TL;DR: EU AI Act Articles 9-15 require seven categories of documentation for high-risk AI systems. These copy-paste templates cover each article with practical fill-in-the-blank sections your team can complete in 2-4 hours, not weeks. A minimum viable documentation checklist is included for teams that need to start quickly.
The EU AI Act does not specify exactly what your documentation must look like. It specifies what it must cover. Articles 9 through 15 list the documentation categories, and Annex IV details the technical documentation contents. What is missing from the regulation are the actual templates.
This page fills that gap. Each section below covers one article, explains what it requires, and provides a copy-paste template your team can complete with real information about your specific AI system deployment.
These templates are for deployers: companies using third-party AI systems in Annex III high-risk applications. If you are building your own high-risk AI system from scratch, your documentation obligations as a provider are broader and you will need Annex IV technical documentation from your own development process.
Before you start: confirm whether your AI system is actually in scope. Our EU AI Act Annex III high-risk AI systems guide covers the category definitions. If you are unsure, consult the EU AI Act compliance guide for small teams for the scoping analysis.
Timeline: what to complete before December 2, 2027 vs December 2027
The EU Digital Omnibus regulation extended most high-risk AI system deployer obligations to December 2, 2027. However, two elements have earlier relevance:
- If the AI system you deploy is built on a GPAI model, your vendor's GPAI compliance documentation should be in place by August 2, 2026. Request it now.
- Prohibited AI practices have applied since February 2025. If any of your AI uses fall into prohibited categories, no documentation saves you.
| Documentation item | Deadline |
|---|---|
| Confirm AI system is not prohibited | Immediate |
| Obtain provider's Article 11 technical documentation | Before deployment |
| Obtain provider's Article 13 instructions for use | Before deployment |
| Article 9 risk management system | December 2, 2027 |
| Article 10 training data documentation | Provider obligation (request records) |
| Article 12 logging and records | December 2, 2027 |
| Article 14 human oversight plan | December 2, 2027 |
| Article 15 accuracy/robustness records | December 2, 2027 |
Starting now gives you 17 months of runway before the December 2027 deadline. Use that time to build documentation iteratively, not in a last-minute sprint.
Article 9 template: risk management system
Article 9 requires a risk management system that runs throughout the AI system lifecycle. It must cover identification and analysis of known and reasonably foreseeable risks, estimation and evaluation of those risks, and risk mitigation measures.
Copy-paste template:
AI System Risk Management Record
System name: [e.g., "Candidate screening AI, powered by [Vendor]"] Date of assessment: [Date] System owner: [Name, role] Deployment context: [e.g., "Used to score job applications for software engineering roles before human reviewer screen"]
Identified risks:
| Risk | Likelihood (1-5) | Impact (1-5) | Risk score | Mitigation |
|---|---|---|---|---|
| Discriminatory scoring across protected characteristics | [e.g., 3] | [e.g., 5] | [15] | Quarterly bias audit, human review of all rejected candidates in protected groups |
| Model error rates above acceptable threshold | [e.g., 2] | [e.g., 4] | [8] | Monthly accuracy monitoring against hiring outcome data |
| Data breach exposing candidate personal data | [e.g., 2] | [e.g., 5] | [10] | Vendor DPA, data minimization, annual security review |
| System unavailability causing process delays | [e.g., 3] | [e.g., 2] | [6] | Manual backup process documented |
Residual risk assessment: After mitigations, overall residual risk is assessed as [acceptable / requiring escalation] because [brief rationale].
Review schedule: This record will be reviewed [quarterly / annually] and upon any material change to the AI system or deployment context.
Article 10 template: training data governance
Article 10 applies primarily to AI providers, not deployers. As a deployer, your obligation is to obtain information about the training data from your provider and document it.
Copy-paste template:
Training Data Record (Deployer)
AI system: [Name and version] Provider: [Company name] Date of information request: [Date] Information received: [Yes / No / Partial]
Provider-supplied training data information:
- Data sources: [e.g., "Provider states training data includes publicly available job postings, proprietary labeled datasets, and synthetic data. Details available in vendor's Annex IV documentation, attached."]
- Data governance practices: [e.g., "Provider confirms data quality checks, de-duplication, and bias testing as described in technical documentation dated [date]."]
- Protected characteristics handling: [e.g., "Provider states model was trained with demographic parity constraints across gender and age."]
Gaps and follow-up: [Note any information the provider has not supplied and what steps you are taking to obtain it. If provider refuses to provide training data information, document this and your risk-based response.]
Article 11 template: technical documentation (Annex IV)
Article 11 requires providers to maintain Annex IV technical documentation. As a deployer, you do not create this documentation. You obtain it from your provider and maintain it in your records.
Copy-paste template:
Technical Documentation Receipt Record
AI system: [Name and version] Provider: [Company name] Documentation version: [e.g., "v2.1, dated [date]"] Document reference: [File name or location]
Confirmation checklist (Annex IV items):
- General description of the AI system and its intended purpose
- Description of design and development process
- Information about training, validation, and testing data
- Description of system monitoring and logging
- Information about accuracy metrics and performance benchmarks
- Cybersecurity measures
Items not covered by provider documentation: [List any gaps. If significant gaps exist, consider whether the system should be deployed without this information.]
Next review date: [Align with provider's documentation update cycle or at least annually]
Article 12 template: logging and record-keeping
Article 12 requires high-risk AI systems to have logging capabilities sufficient to enable post-hoc review of the system's operation. For deployers, this means you must maintain logs and have a documented approach to record retention.
