NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →
EU AI Act Compliance Checklist (Free Excel, 2026)
Resources

EU AI Act Compliance Checklist (Free Excel, 2026)

·Alexander Sverdlov

The EU AI Act compliance checklist on this page is a free Excel workbook that turns Regulation (EU) 2024/1689 into a list you can actually work through. Use this EU AI Act compliance checklist to first classify your AI system by risk tier, then check off the obligations that follow, with the heaviest set - 62 items - covering the duties that fall on providers of high-risk systems. It is built for the compliance lead, CISO, or product owner who has been handed "make us AI Act ready" and wants a defensible starting point rather than a 100-page regulation to read cold. Download it below, open it in Excel or Google Sheets, and start with the classification tab. Nothing is gated behind a sales call, and the file is yours to adapt.

Free download

Get the EU AI Act Readiness Checklist

Classify your AI system and check the obligations that follow. 62 items across the high-risk provider duties.

By downloading, you agree to receive occasional relevant emails from Venvera. Unsubscribe anytime. See our Privacy Policy. This template is a starting point, not legal advice.

One evidence library covering the AI Act and overlapping frameworks
One evidence library, mapped across the AI Act and the frameworks it shares controls with.

What the EU AI Act compliance checklist covers

The workbook is the EU AI Act Readiness Checklist, and it is organized so that classification comes first and obligations follow from it. The opening tab walks you through the four risk tiers the Act defines - prohibited practices, high-risk systems (including the Annex III use cases), limited-risk systems with transparency duties, and minimal-risk - so you land on the correct tier before you touch a single control.

From there, the 62 items map the provider duties for high-risk systems. Each row carries the same columns so the file doubles as a working tracker:

  • Item and the Article reference it traces to, so every line has a source.
  • Obligation in plain language, covering the risk management system, data governance, technical documentation, record-keeping and logs, transparency and human oversight, accuracy and robustness, conformity assessment, and post-market monitoring.
  • Applies to, marking whether the duty sits with the provider or the narrower deployer role.
  • Status, Owner, and Evidence columns you fill in as you go, plus a Notes field for scoping decisions.
Mapping a the AI Act control across other frameworks
A control entered once maps across the AI Act and every framework it also satisfies.

EU AI Act the honest way: what actually matters

The single most important move under the EU AI Act is classification, because classification drives every obligation. The Act sorts AI systems into prohibited practices, high-risk systems (including the Annex III use cases), limited-risk systems that carry transparency duties, and minimal-risk systems. Get the tier wrong and everything downstream is either wasted effort or a gap, so this is where the checklist makes you start.

If you are a provider of a high-risk AI system, the substantive duties are concrete. You must operate a risk management system (Article 9), apply data governance to the datasets behind the system, prepare technical documentation, keep logs, ensure transparency and human oversight, and meet accuracy and robustness requirements. Before the system goes to market you undergo a conformity assessment, and once it is in use you run post-market monitoring. Deployers of high-risk systems have their own, narrower set of duties rather than this full stack, which is why the "Applies to" column matters.

Incident handling is time-boxed. Serious incidents are reported under Article 73 no later than 15 days, tightening to 10 days if a person has died, and to 2 days for a widespread infringement or a serious disruption to critical infrastructure. Finally, these obligations do not all switch on at once: they phase in on staged applicability dates, so part of readiness is knowing which duties are already live for your system and which are still approaching.

the AI Act control health tracked in one dashboard
Track the AI Act readiness continuously instead of in a point-in-time spreadsheet.

How to use the EU AI Act Readiness Checklist

  1. Classify first. Open the classification tab and place each AI system you run into one tier. Do this per system, not per company, because one organization can hold systems in several tiers.
  2. Filter to your tier. If a system is high-risk, work the 62 provider items. If it is limited-risk, you focus on the transparency duties instead of the full set.
  3. Assign an owner per row. Risk management, data governance, and technical documentation rarely sit with one person, so name the accountable owner in the Owner column.
  4. Attach evidence, not opinions. Mark a row done only when the Evidence column points to a real artifact - a signed procedure, a log sample, a conformity assessment record.
  5. Set your incident clock. Note the Article 73 timelines of 15, 10, and 2 days against your reporting process so the deadline is known before an incident, not during one.
  6. Re-run as dates land. Because obligations phase in on staged dates, revisit the file each quarter and move newly-applicable items from "future" to "in scope".
A live the AI Act posture for the board
A live posture keeps the the AI Act picture current for leadership and auditors.

Do this automatically in Venvera

The manual file is a strong starting point, but a spreadsheet goes stale the moment your systems or the staged dates move. In Venvera, the same work lives in the EU AI Act framework as a maintained control set: classification, the Article 9 risk management duties, data governance, technical documentation, human oversight, conformity assessment, and post-market monitoring stay current, and the evidence you attach reuses across other frameworks you already run instead of being re-collected each time. If you are weighing tools, the alternative to Vanta for EU AI Act compliance comparison lays out the differences plainly. Pricing starts from EUR 399/month.

Frequently Asked Questions

Is the EU AI Act compliance checklist really free?

Yes. The EU AI Act compliance checklist downloads as an Excel file through the form on this page, with no purchase and no sales call required. You can edit it, share it internally, and keep it.

Why does the checklist have 62 items?

The 62 items cover the obligations that fall on a provider of a high-risk AI system: the risk management system, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, conformity assessment, and post-market monitoring. If your system is limited-risk or minimal-risk, you work a smaller subset, which is why classification comes first.

What is the difference between a provider and a deployer?

A provider places a high-risk AI system on the market and carries the full obligation set described above. A deployer uses such a system and has a narrower set of duties. The checklist flags which role each item applies to in the "Applies to" column so you only work the rows that are yours.

How fast do serious incidents have to be reported?

Under Article 73, a serious incident is reported no later than 15 days, dropping to 10 days if a person has died and to 2 days for a widespread infringement or a serious disruption to critical infrastructure. The checklist keeps these deadlines next to your reporting process.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

RELATED POSTS