choose us as your EU AI Act documentation company?

An EU AI Act documentation company is judged on whether its file survives a market-surveillance request, not on the articles it quotes. We draft to Article 11 and Annex IV of the EU AI Act from your design, data and test records, put your counsel’s classification on page one, and keep the file true with a change log.

Without a drafted file

!!!!!
  • A compliance PDF that names articles but attaches no records
  • A risk category chosen by a vendor’s marketing, not by your counsel
  • Technical details held by a supplier who will not share them
  • A file frozen on the day it was written while the system keeps changing

With EICRA

Pilot report · CV-screening tool
Annex IV sections9 of 9Source records used17Gaps closed3Approvals recorded2VerdictFile accepted
Illustrative example
  • Every Annex IV section drafted from your real design, data and test records
  • Your counsel’s classification recorded on page one; ours never substituted
  • Gaps listed by section with the named owner who can close them
  • A change log and review date that keep the file true after handover

Is it safe to outsource EU AI Act compliance documentation?

Outsourcing EU AI Act compliance documentation is safe when classification stays with your counsel and access stays read-only, because the risk is who decides scope and who sees design and data records. As a Bangladesh-based company, we draft inside your document system under a non-disclosure agreement, read records only and leave legal advice to counsel. Reviewed By Eicra.com team

Which EU AI Act agreements are signed, and when?

Non-disclosure agreement (NDA) — mutual, and signed before any design document, dataset description, test report or draft changes hands.
Data processing agreement (DPA) — for personal data in data records or examples, the processor terms are those of Article 28(3) of the General Data Protection Regulation (GDPR) or its national equivalent.
International data transfers — standard contractual clauses, or the instrument your jurisdiction prescribes, are signed before any personal data travels.
Access — we read design, data and test records and your document system, nothing more: no production systems, no live data, no credentials held by us.
Certifications — a certification is named only when held; none is claimed here, and we never assert that your system conforms.

What EU AI Act controls, ownership and rework terms apply?

Your accounts Files, records and templates live in your document system from the first draft; we store none of them.
Document ownership The contract assigns you all intellectual property (IP) in the files, so counsel, an assessor or another provider can have them at any time.
Boundary We draft technical documentation; we do not give legal advice, decide your role or risk category, perform conformity assessments or issue any declaration.
Approval A section is final only once your named owner approves that version, and the scope record carries your counsel’s confirmation.
Rework Sections that fail their agreed acceptance list within thirty days of handover are reworked free; new systems, roles or changes in the law are quoted first.

What proof do you get before you pay for EU AI Act compliance documentation?

Before you pay for EU AI Act documentation, you get evidence, not promises: a two-week scope and gap review with your own section-by-section gap list, a pilot file your owner signs before production is quoted, and a free 30-minute call. Client results appear once clients agree to be named.

2 weeks

For the scope and gap review, with each Annex IV section marked present, partial or missing.

4 weeks

To one AI system’s Annex IV technical file, drafted from your records and signed by your owner.

30 days

After handover, a section that misses its agreed acceptance list is redrafted free.

Case studies: files for named clients are shown here only with their consent. For references in your sector, ask on the scoping call.

What do buyers ask about EU AI Act documentation?

How much does EU AI Act compliance documentation cost?

Our documentation is priced per file rather than per hour, and the cards at the top list every figure. A two-week scope and gap review ends in a written verdict, half credited to the pilot. One AI system’s Annex IV technical file is then drafted, reviewed and signed by your owner, and further systems are quoted after the pilot.

What is EU AI Act compliance documentation?

EU AI Act compliance documentation is the set of written records the law expects a provider or deployer to hold. For a high-risk system: the Annex IV technical file, the Article 9 risk management description, the Article 10 data governance record, Article 13 instructions for use and an Article 72 post-market plan. For other systems, the Article 50 notices.

What is technical documentation under Article 11 of the EU AI Act?

Article 11 requires the provider of a high-risk AI system to draw up technical documentation before it is placed on the market or put into service, keep it up to date, and include at least the Annex IV elements, so authorities can assess compliance. Small and medium-sized enterprises, including start-ups, may provide those elements in a simplified form.

What does Annex IV technical documentation include?

Nine items: a general description of the system; its elements and development process; monitoring, functioning and control information; the performance metrics and their appropriateness; the risk management system; changes made through the lifecycle; the harmonised standards or other solutions applied; a copy of the EU declaration of conformity; and the post-market monitoring plan. Each is drafted from your records.

We deploy someone else’s AI system: what must we document?

A deployer keeps its own records, not the provider’s technical file. They show the instructions for use are followed, name the people on human oversight, keep logs under a retention policy and inform workers and affected people where required. Where Article 27 applies, a fundamental rights impact assessment is added. We draft to the deployer articles only.

Start with a free 30-minute scoping call or the two-week scope review.