Skip to main content

Regulation

Choosing and Briefing a Notified Body for AI Assessment

Most high-risk AI systems never touch a notified body — but knowing which ones do, and proving you decided correctly, is the provider's job. A practical route map through Article 43, the deployer-to-provider trap, and what to settle before you sign with an assessment body.

Choosing and Briefing a Notified Body for AI Assessment

The question usually arrives from procurement or a customer's assurance team, and it arrives late: "Which notified body certified this?" For most organisations the honest answer is that none is involved and none is required — but saying so with confidence means you have already done the classification work and can show it. For a minority, a notified body is required, the pool of designated bodies is still building out, and assessment lead time has just become the critical path on a launch date.

Getting this wrong is costly both ways. Budgeting for certification you never needed burns money and delays release. Assuming internal control applies when your system sits in the biometrics category, or is embedded in a product that already carries a CE mark, means placing it on the EU market without a valid conformity assessment — a breach of a core provider obligation, not a paperwork slip.

What a notified body is, and when one is required

A notified body is a conformity assessment body designated by a Member State notifying authority and notified to the Commission under Chapter III, Section 4 of the AI Act. It is not an auditor of your choosing or a scheme you can buy into. It carries a Commission-assigned identification number and appears on the Commission's public list. Its remit is the Annex VII procedure: assessment of your quality management system and technical documentation, plus ongoing surveillance.

The Act does not require a notified body for every high-risk system; Article 43 sets out which route applies.

Your situationAssessment routeNotified body?
Annex III, point 1 (biometrics), harmonised standards or common specifications applied in fullAnnex VI internal control, or Annex VII — provider choosesOptional
Annex III, point 1, where those standards do not exist, were not applied, or applied only in partAnnex VIIRequired
All other Annex III categories — employment, education, credit and insurance, essential services, law enforcement, migration, justiceAnnex VI internal controlNo
High-risk because the system is, or is a safety component of, a product covered by Annex I, Section A legislationThe sectoral procedure already required, with AI Act requirements assessed inside itYes — the existing body, widened scope

Two consequences get missed. First, the large majority of Annex III deployments — the recruitment screeners, credit models and access-to-services tools that dominate mid-size portfolios — take the internal control route. There is no external certificate to obtain and none to demand from a vendor. Second, where a system is high-risk via Annex I, Section A, third-party assessment was already mandatory for the product; the AI Act does not add a second body, it expands what the existing one examines. Confirm your current body was assessed as competent for AI Act control within its own notification — a condition of it acting here.

Who the duty falls on

The duty to ensure a high-risk AI system undergoes conformity assessment before it is placed on the market or put into service falls on the provider, and only on the provider. The same party draws up the EU declaration of conformity, affixes the CE marking and registers the system in the EU database. Deployers do not engage notified bodies.

The trap is that a deployer can become one. Under Article 25 you take on the full set of provider obligations, conformity assessment included, if you put your own name or trade mark on a high-risk system already on the market, make a substantial modification to it while it remains high-risk, or change the intended purpose of a system so that it becomes high-risk. The original provider then ceases to be the provider of that system and must cooperate and give you the information you need — but the assessment is yours to procure. A bank that rebrands a vendor's screening engine, or an employer that repurposes a general-purpose model into a promotion-ranking tool, has crossed that line whether or not anyone noticed.

Importers and distributors have verification duties only: confirm the assessment was carried out and the marking, declaration and documentation exist. A provider established outside the Union, including UK companies placing systems on the EU market, must appoint an authorised representative in the Union by written mandate, whichever route applies; that is routinely overlooked on the internal control route.

Choosing and briefing the body

Before you sign anything:

  • Verify designation on the Commission's published list, under the AI Act specifically and for your Annex category. Designation under the Medical Devices Regulation or the Machinery Regulation alone is not designation for AI Act purposes. Record the identification number and exact scope wording; that number will sit alongside your CE marking.
  • Accept that the body cannot advise you and then assess you — independence rules bar consultancy on the systems it assesses. Plan separately for the remediation work. Ask what it subcontracts and to which subsidiaries; subcontracting needs your agreement and the body stays responsible.
  • Establish the access it will need. Annex VII lets the body require further evidence and testing, access to training and validation datasets, and — where necessary and subject to safeguards — access to the trained model and to source code. Check your vendor contracts permit this before you promise it.
  • Confirm no application is lodged with another body for the same system. Annex VII requires a written declaration on that point, so you cannot run a competitive assessment.
  • Agree the surveillance regime up front — audit frequency, notice, on-site access and cost — and what triggers re-assessment. A substantial modification requires a fresh assessment; pre-determined changes documented in the technical documentation at initial assessment do not. Write those down early; it is far harder to argue afterwards.
  • Ask about capacity and realistic lead times, and diarise certificate validity: a fixed period, no longer than four years for Annex III systems and five for Annex I, extended only on re-assessment.

Where the picture is still incomplete

Several inputs are unsettled. Harmonised standards under the AI Act are still in development, and the choice on the biometrics route depends on whether relevant standards have been cited and whether you applied them in full — so that decision cannot be closed out until the standards position is clear. The pool of designated AI notified bodies is still expanding: check the current list, not a vendor's assertion. The application dates for high-risk obligations have themselves been the subject of Commission proposals linking them to standards readiness, so confirm the operative dates before planning around them.

The limits of this guidance

This explains how the routes work; it is not legal advice and cannot classify your systems for you. Classification is fact-specific, and the line between a supported decision tool and a high-risk system often turns on deployment details no general guide can see. Take specialist advice where the classification is contested, where you rely on an Article 6(3) exemption, where biometric or emotion-recognition functionality sits anywhere in the stack, or where a proposed change might reset you from deployer to provider. Take it before the modification decision, not after.

This also sits alongside, not instead of, data protection law: the same recruitment or credit system will usually engage UK or EU GDPR duties on lawful basis, transparency and automated decision-making, enforceable at up to 4% of global annual turnover in their own right. AI Act penalties reach up to 7% of global annual turnover for prohibited practices and up to 3% for most other obligations, provider duties included; supplying incorrect, incomplete or misleading information to a notified body or competent authority is separately sanctionable at a lower tier. Treat the assessment file as evidence you may one day have to produce, and write it accordingly.

  • EU AI Act
  • Conformity Assessment
  • Notified Bodies
  • High-Risk AI
  • Provider Obligations

More guides

Start Free AI Compliance Review