Practical checklist
EU AI Act compliance checklist for SMEs
A useful compliance programme starts with facts about each system, not a generic policy document. Use this sequence to turn the regulation into owned, reviewable work.
Prepared by EU AI Fit editorial team · Published 24 August 2026 · Source review 31 August 2026
1. Establish scope and ownership
Identify every AI-enabled feature, internal tool and third-party service your organisation builds, buys or deploys. Give each record a named business owner and technical contact.
- Record intended purpose and affected users
- Identify the model or external provider
- Capture where the system is offered and used
- Set a review date and change trigger
2. Determine role and exposure
Your duties depend on whether the organisation is acting as provider, deployer, importer or distributor. Screen for prohibited practices, Annex III high-risk use cases and Article 50 transparency duties.
- Document the role rationale
- Record assumptions and missing facts
- Escalate uncertain or high-impact cases
- Do not treat an early screen as legal approval
3. Build an evidence-backed action plan
Map each applicable obligation to an owner, due date, status and evidence requirement. Keep the source, reviewer and rule version with the decision so it can be revisited when the system or law changes.
- Link policies, testing records and instructions
- Track human-oversight and transparency controls
- Review supplier documentation
- Retain approvals and change history
4. Test whether controls operate in practice
A written control is only useful when people can apply it. Sample current systems, confirm that owners understand their authority, test escalation routes and check whether the evidence matches the deployed version rather than an earlier design.
- Walk through a real decision from input to outcome
- Confirm a person can intervene, pause or escalate
- Check supplier claims against available records
- Turn failed checks into assigned corrective actions
In this scenario: Northstar Recruitment Assistant
Northstar Services Ltd uses an external assistant to rank applicants for human review. Its checklist records the intended purpose, supplier and model version, the people affected, the significance of the ranking, the organisation's deployer role, the human review design and the evidence still required from the supplier. A named owner must revisit the position when the model, purpose or decision process changes.
- Inventory record: one recruitment use case, not only the vendor name
- Exposure record: employment context and impact on applicants
- Evidence record: instructions, validation, oversight test and supplier response
- Review trigger: model update or change from recommendation to automated rejection
5. Maintain the position
Set periodic reviews, but do not rely on the calendar alone. A new purpose, supplier release, user group, geography, data source, level of autonomy, incident or control failure can make the existing assessment stale immediately.
A working checklist your team can retain
Use one row per system. Record the conclusion and its evidence rather than marking a generic organisation-wide box as complete.
| Review area | Decision to retain | Minimum supporting evidence | Suggested owner |
|---|---|---|---|
| Inventory | Is this a distinct AI system or use case, and is the record current? | Purpose, supplier or model, users, affected people, deployment and review date | System owner |
| Territorial scope and role | Why is the organisation in scope and which operator role does it hold for this system? | Market and use locations, contractual chain, branding, modifications and approved rationale | Governance or legal lead |
| Prohibited, high-risk and transparency routes | Which routes were tested, what was concluded and what remains uncertain? | Dated answers, source references, assumptions, reviewer and escalation decision | Qualified reviewer |
| Operational controls | Which controls are required for this use and are they operating? | Oversight instructions, testing, monitoring, security, incident and complaint records | Technical and operational owners |
| People and suppliers | Do relevant people have sufficient direction, and has supplier evidence been challenged? | Role-based learning, system briefings, supplier response, conditions and reassessment date | Learning and procurement leads |
| Evidence and review | Can the current position be reconstructed and when must it be reconsidered? | Approved evidence index, action owners, due dates, change triggers and decision history | Governance lead |
Questions teams usually ask
Can an SME use one EU AI Act checklist for the whole company?
A programme-level checklist is useful for governance, but role, classification, transparency and many evidence decisions must be recorded for each AI system and intended purpose.
Does completing the checklist prove EU AI Act compliance?
No. It helps organise facts, decisions and evidence. Conclusions still depend on accurate system information, applicable law, competent review and controls operating in practice.
Which AI systems should an SME assess first?
Start with systems affecting people, employment, essential services, safety, customer decisions, sensitive data or public-facing AI interactions, while maintaining a wider inventory so lower-priority uses are not lost.
Recommended next step
Run an exposure check, then save the result into a workspace so the follow-up work remains attached to the AI system.
Run the free exposure checkRelated practical guides
Put the guidance into practice