Try all features for free — 3 credits included on sign-upTry for free
Skip to main content
Compliance · Technical Documentation

AI Act Technical Documentation Annex IV: A guide to preparing your compliance file.

Since 2 August 2026, providers of high-risk AI systems must prepare technical documentation compliant with Annex IV of Regulation (EU) 2024/1689. This guide explains the regulatory requirements and offers a methodology to transform these obligations into verifiable technical artefacts.

Jérémy Pierre
Jérémy Pierre
AI Act Compliance Expert
5 August 2026 9 min read
AI Act Technical Documentation (Annex IV): A Practical Guide to Preparing Your Compliance File
Key points · 4 figures to remember
9
regulatory pillars to document under Annex IV
48
control points in the AiActo Annex IV Workbook
23
pages of interactive documentation to get started
72h
deadline to report a serious incident to authorities
01 - Compliance

Why technical documentation is the critical point of compliance control

Annex IV of Regulation (EU) 2024/1689 is not merely an administrative formality. It constitutes the cornerstone of compliance control for high-risk AI systems.

Supervisory authorities, such as the AI Office or the CNIL, will rely on this file to assess the system's compliance. An incomplete or poorly structured file may result in fines of up to €35 million or 7% of global turnover, in accordance with Article 99 of the AI Act.

The technical documentation must demonstrate that the system complies with the requirements of Articles 8 to 15 of the AI Act. It must be updated throughout the system's lifecycle and be available for inspection for ten years after placing on the market.

"Technical documentation is not an exercise in style. It is tangible proof that your AI system has been designed, developed, and deployed in compliance with regulatory requirements."
02 - Technical Documentation

The 9 pillars of Annex IV explained

Annex IV lists nine categories of information to be documented. Here is a detailed analysis of each pillar, along with the expected technical artefacts.

1. General description of the AI system

This section must provide an overview of the system, including:

  • Name and version of the system
  • Description of the main functionalities
  • High-risk category (Annex III)
  • Overall technical architecture
  • Data flow diagram

Expected artefact: System identity sheet (maximum 1 page).

2. Detailed description of the system components and development process

This part must cover:

  • Description of software and hardware components
  • Explanation of the algorithms used
  • Development methodology (e.g., Agile, Waterfall)
  • Testing and validation phases

Expected artefact: Model card and datasheet (based on standards such as Model Cards for Model Reporting and Datasheets for Datasets).

3. Detailed information on training, validation, and test data

The requirements include:

  • Origin and quality of the data
  • Data collection and cleaning process
  • Description of potential biases and mitigation measures
  • Data performance metrics (e.g., representativeness, balance)

Expected artefact: Comprehensive datasheet with a register of data sources.

4. Risk assessment and mitigation measures

This section must document:

  • Risk assessment methodology (e.g., FRIA)
  • Identified risks and their severity
  • Mitigation measures implemented
  • Evidence of the effectiveness of the measures

Expected artefact: Risk matrix and mitigation plan.

5. Description of transparency and user information measures

The elements to document include:

  • User instructions and warnings
  • Explanations of the system's limitations
  • User feedback mechanisms

Expected artefact: User manual and transparency sheet.

6. Description of human oversight measures

This part must include:

  • Roles and responsibilities of human operators
  • Supervision and intervention procedures
  • Tools provided for oversight

Expected artefact: Human oversight procedure and intervention log.

7. Description of robustness, accuracy, and cybersecurity measures

The requirements cover:

  • Performance metrics (e.g., accuracy, recall, F1-score)
  • Robustness tests (e.g., adversarial testing)
  • Cybersecurity measures (e.g., encryption, access control)

Expected artefact: Technical test report and cybersecurity audit.

8. Description of the post-market monitoring system

This section must detail:

  • Continuous monitoring process
  • Feedback collection mechanisms
  • Update and maintenance procedures
  • Incident management plan

Expected artefact: Post-market monitoring plan and incident log.

9. Register of significant modifications

The information to be recorded includes:

  • Description of modifications
  • Justification for changes
  • Impact on compliance
  • Evidence of risk reassessment

Expected artefact: Modification register with versioning.

03 - Pitfalls to avoid

3 common pitfalls to avoid in technical documentation

Compliant technical documentation is not just about ticking boxes. Here are the frequent mistakes that can compromise your compliance.

1. Relying on an average metric score

The AI Act requires a detailed analysis of system performance, including:

  • Disaggregation of metrics by subgroups (e.g., gender, age, origin)
  • Analysis of errors and their impacts
  • Performance evaluation under real-world conditions

An overall accuracy or recall score is insufficient. Performance must be documented for each relevant group, and discrepancies must be explained.

