We'd like to set analytics cookies to measure which pages are useful. They are not needed to run the site, and declining changes nothing about what you can do here. Privacy Policy.
It is the single page that carries legal weight: by signing it the provider takes responsibility for conformity. Everything else — the technical file, the risk management, the testing — exists to make this signature defensible.
Every template on this page is readable in full right here, copyable as Markdown, and downloadable as a PDF. No sign-up, no e-mail address, no click-to-reveal.
Not an official document. This is a working draft built from the text of Regulation (EU) 2024/1689 — it is not issued or endorsed by the European Commission, any national authority or any notified body, and it is not legal advice. Fill it in with your own facts and have it reviewed by counsel before you rely on it.
Who fills this in
The provider of the high-risk AI system, signed by someone with authority to bind the company. Non-EU providers act through their authorised representative under Article 22.
When it has to exist
After the conformity assessment under Article 43 and before the CE marking is affixed and the system placed on the market. A substantial modification means a fresh assessment and a fresh declaration.
Applies from
With the high-risk regime — Annex III systems from 2 December 2027. Annex I product-safety systems follow their sectoral timeline.
Article 47 requires the provider to draw up a written, machine-readable EU declaration of conformity for each high-risk AI system, to keep it at the disposal of the national competent authorities for ten years after the system is placed on the market or put into service, and to state that the system meets the Chapter III requirements. Annex V sets out the information it must contain.
How this document usually fails
Signing it before the evidence exists. The declaration is a statement of fact about work already done; drawn up in parallel with an incomplete technical file, it is an assertion the provider cannot support.
The template, section by section
7 sections. Each one carries what to write and — the part templates normally leave out — what an assessor is looking for when they read it.
1. System name and identification
What to write
The AI system name and any additional unambiguous reference allowing its identification and traceability — type, model, version.
What an auditor looks for
That this string is identical in the technical file, the registration entry and the instructions for use. A declaration that names 'v2' while the file describes 'v2.3' covers nothing.
2. Provider and authorised representative
What to write
Name and address of the provider and, where applicable, of its authorised representative in the Union.
What an auditor looks for
That the legal entity is the one that actually places the system on the market, and that a non-EU provider has an Article 22 representative named here with a real mandate.
3. Statement of sole responsibility
What to write
State that the EU declaration of conformity is issued under the sole responsibility of the provider.
What an auditor looks for
The exact sole-responsibility wording. It is a required element, not boilerplate to be paraphrased away.
4. Conformity statement
What to write
State that the AI system is in conformity with this Regulation and, where applicable, with any other relevant Union harmonisation legislation.
What an auditor looks for
Whether other Union legislation applies and was named. A high-risk AI system that is also a medical device or a machinery safety component has more than one regime to declare against.
5. Standards and common specifications
What to write
References to any relevant harmonised standards or common specifications applied, in full or in part.
What an auditor looks for
Whether the standards cited are actually the ones used. Where none were applied, expect the technical solutions adopted instead to be described in the technical file.
6. Notified body and conformity procedure
What to write
Where applicable, the name and identification number of the notified body, a description of the conformity assessment procedure performed, and the identification of the certificate issued.
What an auditor looks for
Consistency with the route actually taken. Most Annex III systems use internal control under Annex VI and state so; naming a notified body that was not involved is a serious misstatement.
7. Place, date and signatory
What to write
Place and date of issue, the name and function of the person who signed it, and by whom or on whose behalf it was signed.
What an auditor looks for
A dated signature by an identifiable person with authority. An undated declaration, or one signed by a role rather than a person, does not do the job it exists to do.
Take it with you
The same document in two portable forms. The Markdown pastes into Notion, Confluence, Google Docs or a repository; the PDF is laid out to be printed and written on, with ruled fill-in areas and a sign-off block.
