Working Excel templates for EU AI Act compliance: system inventory and classification, Art. 9 risk register, Annex IV technical file, Art. 10 data governance, Art. 50 transparency, vendor due diligence and Art. 4 literacy.
Seven working files covering an EU AI Act programme from the first inventory to the evidence a supervisor asks for.
They are built on a claim this site makes everywhere and that most vendors avoid: most of your AI is not high-risk. Annex III 5(b) expressly excludes financial fraud detection, point 1 excludes 1:1 biometric verification, and algorithmic trading appears nowhere in the annex. That is why the inventory comes first, and why four of the seven files apply whatever tier your systems land in.
Start with the inventory. Then buy only what your classification actually requires.
The Art. 9 risk management system as a working register: risk scenarios pre-mapped to the Annex III categories, scored, with mitigation and residual risk.
Annex IV turned into a section-by-section file with an evidence owner and a completeness state for every required element.
Training, validation and testing data under Art. 10: provenance, representativeness, bias examination and the gaps you must document.
The three templates the Pro tier is built around, without the course.
The obligation with the nearest deadline — 2 August 2026, not deferred — and it applies whatever your risk tier. Touchpoint register, disclosure wording, marking register.
Step one of every programme: list the systems, then classify them along a decision path that puts the carve-outs before Annex III. The tier is derived, not typed.
32 questions to send a supplier, the scoring to read the answers, and eight contract clauses — because a deployer's obligations depend on information only the provider has.
The obligation everyone already owes and almost nobody evidences: curriculum for eight roles, a training register, and coverage that recalculates.
Every working file on this site: inventory and classification, the three high-risk templates, transparency, vendor diligence and the literacy programme. List price EUR 713.
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗The AI System Inventory & Classification workbook. Everything else depends on knowing which systems you have and which tier they fall into — and most organisations find far fewer high-risk systems than they expected, which changes the size of the programme they need to fund.
Probably yes, for three of them. Art. 4 AI literacy applies to every provider and deployer whatever the tier and has been in force since February 2025. Art. 50 transparency applies from 2 August 2026 regardless of tier. And vendor due diligence matters the moment you buy AI from someone else.
Excel workbooks, pre-filled with content rather than empty grids. They deliberately avoid FILTER, SORT, XLOOKUP and array formulas so they open and recalculate identically in Excel, LibreOffice Calc and Google Sheets.
No. These are compliance documentation templates. regulation-ai.eu is not a notified body and not a supervisory authority — your competent authority remains the only source of a binding position.