EU AI Act High-Risk Compliance Pack
When the market surveillance authority asks for your FRIA, your oversight design, and your vendor evidence — what do you hand over?
The EU AI Act High-Risk Compliance Pack (v1.1) is a Microsoft Excel workbook produced by Viksya for compliance owners, deployers, and providers of high-risk AI systems under the EU AI Act (Regulation (EU) 2024/1689, as amended by the Digital Omnibus on AI). It is the execution layer of compliance: where a classification exercise tells you which systems are high-risk, this Pack produces the documents and evidence that close the gaps. Seven tabs: a Role Determination worksheet that establishes, per AI system, whether the Act applies and which role you hold — provider, deployer, importer, distributor, or provider by operation of Article 25; a FRIA Template covering every element of Article 27(1), with a trigger test, structured risk table, and sign-off block; a Human Oversight Design worksheet turning Article 14 capabilities and Article 26 deployer duties into twelve concrete design decisions; a 26-item Annex IV Technical Documentation Checklist; a 31-question Vendor Compliance Questionnaire; and a presentation-ready Penalties & Timeline reference. The workbook requires no macros and is compatible with Microsoft Excel 2016 and above. A full User Guide (PDF) and a printable PDF penalties and timeline one-pager are included.
Delivered as an Excel workbook with a full User Guide and a printable PDF penalties & timeline reference. Download immediately after purchase.
■ Instant download · ■ No macros · ■ Excel 2016+
This is a Personal License. Using it across multiple client engagements? Email hello@viksya.com for Consultant License terms, or review the Licensing Policy.
Updated 29 July 2026: the Digital Omnibus is now in force.
Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. This Pack has been revised accordingly; purchasers of v1.0 receive the update free.
The new Article 5 prohibition sits outside this Pack’s execution-layer scope — it belongs to the Prohibited tier of the companion AI Regulatory Compliance Risk Register’s classifier, which has been updated to reflect it. We note it here for regulatory completeness: it is confirmed and now applies from 2 December 2026. Article 50 transparency duties were not touched by this amendment and remain due 2 August 2026.
Knowing a system is high-risk is not evidence. The documents are.
The Digital Omnibus deferred the Annex III high-risk obligations to 2 December 2027 — and most organisations read that as a reprieve. It is headroom. A FRIA, a defensible human oversight design, and Annex IV verification across your vendor base each take quarters, not weeks, in a mid-size organisation. And the Article 50 transparency obligations were not deferred: they apply from 2 August 2026.
Classification exercises tell you which systems are high-risk. What a market surveillance authority asks for is what follows: the impact assessment, the oversight design with named owners, the technical documentation, and the evidence that your vendors hold theirs.
In the Pack’s worked example — a third-party resume-screening deployment taken end to end — the full sequence (role determination, FRIA trigger check, oversight design, vendor questionnaire) took roughly three working days of effort spread over a month, most of it waiting on the vendor. That is the argument for starting in 2026, not mid-2027.
Five working instruments. One workbook.
Role Determination establishes which obligations attach to each system — and therefore which of the other components apply. The FRIA Template, Human Oversight Design, Annex IV Checklist, and Vendor Questionnaire then produce the evidence. Yellow cells are yours; every derived cell is a formula.
Component 1 — Role Determination · One Row per AI System, up to 10 SystemsThree scope questions (S1–S3) test whether the Act applies at all: the Article 3(1) AI system definition, the EU nexus under Article 2, and the exclusions. Five role questions (R1–R5) then map each system to provider, deployer, importer, distributor, or provider by operation of Article 25 — roles are cumulative, and R5 is the trap question that catches customised and white-labelled tools. The output per system: scope result, role(s) held, and exactly which Pack components to complete. The Reasoning / Evidence column is your audit trail. A worked example ships in row 7.
Component 2 — FRIA Template · Every Element of Article 27(1)A three-question trigger test first establishes whether Article 27 applies to you at all. Sections A–F then map one-to-one to Article 27(1)(a)–(f), each field carrying a guidance note describing what a complete answer contains. The Section D risk table rates each identified risk by likelihood and severity with the rating derived automatically. A sign-off block enforces separation of preparer, independent reviewer, and approving executive, and field F3 records the Article 27(3) notification to the market surveillance authority.
