Manage compliance requirements for AI systems
How to maintain and assess the requirements catalogue of an AI compliance check: create new compliance requirements, edit status and category, mark several requirements as implemented at once, and evidence the implementation status for audits.
The risk classification of an AI compliance check produces specific requirements under the AI Regulation. This article shows how to maintain that requirements catalogue, assess the implementation status of each individual requirement, and make it evidenceable for your ISMS and for audits.
Prerequisites
- You have write access to the AI compliance check in question.
- The check is completed up to the risk classification — especially where a system is classified as “high-risk”, specific requirements arise from Art. 9–15 AI Act, for example on risk management, technical documentation, human oversight, robustness and cybersecurity.
- You are in the detail view of the check, in “Step 5: Result”. The subsection “Compliance requirements” sits there between the fields “Notes on the risk description” and “Notes on the result”.
Create a requirement
- Open the detail view of the AI compliance check and scroll to “Step 5: Result”.
- Click “New” at the top right of the “Compliance requirements” subsection. A slide-over opens with the requirement form.
- Complete the relevant fields: “Status”, “Article of the AI Regulation”, “Short title of the requirements”, “Category of requirements” and the notes.
- Save. The requirement then appears in the table of the subsection.
Assess and edit a requirement
- Click a line in the table. The read-only detail view of the requirement opens in a slide-over.
- Use the available actions there to switch to edit mode.
- Update the “Status” to reflect the actual implementation status and document your assessment in the notes.
- Save your changes. Use “Cancel” to discard the entry.
Assess several requirements at once
- Use the selection boxes at the beginning of each line to select the requirements you need — or the selection box in the header to select all visible entries.
- Click “Actions” at the top right and choose one of the available bulk actions, for example marking several requirements jointly as “implemented”.
Keep large catalogues manageable with “Search term”, “Filter” and “Columns”; the selection menu to the right of “Columns” defines the number of entries per page (5, 10, 25, 50, 100). By default the table is sorted by “Short title of the requirements: A-Z”.
What happens next
- Changes to the status or contents of a requirement are logged in the activity history of the AI compliance check.
- Observers and assigned editors receive a notification.
- The “Status of the compliance requirements” on the overview page of the AI compliance checks is recalculated automatically.
Practical tip: maintain at least one task for each high-risk requirement in the “Tasks” tab of the check. This keeps the who, what and by when traceable — and enables you to provide complete evidence of the implementation status during audits.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.