Template · Article 11 and Annex IV · Applies with the high-risk regime from 2 December 2027 (Annex III)
Annex IV Technical Documentation Template (Article 11)
Annex IV technical documentation is the file that Article 11 of the EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744) requires providers of high-risk AI systems to draw up before market placement and keep up to date afterwards, following the content list in Annex IV — system description, design and data, oversight, testing, risk management, standards, declaration of conformity and post-market monitoring. The duty bites with the high-risk regime: from 2 December 2027 for Annex III systems, from 2 August 2028 for AI in Annex I Section A products. The Digital Omnibus added an express right for SMEs and small mid-caps to provide the information in a simplified form.
Last reviewed: 26 August 2026 · Applies with the high-risk regime from 2 December 2027 (Annex III) · Included in the kit as 15_Technical_Documentation_AnnexIV.docx
What this document is
Document 15 of the RegShelf kit is a fill-in skeleton that follows Annex IV section by section, so a completed copy demonstrates on its face that the documentation contains everything Annex IV asks for. Market surveillance authorities and notified bodies work from this structure; keeping it makes their review — and yours — faster. The template is designed as the hub of the technical file: risk management (doc 16), data governance (doc 17), human oversight (doc 18) and the accuracy and robustness test log (doc 19) plug into it by reference rather than duplication, and a final annex index makes the whole file navigable from one document.
Who needs it
Providers of high-risk AI systems — including SMEs that become providers by building on third-party models and offering the result under their own name, or by white-labelling. Deployers do not owe Annex IV documentation, but they should expect their high-risk vendors to have it (it is what question E2 of the kit's vendor questionnaire probes). The simplified documentation option matters here: the Digital Omnibus gave SMEs (Recommendation 2003/361/EC — in essence fewer than 250 staff within turnover/balance-sheet ceilings), including start-ups, and small mid-caps (Recommendation (EU) 2025/1099 of 21 May 2025 — in essence fewer than 750 employees within separate ceilings) an express right to provide the Annex IV information via the Commission's simplified form, which notified bodies and authorities must accept.
What the law requires — precisely
Article 11 requires the documentation to exist before the system is placed on the market or put into service, to demonstrate compliance with the Chapter III Section 2 requirements, and to be kept up to date. Article 18 requires the provider to keep it for 10 years after market placement. The simplified form condenses, but does not remove, the substance — you still need real answers on intended purpose, data, oversight, testing and risk management. Two honest caveats the template itself flags: SME or small mid-cap status should be re-checked yearly, and the Act does not say when a provider that loses the status must move to full documentation — the template's suggested transition (upgrade at the next significant change in design, anchored in the Article 111 concept) is labelled as an internal approach, not a statutory rule.
What's inside the RegShelf template
Eleven sections mirroring Annex IV, with [core] tags marking the minimum set to carry into the simplified form:
- Document control — including a simplified-form checkbox and the 10-year retention note;
- General description [core] — nine Annex IV point 1 items from intended purpose to instructions for use;
- Elements and development process — methods, third-party and pre-trained components, design specifications [core], architecture, data requirements [core] (referencing the doc 17 data governance log), human oversight assessment [core], predetermined changes, validation and testing [core], and cybersecurity with an AI-specific threat table (data poisoning, model poisoning, adversarial examples, extraction, model flaws);
- Monitoring, functioning and control [core] and appropriateness of performance metrics;
- Risk management system [core] — referencing doc 16;
- Lifecycle change log, harmonised standards applied, EU declaration of conformity (with the Annex V element list), post-market monitoring plan and an evidence index.
How to use it
Complete one copy per high-risk system, starting from the classification assessment that made it high-risk. Attach or link evidence rather than duplicating it, and let docs 16–19 of the kit fill their sections by reference. If you qualify as an SME or small mid-cap, verify status, tick the simplified-form box and complete at least the [core] sections. Version-control every change in the lifecycle table — it is the audit trail an authority reads first — and keep the file 10 years after market placement. The Section 10 plan pairs with the post-market monitoring kit.
Related reading
- Risk Classification Assessment template
- Post-Market Monitoring Plan template
- Timeline & deadlines
- Article 50 transparency
Frequently asked
What must Annex IV technical documentation contain?+
A general description of the system; a detailed description of its elements and development (design specifications, architecture, data requirements, human oversight assessment, validation and testing, cybersecurity); monitoring and control information; the appropriateness of performance metrics; the risk management system; a lifecycle change log; standards applied; a copy of the EU declaration of conformity; and the post-market monitoring plan.
Can SMEs use simplified technical documentation under the AI Act?+
Yes. Since the Digital Omnibus (Regulation (EU) 2026/1744), SMEs including start-ups (Recommendation 2003/361/EC) and small mid-caps (Recommendation (EU) 2025/1099) have an express right to provide the Annex IV information via the Commission's simplified form, which authorities and notified bodies must accept. The form condenses the structure, not the substance.
When does technical documentation have to be ready?+
Before the high-risk system is placed on the market or put into service, and it must be kept up to date afterwards. The high-risk regime applies from 2 December 2027 for Annex III systems and from 2 August 2028 for AI in Annex I Section A products — but building the file realistically takes months, so start when a system enters your pipeline.
How long must technical documentation be kept?+
10 years after the system was placed on the market or put into service (Article 18). Note this retention duty covers the documentation itself — it is not a basis for retaining raw personal training data, which remains governed by the GDPR's storage-limitation principle.
Primary sources
- Regulation (EU) 2024/1689 (consolidated)
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- Commission Recommendation (EU) 2025/1099 (small mid-caps)
This template ships in the EU AI Act Kit
24 fill-in documents in Word and Excel — launch price €149, twelve months of updates included.
See the full kit