2. Overlooking data traceability

Data traceability is a cornerstone of compliance. Authorities will require:

  • A register of data sources
  • Proof of consent or legal basis for each dataset
  • A history of data transformations

Without this traceability, it is impossible to demonstrate compliance with the GDPR or Annex IV.

3. Neglecting human oversight

The AI Act mandates human oversight measures for high-risk systems. This includes:

  • Clear definition of roles and responsibilities
  • Training of human operators
  • Documentation of intervention procedures
  • A log of human actions

An AI system cannot operate in full autonomy. The documentation must prove that human oversight mechanisms are in place and operational.

04 - Methodology

How to turn legal text into an operational action plan

Moving from regulatory requirements to technical deliverables requires a structured methodology. Here is how to proceed.

1. Assign roles and responsibilities

Technical documentation involves several stakeholders:

Role Responsibilities
Tech Lead / CTO Technical supervision, artefact validation
Data Scientist Drafting datasheets and model cards
DPO / Compliance Officer Verification of GDPR and AI Act compliance
Product Owner Documentation of functionalities and limitations
Security Officer Documentation of cybersecurity measures

2. Create a register of evidence

Each requirement of Annex IV must be linked to tangible evidence. Here is an example structure:

Annex IV Requirement Expected Evidence Responsible Status
Description of training data Datasheet + register of sources Data Scientist ✓ Validated / ⚠ In progress / ❌ Not started
Risk assessment Risk matrix + mitigation plan DPO ✓ Validated / ⚠ In progress / ❌ Not started
Cybersecurity measures Audit report + security policies Security Officer ✓ Validated / ⚠ In progress / ❌ Not started

3. Prioritise actions with a risk matrix

Not all Annex IV requirements have the same level of criticality. Use a risk matrix to prioritise:

Regulatory Impact Probability of Inspection Priority
High (fine > €10M) High (likely inspection) P1 - Urgent
Medium (fine €5-10M) Medium (possible inspection) P2 - Important
Low (fine < €5M) Low (unlikely inspection) P3 - Standard

4. Automate evidence collection

Technical documentation must be maintained throughout the system's lifecycle. To achieve this:

  • Integrate versioning tools (e.g., Git, DVC) to track modifications
  • Use MLOps platforms (e.g., MLflow, Weights & Biases) to document experiments
  • Automate report generation (e.g., Python scripts for datasheets)
05 - Resources

Resources to start your technical documentation

To help you prepare your compliance file, AiActo provides a comprehensive and free Annex IV Workbook.

Annex IV Workbook - 23 pages to get started

This interactive workbook guides you step-by-step in preparing your technical file. It includes:

  • 48 operational control points
  • System identity sheet
  • Readiness dashboard
  • Register of evidence
  • Prioritised action plan (P1/P2/P3)
  • Final validation page with signature

Available in English, French, German, and Spanish.

To download the Annex IV Workbook, visit the AiActo Document Generation page or use the direct link: PDF Download EN.

06 - FAQ

Frequently asked questions

Answers to technical and operational questions about AI Act technical documentation.

Article 11 of the AI Act imposes a general obligation for technical documentation for high-risk AI systems. It specifies that this documentation must be retained for ten years and made available to the competent authorities.

Annex IV details the specific content of this documentation. It lists the nine categories of information to be included, such as the description of data, robustness measures, or the post-market monitoring system.

Annex IV applies only to AI systems classified as high-risk under Article 6 and Annex III of the AI Act.

However, minimal technical documentation is recommended for all AI systems, even those with limited risk. This facilitates demonstrating compliance with other obligations, such as those under Article 50 on transparency.

Documenting biases should include:

  • An analysis of subgroups represented in the data (e.g., gender, age, origin)
  • Performance metrics disaggregated by subgroup
  • Performance discrepancies between subgroups and their justification
  • Mitigation measures implemented (e.g., data rebalancing, algorithm adjustments)

Use tools such as Fairlearn to analyse and document biases.

Several tools can help automate technical documentation:

  • MLflow: for tracking experiments and models
  • Weights & Biases: for documenting runs and artefacts
  • DVC: for versioning data and models
  • Fairlearn: for analysing and documenting biases
  • Great Expectations: for validating and documenting data

These tools can automatically generate parts of the documentation, such as datasheets or model cards.

The AI Act requires continuous monitoring of high-risk AI systems after placing on the market. Key steps include:

  1. Monitoring: Implement a monitoring system to detect performance drift or incidents.
  2. Assessment: Reassess risks with each significant modification to the system.
  3. Documentation: Record all modifications in the modification register (Annex IV, point 9).
  4. Notification: Report serious incidents to the competent authorities within 72 hours.

Use MLOps tools to automate parts of this monitoring, such as detecting performance drift.

Jérémy Pierre
Jérémy Pierre
Founder aiacto.eu · AI Act Compliance Expert

Supports providers and deployers of AI in achieving regulatory compliance.

Share this article