Annex IV Technical Documentation Template
Article 11 of the EU AI Act requires providers of high-risk AI systems to draw up technical documentation. They must do this before the system is placed on the market or put into service. The documentation must stay up to date. Providers must make it available to competent authorities on request.
Annex IV specifies exactly what must be included. Below is the complete template with all 9 required sections and guidance on what each one should contain.
Download the free Annex IV template (DOCX)
All nine Annex IV sections as a guided, editable document — every requirement with plain-language instructions, answer boxes, a document-control table and a completeness checklist.
Download the templateDOCX, ~40 KB. Mirrors Annex IV of Regulation (EU) 2024/1689. No email required. Free to use and adapt; not legal advice.
Section 1: General Description of the AI System
This section establishes the identity and scope of the system. Include:
- Intended purpose — What the system does, who it's for, and the specific context of use
- Provider identification — Name, address, and contact details
- System version — Current version and its relationship to previous versions
- Hardware and software interactions — How the system interacts with other hardware, software, or AI systems not part of the system itself
- Software and firmware versions — All relevant version numbers and update requirements
- Distribution forms — How the system is delivered (software package, embedded in hardware, API, download, etc.)
- Hardware requirements — The hardware on which the system is intended to run
- User interface — Basic description of the interface provided to the deployer
- Instructions for use — Reference to the instructions for use provided to deployers
Section 2: Detailed Description of System Elements & Development Process
The most substantial section. Document:
- Development methods — Steps taken, including use of pre-trained systems or third-party tools and how they were integrated or modified
- Design specifications — General logic, key design choices with rationale, assumptions made, classification choices, optimisation targets, and expected output quality
- System architecture — How software components build on each other, integration into overall processing, and computational resources used
- Data requirements — Training methodologies, dataset descriptions, provenance, scope, characteristics, acquisition methods, labelling procedures, and data cleaning methods
- Human oversight assessment — Measures needed per Article 14 and technical measures for output interpretation
- Pre-determined changes — If applicable, describe any planned changes to the system and how continuous compliance will be maintained
- Validation and testing — Procedures used, data and main characteristics, metrics, discriminatory impact assessment, and signed test reports
- Cybersecurity measures — Technical protections put in place
Section 3: Monitoring, Functioning & Control
Detail the system's operational characteristics:
- Capabilities and limitations in performance
- Degrees of accuracy for specific persons or groups the system is intended for, and overall expected accuracy
- Foreseeable unintended outcomes and sources of risk to health, safety, fundamental rights, and discrimination
- Human oversight measures per Article 14
- Technical measures enabling deployers to interpret output
- Input data specifications where appropriate
Section 4: Performance Metrics Appropriateness
Describe why the chosen performance metrics are appropriate for the specific AI system. This should explain the rationale for selecting certain metrics over alternatives and how they meaningfully capture the system's performance in its intended context.
Section 5: Risk Management System
Provide a detailed description of the risk management system established per Article 9. This is a continuous, iterative process that runs throughout the entire lifecycle and must include:
- Identification and analysis of known and reasonably foreseeable risks
- Estimation and evaluation of risks from intended use and reasonably foreseeable misuse
- Evaluation of risks from analysis of data gathered through post-market monitoring
- Adoption of appropriate risk management measures
Section 6: Lifecycle Changes
Document all relevant changes made to the system by the provider throughout its lifecycle. This creates a change history that auditors and authorities can review.
Section 7: Standards & Technical Specifications
List all harmonised standards applied, either in full or in part, with references to their publication in the Official Journal of the EU. Where no harmonised standards were applied:
- Provide a detailed description of the solutions adopted to meet the requirements of Chapter III, Section 2
- List any other relevant standards and technical specifications applied
Section 8: EU Declaration of Conformity
Include a copy of the EU Declaration of Conformity as drawn up per Article 47. This must be kept up to date and made available to competent authorities for 10 years after the system is placed on the market.
Section 9: Post-Market Performance Evaluation
Describe the system in place to evaluate the AI system's performance in the post-market phase, as required by Article 72. This must include:
- A post-market monitoring plan that is proportionate to the nature of the AI system and the risks it presents
- Procedures for collecting, analysing, and acting on data about the system's performance after deployment
Frequently asked questions
What is Annex IV of the EU AI Act?
Annex IV defines the minimum content of the technical documentation for every high-risk AI system. The provider must draw it up before placing the system on the EU market and keep it up to date (Article 11(1)). It has nine sections, from a general description of the system through to the post-market monitoring plan.
Who has to produce Annex IV technical documentation?
The provider of the high-risk AI system. Importers must verify the documentation exists before placing a system on the EU market. Notified bodies assess it during conformity assessment. But drawing it up is the provider's obligation under Article 16.
When does the technical documentation have to be ready?
Before the high-risk AI system is placed on the market or put into service. Providers must then keep it up to date throughout the system's lifecycle. Annex III high-risk obligations apply from 2 December 2027. So providers should treat documentation as a design-time activity, not a launch-week scramble.
Is there a simplified version for SMEs and start-ups?
Yes. Article 11(1) allows SMEs, including start-ups, to provide the Annex IV elements in a simplified manner. It also requires the Commission to establish a simplified technical documentation form for small and microenterprises. Notified bodies must accept that form for conformity assessment.
Does the EU AI Act prescribe a format for Annex IV documentation?
No — the regulation prescribes content, not format. Our free DOCX template mirrors the nine required sections. LandingRed can also generate the documentation automatically from your AI system inventory. It comes pre-filled with your risk classification and system data.
Related resources
- Annex III high-risk classification guide — check whether your system is high-risk
- Free AI Act risk self-assessment — get a shareable readiness report
Skip the blank page. LandingRed's documentation engine generates Annex IV-compliant drafts from your actual system data using AI. Every section is pre-structured and populated with context from your risk classification and system inventory.
LandingRed automates all of this
Stop managing compliance in spreadsheets. Classify, document, assess, and monitor your AI systems from one platform.