# Notified Body Assessment Procedures — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/notified-body-assessment-procedures
> Sources are cited per item. Verify against the official texts before relying on them.

The content extensively covers the operational procedures and methodologies that notified bodies must follow when conducting conformity assessments, which deserves its own dedicated topic.

## Overview

## Legal Framework

Notified body assessment procedures under the AI Act are governed primarily by [Article 43](/laws/ai-act/art-43), which establishes the conformity assessment pathways for high-risk AI systems. Providers of such systems must, under [Article 16(1)(f)](/laws/ai-act/art-16#par-f), ensure compliance before market placement:

> "ensure that the high-risk AI system undergoes the relevant conformity assessment procedure as referred to in Article 43, prior to its being placed on the market or put into service"
> — [AI Act Art. 16](/laws/ai-act/art-16#par-f)

Article 43 offers two routes for systems listed in point 1 of Annex III where harmonised standards or common specifications have been applied: internal control under Annex VI, or a fuller assessment involving a notified body under Annex VII. Where harmonised standards do not exist, have been only partially applied, or carry restrictions, the provider must follow the Annex VII procedure with notified body involvement. Critically, provider choice is preserved:

> "the provider may choose any of the notified bodies"
> — [AI Act Art. 43](/laws/ai-act/art-43#par-2)

Downstream actors carry verification duties. Authorised representatives must confirm that an appropriate conformity assessment was performed by the provider, as must importers before placing systems on the Union market. Importers must verify that the CE marking, EU declaration of conformity, and technical documentation are all in place.

## Key Developments

The AI Act's conformity assessment architecture draws on established Union product safety principles, including the New Legislative Framework. The CJEU has reinforced that independent oversight of regulatory compliance is essential to ensuring effective protection. In *VB v Natsionalna agentsia za prihodite*, the Court emphasised that supervisory mechanisms must operate with sufficient rigour to guarantee substantive rights. While that case arose under data protection law, its underlying logic—that procedural safeguards must be meaningful, not merely formal—applies squarely to notified body assessments under the AI Act.

The *Maximillian Schrems* litigation further underscores that adequacy of safeguards is assessed against the effectiveness of enforcement, not merely the existence of rules on paper. For notified body procedures, this means that the quality management system review and technical documentation assessment under Annex VII must be substantive exercises, not box-ticking.

Enforcement actions by national authorities, such as the Romanian ANSPDCP's fine against SC Cntar Tarom SA for inadequate technical and organisational measures, illustrate regulators' willingness to penalise failures in procedural compliance—reinforcing that conformity assessment documentation must withstand scrutiny.

## Practical Guidance

- **Determine your assessment pathway early.** Under [Article 43(1)](/laws/ai-act/art-43#par-1-cont-1), providers applying harmonised standards in full may opt for internal control (Annex VI). If standards are absent, partial, or restricted, the Annex VII notified body route is mandatory—plan timelines accordingly.

- **Select a notified body strategically.** Article 43(2) grants providers free choice among notified bodies, but consider sectoral expertise, accreditation scope, and capacity. For law enforcement or immigration systems, specialised notified bodies may be designated.

- **Prepare technical documentation to Annex IV standards.** Both authorised representatives under [Article 22(3)(a)](/laws/ai-act/art-22#par-3-pnt-a) and importers under [Article 23(1)(a)](/laws/ai-act/art-23#par-1-pnt-a) must verify that conformity assessment was properly conducted. Gaps in documentation will block market access.

- **Establish a robust quality management system.** The Annex VII procedure centres on QMS and technical documentation review. Ensure your QMS under [Article 17](/laws/ai-act/art-16) covers the full lifecycle of the AI system and is audit-ready.

- **Maintain conformity evidence for the full retention period.** Authorised representatives must keep declarations and documentation available for 10 years post-placement on the market. Ensure records are complete, accessible, and version-controlled.

## Legislation (full text of key provisions)

### Derogation from conformity assessment procedure

*Source: AI Act, aiact-art-46-en, 2024-06-12 — https://overview.legal/posts/92688*

### Recital 125 — High-risk AI systems conformity assessment procedure

*Source: AI Act, aiact-rec-125-en, 2024-06-12 — https://overview.legal/posts/93932*

Given the complexity of high-risk AI systems and the risks that are associated with them, it is important to develop an adequate conformity assessment procedure for high-risk AI systems involving notified bodies, so-called third party conformity assessment. However, given the current experience of professional pre-market certifiers in the field of product safety and the different nature of risks involved, it is appropriate to limit, at least in an initial phase of application of this Regulation, the scope of application of third-party conformity assessment for high-risk AI systems other than those related to products. Therefore, the conformity assessment of such systems should be carried out as a general rule by the provider under its own responsibility, with the only exception of AI systems intended to be used for biometrics.