Full template as Markdown — select it, or use the button
# EU Declaration of Conformity
**Legal basis:** Article 47, Annex V, Article 43, Article 16 — Regulation (EU) 2024/1689 (EU AI Act).
> Not an official document. This is a working draft built from the text of Regulation (EU) 2024/1689 — it is not issued or endorsed by the European Commission, any national authority or any notified body, and it is not legal advice. Fill it in with your own facts and have it reviewed by counsel before you rely on it.
**Who fills this in:** The provider of the high-risk AI system, signed by someone with authority to bind the company. Non-EU providers act through their authorised representative under Article 22.
**When:** After the conformity assessment under Article 43 and before the CE marking is affixed and the system placed on the market. A substantial modification means a fresh assessment and a fresh declaration.
| Field | Value |
| --- | --- |
| Organisation | |
| AI system | |
| Version / reference | |
| Document owner | |
| Date | |
| Version of this document | |
## 1. System name and identification
*What to write:* The AI system name and any additional unambiguous reference allowing its identification and traceability — type, model, version.
*What an auditor looks for:* That this string is identical in the technical file, the registration entry and the instructions for use. A declaration that names 'v2' while the file describes 'v2.3' covers nothing.
_[Your text here]_
## 2. Provider and authorised representative
*What to write:* Name and address of the provider and, where applicable, of its authorised representative in the Union.
*What an auditor looks for:* That the legal entity is the one that actually places the system on the market, and that a non-EU provider has an Article 22 representative named here with a real mandate.
_[Your text here]_
## 3. Statement of sole responsibility
*What to write:* State that the EU declaration of conformity is issued under the sole responsibility of the provider.
*What an auditor looks for:* The exact sole-responsibility wording. It is a required element, not boilerplate to be paraphrased away.
_[Your text here]_
## 4. Conformity statement
*What to write:* State that the AI system is in conformity with this Regulation and, where applicable, with any other relevant Union harmonisation legislation.
*What an auditor looks for:* Whether other Union legislation applies and was named. A high-risk AI system that is also a medical device or a machinery safety component has more than one regime to declare against.
_[Your text here]_
## 5. Standards and common specifications
*What to write:* References to any relevant harmonised standards or common specifications applied, in full or in part.
*What an auditor looks for:* Whether the standards cited are actually the ones used. Where none were applied, expect the technical solutions adopted instead to be described in the technical file.
_[Your text here]_
## 6. Notified body and conformity procedure
*What to write:* Where applicable, the name and identification number of the notified body, a description of the conformity assessment procedure performed, and the identification of the certificate issued.
*What an auditor looks for:* Consistency with the route actually taken. Most Annex III systems use internal control under Annex VI and state so; naming a notified body that was not involved is a serious misstatement.
_[Your text here]_
## 7. Place, date and signatory
*What to write:* Place and date of issue, the name and function of the person who signed it, and by whom or on whose behalf it was signed.
*What an auditor looks for:* A dated signature by an identifiable person with authority. An undated declaration, or one signed by a role rather than a person, does not do the job it exists to do.
_[Your text here]_
---
Template by Conformly — getconformly.com/templates/declaration-of-conformity. Free to copy and adapt. Not an official document. This is a working draft built from the text of Regulation (EU) 2024/1689 — it is not issued or endorsed by the European Commission, any national authority or any notified body, and it is not legal advice. Fill it in with your own facts and have it reviewed by counsel before you rely on it.
Questions people ask
How long must the EU declaration of conformity be kept?
Ten years after the high-risk AI system has been placed on the market or put into service, at the disposal of the national competent authorities on request.
Do I need a notified body to sign a declaration of conformity?
Usually not. Most Annex III high-risk systems use internal control under Annex VI, meaning the provider self-assesses and signs. A notified body is required only in specific cases, notably certain biometric systems where harmonised standards were not applied.
What does machine-readable mean here?
Article 47 requires the declaration to be drawn up in a machine-readable, physical or electronically signed form. In practice: keep a structured electronic copy, not only a scan of a signed page.