EU AI ActArt. 11 · Annex IV

Annex IV technical documentation: the file a conformity assessment expects

For a high-risk system, the technical documentation described in Annex IV is the file that demonstrates conformity — the dossier an authority or assessor opens to check that the system is what its provider claims. It's a provider duty, but deployers who don't understand it get caught out. Here's what it really contains.

What it is, and what it's for

Article 11 requires providers of high-risk systems to draw up technical documentation before the system goes to market, and to keep it up to date. Annex IV lists what it must contain. Its purpose is singular: to let a competent authority assess whether the system complies — so it has to be specific, current and honest, not marketing. Think of it as the engineering logbook that proves the risk-management, data-governance and testing work actually happened.

What's inside

At a high level, Annex IV expects a general description of the system and its intended purpose; details of its design, development and the data used; the risk-management measures and testing done; performance metrics and their limits; the human-oversight measures; and how the system is monitored after it goes live. The theme is traceability — someone should be able to follow how the system was built, why it's considered safe enough, and how you'd know if that changed.

It's a living document

The most common misconception is that the technical file is written once, at launch. It isn't. As the system is updated — retrained, extended, repurposed — the documentation must keep pace, because an assessment relies on it being current. This is another place where a running management system pays off: if your change management already updates records when the system changes, the technical file stays honest for free.

Why deployers should care about a provider's file

If you deploy a high-risk system you didn't build, Annex IV is technically the provider's job — but you depend on it. Before you rely on a third-party high-risk system, confirm the provider maintains this documentation and can show it, because your own compliance leans on their diligence. And the moment you substantially modify the system, you may inherit provider duties, including this one.

The practical lens. Annex IV is the file that turns "we built it responsibly" into something an assessor can verify. If you provide, build it as a living logbook; if you deploy, make a provider's ability to produce it part of your vendor due diligence.
BJ

Former IBM and Deloitte strategy consultant, now advising mid-market companies on AI governance. Founder of Govern42.

Questions about your ISO 42001 or EU AI Act programme? Email me directly: bigjay11@gmail.com

Educational orientation, not legal advice. EU AI Act references current as of September 2026. For binding interpretation of your obligations, consult qualified counsel.