Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What evidence will an AI auditor or regulator request?

Updated

Two different things get called an audit. Under Regulation (EU) 2024/1689 authorities can compel documentation, logs and, on conditions, source code. A certification auditor asks by contract and standard. Not legal advice. This page is not a regulator filing pack.

AI audit and regulator evidence, last verified 10 September 2026 against Articles 11, 12, 18, 19, 21, 23, 26, 47, 49, 71, 73 and 74 of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024). ISO/IEC 42001:2023 is a management-system standard, not the regulation, and an ISO 42001 audit is not a market-surveillance action. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages, AI Office materials and national authority guidance are guidance, not the regulation. This page is not legal advice, not a filing, and does not start a clock. It does not determine that the Act applies to YOU, that YOU are a provider or a deployer, or that YOUR system is high-risk.

This is Articles 21, 74 and ISO 42001 practice, not YOUR response pack

Audience: a compliance owner, CISO, counsel, or engineering lead preparing for scrutiny — from a market-surveillance authority, from a certification body, or from an enterprise customer running its own third-party review. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the Act applies, that YOU are a provider or a deployer, or that YOUR system is high-risk. This product does not respond to authorities on your behalf.

The AI Act is Regulation (EU) 2024/1689 of 13 June 2024, OJ L 2024/1689, 12.7.2024. ELI: http://data.europa.eu/eli/reg/2024/1689/oj. The critical distinction on this page is between power and practice. Article 21 and Article 74 describe what a competent authority can require. ISO/IEC 42001:2023 audit practice describes what a certification body typically asks, because it is auditing a management system against a standard it published. Preparing for the second is not preparing for the first. Last verified 10 September 2026. Not legal advice.

  • Statute versus standard versus guidance versus product: Articles 11, 12, 18, 19, 21, 23, 26, 47, 49, 71, 73 and 74 of 2024/1689 are legal requirements only if they apply. ISO/IEC 42001:2023 and the audit practice around it are a standard and industry practice, not a legal substitute for the Act. National market-surveillance authority guidance and Commission or AI Office materials are guidance, not the regulation. The preparation advice below is a ShipReadyMetrics recommendation. This page labels which kind of text each claim rests on.
  • The evidence-retention-checklist guide on this site is the Articles 12, 18 and 19 retention-matrix page. The technical-documentation guide on this site is the Articles 11 and 53 Annex IV/XI/XII page. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. The how-shipreadymetrics-produces-ai-governance-evidence guide on this site is the product page for the evidence flow. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
  • Nothing here is a filing pack. A regulator request arrives with its own legal basis, addressee, scope, and deadline, and counsel answers it. Assembling documents in advance shortens the response; it does not pre-answer the request and does not start or stop a clock.

What authorities can compel versus what auditors typically ask

The left-hand column is a legal power that exists whether or not you like the request. The right-hand column is a commercial and standards relationship you entered voluntarily. Confusing the two produces either panic or complacency. Last verified 10 September 2026. Not legal advice.

