Two founders asked me the same week about the EU AI Act, and they were wrong in opposite directions. One was sure he could tick a box and “self-certify” his hiring tool with no outside involvement. The other had frozen a product launch because she believed every AI system now needs an external auditor and a CE mark. The truth sits between them — and getting it wrong costs either a failed audit or months of unnecessary delay.
I’m Anand, one of the co-founders of AramGRC. Here’s a plain-English guide to what an EU AI Act conformity assessment actually is, the difference between self-assessment and a third-party (notified body) assessment, and — the question everyone actually has — when you genuinely need an external assessor.
A quick note: this is general information to help you scope the problem, not legal advice. For your specific system, confirm the current requirements with qualified counsel — the rules and deadlines are still settling.
What is a conformity assessment under the EU AI Act?
A conformity assessment is the process of demonstrating, before your AI goes on the EU market, that a high-risk AI system meets the EU AI Act’s requirements — things like risk management, data governance, technical documentation, transparency, human oversight, accuracy and robustness. If it passes, you draw up an EU declaration of conformity, affix the CE marking, and register the system in the EU database. It’s the AI equivalent of the safety conformity process that already exists for many regulated products.
Key takeaway
Conformity assessment applies to high-risk AI systems. The first real question is not “who assesses us?” — it’s “are we high-risk at all?”
Step one: are you even high-risk?
Most of the Act’s heaviest obligations, including conformity assessment, apply to high-risk AI systems. Broadly, a system is high-risk if it’s a safety component of a regulated product, or if it falls into the Act’s listed high-risk use cases (Annex III) — for example AI used in biometrics, critical infrastructure, education, employment and hiring, access to essential services and credit, law enforcement, migration, or the administration of justice. Plenty of AI — chatbots, productivity tools, most content generation — is not high-risk, and instead has lighter transparency obligations. So the first job is an honest classification: minimal, limited, high-risk, or prohibited. Get this right and the rest of the path becomes clear.
The two routes: self-assessment vs a notified body
For high-risk systems, the Act provides two conformity-assessment procedures:
| Self-assessment (internal control) | Third-party assessment (notified body) |
| What it is | The provider assesses its own conformity against the requirements (Annex VI) | An accredited independent body (a “notified body”) assesses the system (Annex VII) |
| Who relies on it | Many Annex III high-risk systems can currently use this route | Required for certain cases (see below) |
| Effort | You build the evidence and declare conformity | External assessment of your quality management system and technical documentation |
| Output | EU declaration of conformity + CE marking + registration | Notified-body certificate, then declaration + CE marking + registration |
A notified body is an independent organisation officially designated (accredited) to assess conformity on the regulator’s behalf. Think of it as the AI counterpart to the labs that certify other CE-marked products.
So when do you actually need a third-party (notified body) assessor?
This is the part everyone gets wrong. Under the current framework:
- Many Annex III high-risk systems can go through self-assessment (internal control) — provided you’ve properly applied the relevant harmonised standards once they exist.
- A notified body is required in specific cases — most notably certain biometric systems, and situations where harmonised standards or common specifications don’t exist or haven’t been fully applied by the provider.
- If your AI is a safety component of a product already covered by third-party CE rules (Annex I product legislation), it follows that product’s existing conformity route, which often already involves a notified body.
In short: a lot of high-risk AI can self-assess today, but a meaningful slice must use a notified body — and the boundary can shift as standards and guidance evolve. Assume nothing; classify carefully.
Key takeaway
Even where the law lets you self-assess, your enterprise customers increasingly won’t. “Independent assessment” is becoming a procurement requirement, not just a legal one.
What a conformity assessment involves in practice
Whichever route applies, you need to have built and be able to evidence:
- A quality management system for how you develop and monitor the AI.
- Technical documentation (Annex IV) describing the system, its design, data and performance.
- A risk management system across the lifecycle.
- Data and data-governance quality for training, validation and testing.
- Record-keeping and logging.
- Transparency and clear information for deployers.
- Human oversight designed into the system.
- Accuracy, robustness and cybersecurity — demonstrated, not asserted.
- Post-market monitoring after you go live.
This is exactly where independent testing earns its place: a red-team and robustness assessment is some of the strongest evidence you can put behind the “accuracy, robustness and cybersecurity” and “risk management” requirements — whether or not a notified body is formally involved.
A note on timing
The Act’s obligations are phasing in, with the high-risk requirements landing across 2026 and into 2027 depending on the category, and some prohibitions and transparency duties already in force. Because the exact dates depend on your system’s classification and are still being clarified, treat any specific deadline you read (including here) as something to verify against the current official timeline before you plan around it.
What to do now
- Classify every AI system: minimal, limited, high-risk, or prohibited.
- For anything high-risk, determine your route: self-assessment or notified body.
- Build the evidence base early — QMS, Annex IV technical documentation, risk management, and independent testing of robustness and safety.
- Don’t wait for the deadline to discover a gap; the documentation and evidence take longer than the paperwork suggests.
How we help at AramGRC
We help AI product companies — in India and the US selling into Europe, as well as EU providers — get ready for EU AI Act conformity: classifying systems, mapping the requirements, and producing the independent red-teaming and assurance evidence that stands behind the robustness, security and risk-management obligations. We’re not a notified body, and we’ll always tell you honestly when you need one; what we do is get you to the point where the assessment — self or third-party — actually passes.
Not sure if the EU AI Act makes you high-risk — or who has to assess you?
We’ll help you classify your AI, map the conformity path, and build the evidence to pass. For AI companies in India, the US and the EU.
Talk to the AramGRC team
Frequently asked questions
What is a conformity assessment under the EU AI Act?
It’s the process of demonstrating that a high-risk AI system meets the EU AI Act’s requirements before it goes on the EU market — covering risk management, data governance, technical documentation, transparency, human oversight, accuracy and robustness — after which you draw up an EU declaration of conformity, affix the CE marking, and register the system.
Does the EU AI Act require a third-party assessor?
Not for every high-risk system. Many Annex III high-risk systems can use self-assessment (internal control), but certain cases — notably some biometric systems, and where harmonised standards haven’t been applied — require assessment by an independent notified body. Classification determines which route applies.
What is a notified body?
A notified body is an independent organisation officially accredited to assess conformity on the regulator’s behalf — the AI equivalent of the labs that certify other CE-marked products. It issues a certificate that supports your declaration of conformity.
Can I self-assess my high-risk AI system?
In many cases yes — a large share of Annex III high-risk systems can currently go through self-assessment, provided you properly apply the relevant harmonised standards and can evidence conformity. Some categories still require a notified body, and enterprise buyers may demand independent assessment regardless.
Is CE marking required for AI?
Yes — high-risk AI systems that pass conformity assessment must carry the CE marking, accompanied by an EU declaration of conformity and registration in the EU database, before being placed on the EU market.
When does the EU AI Act conformity assessment apply?
The high-risk obligations are phasing in through 2026 and into 2027 depending on the system category, with some prohibitions and transparency duties already in effect. Confirm the exact timeline for your classification against the current official guidance.
About the author
Anand — Co-founder, AramGRC. AramGRC is an independent AI assurance partner. We help AI product companies in India, the US and the EU prepare for the EU AI Act, ISO/IEC 42001 and NIST AI RMF through classification, gap assessment, and independent AI red teaming and assurance reporting.