Practical checklist

EU AI Act compliance checklist for SMEs

A useful compliance programme starts with facts about each system, not a generic policy document. Use this sequence to turn the regulation into owned, reviewable work.

Prepared by EU AI Fit editorial team · Published 24 August 2026 · Source review 31 August 2026

1. Establish scope and ownership

Identify every AI-enabled feature, internal tool and third-party service your organisation builds, buys or deploys. Give each record a named business owner and technical contact.

  • Record intended purpose and affected users
  • Identify the model or external provider
  • Capture where the system is offered and used
  • Set a review date and change trigger

2. Determine role and exposure

Your duties depend on whether the organisation is acting as provider, deployer, importer or distributor. Screen for prohibited practices, Annex III high-risk use cases and Article 50 transparency duties.

  • Document the role rationale
  • Record assumptions and missing facts
  • Escalate uncertain or high-impact cases
  • Do not treat an early screen as legal approval

3. Build an evidence-backed action plan

Map each applicable obligation to an owner, due date, status and evidence requirement. Keep the source, reviewer and rule version with the decision so it can be revisited when the system or law changes.

  • Link policies, testing records and instructions
  • Track human-oversight and transparency controls
  • Review supplier documentation
  • Retain approvals and change history

4. Test whether controls operate in practice

A written control is only useful when people can apply it. Sample current systems, confirm that owners understand their authority, test escalation routes and check whether the evidence matches the deployed version rather than an earlier design.

  • Walk through a real decision from input to outcome
  • Confirm a person can intervene, pause or escalate
  • Check supplier claims against available records
  • Turn failed checks into assigned corrective actions

In this scenario: Northstar Recruitment Assistant

Northstar Services Ltd uses an external assistant to rank applicants for human review. Its checklist records the intended purpose, supplier and model version, the people affected, the significance of the ranking, the organisation's deployer role, the human review design and the evidence still required from the supplier. A named owner must revisit the position when the model, purpose or decision process changes.

  • Inventory record: one recruitment use case, not only the vendor name
  • Exposure record: employment context and impact on applicants
  • Evidence record: instructions, validation, oversight test and supplier response
  • Review trigger: model update or change from recommendation to automated rejection

5. Maintain the position

Set periodic reviews, but do not rely on the calendar alone. A new purpose, supplier release, user group, geography, data source, level of autonomy, incident or control failure can make the existing assessment stale immediately.

A working checklist your team can retain

Use one row per system. Record the conclusion and its evidence rather than marking a generic organisation-wide box as complete.

Review areaDecision to retainMinimum supporting evidenceSuggested owner
InventoryIs this a distinct AI system or use case, and is the record current?Purpose, supplier or model, users, affected people, deployment and review dateSystem owner
Territorial scope and roleWhy is the organisation in scope and which operator role does it hold for this system?Market and use locations, contractual chain, branding, modifications and approved rationaleGovernance or legal lead
Prohibited, high-risk and transparency routesWhich routes were tested, what was concluded and what remains uncertain?Dated answers, source references, assumptions, reviewer and escalation decisionQualified reviewer
Operational controlsWhich controls are required for this use and are they operating?Oversight instructions, testing, monitoring, security, incident and complaint recordsTechnical and operational owners
People and suppliersDo relevant people have sufficient direction, and has supplier evidence been challenged?Role-based learning, system briefings, supplier response, conditions and reassessment dateLearning and procurement leads
Evidence and reviewCan the current position be reconstructed and when must it be reconsidered?Approved evidence index, action owners, due dates, change triggers and decision historyGovernance lead

Questions teams usually ask

Can an SME use one EU AI Act checklist for the whole company?

A programme-level checklist is useful for governance, but role, classification, transparency and many evidence decisions must be recorded for each AI system and intended purpose.

Does completing the checklist prove EU AI Act compliance?

No. It helps organise facts, decisions and evidence. Conclusions still depend on accurate system information, applicable law, competent review and controls operating in practice.

Which AI systems should an SME assess first?

Start with systems affecting people, employment, essential services, safety, customer decisions, sensitive data or public-facing AI interactions, while maintaining a wider inventory so lower-priority uses are not lost.

Recommended next step

Run an exposure check, then save the result into a workspace so the follow-up work remains attached to the AI system.

Run the free exposure check

Related practical guides

Put the guidance into practice

Continue your EU AI Act review