Article 31
CurrentFrom 2 Aug 2025Maintain the Governance, Independence, Resources and Competence Required of an AI Notified Body
Applies to Notified Body.
- Actors
- Notified Body
- Themes
- Risk & AssuranceSecurity & Resilience
Tracker Guidance
Maintain the organisational, quality, resource, process, independence, confidentiality, insurance, competence and cybersecurity arrangements required to perform AI conformity assessments with integrity and impartiality.
Official text
1. A notified body shall be established under the national law of a Member State and shall have legal personality. 2. Notified bodies shall satisfy the organisational, quality management, resources and process requirements that are necessary to fulfil their tasks, as well as suitable cybersecurity requirements. 3. The organisational structure, allocation of responsibilities, reporting lines and operation of notified bodies shall ensure confidence in their performance, and in the results of the conformity assessment activities that the notified bodies conduct. 4. Notified bodies shall be independent of the provider of a high-risk AI system in relation to which they perform conformity assessment activities. Notified bodies shall also be independent of any other operator having an economic interest in high-risk AI systems assessed, as well as of any competitors of the provider. This shall not preclude the use of assessed high-risk AI systems that are necessary for the operations of the conformity assessment body, or the use of such high-risk AI systems for personal purposes. 5. Neither a conformity assessment body, its top-level management nor the personnel responsible for carrying out its conformity assessment tasks shall be directly involved in the design, development, marketing or use of high-risk AI systems, nor shall they represent the parties engaged in those activities. They shall not engage in any activity that might conflict with their independence of judgement or integrity in relation to conformity assessment activities for which they are notified. This shall, in particular, apply to consultancy services. [Excerpt - see official source for complete provision]
Excerpt stored at a complete legal-unit boundary. See the official source for the full provision.
Sub-obligations
These are independently assessable parts of the parent requirement.
Article 31(1)-(3)
CurrentMaintain Appropriate Organisation, Quality Management, Processes and Cybersecurity
Tracker Guidance
Maintain legal personality and an organisational structure, allocation of responsibilities, reporting lines, quality arrangements, resources, processes and suitable cybersecurity that support confidence in conformity-assessment performance.
Official text
Article 31(1)-(3)Official source 1. A notified body shall be established under the national law of a Member State and shall have legal personality. 2. Notified bodies shall satisfy the organisational, quality management, resources and process requirements that are necessary to fulfil their tasks, as well as suitable cybersecurity requirements. 3. The organisational structure, allocation of responsibilities, reporting lines and operation of notified bodies shall ensure confidence in their performance, and in the results of the conformity assessment activities that the notified bodies conduct.
Article 31(4)-(6)
CurrentSafeguard Independence, Objectivity and Impartiality in AI Conformity Assessment
Tracker Guidance
Remain independent of assessed providers and other economically interested operators, prevent conflicts arising from design, development, marketing, use or consultancy, and document procedures that safeguard impartiality.
Official text
Article 31(4)-(6)Official source 4. Notified bodies shall be independent of the provider of a high-risk AI system in relation to which they perform conformity assessment activities. Notified bodies shall also be independent of any other operator having an economic interest in high-risk AI systems assessed, as well as of any competitors of the provider. This shall not preclude the use of assessed high-risk AI systems that are necessary for the operations of the conformity assessment body, or the use of such high-risk AI systems for personal purposes. 5. Neither a conformity assessment body, its top-level management nor the personnel responsible for carrying out its conformity assessment tasks shall be directly involved in the design, development, marketing or use of high-risk AI systems, nor shall they represent the parties engaged in those activities. They shall not engage in any activity that might conflict with their independence of judgement or integrity in relation to conformity assessment activities for which they are notified. This shall, in particular, apply to consultancy services. 6. Notified bodies shall be organised and operated so as to safeguard the independence, objectivity and impartiality of their activities. Notified bodies shall document and implement a structure and procedures to safeguard impartiality and to promote and apply the principles of impartiality throughout their organisation, personnel and assessment activities.
Article 31(7); Article 78
CurrentProtect Confidentiality and Professional Secrecy in Notified-Body Activities
Tracker Guidance
Maintain documented procedures so staff, committees, subsidiaries, subcontractors and associated external personnel protect confidential information and professional secrecy, subject to lawful disclosure requirements.
