Working template

EU AI Act Technical Documentation File — Annex IV Template (Art. 11)

Updated

Annex IV reads as nine dense paragraphs. This turns them into 30 discrete elements, each with an owner, a state and a place to point at the evidence, so readiness becomes a number.

€99 excl. VAT · one-time

Delivered by email immediately after payment. Excel file, one named user.

Art. 11 says the technical documentation must be drawn up before the system is placed on the market and kept up to date. Annex IV says what has to be in it.

Annex IV is nine paragraphs of dense prose. Read as prose, it produces meetings. Read as a checklist, it produces a file.

What is in the file

Thirty discrete elements, extracted from the nine Annex IV sections and listed individually — from "intended purpose, provider name, version" through "validation and testing procedures, metrics used, and test logs" to "the post-market monitoring plan under Art. 72".

Each element carries a state (missing, drafted, reviewed, complete, not applicable), an owner, and a link to where the evidence actually lives. That last column is the one that turns a documentation exercise into an audit trail.

A completeness view that recalculates per section, so "are we ready" has a percentage instead of an opinion — and so the section that is 0% is visible before an auditor finds it.

A change log, because Art. 11 requires the file to be kept up to date and a file with no version history cannot show that it was.

Who fills it in

If you are the provider, all of it. If you are a deployer, you do not owe an Annex IV file — but you will need much of its content anyway, and getting it out of your vendor is a contractual matter best settled before signing. The vendor due diligence pack is the questionnaire for that.

One thing worth knowing

Art. 18 requires this documentation to be kept for ten years after the system is placed on the market. Reaching 100% completeness is the beginning of that obligation, not the end of it.

What it covers in the regulation

Frequently Asked Questions

Before the high-risk system is placed on the market or put into service (Art. 11), and it must be kept up to date afterwards. Art. 18 then requires it to be retained for ten years.

No, that is a provider obligation. But a deployer needs much of its content to meet Art. 26 duties, which is why getting it from the vendor is a contractual question best settled before signing.

Annex IV §7 asks for the list of harmonised standards applied, and where none apply, a description of the solutions adopted to meet the requirements. Absence of a standard is not absence of an obligation.