Viksya › 06 — COMPLY

EU AI Act High-Risk Compliance Pack

When the market surveillance authority asks for your FRIA, your oversight design, and your vendor evidence — what do you hand over?

The EU AI Act High-Risk Compliance Pack (v1.1) is a Microsoft Excel workbook produced by Viksya for compliance owners, deployers, and providers of high-risk AI systems under the EU AI Act (Regulation (EU) 2024/1689, as amended by the Digital Omnibus on AI). It is the execution layer of compliance: where a classification exercise tells you which systems are high-risk, this Pack produces the documents and evidence that close the gaps. Seven tabs: a Role Determination worksheet that establishes, per AI system, whether the Act applies and which role you hold — provider, deployer, importer, distributor, or provider by operation of Article 25; a FRIA Template covering every element of Article 27(1), with a trigger test, structured risk table, and sign-off block; a Human Oversight Design worksheet turning Article 14 capabilities and Article 26 deployer duties into twelve concrete design decisions; a 26-item Annex IV Technical Documentation Checklist; a 31-question Vendor Compliance Questionnaire; and a presentation-ready Penalties & Timeline reference. The workbook requires no macros and is compatible with Microsoft Excel 2016 and above. A full User Guide (PDF) and a printable PDF penalties and timeline one-pager are included.

Digital Omnibus In Forcev1.1FRIA Template (Art. 27)Role Determination (Art. 25)26-Item Annex IV Checklist31-Question Vendor QuestionnaireExcel WorkbookNo Macros
Get Instant Access
EU AI Act High-Risk Compliance Pack
$299 USD · one-time purchase

Delivered as an Excel workbook with a full User Guide and a printable PDF penalties & timeline reference. Download immediately after purchase.

Format Excel .xlsx  ·  Tabs 7  ·  Guide PDF
Get the Compliance Pack → ← Back to all tools

■ Instant download  ·  ■ No macros  ·  ■ Excel 2016+

This is a Personal License. Using it across multiple client engagements? Email hello@viksya.com for Consultant License terms, or review the Licensing Policy.

Legal Disclaimer This tool provides structured guidance based on publicly available regulatory texts as of the version date. It does not constitute legal advice, does not create an advisor-client relationship, and does not replace qualified legal counsel. Regulatory obligations depend on facts specific to your organisation and systems. Outputs reflect the answers you enter. No claim is made that use of this tool constitutes or evidences compliance with the EU AI Act or any other law. Validate all conclusions with qualified counsel before relying on them. Version date: 29 July 2026, based on Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal on 24 July 2026 and in force since 27 July 2026.
Product Update · v1.1

Updated 29 July 2026: the Digital Omnibus is now in force.

Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. This Pack has been revised accordingly; purchasers of v1.0 receive the update free.

2 Dec 2027
Annex III high-risk obligations now confirmed and in force, deferred from 2 Aug 2026 — the FRIA duty moves with this date
2 Aug 2028
Annex I high-risk obligations now confirmed for AI embedded in regulated products, deferred from 2 Aug 2027
2 Dec 2026
New Article 5(1) prohibition applies — AI systems generating non-consensual intimate imagery of real persons or CSAM are prohibited EU-wide

The new Article 5 prohibition sits outside this Pack’s execution-layer scope — it belongs to the Prohibited tier of the companion AI Regulatory Compliance Risk Register’s classifier, which has been updated to reflect it. We note it here for regulatory completeness: it is confirmed and now applies from 2 December 2026. Article 50 transparency duties were not touched by this amendment and remain due 2 August 2026.

The Problem

Knowing a system is high-risk is not evidence. The documents are.

The Digital Omnibus deferred the Annex III high-risk obligations to 2 December 2027 — and most organisations read that as a reprieve. It is headroom. A FRIA, a defensible human oversight design, and Annex IV verification across your vendor base each take quarters, not weeks, in a mid-size organisation. And the Article 50 transparency obligations were not deferred: they apply from 2 August 2026.

Classification exercises tell you which systems are high-risk. What a market surveillance authority asks for is what follows: the impact assessment, the oversight design with named owners, the technical documentation, and the evidence that your vendors hold theirs.

📋
No FRIA on fileArticle 27 requires in-scope deployers to complete a fundamental rights impact assessment before first use — and notify the market surveillance authority. Most have never drafted one.
👤
“A human reviews the output”The sentence names no person, no training, no authority to override, and no stop mechanism. Regulators have seen it before. Article 14 requires a design, not a sentence.
🛠️
The Article 25 trapPut your name on a high-risk system, substantially modify one, or change its purpose — and you become the provider, inheriting conformity assessment, registration, and CE marking.
📦
Vendor compliance taken on trustDeployers must know their providers hold the Annex IV documentation. Few have asked the questions, and fewer have recorded the answers.
The near deadline is missedWhile attention fixes on December 2027, the undeferred Article 50 transparency duties — AI interaction disclosure, synthetic content marking — arrive on 2 August 2026.