Regulator power versus auditor practice (not YOUR obligation to produce anything; not legal advice)
AskWhat the cited text or practice isKind of textLast verified
All information and documentation necessary to demonstrate conformity, on a reasoned requestArticle 21(1), in substance: providers of high-risk AI systems shall, upon a reasoned request by a competent authority, provide that authority all the information and documentation necessary to demonstrate the conformity of the high-risk AI system with the requirements set out in Chapter III Section 2, in a language which can be easily understood by the authority in one of the official languages of the institutions of the Union as indicated by the Member State concerned.Article 21 of 2024/1689. Legal requirement, only if it applies. A power the authority holds, exercised by reasoned request. This page does not answer that request for YOU.10 September 2026
Access to the automatically generated logs, to the extent they are under the provider's controlArticle 21(2), in substance: upon a reasoned request by a competent authority, providers shall also give the requesting competent authority access to the automatically generated logs of the high-risk AI system referred to in Article 12(1), to the extent such logs are under their control. Article 21(3) applies the Article 78 confidentiality obligations to information so obtained.Article 21 of 2024/1689. Legal requirement, only if it applies. Note the same control qualifier that appears in Articles 19 and 26(6).10 September 2026
Documentation and cooperation from importersArticle 23, in substance: importers shall, upon a reasoned request, provide national competent authorities with the necessary information and documentation to demonstrate the conformity of a high-risk AI system with the requirements of Chapter III Section 2, in a language easily understood, and shall cooperate with those authorities in any action taken in relation to a system they placed on the market.Article 23 of 2024/1689. Legal requirement, only if it applies. An importer duty, distinct from the provider duty in Article 21.10 September 2026
Deployer cooperation, and the deployer's logsArticle 26(12), in substance: deployers shall cooperate with the relevant competent authorities in any action those authorities take in relation to the high-risk AI system in order to implement the Regulation. Article 26(6) is the deployer's own log-keeping duty, for a period appropriate to the intended purpose of at least six months.Article 26 of 2024/1689. Legal requirement, only if it applies. A deployer duty, distinct from the provider duties.10 September 2026
Full access to documentation and to training, validation and testing data setsArticle 74(13), in substance: market surveillance authorities shall be granted full access to the documentation as well as the training, validation and testing data sets used for the development of the high-risk AI system, including, where appropriate and subject to security safeguards, through application programming interfaces or other relevant technical means and tools enabling remote access.Article 74 of 2024/1689. Legal requirement, only if it applies. Data sets, not only documents. This is a power no commercial auditor holds.10 September 2026
Source code, on a reasoned request and only on conditionsArticle 74(14), in substance: access to the source code of the high-risk AI system shall be granted to market surveillance authorities upon a reasoned request and only when both of the following conditions are fulfilled — access to source code is necessary to assess the conformity of the system with the requirements set out in Chapter III Section 2, and testing or auditing procedures and verifications based on the data and documentation provided by the provider have been exhausted or proved insufficient.Article 74 of 2024/1689. Legal requirement, only if it applies. Conditional and last-resort by its own wording. Counsel reads the authentic paragraph before anyone hands over a repository.10 September 2026
The serious-incident report and the investigation that follows itArticle 73 requires providers of high-risk AI systems placed on the Union market to report serious incidents to the market surveillance authorities of the Member States where the incident occurred, on outer caps of 15 days, two days, and 10 days, and Article 73(6) requires the necessary investigations, a risk assessment, and corrective action, without altering the system in a way that may affect subsequent evaluation before informing the authorities.Article 73 of 2024/1689. Legal requirement, only if it applies. This page does not start a clock and no product files. The AI-incident-reporting guide on this site is that page.10 September 2026
The management-system evidence a certification auditor asks forAn ISO/IEC 42001:2023 certification audit typically walks scope and context, the AI policy, roles and responsibilities, the Statement of Applicability, AI impact assessments, life-cycle records, data records, supplier and third-party arrangements, internal audit, management review, and corrective actions — because those are what the standard asks an organisation to maintain.ISO/IEC 42001:2023 and industry audit practice. Not a legal power. An accredited certification body is not a market-surveillance authority, and a certificate is not CE marking or an Article 43 conformity assessment.10 September 2026
The security questionnaire an enterprise customer sendsA contractual diligence exercise. It often asks the same questions in a different order, with commercial consequences rather than legal ones. ShipReady Passport is one way to answer it with a shareable posture snapshot.Industry practice plus ShipReadyMetrics recommendation. Not a legal power and not legal conformity.10 September 2026

Evidence requests by role and obligation

The same artefact is asked for by different people for different reasons. This table maps the common requests to the obligation behind them and the role that would owe it, only if the Act applies. It is not a determination that YOU hold that role, and not a list of what YOU will be asked. Last verified 10 September 2026. Not legal advice.