### Recital 50 — high-risk classification of safety-related AI systems

*Source: AI Act, aiact-rec-50-en, 2024-06-12 — https://overview.legal/posts/93782*

As regards AI systems that are safety components of products, or which are themselves products, falling within the scope of certain Union harmonisation legislation listed in an annex to this Regulation, it is appropriate to classify them as high-risk under this Regulation if the product concerned undergoes the conformity assessment procedure with a third-party conformity assessment body pursuant to that relevant Union harmonisation legislation. In particular, such products are machinery, toys, lifts, equipment and protective systems intended for use in potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft equipment, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, automotive and aviation.

### Recital 78 — conformity assessment cybersecurity high-risk AI

*Source: AI Act, aiact-rec-78-en, 2024-06-12 — https://overview.legal/posts/93838*

The conformity assessment procedure provided by this Regulation should apply in relation to the essential cybersecurity requirements of a product with digital elements covered by a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and classified as a high-risk AI system under this Regulation. However, this rule should not result in reducing the necessary level of assurance for critical products with digital elements covered by a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements. Therefore, by way of derogation from this rule, high-risk AI systems that fall within the scope of this Regulation and are also qualified as important and critical products with digital elements pursuant to a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and to which the conformity assessment procedure based on internal control set out in an annex to this Regulation applies, are subject to the conformity assessment provisions of a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements insofar as the essential cybersecurity requirements of that regulation are concerned. In this case, for all the other aspects covered by this Regulation the respective provisions on conformity assessment based on internal control set out in an annex to this Regulation should apply. Building on the knowledge and expertise of ENISA on the cybersecurity policy and tasks assigned to ENISA under the Regulation (EU) 2019/881 of the European Parliament and of the Council (37), the Commission should cooperate with ENISA on issues related to cybersecurity of AI systems.

### Recital 81 — provider quality management system

*Source: AI Act, aiact-rec-81-en, 2024-06-12 — https://overview.legal/posts/93844*

The provider should establish a sound quality management system, ensure the accomplishment of the required conformity assessment procedure, draw up the relevant documentation and establish a robust post-market monitoring system. Providers of high-risk AI systems that are subject to obligations regarding quality management systems under relevant sectoral Union law should have the possibility to include the elements of the quality management system provided for in this Regulation as part of the existing quality management system provided for in that other sectoral Union law. The complementarity between this Regulation and existing sectoral Union law should also be taken into account in future standardisation activities or guidance adopted by the Commission. Public authorities which put into service high-risk AI systems for their own use may adopt and implement the rules for the quality management system as part of the quality management system adopted at a national or regional level, as appropriate, taking into account the specificities of the sector and the competences and organisation of the public authority concerned.

### Recital 139 — AI regulatory sandboxes innovation objectives

*Source: AI Act, aiact-rec-139-en, 2024-06-12 — https://overview.legal/posts/93960*

The objectives of the AI regulatory sandboxes should be to foster AI innovation by establishing a controlled experimentation and testing environment in the development and pre-marketing phase with a view to ensuring compliance of the innovative AI systems with this Regulation and other relevant Union and national law. Moreover, the AI regulatory sandboxes should aim to enhance legal certainty for innovators and the competent authorities’ oversight and understanding of the opportunities, emerging risks and the impacts of AI use, to facilitate regulatory learning for authorities and undertakings, including with a view to future adaptions of the legal framework, to support cooperation and the sharing of best practices with the authorities involved in the AI regulatory sandbox, and to accelerate access to markets, including by removing barriers for SMEs, including start-ups. AI regulatory sandboxes should be widely available throughout the Union, and particular attention should be given to their accessibility for SMEs, including start-ups. The participation in the AI regulatory sandbox should focus on issues that raise legal uncertainty for providers and prospective providers to innovate, experiment with AI in the Union and contribute to evidence-based regulatory learning. The supervision of the AI systems in the AI regulatory sandbox should therefore cover their development, training, testing and validation before the systems are placed on the market or put into service, as well as the notion and occurrence of substantial modification that may require a new conformity assessment procedure. Any significant risks identified during the development and testing of such AI systems should result in adequate mitigation and, failing that, in the suspension of the development and testing process. Where appropriate, national competent authorities establishing AI regulatory sandboxes should cooperate with other relevant authorities, including those supervising the protection of fundamental rights, and could allow for the involvement of other actors within the AI ecosystem such as national or European standardisation organisations, notified bodies, testing and experimentation facilities, research and experimentation labs, European Digital Innovation Hubs and relevant stakeholder and civil society organisations. To ensure uniform implementation across the Union and economies of scale, it is appropriate to establish common rules for the AI regulatory sandboxes’ implementation and a framework for cooperation between the relevant authorities involved in the supervision of the sandboxes. AI regulatory sandboxes established under this Regulation should be without prejudice to other law allowing for the establishment of other sandboxes aiming to ensure compliance with law other than this Regulation. Where appropriate, relevant competent authorities in charge of those other regulatory sandboxes should consider the benefits of using those sandboxes also for the purpose of ensuring compliance of AI systems with this Regulation. Upon agreement between the national competent authorities and the participants in the AI regulatory sandbox, testing in real world conditions may also be operated and supervised in the framework of the AI regulatory sandbox.

