Step one of every AI Act programme: list your systems, then classify them along a decision path that puts the carve-outs before Annex III. The tier is derived from your answers, not typed.
Delivered by email immediately after payment. Excel file, one named user.
You cannot classify what you have not listed, and you cannot budget a programme without knowing how many systems land in each tier. This file does both, in the order that avoids the usual mistakes.
Most classification exercises go straight to Annex III and ask "is this in the list?". That is how a fraud-detection model ends up classified as high-risk — it looks like credit scoring, and the carve-out that excludes it sits inside the same point.
The decision path here asks the eight questions in the order that gets the answer right:
You answer five yes/no questions per system. The workbook computes the tier. That matters more than it sounds: a classification someone typed is an opinion, while a classification a formula derived from stated answers is an audit trail. If a supervisor disagrees, you can show which answer drove the outcome.
Empty rows stay empty — they do not silently count as high-risk. The summary tab gives you the counts a budget conversation needs: systems listed, out of scope, prohibited, high-risk, not high-risk.
Organisations come out of this with far fewer high-risk systems than they feared, and one or two they had not noticed — typically in HR, because Annex III point 4 catches you as an employer whatever your sector.
If every system in your inventory comes out high-risk, the classification is wrong. The file says so explicitly, and tells you which three carve-outs to re-read.
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗No. Art. 3(1) requires a system that infers from input how to generate outputs. A deterministic engine executing conditions a human wrote infers nothing, and the Commission guidelines of February 2025 confirm simple rule-based systems are excluded.
Profiling of natural persons. A system that profiles is always high-risk, whatever else it does. And if you rely on the filter you must document the assessment before market placement and register the system in the EU database.
Because a typed classification is an opinion and a derived one is an audit trail. If a supervisor disagrees, you can show which stated answer produced the outcome.