In the Pack’s worked example — a third-party resume-screening deployment taken end to end — the full sequence (role determination, FRIA trigger check, oversight design, vendor questionnaire) took roughly three working days of effort spread over a month, most of it waiting on the vendor. That is the argument for starting in 2026, not mid-2027.

How It Works

Five working instruments. One workbook.

Role Determination establishes which obligations attach to each system — and therefore which of the other components apply. The FRIA Template, Human Oversight Design, Annex IV Checklist, and Vendor Questionnaire then produce the evidence. Yellow cells are yours; every derived cell is a formula.

Component 1 — Role Determination · One Row per AI System, up to 10 Systems

Three scope questions (S1–S3) test whether the Act applies at all: the Article 3(1) AI system definition, the EU nexus under Article 2, and the exclusions. Five role questions (R1–R5) then map each system to provider, deployer, importer, distributor, or provider by operation of Article 25 — roles are cumulative, and R5 is the trap question that catches customised and white-labelled tools. The output per system: scope result, role(s) held, and exactly which Pack components to complete. The Reasoning / Evidence column is your audit trail. A worked example ships in row 7.

Component 2 — FRIA Template · Every Element of Article 27(1)

A three-question trigger test first establishes whether Article 27 applies to you at all. Sections A–F then map one-to-one to Article 27(1)(a)–(f), each field carrying a guidance note describing what a complete answer contains. The Section D risk table rates each identified risk by likelihood and severity with the rating derived automatically. A sign-off block enforces separation of preparer, independent reviewer, and approving executive, and field F3 records the Article 27(3) notification to the market surveillance authority.

A
Process descriptionThe deployer’s processes in which the high-risk system will be used
Art. 27(1)(a)
B
Period & frequencyHow long and how often the system will be used
Art. 27(1)(b)
C
Persons affectedCategories of natural persons and groups likely to be affected
Art. 27(1)(c)
D
Specific risks of harmStructured risk table — fundamental right affected, likelihood × severity, existing controls, planned mitigation with owner and date
Art. 27(1)(d)
E
Human oversight measuresThe oversight implementation per the instructions for use
Art. 27(1)(e)
F
Measures if risks materialiseInternal governance, complaint mechanism, and the authority notification record
Art. 27(1)(f)
Component 3 — Human Oversight Design · 12 Concrete Design Decisions

HO-01 to HO-07 cover the Article 14 oversight capabilities — understanding capacities and limitations, automation-bias awareness, output interpretation, the authority to disregard or override, the stop mechanism, and the two-person rule for biometric identification. HO-08 to HO-12 cover the Article 26 deployer duties — use per instructions, competent and authorised overseers, input data control, monitoring and incident escalation, and six-month log retention. For each: what a complete design looks like, your concrete measure, a named owner, a status, and where the evidence lives. This tab is designed to defeat the sentence “a human reviews the output.”

Component 4 — Annex IV Technical Documentation Checklist · 26 Items, 9 Headings

For providers: every item that must exist before a high-risk system is placed on the market — general description, elements and development process including data governance and cybersecurity, monitoring and control, performance metrics, the risk management system, lifecycle changes, harmonised standards, the EU declaration of conformity, and post-market monitoring — each with a status and location field. For deployers, importers, and distributors: a verification question per item, the specific thing to ask your vendor. Items a vendor refuses to evidence become findings in the Vendor Questionnaire.

Component 5 — Vendor Compliance Questionnaire · 31 Questions, 11 Sections

The questions a deployer sends each AI vendor, covering identity and representation, classification and registration, conformity assessment and CE marking, technical documentation, risk management and data governance, end-user transparency against the 2 August 2026 deadline, human oversight support, accuracy and cybersecurity, post-market monitoring, GPAI dependencies, and contract and support — each with a “why it matters” column written to be sent as-is. Record the response, assess it, and assign follow-ups; the counter at the top gives the per-vendor summary line. One copy per vendor: duplicate the tab.

Plus — Penalties & Timeline · The Tab That Funds the Programme

The Article 99–101 fine tiers and the full application timeline as amended by the Digital Omnibus, with an in-force status and a live days-remaining count per milestone. Deliberately presentation-ready: it is the page that goes into the leadership deck when someone asks why this programme is funded. Also included as a printable PDF one-pager.