### Recital 173 — Commission delegated powers to adapt AI rules

*Source: AI Act, aiact-rec-173-en, 2024-06-12 — https://overview.legal/posts/94028*

In order to ensure that the regulatory framework can be adapted where necessary, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission to amend the conditions under which an AI system is not to be considered to be high-risk, the list of high-risk AI systems, the provisions regarding technical documentation, the content of the EU declaration of conformity the provisions regarding the conformity assessment procedures, the provisions establishing the high-risk AI systems to which the conformity assessment procedure based on assessment of the quality management system and assessment of the technical documentation should apply, the threshold, benchmarks and indicators, including by supplementing those benchmarks and indicators, in the rules for the classification of general-purpose AI models with systemic risk, the criteria for the designation of general-purpose AI models with systemic risk, the technical documentation for providers of general-purpose AI models and the transparency information for providers of general-purpose AI models. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (55). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.

## Case law

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

### VB v Natsionalna agentsia za prihodite

*Source: CJEU, C-340/21, 2023-12-14 — https://overview.legal/posts/51485 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0340*

Data breach alone does not establish inadequate security measures. Burden on controller to prove adequacy.

## Guidance

### Opinion 15/2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal to be used as tool for transfers pursuant to Articles 42 and 46 GDPR

*Source: EDPB, opinion-152026-on-the-europrivacy-certification-criteria-en, 2026-04-16 — https://overview.legal/posts/125681 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-152026-on-the-europrivacy-certification-criteria_en*

Opinion 15 / 2026 on the Europrivacy certification criteria regarding their approval by the Board as European Data Protection Seal to be used as tool for transfers pursuant to Articles 42 and 46 GDPR Adopted on 15 April 2026 1 | Adopted 2 | Adopted The European Data Protection Board Having regard to Article 63, Article 64(2), Article 42 and Article 46 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to…

### Guidelines 04/2022 on the calculation of administrative fines under the GDPR

*Source: EDPB, edpb-guidelines-on-the-calculation-of-administrative-fines-under-the-gdpr, 2023-05-24 — https://overview.legal/posts/38068 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042022-on-the-calculation-of-administrative-fines-under-the-gdpr_en*

The European Data Protection Board (EDPB) has adopted these guidelines to harmonise the methodology supervisory  authorities use  when calculating of the amount of the fine. These Guidelines complement the previously  adopted Guidelines on the application and setting of administrative fines  for the purpose  of the Regulation 2016/679 (WP253), which focus on the circumstances in which to impose a fine. The calculation of the amount of the fine is at the discretion of the supervisory  authority, ...

### Guidelines 02/2022 on the application of Article 60 GDPR

*Source: EDPB, edpb-guidelines-on-the-application-of-article-60-gdpr, 2022-03-14 — https://overview.legal/posts/38066 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-022022-on-the-application-of-article-60-gdpr_en*

With the introduction of the GDPR, the concept of the one-stop shop was established as one of the main innovations. In cross-border processing cases, the supervisory authority in the Member State of the controller's or processor's main establishment is the authority leading the  enforcement of the GDPR for the respective cross-border processing activities, in cooperation with all the authorities which may face the effects of the processing activities at stake: be it  through  the establishments ...