Copy-paste template:
AI System Logging and Record-Keeping Policy
System: [Name] Log storage location: [e.g., "Vendor-maintained logs accessible via API / Internal data warehouse / Both"] Log retention period: [Minimum 6 months for most uses; longer for specific sectors]
What is logged:
- Each use of the system: [Yes / No / Partial]
- Input data: [Yes / No. Note: logging input data may create additional data protection obligations]
- Output and recommendation produced: [Yes / No]
- Whether human review was completed: [Yes / No]
- Human override decisions: [Yes / No]
- Timestamp and user ID: [Yes / No]
Access controls: Logs are accessible to [roles with access]. Access is [logged / not logged]. Unauthorized access controls: [describe].
Retention and deletion: Logs are retained for [period] and deleted [automatically / manually] in accordance with [policy reference]. Retention of 10 years is required for documentation under Article 18 where logs form part of the compliance record.
Article 13 template: transparency and information to deployers
Article 13 requires providers to give deployers sufficient information to use the AI system safely. As a deployer, you should also provide transparency information to affected individuals where appropriate.
Copy-paste template (deployer user notice):
Notice of AI-assisted decision-making
[Organisation name] uses an AI system to [describe function, e.g., "assess job applications as part of our recruitment process"].
What the AI system does: [Brief plain-language description, e.g., "The system analyzes application materials to produce a relevance score that our recruitment team uses as one input when selecting candidates for interview."]
Who makes the final decision: A human recruiter reviews AI recommendations before any decision affecting your application is made.
Your rights: You have the right to request a human review of any AI-assisted decision that significantly affects you. To exercise this right, contact [email / process].
Data used: [Description of what data the AI system processes. Align with UK/EU GDPR privacy notice.]
How to get more information: [Contact details]
Article 14 template: human oversight
Article 14 requires that high-risk AI systems be designed and deployed with human oversight measures that allow humans to understand, monitor, and intervene in system operation.
Copy-paste template:
Human Oversight Plan
AI system: [Name] Oversight owner: [Role] Date: [Date]
Oversight mechanism:
Outputs from this AI system are reviewed by [role] before any [decision/action] is taken. The AI system [can / cannot] take autonomous action without human review.
Escalation triggers: Human review is mandatory before action when:
- AI system confidence score is below [threshold]
- The decision affects an individual in a [protected category, high-stakes situation]
- The AI system flags an anomaly or uncertainty
- The case is outside the system's documented intended use
Override process: Any human reviewer may override the AI system's recommendation. Overrides are [logged with reason / not logged]. Override rate is reviewed [quarterly] to identify systematic issues.
Training for oversight staff: Staff conducting oversight of this AI system have completed [training, e.g., "AI system user training, date"] and understand [key risk areas].
Stopping the system: The system can be [paused / disabled] by [role] in the event of suspected malfunction or unexpected behaviour. Contact: [name, contact details].
Article 15 template: accuracy, robustness, and cybersecurity
Article 15 covers the technical performance of high-risk AI systems. For deployers, this primarily means monitoring and verifying that the system continues to perform as specified.
Copy-paste template:
Performance and Robustness Monitoring Record
System: [Name] Monitoring owner: [Role] Monitoring frequency: [Monthly / Quarterly]
Accuracy metrics:
| Metric | Baseline (from vendor documentation) | Current measurement | Date measured | Action if threshold breached |
|---|---|---|---|---|
| [e.g., Precision] | [e.g., 0.87] | [Current value] | [Date] | Suspend use and contact vendor |
| [e.g., Recall] | [e.g., 0.82] | [Current value] | [Date] | Suspend use and contact vendor |
| [e.g., False positive rate] | [e.g., 0.08] | [Current value] | [Date] | Flag for human review |
Robustness checks:
- Out-of-distribution input handling: [How does the system behave when inputs fall outside its training distribution? Describe the check and results.]
- Performance across demographic groups: [Are accuracy metrics consistent across relevant groups? Describe the check and results.]
Cybersecurity: [Describe security measures protecting the AI system, including access controls, data encryption, and vendor security certifications. Reference vendor security documentation.]
Last formal review date: [Date] Next review date: [Date]
Minimum viable documentation checklist
If you are starting from scratch and need a usable baseline quickly, complete these four items first:
- One-page risk management summary (Article 9 template above, simplified)
- Vendor's technical documentation on file and reviewed (Article 11)
- User transparency notice published or distributed (Article 13 template above)
- Human oversight process documented and staff briefed (Article 14 template above)
This baseline set takes 2-4 hours for a team that has already gathered the vendor's documentation. It covers the most likely starting questions in any regulatory inquiry and demonstrates good-faith compliance intent.
For gaps in your current evidence, our EU AI Act deployer evidence gaps SME August 2026 guide maps the most common missing items.
Related reading
- EU AI Act deployer evidence gaps SME August 2026
- EU AI Act compliance guide for small teams
- EU AI Act August 2026 what is delayed vs what applies
- EU AI Act GPAI compliance checklist August 2
- EU AI Act Annex III high-risk AI systems
- AI governance checklist 2026
- ISO 42001 vs NIST AI RMF for small teams
- AI tool register template for small teams
- Third-party AI tool risk assessment template
- One documentation set for EU AI Act, NIST AI RMF, and Texas TRAIGA
- AI Model Cards in 2026: What Regulators Now Expect and How to Write One
- EU AI Act Conformity Assessment: What It Is and Who Must Do It