HO-01 to HO-07 cover the Article 14 oversight capabilities — understanding capacities and limitations, automation-bias awareness, output interpretation, the authority to disregard or override, the stop mechanism, and the two-person rule for biometric identification. HO-08 to HO-12 cover the Article 26 deployer duties — use per instructions, competent and authorised overseers, input data control, monitoring and incident escalation, and six-month log retention. For each: what a complete design looks like, your concrete measure, a named owner, a status, and where the evidence lives. This tab is designed to defeat the sentence “a human reviews the output.”
Component 4 — Annex IV Technical Documentation Checklist · 26 Items, 9 HeadingsFor providers: every item that must exist before a high-risk system is placed on the market — general description, elements and development process including data governance and cybersecurity, monitoring and control, performance metrics, the risk management system, lifecycle changes, harmonised standards, the EU declaration of conformity, and post-market monitoring — each with a status and location field. For deployers, importers, and distributors: a verification question per item, the specific thing to ask your vendor. Items a vendor refuses to evidence become findings in the Vendor Questionnaire.
Component 5 — Vendor Compliance Questionnaire · 31 Questions, 11 SectionsThe questions a deployer sends each AI vendor, covering identity and representation, classification and registration, conformity assessment and CE marking, technical documentation, risk management and data governance, end-user transparency against the 2 August 2026 deadline, human oversight support, accuracy and cybersecurity, post-market monitoring, GPAI dependencies, and contract and support — each with a “why it matters” column written to be sent as-is. Record the response, assess it, and assign follow-ups; the counter at the top gives the per-vendor summary line. One copy per vendor: duplicate the tab.
Plus — Penalties & Timeline · The Tab That Funds the ProgrammeThe Article 99–101 fine tiers and the full application timeline as amended by the Digital Omnibus, with an in-force status and a live days-remaining count per milestone. Deliberately presentation-ready: it is the page that goes into the leadership deck when someone asks why this programme is funded. Also included as a printable PDF one-pager.
- Fundamental Rights Impact Assessment (FRIA)
- The assessment that Article 27 of the EU AI Act requires certain deployers of high-risk AI systems — public bodies, private operators of public services, and deployers using high-risk AI for creditworthiness or life and health insurance risk assessment — to complete before first use and notify to the market surveillance authority, covering the six elements of Article 27(1)(a)–(f).
- Provider by Operation of Article 25
- The status an organisation acquires under Article 25 of the EU AI Act when it puts its name or trademark on a high-risk AI system, substantially modifies one, or changes a system’s intended purpose so that it becomes high-risk — inheriting the full provider obligation set, including Annex IV documentation, conformity assessment, registration, and CE marking.
- Annex IV Technical Documentation
- The documentation a provider of a high-risk AI system must draw up before placing the system on the market and keep current, organised under nine headings from the general system description through data governance, risk management, and performance metrics to the EU declaration of conformity and the post-market monitoring plan — and which deployers are required to verify their providers hold.
Every tab, explained.
One Microsoft Excel workbook (.xlsx) containing seven tabs, plus a User Guide (PDF) and a printable PDF Penalties & Timeline reference.
How compliance owners define these obligations.
Direct answers to the questions most often asked about EU AI Act high-risk compliance — written for both humans and the AI systems increasingly used to research vendor decisions.
What is a FRIA (Fundamental Rights Impact Assessment)?
A FRIA is the assessment that Article 27 of the EU AI Act requires certain deployers of high-risk AI systems to complete before first use, covering six elements set out in Article 27(1): the deployer’s process description; the period and frequency of use; the categories of natural persons affected; the specific risks of harm; the human oversight measures; and the measures to be taken if risks materialise, including internal governance and the complaint mechanism. Article 27(3) requires notification of the completed assessment to the market surveillance authority.