### Guidelines 04/2021 on Codes of Conduct as tools for transfers

*Source: EDPB, edpb-guidelines-on-codes-of-conduct-as-tools-for-transfers, 2022-02-22 — https://overview.legal/posts/38133 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042021-on-codes-of-conduct-as-tools-for-transfers_en*

The  GDPR  requires  in  its  Article  46  that  controllers/processors shall  put  in  place  appropriate safeguards for transfers of personal data to third countries or international organisations. To that end, the GDPR diversifies the appropriate safeguards that may be used by organisations under Article 46 for  framing transfers  to third countries  by  introducing  amongst  others, codes  of  conduct  as a new transfer  mechanism  (articles  40-3  and  46-2-e).  In  this  respect, as  provi...

### Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-codes-of-conduct-and-monitoring-bodies, 2019-06-04 — https://overview.legal/posts/38051 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-12019-on-codes-of-conduct-and-monitoring-bodies-under-regulation_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the framework for codes of conduct and monitoring bodies under Articles 40 and 41 of the GDPR. The guidelines address the admissibility, content, and approval requirements for draft codes of conduct, as well as the criteria and accreditation process for monitoring bodies responsible for verifying compliance with such codes. This version (2.0) was adopted on 4 June 2019 following public consultation.

### Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation

*Source: EDPB, edpb-guidelines-on-certification-and-identifying-certification-criteria, 2019-06-04 — https://overview.legal/posts/38048 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-12018-on-certification-and-identifying-certification-criteria-in_en*

The EDPB issued Guidelines 1/2018 to clarify the framework for data protection certification and the identification of certification criteria under Articles 42 and 43 of the GDPR. The guidelines address key concepts such as the interpretation of "certification," the roles of supervisory authorities and certification bodies, and the process for approving certification criteria. This document provides practical guidance to stakeholders on how GDPR certification mechanisms, seals, and marks should be established and operated.

## Enforcement decisions

### SC Cntar Tarom SA: Insufficient technical and organisational measures to ensure information security

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2020-07-27 — https://overview.legal/posts/46475 — original: https://www.enforcementtracker.com/ETid-360*

Unauthorised disclosure of the data of five Tarom passengers due to inadequate technical and organisational measures for secure data processing. Among other things, the company was required to take corrective action, including training its employees and conducting risk assessment procedures.

## Recent developments

### Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems?

*Source: Gaming Tech Law, 2023-03-29 — https://overview.legal/posts/6223 — original: https://www.gamingtechlaw.com/2023/03/draft-ai-act-general-purpose-artificial-intelligence/#entry-4244*

> The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing artificial intelligence in the European Union. As previously reported, the EU Parliament has already broadened the definition of artificial intelligence for the purposes of the AI Act…

### HvJ: De PNR-richtlijn is geldig, mits deze beperkt blijft tot wat "strikt noodzakelijk" is.

*Source: eucrim, 2022-08-04 — https://overview.legal/posts/51841*

Op 21 juni 2022 heeft het Gerechtshof van de Europese Unie (Groot Beschouwingscollege) een baanbrekende uitspraak gedaan waarin het het EU-regime voor het verzamelen en gebruiken van gegevens van reizigers bevestigde, mits dit strikt wordt geïnterpreteerd in overeenstemming met de fundamentele rechten van de EU. Bovendien is het zonder onderscheid verwerken van deze gegevens bij vluchten die uitsluitend binnen de EU plaatsvinden verboden, tenzij er een dreiging van terrorisme bestaat. Over het algemeen moeten de gegevens van de passagiers ook binnen zes maanden worden verwijderd.

### “Social media profiles and phone contacts” used as proof of identity for deportations

*Source: European Digital Rights, 2023-03-29 — https://overview.legal/posts/6226 — original: https://edri.org/our-work/social-media-profiles-and-phone-contacts-used-as-proof-of-identity-for-deportations/#entry-4248*

> 
					Thirteen non-EU countries sometimes accept “social media profiles and phone contacts” as evidence of identity for the purpose of deportations, according to an internal European Commission assessment of third country cooperation on readmission.

## Related topics

- **Conformity Assessment Procedures and Methodologies** — https://overview.legal/topics/conformity-assessment-procedures-ai
  This new topic is needed to specifically address the procedural and methodological aspects of conformity assessment for AI systems, including step-by-step proce
- **AI Act Procedures** — https://overview.legal/topics/ai-act-procedural-framework
  The 'Procedure' section of the AI Act establishes the overarching procedural framework and mechanisms for implementing and enforcing the regulation. This topic 
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals

---
Generated by overview.legal · https://overview.legal/topics/notified-body-assessment-procedures · 2026-08-22
