Eight-module certification for providers of high-risk AI systems: risk management, data governance, Annex IV documentation, oversight by design, conformity assessment, CE marking, registration and post-market monitoring.

The provider obligations are the heaviest part of the Regulation, and the part most organisations assume does not apply to them. It frequently does. Art. 3(3) makes you the provider if you develop a system and put it into service under your own name — whether or not you sell it, and whether or not you wrote the code. An internal model built by your own team has a provider, and it is you.

This track works through Chapter III in the order you actually build it: what you must establish before development, what you must produce during it, what you must sign before placing the system on the market, and what you must keep doing afterwards.

The eight modules

Module 1 — Are you a provider, and by which route? Art. 3(3), placing on the market versus putting into service, the Art. 25 inheritance, and the fork between the Annex I and Annex III regimes.

Module 2 — The risk management system (Art. 9) A continuous iterative process across the lifecycle, not a document produced once. Identification, estimation, evaluation, mitigation, and the residual risk you must be able to defend.

Module 3 — Data and data governance (Art. 10) Training, validation and testing data: relevance, representativeness, error, completeness, bias examination — and the narrow permission in Art. 10(5) to process special-category data to detect bias.

Module 4 — Technical documentation (Art. 11 + Annex IV) The file, element by element, drawn up before the system is placed on the market and kept current.

Module 5 — Logging, instructions, oversight by design (Art. 12-14) What the system must record, what the deployer must be told, and what the interface must let a human do.

Module 6 — Accuracy, robustness, cybersecurity, and the QMS (Art. 15, Art. 17) Declared performance under stated conditions, resilience, adversarial threats specific to AI, and the management system that holds it together.

Module 7 — Conformity, declaration, marking, registration (Art. 43, 47-49) Annex VI or Annex VII, what the declaration asserts, where the CE marking goes, and what the EU database entry contains.

Module 8 — After the market: monitoring and incidents (Art. 72-73) The post-market monitoring plan, serious incident reporting and its deadlines, and what a substantial modification does to everything above.

What the examination asks

Twenty-five questions drawn from a bank, stratified so every module is covered, graded on our server. The pass mark is 70%.

Before you start

This track assumes the free Fundamentals course, and reads better after the Deployer track — because a provider that does not understand what its deployers owe will not write usable instructions for use, and Art. 13 makes that a defect in the product.

This is not the same examination

The Fundamentals examination checks that you have read the Regulation. This one checks that you could apply it to a real case — same subject, different question.

Fundamentals (free) Provider (this track)
Questions served 1525
Question bank 60109
Modules covered 58
What is tested Whether you are in scope, and by what Determinations that are cheap now and unaffordable to reverse later
Access Open, no card required Track holders only

Two sample questions on the same article. They are written for this page and appear in no bank.

Fundamentals — free

Which annex sets out the content of the technical documentation for a high-risk AI system?

  1. Annex III
  2. Annex IV
  3. Annex VI
  4. Annex XI
Show the answer and the reasoning

Answer 2. Annex III lists the high-risk use cases, Annex VI is the internal-control assessment procedure and Annex XI is the GPAI model documentation. Recall of a reference, and nothing more.

Provider — this track

You are placing an Annex III point 4 recruitment screening system on the market. You have applied no harmonised standard, because none yet covers your requirement. Which conformity assessment route applies?

  1. Annex VII — a notified body must assess the quality management system and the technical documentation
  2. Annex VI internal control, with Annex IV element 7 describing the solutions you adopted instead
  3. The sectoral route under the Annex I legislation governing employment
  4. No assessment until harmonised standards are published
Show the answer and the reasoning

Answer 2. Art. 43 routes Annex III points 2 to 8 through internal control; the notified body requirement attaches to point 1 biometrics in defined circumstances, and to Annex I products via their own legislation. Budgeting for a notified body on an employment system is the commonest and most expensive planning error in this area — and the absence of a standard changes what you write in element 7, not which route you take.

Every paper is drawn per candidate and stratified across all modules; the order of the options differs between candidates. Grading happens on the server — the answer key never reaches the browser.

Frequently Asked Questions

Art. 3(3): a natural or legal person that develops an AI system or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge. Note what is absent — nothing about who wrote the code, and nothing about selling. Building a system for your own internal use makes you its provider.

Annex III systems are high-risk in their own right, as standalone systems, and their Chapter III obligations apply from 2 December 2027. Annex I systems are AI acting as a safety component of, or as, a product already covered by Union harmonisation legislation — machinery, medical devices, lifts and so on — and are governed jointly with that legislation, with obligations applying from 2 August 2028. The conformity assessment route differs accordingly.

No. For most Annex III systems, Art. 43 allows conformity assessment based on internal control under Annex VI — a self-assessment against the requirements, with no third party. A notified body under Annex VII is required for Annex III point 1 biometrics in defined circumstances, and for Annex I products the route follows the underlying sectoral legislation. Assuming a notified body is always required is a common and expensive misreading.

The Annex IV technical documentation (Art. 11) is the evidence: how the system was built, what data it was trained on, how it performs, what risks were identified and mitigated. The EU declaration of conformity (Art. 47) is the assertion: a signed statement that the system meets the requirements. One is the file; the other is the signature on it, and it is kept for ten years after the system is placed on the market.

No, and none exists. In the AI Act, conformity assessment and notified bodies apply to AI systems, not to people. This is a private certificate with a public id anyone can verify, issued by Regulation AI, and we say so on the certificate itself.

Take compliance further with the AI Act Academy

A free course, a server-graded exam, a verifiable certificate — and the working templates.