Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Third-Party Governance

Authorised Representative Governance

What this control does

Appoint, mandate, monitor and support authorised representatives where required.

How to implement

Identify whether an authorized representative is required for the relevant provider and appoint an EU-established representative through the applicable written mandate. Distinguish high-risk AI system duties under Article 22 from GPAI model duties under Article 54. Provide the information and access needed to perform the mandated tasks, verify required records and monitor material concerns. Document how a mandate is terminated and how required notifications and continuity are handled. Do not treat a representative as taking over every responsibility of the provider.

Suggested timing and triggers

Before appointment and applicable market access; on changes to mandate or provider; ongoing mandated tasks; periodic reviews set by the organization.

Evidence examples

Appointment decision and written mandate Due-diligence and task-allocation records Required retained documentation and verification results Review correspondence and escalations Termination notices and handover records where applicable

How to check this control

Select an appointment and test whether the representative can perform a specific mandated task and retrieve the required records. Check that the mandate reflects the correct legal route and that a material compliance concern would be escalated.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Authorised Representative Governance | EU AI Act Suggested Control | Tracker Networks