Key Terms
Fundamental Rights Impact Assessment (FRIA)
The assessment that Article 27 of the EU AI Act requires certain deployers of high-risk AI systems — public bodies, private operators of public services, and deployers using high-risk AI for creditworthiness or life and health insurance risk assessment — to complete before first use and notify to the market surveillance authority, covering the six elements of Article 27(1)(a)–(f).
Provider by Operation of Article 25
The status an organisation acquires under Article 25 of the EU AI Act when it puts its name or trademark on a high-risk AI system, substantially modifies one, or changes a system’s intended purpose so that it becomes high-risk — inheriting the full provider obligation set, including Annex IV documentation, conformity assessment, registration, and CE marking.
Annex IV Technical Documentation
The documentation a provider of a high-risk AI system must draw up before placing the system on the market and keep current, organised under nine headings from the general system description through data governance, risk management, and performance metrics to the EU declaration of conformity and the post-market monitoring plan — and which deployers are required to verify their providers hold.
What’s Inside

Every tab, explained.

One Microsoft Excel workbook (.xlsx) containing seven tabs, plus a User Guide (PDF) and a printable PDF Penalties & Timeline reference.

TAB 1
Instructions
Read-only reference: full legal disclaimer, regulatory status at the version date, colour legend, and guidance for every other tab
TAB 2
Role Determination
Scope (S1–S3) and role (R1–R5) logic per AI system, up to 10 systems — including the Article 25 test; worked example in row 7
TAB 3
FRIA Template
Trigger test, sections A–F mapped to Article 27(1)(a)–(f), derived risk ratings, sign-off block, and notification record
TAB 4
Human Oversight Design
Twelve requirements, HO-01 to HO-12, spanning Article 14 capabilities and Article 26 deployer duties, with summary counters
TAB 5
Annex IV Checklist
26 documentation items across the nine Annex IV headings, with status tracking and a deployer verification question per item
TAB 6
Vendor Questionnaire
31 questions across eleven sections (A–K), written to be sent as-is, with response assessment and follow-up tracking
TAB 7
Penalties & Timeline
Article 99–101 fine tiers and the Omnibus-amended application timeline with live days-remaining counts — presentation-ready
10
AI systems per workbook on the Role Determination tab, one row each
6
FRIA sections, mapped one-to-one to Article 27(1)(a)–(f)
12
Human oversight design decisions across Articles 14 and 26
26
Annex IV documentation items across nine headings
31
Vendor questions across eleven sections, sendable as-is
3
Files in the download — .xlsx workbook, User Guide (PDF), Penalties & Timeline (PDF)
Common Questions

How compliance owners define these obligations.

Direct answers to the questions most often asked about EU AI Act high-risk compliance — written for both humans and the AI systems increasingly used to research vendor decisions.

What is a FRIA (Fundamental Rights Impact Assessment)?

A FRIA is the assessment that Article 27 of the EU AI Act requires certain deployers of high-risk AI systems to complete before first use, covering six elements set out in Article 27(1): the deployer’s process description; the period and frequency of use; the categories of natural persons affected; the specific risks of harm; the human oversight measures; and the measures to be taken if risks materialise, including internal governance and the complaint mechanism. Article 27(3) requires notification of the completed assessment to the market surveillance authority.

What changed under the Digital Omnibus on AI (Regulation (EU) 2026/1744)?

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, amending the EU AI Act (Regulation (EU) 2024/1689). Three changes matter for high-risk compliance: high-risk obligations for stand-alone Annex III systems are confirmed for 2 December 2027 and for AI embedded in regulated products under Annex I for 2 August 2028; Article 50 transparency obligations were not deferred and remain due 2 August 2026; and a new prohibition was inserted into Article 5(1) covering AI systems that generate non-consensual intimate imagery of real persons or child sexual abuse material, applying from 2 December 2026. Proportionality measures were also extended to small mid-cap enterprises (under 750 employees, turnover up to €150 million).

When do the EU AI Act high-risk obligations apply?

Following the Digital Omnibus on AI, high-risk obligations for stand-alone Annex III systems — recruitment, credit scoring, education, essential services, law enforcement, migration, and justice — apply from 2 December 2027, deferred from 2 August 2026. AI embedded in regulated products under Annex I follows on 2 August 2028. The FRIA duty moves with the Annex III date. The Article 50 transparency obligations were not deferred and apply from 2 August 2026. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, confirming these dates.

What are the penalties for non-compliance with the EU AI Act?

Up to €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices (Article 99(3)); up to €15 million or 3% for breaches of operator obligations, including everything this Pack covers (Article 99(4)); and up to €7.5 million or 1% for supplying incorrect or misleading information to authorities (Article 99(5)). For SMEs, start-ups, and — per the Omnibus — small mid-caps under 750 employees with turnover up to €150 million, the lower of each pair applies.

