EU AI Act compliance documentation is a file, not an opinion. As a Dhaka-based company, we draft that file from your design and test records for international companies, one system and one file at a time, at a fixed price per file: the technical documentation Article 11 and Annex IV require, the risk management description, the data governance record, instructions for use and the post-market plan. A documentation lead and an engineer work inside your document system; your counsel classifies, your owner approves.
You can stop after every step; none obliges you to buy the next. We start with the one AI system your counsel has placed, or may place, in scope: the hiring screen, the credit model, the safety component, the chatbot that needs a notice. Its role and category as counsel states them are recorded, existing records are collected, the missing Annex IV sections are listed, and the file is priced from your own figures.
You get a written verdict — a scope record first, one system’s technical file, deployer records instead of a provider file, transparency notices only, or a governance inventory before any law-specific work. If nothing is in scope, you stop here and keep the gap review.
EU AI Act compliance documentation covers six records drafted from your own design, data and test records: a scope and applicability record, the Annex IV technical file, the risk management description, the data governance record, instructions for use and transparency notices, and a post-market plan with a change log. Each card below is one deliverable.
On the Article 50 notices, the European Commission’s guidance adds: “Published text that has undergone human review or editorial control – does not need to be labelled.”
Your role as provider or deployer and the risk category are recorded exactly as your counsel states them. The articles that follow, and the records each asks for, are written down before drafting.
The nine Annex IV sections are drafted from your design, development, test and monitoring records. They run from the general description to metrics, risk management, changes and the post-market plan.
The Article 9 risk management system is written as a document. It covers known and foreseeable risks, the measures taken, residual risk, testing against the measures and the review cycle.
The Article 10 record covers training, validation and testing data: origin, collection, annotation, labelling and enrichment, assumptions, gaps and bias examination. Each dataset gets an owner.
Article 13 instructions for deployers are drafted in plain language. So are the Article 50 notices users must see when they talk to a machine or view synthetic content.
The Article 72 post-market monitoring plan comes with a change log that keeps Annex IV section six true as the system evolves. A handover session follows, then optional quarterly reviews.
EU AI Act compliance documentation for a high-risk provider rests on four records; the scope review says which you lack first. The Annex IV technical file is the spine; the Article 9 risk description and the Article 10 data record feed it; the Article 72 post-market plan keeps it true after release. All four sit inside our AI services.
Article 11 of the EU AI Act requires that “the technical documentation of a high-risk AI system shall be drawn up before that system is placed on the market or put into service and shall be kept up-to date”.
The nine Annex IV sections in one document, when your counsel has placed a system in Annex III and no file exists yet.
The Article 9 risk management system written out with measures and residual risk, when testing exists, but nobody has described it.
The Article 10 account of training, validation and test data, when a vendor model or scraped data leaves the origin of the data unanswered.
The Article 72 plan and change log, when the system is already live and the file must stay true as it changes.
EU AI Act compliance documentation for one AI system takes four weeks in the pilot, after a two-week scope review. The example is a curriculum vitae (CV) screening tool whose provider role and Annex III category counsel had stated; each item traces to an Annex IV section and an approver.
Pilot log · CV-screening tool
The file at that step · its result
Scope signed
The position your counsel states, on record first.
| Scope item | Sample system |
|---|---|
| System | CV-screening tool |
| Role | Provider, as counsel states |
| Category | Annex III, as counsel states |
| Annex IV sections | 9 |
| Owner | Named |
Records collected
What your existing records already cover.
Gaps closed
Missing evidence requested from named owners.
Owner sign-off · a person signs
Your owner reviews every section.
Handed over
The file stays in your own system.
Open a step, or a number below, to see the file at that stage
Every quarter the change log is reconciled with what shipped, and Annex IV section six is updated.
Illustrative example. Yellow is where your owner signs; your counsel classifies the system, and we draft to that position.
EU AI Act technical documentation gets written in five steps, each an exit, because documentation fails when it starts from a template and ends in a legal opinion: a free scoping call, a two-week scope and gap review, a four-week pilot drafting one system’s file, production for further systems, then quarterly Managed Ops; every stage ends in a signed document.
A documentation lead who owns the file and the section list, an engineer who reads the architecture, data and tests, and a reviewer who checks each section against Annex IV.
The first piece of EU AI Act documentation you need depends on your situation; five questions show which fits. Role and category unstated means a scope record first; a provider of an Annex III system, one system’s technical file; a deployer, deployer records; a chatbot or synthetic content, transparency notices; no list of AI systems, AI governance documentation first.
1. Has your counsel stated your role?
2. Has your counsel stated the risk category?
3. Is there a list of your AI systems?
4. Which records exist for the system?
5. Does the system talk to people or generate content?
Nothing in this law can be drafted before the role and the category are on record: your counsel’s position is written down with the articles that follow from it, existing records are collected, and each required document is marked present, partial or missing.
A first estimate; the scope review confirms it.
How the verdict is decided
An EU AI Act documentation company is judged on whether its file survives a market-surveillance request, not on the articles it quotes. We draft to Article 11 and Annex IV of the EU AI Act from your design, data and test records, put your counsel’s classification on page one, and keep the file true with a change log.
Outsourcing EU AI Act compliance documentation is safe when classification stays with your counsel and access stays read-only, because the risk is who decides scope and who sees design and data records. As a Bangladesh-based company, we draft inside your document system under a non-disclosure agreement, read records only and leave legal advice to counsel. Reviewed By Eicra.com team
Before you pay for EU AI Act documentation, you get evidence, not promises: a two-week scope and gap review with your own section-by-section gap list, a pilot file your owner signs before production is quoted, and a free 30-minute call. Client results appear once clients agree to be named.
For the scope and gap review, with each Annex IV section marked present, partial or missing.
To one AI system’s Annex IV technical file, drafted from your records and signed by your owner.
After handover, a section that misses its agreed acceptance list is redrafted free.
Our documentation is priced per file rather than per hour, and the cards at the top list every figure. A two-week scope and gap review ends in a written verdict, half credited to the pilot. One AI system’s Annex IV technical file is then drafted, reviewed and signed by your owner, and further systems are quoted after the pilot.
EU AI Act compliance documentation is the set of written records the law expects a provider or deployer to hold. For a high-risk system: the Annex IV technical file, the Article 9 risk management description, the Article 10 data governance record, Article 13 instructions for use and an Article 72 post-market plan. For other systems, the Article 50 notices.
Article 11 requires the provider of a high-risk AI system to draw up technical documentation before it is placed on the market or put into service, keep it up to date, and include at least the Annex IV elements, so authorities can assess compliance. Small and medium-sized enterprises, including start-ups, may provide those elements in a simplified form.
Nine items: a general description of the system; its elements and development process; monitoring, functioning and control information; the performance metrics and their appropriateness; the risk management system; changes made through the lifecycle; the harmonised standards or other solutions applied; a copy of the EU declaration of conformity; and the post-market monitoring plan. Each is drafted from your records.
A deployer keeps its own records, not the provider’s technical file. They show the instructions for use are followed, name the people on human oversight, keep logs under a retention policy and inform workers and affected people where required. Where Article 27 applies, a fundamental rights impact assessment is added. We draft to the deployer articles only.