Conformity assessment under Article 43 is the mandatory process for verifying that high-risk AI systems meet all essential requirements (Chapter III, Section 2) and that the provider's Quality Management System (QMS) per Article 17 is effective. Planning for it involves a structured, multi-phase approach that addresses classification, documentation, route selection, resource allocation, and ongoing maintenance. This article explores the required planning from regulatory, operational, strategic, and practical perspectives, detailing core requirements, associated effort (resource/cost implications), and estimated timelines based on organization size, system complexity, and route chosen. Examples illustrate real-world application, with nuances for SMEs, large enterprises, and edge cases like continuously learning systems.
Regulatory Foundation: Core Requirements for Conformity Assessment Planning
Article 43 and Annexes VI-VII outline the conformity assessment procedures, which must be planned and executed before placing a high-risk system on the market or putting it into service. Planning requirements stem from the need to integrate the QMS (Article 17), technical documentation (Annex IV), and post-market obligations (Articles 72-73). Key elements include:
- System Classification: Accurately classify AI as high-risk (Annex III) or otherwise; document rationale to withstand authority challenges.
- QMS Establishment: Build/document the 13 QMS elements (e.g., risk management system, data governance procedures, incident reporting mechanisms).
- Technical Documentation Preparation: Compile Annex IV details (system description, risk assessments, validation evidence, change logs).
- Route Selection: Choose internal control (Annex VI) or notified-body assessment (Annex VII) based on category (e.g., biometrics require third-party).
- Execution & Declaration: Perform assessment, issue EU declaration of conformity, affix CE marking, register in EU database (Article 49).
- Ongoing Maintenance: Plan for post-market monitoring, substantial modification re-assessments, and periodic internal audits.
Planning must be proportionate (SME flexibility via lighter documentation) but comprehensive - non-compliance risks market exclusion, recalls, and fines up to €35 million or 7% global turnover. The Digital Omnibus proposals (November 2025) may introduce simplifications, such as extended SME relief or streamlined post-market plans, if adopted.
Effort Involved: Resource, Cost, and Organizational Implications
Effort varies by organization size, existing maturity (e.g., ISO 9001-certified vs. startups), system complexity (static vs. adaptive ML), and route (internal vs. notified-body). General estimates:
- Human Resources: Requires a cross-functional team (legal, engineering, quality, risk experts); SMEs may need 1-2 dedicated roles (e.g., AI compliance officer at 50-100% time); large enterprises often form 5-10 person teams or hire consultants (effort: 500-2000 person-hours for initial setup).
- Costs: Internal route: €10k-€50k (tools, training, audits); Notified-body route: €50k-€200k+ (certification fees €20k-€100k, plus surveillance €10k/year); Software/tools (QMS platforms like Greenlight Guru or custom): €5k-€20k/year; External expertise (lawyers/consultants): €20k-€100k for gap analysis/implementation.
- Organizational Impact: High for immature systems (full QMS build from scratch); lower for those with sectoral overlaps (e.g., medtech leveraging MDR QMS). Effort includes cultural shift toward documented accountability and risk-based thinking.
Example: A mid-sized fintech deploying credit-scoring AI (high-risk per Annex III) might spend €80k and 800 person-hours on internal route planning (gap analysis, QMS adaptation, documentation), versus €150k and 1200 hours for notified-body if biometrics are involved.
Estimated Timeline: Phased Planning and Milestones
A typical 12-18 month timeline assumes starting in Q1 2026 for August 2026 readiness; adjust for extensions (e.g., legacy systems to 2027, standards delays). Phases include:
- Preparation (1-3 months, Q1-Q2 2026): Classify systems, conduct gap analysis vs. Article 17/essential requirements; effort: low-medium (100-300 hours); milestone: Classification report and gap roadmap.
- Build & Document (3-6 months, Q2-Q3 2026): Implement QMS elements, prepare technical documentation; effort: high (300-800 hours); use EN 18286 draft for structure; milestone: Draft QMS manual and technical files.
- Internal Review & Route Execution (3-6 months, Q3-Q4 2026): Perform mock audits, engage notified body if required (6-12 month cycles); effort: medium-high (200-500 hours); milestone: Completed assessment, declaration/CE marking.
- Maintenance (Ongoing from Q4 2026): Activate post-market monitoring; annual internal audits/management reviews; effort: low-ongoing (100-200 hours/year).
Edge case: Continuously learning systems add 2-4 months/effort for change-control planning; SMEs may compress to 9-12 months with EU AI Office tools; delays if prEN 18286 citation lags (fallback to direct Article 17 alignment).
Practical Implementation: Strategies and Examples
Effective planning uses a project-management approach:
- Tools & Best Practices: Leverage EU AI Office compliance checkers, templates; adopt agile sprints for QMS build; train staff on Act/EN 18286 via e-learning (€5k-€10k).
- Example - Biometric Startup: 12-month plan: Month 1-2: Classification/gap analysis (effort: 150 hours, cost: €10k consultants); Month 3-7: QMS/documentation (500 hours, €30k tools/experts); Month 8-11: Notified-body assessment (300 hours, €50k fees); Month 12: Registration/maintenance setup.
- Example - Large Medtech Firm: 9-month plan leveraging MDR QMS: Month 1: Integrate AI elements (100 hours); Month 2-5: Documentation/validation (400 hours, €20k); Month 6-8: Internal assessment (200 hours); Month 9: Declaration/registration.
Proactive planning mitigates risks: allocate 20% buffer for revisions; prioritize high-impact systems; monitor standards/Digital Omnibus for timeline shifts.
Integration, Nuances, and Strategic Implications
Integrate with existing frameworks (ISO 9001, ISO/IEC 42001) for efficiency; nuances: extraterritorial providers face "Brussels effect" (global alignment); strategic: view as investment in trust/competitiveness (reduced liability, faster scaling); implications: delayed planning risks market exclusion post-Aug 2026.
For SMEs: Use free resources (EU AI Office guides); for enterprises: Appoint dedicated teams. Overall, planning effort pays off in sustainable, compliant AI operations.
Summary
Effective conformity assessment planning under the EU AI Act is not a one-time event but a structured, ongoing capability. Organizations that invest early in classification, QMS development, technical documentation, and audit trails will be best positioned to achieve compliance efficiently and maintain it sustainably after 2 August 2026.
Content based on the EU AI Act (Regulation (EU) 2024/1689), Article 17, and the prEN 18286 draft standard. The standard remains under revision; always consult the latest CEN/CENELEC drafts, EU AI Office guidance, and legal experts for implementation. High-risk provisions, including Article 17 QMS, become fully applicable on 2 August 2026.