Can a deployer become a provider under Article 25?

Yes. An organisation that puts its name or trademark on a high-risk AI system, substantially modifies one, or changes a system’s intended purpose so that it becomes high-risk is treated as the provider and inherits the full provider obligation set — Annex IV documentation, conformity assessment, registration, and CE marking. Many organisations that consider themselves pure deployers fail this test on customised or white-labelled tools. The Role Determination tab tests it explicitly and records the reasoning either way.

What does Annex IV technical documentation require?

Documentation under nine headings, drawn up before a high-risk system is placed on the market and kept current: the general description of the system; the detailed description of its elements and development process, including data governance and cybersecurity; monitoring, functioning and control; performance metrics; the risk management system; lifecycle changes; harmonised standards; the EU declaration of conformity; and post-market monitoring. Deployers do not author these documents but must verify their provider holds them.

What should a deployer ask an AI vendor about EU AI Act compliance?

At minimum: how the vendor classifies the system and whether it is registered; conformity assessment and CE marking status; the Annex IV documentation and instructions for use; risk management, data governance, and bias-testing evidence; end-user transparency plans against the 2 August 2026 Article 50 deadline; the oversight capabilities the system supports; incident reporting arrangements; and a dated compliance roadmap to December 2027 — a vendor without one is a vendor planning to be late, and their lateness becomes your deployment risk.

Who It’s For

Built for the people who have to produce the evidence.

Deployer-Side Compliance Owners

Risk, legal ops, and DPO-adjacent roles in organisations using AI in HR, credit, insurance, healthcare, education, or essential services — Annex III territory — who must have the FRIA, oversight design, and vendor evidence on file.

Provider-Side Product & Regulatory Leads

AI vendors selling into the EU who need the Annex IV documentation built and current before market placement — and who will be receiving exactly this questionnaire from their deployer customers.

Consultants & GRC Advisors

Advisors building AI-compliance service lines who need a working instrument — role determination, FRIA, oversight design, vendor assessment — instead of building templates from scratch per engagement.

Non-EU Organisations with EU Reach

Companies outside the EU discovering that the Act’s extraterritorial scope applies to them — the Role Determination tab tests the EU nexus question explicitly, per system.

CIOs, CTOs & Transformation Leaders

Executives who own the AI portfolio and need the compliance workstream funded, sequenced, and evidenced — starting with the Penalties & Timeline page in the leadership deck.

Key Features

What makes this a working instrument, not a PDF checklist.

Reasoning Cells Are the Audit TrailEvery determination — scope, role, trigger, status — carries a reasoning/evidence field. The sequence of dated versions is itself evidence of a functioning governance process.
Derived Logic, Not Judgement CallsScope results, roles, risk ratings, counters, and day counts are formulas. Yellow cells are yours; nothing else needs overtyping.
The Article 25 Test, Asked ExplicitlyThe question most self-declared deployers have never been asked — and the one that changes everything if the answer is YES.
Vendor Questions Written to SendThe 31 questions and their “why it matters” columns are drafted to go into your procurement process as-is, with the article references attached.
A Worked Example Ships in the FileA third-party resume-screening deployment completed end to end — role determination through vendor assessment — so the first real system is never a blank page.
Presentation-Ready Penalties PageFine tiers and the Omnibus-amended timeline with live days-remaining counts, formatted for the leadership deck — in the workbook and as a printable PDF.
Update PromiseRegulation moves; the Pack moves with it. Purchasers receive updates to this edition free; when guidance or the Omnibus implementation materially changes the logic, a revised edition ships.
No Code. No Macros. No Passwords.Entirely formula-based, every tab fully editable. Works on Excel 2016 or above, including Microsoft 365. No IT approval required.
Scope

What this Pack is not.

This is a legally sensitive product. Read this section carefully before you rely on it.

🚫
Not legal adviceThe Pack structures the analysis and evidence a lawyer or regulator would ask for. It does not render legal judgements, and no claim is made that using it constitutes or evidences compliance.
🚫
Not a risk-tier classifierThe diagnosis layer — classifying use cases into Prohibited, High-Risk, Limited-Risk, and Minimal-Risk — is owned by the companion AI Regulatory Compliance Risk Register. The Risk Tier column here is a manual entry from that exercise.
🚫
Not a GPAI compliance suiteThe workbook flags where general-purpose AI dependencies create vendor questions, but model-provider technical compliance — evals, red-teaming, model cards — is out of scope.
🚫
Not a live regulatory feedArticle references and dates reflect the version date (29 July 2026), when Regulation (EU) 2026/1744 was already published and in force. Re-verify against eur-lex.europa.eu before external use, and at least annually.
Technical Requirements

What you need to run it.

