Documentation
High-Risk AI Technical Documentation Management
What this control does
Create, maintain and review technical documentation demonstrating compliance with applicable high-risk AI requirements.
How to implement
For high-risk AI providers, maintain a controlled technical file for the system rather than a collection of unowned documents.
- Assign a documentation owner and map the applicable Annex IV information to current records.
- Link system purpose, design, data, tests, oversight and risk measures to the version being released. Include the applicable post-market monitoring plan.
- Review completeness before market placement or putting into service, and update affected documents after material changes.
- Control access, approvals and retention, and make the file retrievable for authorized reviewers. For product-related systems, coordinate the AI and sectoral documentation. Use a simplified documentation route only when its conditions are met. Where this control supports provider identification, verify the actual system, packaging or accompanying information as well as the file. For the Article 59 sandbox mapping, adapt these record-management steps to the required sandbox documentation and results summary.
Suggested timing and triggers
Before market placement or putting into service; keep current after relevant changes; periodic completeness checks set by the organization.
Evidence examples
Version-controlled technical-file index and completeness review Current design, data, test, risk and oversight records Post-market monitoring plan and change assessments Document approvals, access records and retention arrangements Provider identification and accompanying-document checks where applicable
How to check this control
Select a released system and compare its version with the technical file. Follow one significant design change into the affected records. Test retrieval of an applicable document and check that an index entry does not point to an obsolete or empty file.
Related EU AI Act obligations
Article 11; Annex IV
Prepare and Maintain Technical Documentation for High-Risk AI Systems
Article 16(b)
Identify the High-Risk AI Provider and Provide Contact Information
Article 72(3)-(4)
Maintain the High-Risk AI Post-Market Monitoring Plan in Technical Documentation
Sub-obligation of Article 72: Establish and Maintain Post-Market Monitoring for High-Risk AI
Article 59(1)(i)-(j)
Document Sandbox Training, Testing and Validation and Prepare the Required Project Summary
Sub-obligation of Article 59: Apply Article 59 Safeguards When Further Processing Personal Data in an AI Regulatory Sandbox