Use this checklist to organise the work. The exact requirements depend on the system, role, risk category and application date.
1. Establish ownership and an AI inventory
Name an accountable owner for the programme and an owner for each AI system. Build an inventory that covers purchased tools, internally developed systems, embedded AI, pilots and employee use of general-purpose assistants.
- Record intended purpose, users, affected people, locations, supplier and system version.
- Identify inputs, outputs, integrations and consequential decisions.
- Link contracts, instructions, policies, technical files and operational records.
2. Decide scope, role and classification
For each use case, document whether the Act applies, which legal entity is involved and whether it acts as provider, deployer, importer, distributor, product manufacturer or GPAI model provider. Then screen prohibited practices, high-risk routes and transparency duties.
- Escalate prohibited-practice concerns immediately.
- Do not reuse a classification when the intended purpose differs.
- Record evidence, assumptions, reviewer and approval date.
3. Map applicable requirements to controls
Create a requirements register for the system and role. For high-risk systems this may cover risk management, data and data governance, technical documentation, record keeping, transparency and instructions, human oversight, accuracy, robustness, cybersecurity, quality management, conformity assessment, registration, monitoring and incident reporting.
For each requirement, name the control owner, evidence source, review frequency and current gap. Separate a written policy from evidence that the control operated in practice.
4. Prepare people and operating procedures
Support AI literacy for staff and other people who operate or use systems on the organisation's behalf. Tailor guidance to their knowledge, role, system and risk. High-risk deployments may require specific competence for human oversight.
- Define permitted and prohibited uses.
- Train reviewers to understand limitations and interpret outputs.
- Provide escalation routes for errors, bias, security events and affected-person complaints.
- Keep attendance, materials, acknowledgements and update records.
5. Implement transparency and monitoring
Where Article 50 applies, design notices, labels or machine-readable marking into the system and workflow. Test that disclosures are timely, clear and accessible rather than hidden in general terms.
Monitor performance, misuse, incidents, complaints and changes after deployment. Define thresholds for investigation, correction, suspension and regulatory reporting. Keep logs and decisions for the periods that apply to your role.
6. Review suppliers, changes and deadlines
Contracts should support the information, access, cooperation and change notification needed for your duties. A contract does not replace your own role analysis or operational controls.
- Track applicable dates by system and obligation.
- Review supplier updates and model or feature changes.
- Reassess after a new purpose, material modification, incident or legal update.
- Report progress and unresolved gaps to accountable management.
Completion of a generic checklist does not prove compliance. Preserve the system-specific reasoning and evidence behind every answer.
Official sources
Use the official text and current Commission guidance for decisions about a specific system.