Evidence requests by role and obligation (not YOUR response pack; not a determination of YOUR role; not legal advice)
Evidence requestedRole it would fall onObligation behind itKind of textLast verified
The Annex IV technical documentation for a named system, current as of todayProvider of a high-risk AI systemArticle 11 to draw it up and keep it up to date; Article 18(1)(a) to keep it at the disposal of national competent authorities for 10 years; Article 21(1) to hand it over on a reasoned request.Legal requirements of 2024/1689, only if they apply. The technical-documentation guide on this site is that page.10 September 2026
The quality-management-system documentationProvider of a high-risk AI systemArticle 17 to have it, Article 18(1)(b) to keep it for 10 years. An ISO 42001 certificate does not discharge Article 17.Legal requirements of 2024/1689, only if they apply, plus ISO/IEC 42001:2023 as a standard, not a substitute.10 September 2026
Automatically generated logs for a stated windowProvider under Article 19; deployer under Article 26(6) — whoever has them under their controlArticle 12(1) for the capability, Article 19(1) and Article 26(6) for keeping them for a period appropriate to the intended purpose of at least six months, Article 21(2) for access on a reasoned request.Legal requirements of 2024/1689, only if they apply. The evidence-retention-checklist guide on this site is that page.10 September 2026
Risk-management records showing the process was continuous, not a one-offProvider of a high-risk AI systemArticle 9 — a risk management system established, implemented, documented and maintained as a continuous iterative process throughout the entire lifecycle, requiring regular systematic review and updating.Legal requirement of 2024/1689, only if it applies. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page.10 September 2026
Testing and evaluation results, including how thresholds were chosenProvider of a high-risk AI system; provider of a GPAI model with systemic risk on its own trackArticle 9(6) and 9(8) on testing against preliminarily defined metrics and probabilistic thresholds, Article 15 on accuracy, robustness and cybersecurity, and Article 55(1)(a) on evaluation for systemic-risk models.Legal requirements of 2024/1689, only if they apply. A dedicated model-evaluation-requirements guide is not on this site yet. Naming it is not a link.10 September 2026
The EU declaration of conformity, and any notified-body documentsProvider of a high-risk AI systemArticle 47 for the declaration, Article 18(1)(c)–(e) for keeping it and the notified-body documents for 10 years.Legal requirements of 2024/1689, only if they apply. This product is not a notified body and does not issue certifications.10 September 2026
Proof of registration in the EU database, or of the Article 6(3) not-high-risk conclusionProvider or authorised representative under Article 49(1) or 49(2); public-authority deployer under Article 49(3)Articles 49 and 71 with Annex VIII. The Commission operates the database; registration happens there, not in a vendor tool.Legal requirements of 2024/1689, only if they apply. The ai-inventory-requirements guide on this site is that page.10 September 2026
Human-oversight design and the named people in the seatProvider under Article 14; deployer under Article 26(2)Article 14 for the design measures and the Article 14(4) enabling list; Article 26(2) for assigning natural persons with the necessary competence, training and authority, as well as the necessary support.Legal requirements of 2024/1689, only if they apply. The AI-ownership-accountability guide on this site is that page.10 September 2026
Instructions for use held by the deployer, and evidence they are followedDeployer of a high-risk AI systemArticle 26(1) — appropriate technical and organisational measures to ensure use in accordance with the instructions for use accompanying the systems.Legal requirement of 2024/1689, only if it applies. The provider-vs-deployer guide on this site is that page.10 September 2026
The GPAI documentation pack and the training-content summaryProvider of a general-purpose AI modelArticle 53, including the sufficiently detailed summary about the content used for training under Article 53(1)(d). Chapter V applies from 2 August 2025 under Article 113(b), except Article 101.Legal requirements of 2024/1689, only if they apply. The GPAI-requirements and training-data-transparency guides on this site are those pages.10 September 2026
The incident file: what happened, when awareness arose, what was reported, and what changed afterProvider under Article 73; provider of a systemic-risk GPAI model under Article 55(1)(c)Article 73(1)–(6) for the report, the investigation, the risk assessment, and corrective action; Article 55(1)(c) for the separate GPAI duty to the AI Office without undue delay.Legal requirements of 2024/1689, only if they apply. This page does not start a clock and does not determine that YOUR event was reportable.10 September 2026
The AI policy, the Statement of Applicability, internal audit and management reviewAny organisation running an AI management systemISO/IEC 42001:2023 asks for these. No article of 2024/1689 asks for a Statement of Applicability.ISO/IEC 42001:2023. Standard and audit practice, not a legal requirement of the Act.10 September 2026

Legal requirement versus guidance versus ShipReady recommendation

The table below labels each text. Do not treat a certification audit as a market-surveillance action, do not treat a prepared folder as a filing, and do not treat a product surface as a determination. Last verified 10 September 2026. Not legal advice.

