Short answer. A conformity assessment is the formal procedure that proves a high-risk AI system meets the requirements of the EU AI Act before it is placed on the market. From 2 August 2026, providers of high-risk systems cannot sell or put them into service in the EU without completing one. Most high-risk systems follow an internal-control self-assessment under Annex VI. A narrower set requires an independent notified body under Annex VII. The output is an EU declaration of conformity and a CE marking.
A conformity assessment is the audit that stands between a finished high-risk AI system and the EU market. Article 43 of Regulation (EU) 2024/1689 makes it a precondition, not a formality: without a completed assessment, placing the system on the market or putting it into service is unlawful. The provider carries the obligation, and the assessment covers the full set of requirements in Chapter III, Section 2, from data governance and technical documentation to human oversight, accuracy, robustness, and cybersecurity.
The assessment is evidence-based. The provider assembles the technical documentation and verifies that the quality management system, the design and development process, and the post-market monitoring plan all line up with what the documentation claims. In banking and insurance, the systems that trigger this obligation are concrete:
Each of these must clear a conformity assessment before it reaches production, and again after any substantial change.
For financial services and insurance in Central Europe, the conformity assessment is where the EU AI Act stops being a policy document and becomes a delivery gate. The high-risk obligations apply from 2 August 2026. A credit-decisioning model or an insurance-pricing engine that is not assessed by that date cannot legally serve EU customers, regardless of how well it performs.
The obligation also reaches beyond the provider. Under Article 49, high-risk systems must be registered in the EU database before they go live, and the declaration of conformity must be kept available for 10 years. For a bank or insurer that builds AI in-house, that means the institution is the provider and owns every step: the assessment, the CE marking, the registration, and the record-keeping. Treating conformity as a late compliance sign-off, rather than an engineering requirement designed in from the start, is the most common way projects miss the date.
A conformity assessment proves a high-risk AI system meets the EU AI Act before it reaches the market, and is mandatory from 2 August 2026.
The EU AI Act defines two procedures. The first, internal control under Annex VI, is a self-assessment: the provider verifies that its quality management system meets Article 17, examines the technical documentation to confirm the system satisfies the Section 2 requirements, and checks that the design, development, and post-market monitoring are consistent with that documentation. No external body is involved.
The second, Annex VII, adds an independent notified body that assesses both the quality management system and the technical documentation. Which route applies depends on the Annex III category. For high-risk systems in points 2 to 8 of Annex III, which include credit scoring and insurance pricing, the internal-control route under Annex VI applies. For biometric systems in point 1, the provider may use internal control where harmonised standards are applied, and otherwise must involve a notified body.
A notified body is an independent conformity assessment organisation designated to perform third-party testing, certification, and inspection under the EU AI Act. Most high-risk AI in banking and insurance does not require one, because credit and insurance systems fall under the internal-control route. The notified-body route becomes mandatory mainly for biometric systems under Annex III point 1 when the provider has not applied the relevant harmonised standards or common specifications. When a notified body is involved, its identification number is affixed alongside the CE marking, signalling that an external party has verified the system.
A passed assessment produces two artefacts. Under Article 47, the provider draws up a written EU declaration of conformity, stating that the system meets the Section 2 requirements, and keeps it available to national authorities for 10 years. Under Article 48, the provider affixes the CE marking, visibly and legibly, or through a digital CE marking for systems delivered online. The CE marking is the outward signal that the system is lawful to place on the EU market. Where a notified body carried out the assessment, its identification number accompanies the marking.
A conformity assessment is not a one-time clearance. Whenever a high-risk AI system is substantially modified, or its intended purpose changes in a way that affects compliance with the EU AI Act, the system must undergo a new assessment. For AI models that are retrained, tuned, or extended to new use cases, this makes conformity a recurring obligation tied to the model lifecycle, not a single event at launch. Post-market monitoring under Article 72 feeds this process by tracking real-world performance and surfacing changes that trigger a fresh assessment.
The EU AI Act and DORA are separate regimes that overlap in financial services. DORA governs digital operational resilience, ICT risk, and third-party dependency. The AI Act governs the AI system itself through the conformity assessment, CE marking, and post-market monitoring. A bank deploying a high-risk credit model must satisfy both: conformity under the AI Act and ICT resilience and incident handling under DORA. The practical move is to map the AI Act’s technical documentation, quality management, and monitoring requirements onto existing model-risk and ICT-risk controls, so one governance system serves both regimes rather than two parallel programmes.
Conformity assessment rewards teams that build documentation, monitoring, and governance into the system from day one, not teams that bolt them on before an audit. Ableneo shipped 34 production AI projects in 2025, with roughly 80% reaching production, and works inside regulated cores in banking and insurance across Slovakia, the Czech Republic, and Austria. That production track record is what turns a conformity assessment from a scramble into a checklist the system already satisfies. See how we structure this in our AI transformation work, where governance and documentation are engineered into the build, not added at the end.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.