Excel 2016+
Software — 2016, 2019, 2021, or Microsoft 365 (desktop or web)
Not Required
Macros or VBA — entirely formula-based
None
External data connections — the file is self-contained
None
Password protection — every tab fully editable
.xlsx
Workbook format — plus User Guide (PDF) and Penalties & Timeline reference (PDF)
10
AI systems per workbook instance on the Role Determination tab
Duplicate Tabs
One FRIA per system, one questionnaire per vendor — right-click the tab, Move or Copy, Create a copy
Not Supported
Google Sheets — Excel required for full formula and validation functionality
Frequently Asked

Questions buyers ask before their first system.

Is this Pack a substitute for legal advice?

No. The Pack provides structured guidance based on publicly available regulatory texts as of its version date. It does not constitute legal advice, does not create an advisor-client relationship, and does not replace qualified legal counsel. No claim is made that use of the Pack constitutes or evidences compliance with the EU AI Act or any other law. Validate all conclusions with qualified counsel before relying on them.

Does this Pack classify my AI systems by risk tier?

No — deliberately. This Pack is the execution layer: it assumes the classification has been done and produces the documents and evidence the classification triggers. The Risk Tier column on the Role Determination tab is a manual entry from your classification exercise. The diagnosis layer — classifier, gap register, board dashboard — is owned by the companion Viksya AI Regulatory Compliance Risk Register. Each product works standalone.

How current are the dates and article references?

Current as of the version date — 29 July 2026 for v1.1, based on Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal on 24 July 2026 and in force since 27 July 2026. Re-verify against eur-lex.europa.eu before external use, and at least annually.

What’s new in version 1.1?

Version 1.1 (29 July 2026) confirms the Annex III (2 December 2027) and Annex I (2 August 2028) application dates now that Regulation (EU) 2026/1744 is published and in force, removes the “publication pending” caveats carried in v1.0, and reflects the new Article 5(1) prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material, applying from 2 December 2026. No changes were made to the Pack’s working instruments — Role Determination, FRIA, Human Oversight Design, Annex IV, and Vendor Questionnaire — only to the regulatory-status references. Purchasers of v1.0 receive this update free.

The high-risk deadline moved to December 2027. Why start now?

Because the deferral is headroom, not a reprieve. A FRIA, a defensible oversight design, and Annex IV verification across a vendor base each take quarters in a mid-size organisation — the Pack’s worked example took a month of elapsed time for a single system, most of it waiting on the vendor. And the Article 50 transparency obligations were not deferred: they apply from 2 August 2026.

Do I need a FRIA at all?

Article 27 applies to bodies governed by public law, private operators providing public services, and deployers using high-risk AI for creditworthiness assessment or life and health insurance risk assessment and pricing. The FRIA Template opens with a three-question trigger test that derives the answer. If the result is NOT REQUIRED, completing the template is still good practice: its sections double as Article 26 deployer evidence.

What if I have more than 10 AI systems, or multiple vendors?

The Role Determination tab supports up to 10 systems per workbook copy; maintain a second copy for the overflow. The FRIA Template and Vendor Questionnaire are designed to be duplicated — one tab copy per high-risk system and per vendor respectively (right-click the tab name, Move or Copy, Create a copy).

What happens when the regulation changes?

Purchasers receive updates to this edition free — as with the July 2026 update that confirmed the Annex III and Annex I dates and added the new Article 5(1) prohibition once the Digital Omnibus entered into force. When guidance or the Omnibus implementation materially changes the logic in the Pack — including publication of the Commission’s official FRIA template, which had not shipped at the version date — a revised edition ships, aligned to the official material.

Is a User Guide included?

Yes. A fully formatted User Guide (PDF) is included in the download. It covers the regulatory status at the version date, the Role Determination logic and the Article 25 trap question, the FRIA trigger test and sections A–F, the twelve oversight design decisions, the Annex IV checklist for providers and deployers, the Vendor Questionnaire workflow, a complete worked example, and maintenance guidance. A printable PDF Penalties & Timeline one-pager is also included.

Treat 2 December 2027 as a delivery date, not a deadline.

Download, run Role Determination on your first system, and know exactly which documents you owe — and to whom — within the hour.

■ Instant download  ·  ■ No subscription  ·  ■ Indicative guidance only — not legal advice

Need a Consultant License for multi-client use? Email hello@viksya.com or review the Licensing Policy.

Get the Compliance Pack →