Article 34
CurrentFrom 2 Aug 2025Perform Notified-Body AI Conformity Assessment Activities in Accordance With the Act
Applies to Notified Body.
- Actors
- Notified Body
- Themes
- Risk & AssuranceMonitoring, Reporting & Improvement
Tracker Networks Guidance
Verify high-risk AI conformity using the applicable Article 43 procedures, avoid unnecessary provider burden while preserving the required level of rigour, and support notifying-authority monitoring.
Official text
1. Notified bodies shall verify the conformity of high-risk AI systems in accordance with the conformity assessment procedures set out in Article 43. 2. Notified bodies shall avoid unnecessary burdens for providers when performing their activities, and take due account of the size of the provider, the sector in which it operates, its structure and the degree of complexity of the high-risk AI system concerned, in particular in view of minimising administrative burdens and compliance costs for micro- and small enterprises within the meaning of Recommendation 2003/361/EC. The notified body shall, nevertheless, respect the degree of rigour and the level of protection required for the compliance of the high-risk AI system with the requirements of this Regulation. 3. Notified bodies shall make available and submit upon request all relevant documentation, including the providers’ documentation, to the notifying authority referred to in Article 28 to allow that authority to conduct its assessment, designation, notification and monitoring activities, and to facilitate the assessment outlined in this Section.
Suggested controls
Related risks
Notified-Body Subcontracting, Certificate or Reporting Failure
Subcontracted assessment work, certificate management or required regulatory reporting may not meet AI Act requirements.
Sub-obligations
These are independently assessable parts of the parent requirement.
Article 34(1)-(2)
CurrentVerify High-Risk AI Conformity Using the Applicable Assessment Procedure
Tracker Networks Guidance
Perform the applicable conformity assessment with the required level of rigour while taking proportionate account of provider size, sector, structure and system complexity.
Official text
Article 34(1)-(2)Official source 1. Notified bodies shall verify the conformity of high-risk AI systems in accordance with the conformity assessment procedures set out in Article 43. 2. Notified bodies shall avoid unnecessary burdens for providers when performing their activities, and take due account of the size of the provider, the sector in which it operates, its structure and the degree of complexity of the high-risk AI system concerned, in particular in view of minimising administrative burdens and compliance costs for micro- and small enterprises within the meaning of Recommendation 2003/361/EC. The notified body shall, nevertheless, respect the degree of rigour and the level of protection required for the compliance of the high-risk AI system with the requirements of this Regulation.
Suggested controls
Related risks
Notified-Body Subcontracting, Certificate or Reporting Failure
Subcontracted assessment work, certificate management or required regulatory reporting may not meet AI Act requirements.
Article 34(3)
CurrentProvide Relevant Assessment Documentation to the Notifying Authority on Request
Tracker Networks Guidance
Make available and submit relevant documentation, including provider documentation, when requested for assessment, designation, notification and monitoring activities.
Official text
Article 34(3)Official source 3. Notified bodies shall make available and submit upon request all relevant documentation, including the providers’ documentation, to the notifying authority referred to in Article 28 to allow that authority to conduct its assessment, designation, notification and monitoring activities, and to facilitate the assessment outlined in this Section.
Suggested controls
Regulatory Information and Cooperation Process
Respond to reasoned regulator requests with controlled, complete and retrievable compliance information and logs.
Notified-Body Regulatory Reporting and Continuity
Report required information to notifying authorities and peer notified bodies and manage continuity when designation changes or activities cease.
Related risks
Regulatory Cooperation Failure
The organisation may be unable to provide complete, timely and understandable information, records or cooperation to competent authorities.
Notified-Body Subcontracting, Certificate or Reporting Failure
Subcontracted assessment work, certificate management or required regulatory reporting may not meet AI Act requirements.