Regulation (EU) 2024/1689 Every article and annex, on every file — verified, not assumed

The most rigorous Annex IV conformity file an AI provider can deliver.

The EU AI Act Conformity File Engine assembles a regulator-ready technical file — Annex IV technical documentation, Article 9 risk-management file, data-governance record, post-market monitoring plan, and a draft EU Declaration of Conformity — checked against the letter of the AI Act before a qualified reviewer releases it.

Every article of Regulation (EU) 2024/1689Annex IV nine sections, gate-checkedRisk classification · evidence mapping · gap analysisQualified reviewer release on every file5-business-day SLA
Why files fail

A single missing element can trigger a €15M fine.

An AI provider's conformity assessment is only as strong as the technical file behind it. Miss one of the nine Annex IV sections, skip a required risk-management step, misclassify the system, or fail to document data governance — and the provider faces administrative fines up to €15M or 3% of worldwide annual turnover.

Most providers run this by hand, from memory, once or twice before a deadline. The Act has not been read end-to-end since the last time it mattered. That is exactly where completeness gaps hide.

The EU AI Act Conformity File Engine exists to close that gap with a single, exhaustive standard applied identically to every file.

1 of 9
missing Annex IV sections is enough to jeopardize a conformity assessment
The benchmark

Measured against the letter of the AI Act — article by article, annex by annex.

We do not summarize the law and hope. Every file is scored against a versioned rule pack tied to the exact text of Regulation (EU) 2024/1689. These are the provisions each file is held to.

Art. 11 & Annex IV

Nine technical documentation sections

General description, development methodology, system architecture, training data, performance metrics, risk management, data governance, transparency, and human oversight — all present, or the file does not release.

Art. 9

Risk-management system

A documented risk-management process covering identification, analysis, evaluation, mitigation, and residual risk acceptance — mapped to the system's intended purpose and reasonably foreseeable misuse.

Art. 10

Data governance

Training, validation, and testing data provenance, bias detection, and suitability assessment — including data collection, labeling, and preprocessing practices.

Art. 43 & Annex VI

Internal-control conformity assessment

For most Annex III high-risk systems, the provider self-assesses. The file must demonstrate compliance with Articles 9–15 and Annex IV — no notified body required.

Art. 16(g) & Art. 21

Post-market monitoring plan

A systematic plan to collect, document, and analyze data on system performance and incidents throughout the lifetime of the system.

Art. 47 & Art. 48

EU Declaration of Conformity & CE marking

A draft Declaration of Conformity referencing the relevant harmonized standards, and a CE-marking checklist — sequenced so the provider can affix the mark and register in the EU database.

How a file is built

Intake to qualified reviewer release, with deterministic gates the AI cannot overrule.

AI extracts and drafts. Deterministic rules — running as code, outside the model — decide what is complete. A qualified AI-governance reviewer signs every release. That order is never reversed.

01

System Gap Scan

Upload system artifacts (model cards, datasheets, evaluation reports, architecture docs). We return a free completeness read: which Annex IV sections and Act requirements you already have, and which are missing.

02

Risk classification & evidence mapping

We classify the system under Annex III (high-risk, limited, minimal, or GPAI) and map each Act requirement to existing evidence — flagging gaps for drafting.

03

Grounded drafting

The nine Annex IV sections are drafted from your validated artifacts and the AI Act rule pack into field-locked templates — no legal opinions, no invented facts.

04

Deterministic completeness gates

Every article and annex requirement is checked; risk management is verified; data governance is resolved; post-market monitoring plan is present. Any failure blocks release.

05

Qualified reviewer attestation

A qualified AI-governance reviewer reviews the exception queue and attests that the file is complete and internally consistent. High-risk or GPAI systems route to attorney review first.

06

Delivery

You receive the file: Annex IV technical documentation, risk-management file, data-governance record, post-market monitoring plan, draft Declaration of Conformity, and a gap-remediation plan — ready for the provider to sign and self-declare.

The bar we hold

Rigor you can measure.

100%
Qualified-reviewer attested
No file ships without a human signature.
5 days
Standard SLA
From complete intake to released file.
<1%
Critical-defect target
Tracked against a gold-standard file library.
9
Annex IV sections
Every section gate-checked, every time.
Why the EU AI Act Conformity File Engine

Built to be the most thorough option an AI provider has.

Documentation-complete, by design

The deliverable is completeness itself — every article and annex requirement accounted for or explicitly exception-coded. Nothing is left implicit.

Deterministic, not vibes

The gates that decide completeness are code, not a model's opinion. A drafting error cannot slip past a statutory requirement.

In its lane, on purpose

We prepare documentation and run evidence mapping as your clerical agent. We never provide legal advice, classify systems as high-risk, or sign the Declaration of Conformity.

Engagement

Flat fee, per released file. No hourly billing, ever.

Simple, predictable, and aligned with a documentation standard — not a cut of any recovery.

  • A free System Gap Scan before you commit — see exactly what is missing.
  • One flat fee per released Conformity File; disclosed pass-through search fees.
  • Optional fixed-fee attorney review for high-risk or GPAI systems.
  • Optional Post-Market Monitoring Add-on for continuous re-attestation and updates.
FAQ

Questions, answered precisely.

Is the EU AI Act Conformity File Engine a law firm?
No. The EU AI Act Conformity File Engine, a service of Your Deputy, Obuke LLC, provides documentation-completeness services. It is not a law firm, does not provide legal advice, and does not represent you in any legal matter. Attorney review is available and recommended for high-risk or GPAI systems.
Do you classify my system as high-risk or sign the Declaration of Conformity?
Never. The provider retains full responsibility for risk classification and signing the Declaration of Conformity. We provide a completeness-attested file and a gap-remediation plan to support your internal assessment.
What makes a file 'complete'?
Completeness is defined by the AI Act: the nine Annex IV sections present, the Article 9 risk-management system documented, data governance under Article 10 resolved, post-market monitoring plan in place, and a draft Declaration of Conformity. Deterministic gates enforce each one before release.
How fast is it?
The standard SLA is five business days from complete intake to a qualified-reviewer attested file. The free Gap Scan is returned much sooner and tells you exactly what is still needed.
How are you priced?
A flat fee per released file, plus disclosed pass-through costs. No hourly billing and no percentage of any revenue or savings.

See what's missing before it costs you €15M.

Start with a free System Gap Scan. Send your system artifacts and we'll return a completeness read against every article and annex of the AI Act.

Documentation-completeness service · not legal advice · the provider signs every declaration.