Official text
Article 31(7)Official source 7. Notified bodies shall have documented procedures in place ensuring that their personnel, committees, subsidiaries, subcontractors and any associated body or personnel of external bodies maintain, in accordance with Article 78, the confidentiality of the information which comes into their possession during the performance of conformity assessment activities, except when its disclosure is required by law. The staff of notified bodies shall be bound to observe professional secrecy with regard to all information obtained in carrying out their tasks under this Regulation, except in relation to the notifying authorities of the Member State in which their activities are carried out.
Article 78Official source 1. The Commission, market surveillance authorities and notified bodies and any other natural or legal person involved in the application of this Regulation shall, in accordance with Union or national law, respect the confidentiality of information and data obtained in carrying out their tasks and activities in such a manner as to protect, in particular: (a) the intellectual property rights and confidential business information or trade secrets of a natural or legal person, including source code, except in the cases referred to in Article 5 of Directive (EU) 2016/943 of the European Parliament and of the Council (1); (b) the effective implementation of this Regulation, in particular for the purposes of inspections, investigations or audits; (c) public and national security interests; (d) the conduct of criminal or administrative proceedings; (e) information classified pursuant to Union or national law. 2. The authorities involved in the application of this Regulation pursuant to paragraph 1 shall request only data that is strictly necessary for the assessment of the risk posed by AI systems and for the exercise of their powers in accordance with this Regulation and with Regulation (EU) 2019/1020. They shall put in place adequate and effective cybersecurity measures to protect the security and confidentiality of the information and data obtained, and shall delete the data collected as soon as it is no longer needed for the purpose for which it was obtained, in accordance with applicable Union or national law. [Excerpt - see official source for complete provision]
Excerpt stored at a complete legal-unit boundary. See the official source for the full provision.
Article 31(8)-(9)
CurrentMaintain Proportionate Assessment Procedures and Appropriate Liability Insurance
Tracker Guidance
Use assessment procedures that take account of provider size, sector, structure and system complexity while preserving required rigour, and maintain appropriate liability insurance unless the statutory public-liability exception applies.
Official text
Article 31(8)-(9)Official source 8. Notified bodies shall have procedures for the performance of activities which take due account of the size of a provider, the sector in which it operates, its structure, and the degree of complexity of the AI system concerned. 9. Notified bodies shall take out appropriate liability insurance for their conformity assessment activities, unless liability is assumed by the Member State in which they are established in accordance with national law or that Member State is itself directly responsible for the conformity assessment.
Article 31(10)-(11)
CurrentMaintain Sufficient Professional Competence and Qualified Personnel
Tracker Guidance
Maintain professional integrity and sufficient internal administrative, technical, legal and scientific expertise to perform and oversee conformity-assessment activities, including evaluation of externally performed work.
Official text
Article 31(10)-(11)Official source 10. Notified bodies shall be capable of carrying out all their tasks under this Regulation with the highest degree of professional integrity and the requisite competence in the specific field, whether those tasks are carried out by notified bodies themselves or on their behalf and under their responsibility. 11. Notified bodies shall have sufficient internal competences to be able effectively to evaluate the tasks conducted by external parties on their behalf. The notified body shall have permanent availability of sufficient administrative, technical, legal and scientific personnel who possess experience and knowledge relating to the relevant types of AI systems, data and data computing, and relating to the requirements set out in Section 2.
Article 31(12); Article 38
CurrentParticipate in Notified-Body Coordination and Remain Current on Relevant Standards
Tracker Guidance
Participate directly or through representation in required coordination activities and standardisation work, or otherwise ensure current awareness of relevant standards.
Official text
Article 31(12)Official source 12. Notified bodies shall participate in coordination activities as referred to in Article 38. They shall also take part directly, or be represented in, European standardisation organisations, or ensure that they are aware and up to date in respect of relevant standards.
Article 38Official source 1. The Commission shall ensure that, with regard to high-risk AI systems, appropriate coordination and cooperation between notified bodies active in the conformity assessment procedures pursuant to this Regulation are put in place and properly operated in the form of a sectoral group of notified bodies. 2. Each notifying authority shall ensure that the bodies notified by it participate in the work of a group referred to in paragraph 1, directly or through designated representatives. 3. The Commission shall provide for the exchange of knowledge and best practices between notifying authorities.