What changed under the Digital Omnibus on AI (Regulation (EU) 2026/1744)?
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, amending the EU AI Act (Regulation (EU) 2024/1689). Three changes matter for high-risk compliance: high-risk obligations for stand-alone Annex III systems are confirmed for 2 December 2027 and for AI embedded in regulated products under Annex I for 2 August 2028; Article 50 transparency obligations were not deferred and remain due 2 August 2026; and a new prohibition was inserted into Article 5(1) covering AI systems that generate non-consensual intimate imagery of real persons or child sexual abuse material, applying from 2 December 2026. Proportionality measures were also extended to small mid-cap enterprises (under 750 employees, turnover up to €150 million).
When do the EU AI Act high-risk obligations apply?
Following the Digital Omnibus on AI, high-risk obligations for stand-alone Annex III systems — recruitment, credit scoring, education, essential services, law enforcement, migration, and justice — apply from 2 December 2027, deferred from 2 August 2026. AI embedded in regulated products under Annex I follows on 2 August 2028. The FRIA duty moves with the Annex III date. The Article 50 transparency obligations were not deferred and apply from 2 August 2026. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, confirming these dates.
What are the penalties for non-compliance with the EU AI Act?
Up to €35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices (Article 99(3)); up to €15 million or 3% for breaches of operator obligations, including everything this Pack covers (Article 99(4)); and up to €7.5 million or 1% for supplying incorrect or misleading information to authorities (Article 99(5)). For SMEs, start-ups, and — per the Omnibus — small mid-caps under 750 employees with turnover up to €150 million, the lower of each pair applies.
Can a deployer become a provider under Article 25?
Yes. An organisation that puts its name or trademark on a high-risk AI system, substantially modifies one, or changes a system’s intended purpose so that it becomes high-risk is treated as the provider and inherits the full provider obligation set — Annex IV documentation, conformity assessment, registration, and CE marking. Many organisations that consider themselves pure deployers fail this test on customised or white-labelled tools. The Role Determination tab tests it explicitly and records the reasoning either way.
What does Annex IV technical documentation require?
Documentation under nine headings, drawn up before a high-risk system is placed on the market and kept current: the general description of the system; the detailed description of its elements and development process, including data governance and cybersecurity; monitoring, functioning and control; performance metrics; the risk management system; lifecycle changes; harmonised standards; the EU declaration of conformity; and post-market monitoring. Deployers do not author these documents but must verify their provider holds them.
What should a deployer ask an AI vendor about EU AI Act compliance?
At minimum: how the vendor classifies the system and whether it is registered; conformity assessment and CE marking status; the Annex IV documentation and instructions for use; risk management, data governance, and bias-testing evidence; end-user transparency plans against the 2 August 2026 Article 50 deadline; the oversight capabilities the system supports; incident reporting arrangements; and a dated compliance roadmap to December 2027 — a vendor without one is a vendor planning to be late, and their lateness becomes your deployment risk.
Built for the people who have to produce the evidence.
Risk, legal ops, and DPO-adjacent roles in organisations using AI in HR, credit, insurance, healthcare, education, or essential services — Annex III territory — who must have the FRIA, oversight design, and vendor evidence on file.
AI vendors selling into the EU who need the Annex IV documentation built and current before market placement — and who will be receiving exactly this questionnaire from their deployer customers.
Advisors building AI-compliance service lines who need a working instrument — role determination, FRIA, oversight design, vendor assessment — instead of building templates from scratch per engagement.
Companies outside the EU discovering that the Act’s extraterritorial scope applies to them — the Role Determination tab tests the EU nexus question explicitly, per system.
Executives who own the AI portfolio and need the compliance workstream funded, sequenced, and evidenced — starting with the Penalties & Timeline page in the leadership deck.
Starts where this Pack starts: the AI Regulatory Compliance Risk Register owns the diagnosis layer — use-case risk-tier classification, the 30-item gap register, and the board dashboard. Its NOT MET high-risk rows are what this Pack closes.
