Start with classification, not documentation
Every other decision on this page depends on one answer: is your system high-risk under Annex III of the AI Act, or not? Skipping this step is the single most common way companies overspend — buying the full technical documentation package for a system that only needed a transparency notice.
Phase 1 — Classify and register (every company needs this)
- AI Act Risk Classification Checklist — the decision tree that answers the Annex III question first.
- AI Systems Registry Template — the inventory every subsequent template assumes you already have.
Phase 2 — High-risk documentation (only if Phase 1 says yes)
Article 11 and Annex IV apply here. Don't buy these before classification confirms you need them.
- Technical Documentation — Annex IV Template
- EU Declaration of Conformity Template
- Model Card Template
- DPIA Template — needed whenever the system processes personal data, which most high-risk systems do.
Phase 3 — Governance and ongoing oversight (every deployer needs this)
These aren't one-time paperwork — they're the operational layer Articles 14 and 26 expect to keep running after go-live.
Phase 4 — If you don't know where to start
- AI Act Starter Kit — bundles the classification checklist, registry and starter policies in one purchase.
- Audit Documentation Pack — for when an auditor or client due-diligence request is already on the calendar.
Which article each template answers
| Template | AI Act reference |
|---|---|
| Risk Classification Checklist | Article 6, Annex III |
| Technical Documentation (Annex IV) | Article 11 |
| EU Declaration of Conformity | Article 47 |
| Human Oversight Procedure | Article 14, Article 26(2) |
| Serious Incident Report | Article 73 |
| Post-Market Monitoring Plan | Article 72 |
Frequently asked questions
What templates do I need to comply with the AI Act?
It depends on your risk classification. Every company needs a risk classification checklist and a system registry. Only systems that come out high-risk need the heavier package: technical documentation (Annex IV), an EU declaration of conformity, a model card, and often a DPIA. Everything else needs governance basics — human oversight and incident procedures.
Do I need the full technical documentation for every AI system?
No. Article 11 and Annex IV's full technical documentation requirement applies specifically to high-risk systems. A limited-risk system, like a customer-facing chatbot, mainly needs a transparency disclosure, not the full documentation package.
Are templates enough, or do I still need a lawyer?
Templates give you the structure and the fields regulators and auditors expect to see filled in — they don't replace legal review of your specific facts. Treat them as the operational foundation that makes a lawyer's review faster and cheaper, not a substitute for it.
What's the cheapest way to start if I don't know where I stand?
Run the free risk classification exercise first — it's the one step that tells you which of the more expensive documentation templates you actually need, so you don't buy the high-risk package for a system that never required it.