A complete EU AI Act compliance documentation system, rebuilt around one procedure per process. Governance, classification, risk and impact, data, lifecycle, human oversight, conformity, post-market and incidents — for providers, deployers and GPAI model providers.
One procedure per process — not four documents on the same subject. Every procedure opens with a requirement coverage table that maps each article to the step, the role and the record that satisfies it.
Each process has exactly one procedure covering every aspect of it. Forms are standalone documents you fill in, and exist only where the Regulation requires a record. The three conditional procedures state at the top when they apply — if they do not describe you, they are not part of your work.
No second document on the same subject. Incident handling, notification and corrective action are one route on one clock, not four files that have to be reconciled by hand.
Every procedure opens with a table mapping each obligation to the step that discharges it, with one accountable role and one output record. It is the page a notified body reads first.
A form exists only where the Regulation asks for a record. Everything continuous — inventory, risks, incidents, training — lives in one registers workbook instead of a folder of near-identical tables.
Retention periods are stated in one procedure. Indicators and targets in one. Declared performance figures appear identically in the test report, the Annex IV file and the instructions for use.
GPAI, importer and distributor, and real-world testing each state when they apply. Classification decides what is yours; the rest you close and ignore.
Harmonised standards and two Commission templates are not yet published. The kit says so where it matters, and carries a field for the date you last checked.
Full documents, not extracts. Judge the writing, the structure and the depth for yourself.
The procedure that decides which of the other documents apply to you: role, prohibited practices, risk class, transparency duties, GPAI status.
Download sampleArticle 14 made operational: oversight design, named overseers, authority to override and stop, and the evidence that it works in practice.
Download sampleAnnex V content, with the version control that keeps the declaration aligned to the system it covers.
Download sampleThe Regulation assigns different obligations depending on what you are. Run the classification procedure first and it tells you which documents are yours.
The full path: classification, risk and impact, data governance, lifecycle and testing, human oversight, technical documentation, declaration of conformity, CE marking, registration, post-market monitoring and incident reporting.
Article 26 obligations, human oversight assignment, input data checks, information to affected persons, the right to explanation under Article 86, and the fundamental rights impact assessment where Article 27 applies.
Annex XI documentation, the Annex XII downstream pack, copyright policy and training-content summary, and the systemic risk route under Article 55 including the notification to the Commission.
One-time payment, single entity licence, twelve months of updates. Editable DOCX and XLSX, ready to tailor.
Documentation templates, not legal advice and not certification. Conformity assessment under Article 43 is performed by you under Annex VI or by a notified body under Annex VII, and is not affected by this purchase.