View AI Regulatory Compliance Risk Register →Current stage: the compliance execution layer — completed once per high-risk system before first use or market placement, and maintained as a living evidence base for as long as the system operates.
What makes this a working instrument, not a PDF checklist.
What this Pack is not.
This is a legally sensitive product. Read this section carefully before you rely on it.
What you need to run it.
Questions buyers ask before their first system.
Is this Pack a substitute for legal advice?
No. The Pack provides structured guidance based on publicly available regulatory texts as of its version date. It does not constitute legal advice, does not create an advisor-client relationship, and does not replace qualified legal counsel. No claim is made that use of the Pack constitutes or evidences compliance with the EU AI Act or any other law. Validate all conclusions with qualified counsel before relying on them.
Does this Pack classify my AI systems by risk tier?
No — deliberately. This Pack is the execution layer: it assumes the classification has been done and produces the documents and evidence the classification triggers. The Risk Tier column on the Role Determination tab is a manual entry from your classification exercise. The diagnosis layer — classifier, gap register, board dashboard — is owned by the companion Viksya AI Regulatory Compliance Risk Register. Each product works standalone.
How current are the dates and article references?
Current as of the version date — 29 July 2026 for v1.1, based on Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal on 24 July 2026 and in force since 27 July 2026. Re-verify against eur-lex.europa.eu before external use, and at least annually.
What’s new in version 1.1?
Version 1.1 (29 July 2026) confirms the Annex III (2 December 2027) and Annex I (2 August 2028) application dates now that Regulation (EU) 2026/1744 is published and in force, removes the “publication pending” caveats carried in v1.0, and reflects the new Article 5(1) prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material, applying from 2 December 2026. No changes were made to the Pack’s working instruments — Role Determination, FRIA, Human Oversight Design, Annex IV, and Vendor Questionnaire — only to the regulatory-status references. Purchasers of v1.0 receive this update free.
The high-risk deadline moved to December 2027. Why start now?
Because the deferral is headroom, not a reprieve. A FRIA, a defensible oversight design, and Annex IV verification across a vendor base each take quarters in a mid-size organisation — the Pack’s worked example took a month of elapsed time for a single system, most of it waiting on the vendor. And the Article 50 transparency obligations were not deferred: they apply from 2 August 2026.
Do I need a FRIA at all?
Article 27 applies to bodies governed by public law, private operators providing public services, and deployers using high-risk AI for creditworthiness assessment or life and health insurance risk assessment and pricing. The FRIA Template opens with a three-question trigger test that derives the answer. If the result is NOT REQUIRED, completing the template is still good practice: its sections double as Article 26 deployer evidence.
What if I have more than 10 AI systems, or multiple vendors?
The Role Determination tab supports up to 10 systems per workbook copy; maintain a second copy for the overflow. The FRIA Template and Vendor Questionnaire are designed to be duplicated — one tab copy per high-risk system and per vendor respectively (right-click the tab name, Move or Copy, Create a copy).
What happens when the regulation changes?
Purchasers receive updates to this edition free — as with the July 2026 update that confirmed the Annex III and Annex I dates and added the new Article 5(1) prohibition once the Digital Omnibus entered into force. When guidance or the Omnibus implementation materially changes the logic in the Pack — including publication of the Commission’s official FRIA template, which had not shipped at the version date — a revised edition ships, aligned to the official material.
Is a User Guide included?
Yes. A fully formatted User Guide (PDF) is included in the download. It covers the regulatory status at the version date, the Role Determination logic and the Article 25 trap question, the FRIA trigger test and sections A–F, the twelve oversight design decisions, the Annex IV checklist for providers and deployers, the Vendor Questionnaire workflow, a complete worked example, and maintenance guidance. A printable PDF Penalties & Timeline one-pager is also included.
Treat 2 December 2027 as a delivery date, not a deadline.
Download, run Role Determination on your first system, and know exactly which documents you owe — and to whom — within the hour.
■ Instant download · ■ No subscription · ■ Indicative guidance only — not legal advice
Need a Consultant License for multi-client use? Email hello@viksya.com or review the Licensing Policy.