Statute versus standard versus guidance versus product (not a ranking; not legal advice; last verified 10 September 2026)
TextWhat it isWhat this page does not do
Regulation (EU) 2024/1689 Articles 21, 23, 26 and 74Legal requirements — cooperation and information duties on providers, importers and deployers, and market-surveillance powers over documentation, data sets and, conditionally, source code, only if they apply.Does not answer a reasoned request for YOU, does not determine that YOU hold any of those roles, and does not decide what is in scope of a request.
Regulation (EU) 2024/1689 Articles 11, 12, 18, 19, 47, 49 and 71Legal requirements — the documentation, the logging capability, the retention periods, the declaration of conformity, and registration in the Commission-operated EU database, only if they apply.Does not keep YOUR records, does not register anything, and does not treat a prepared folder as satisfying any of them.
Regulation (EU) 2024/1689 Article 73Legal requirement — serious-incident reporting to market-surveillance authorities on 15-day, two-day and 10-day outer caps, only if it applies.Does not start a clock, does not determine that YOUR event is reportable, and does not file.
ISO/IEC 42001:2023 and certification audit practiceBest practice / standard, plus industry practice. An accredited certification body auditing a management system against a published standard.Does not treat a certificate as CE marking, as an Article 43 conformity assessment, or as an answer to a market-surveillance authority.
National market-surveillance authority guidance, Commission AI Act pages, and AI Office materialsGuidance, not the regulation, even when it tells you exactly what a particular authority expects.Does not treat authority guidance as rewriting Article 21 or Article 74.
This product's evidence collection, evidence review, and ShipReady PassportShipReady recommendation: collected artefacts, a human review overlay, and a shareable posture snapshot. Not a legal determination.Not a regulator filing pack, not forensic chain of custody, and not legal conformity. A named human still owns the assessment.

What to do now

As of last verification on 10 September 2026, Articles 21, 23, 26, 49, 71, 73 and 74 sit on the Article 113 residual application of 2 August 2026, and Article 113(c) keeps Article 6(1) and the corresponding obligations on 2 August 2027. The list below is operational preparation. It is not a determination that any request will be made of YOU or that any of those articles binds YOU. Walk it with counsel.

  • Decide now who receives a regulator request and who is authorised to answer it. The worst version of this is an engineer replying helpfully to an authority before counsel has read the legal basis.
  • Assemble per-system, not per-topic. Every request in the table above names a system; a folder organised by document type will be re-sorted under time pressure.
  • Check you can actually produce logs for a stated window today. Article 21(2) access is worth nothing if the retention decision was never made — the evidence-retention-checklist guide on this site is that page.
  • Do not volunteer source code. Article 74(14), if it applies, is conditional and last-resort by its own wording, and counsel reads it before anything is handed over.
  • Keep the certification track and the regulator track visibly separate in whatever you build. An ISO/IEC 42001:2023 audit and a market-surveillance action are not the same event and do not have the same consequences.
  • The how-shipreadymetrics-produces-ai-governance-evidence guide on this site is the product page for the evidence flow. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.

Checklist

This is a question list, not a determination that any authority will ask YOU for anything, and not a filing. Walk it with counsel. The evidence-retention-checklist guide on this site is the Articles 12, 18 and 19 retention-matrix page.

  • Does the Act apply to YOU at all? Articles 2 and 3. This page does not run that test.
  • For each system, are YOU the provider, importer, distributor, or deployer? Article 21, Article 23 and Article 26 fall on different parties.
  • Could you produce the Annex IV documentation for a named system today, in a language the authority can easily understand?
  • Could you produce logs for a stated window, and are those logs under your control?
  • Do you know who your market-surveillance authority would be, and who inside the organisation talks to it?
  • Is a certification audit the same thing as a regulator request? No. One is a voluntary standards relationship; the other is a legal power under Articles 21 and 74.
  • Is a prepared evidence folder a filing? No. It shortens a response. It does not answer a request, and it does not start or stop a clock.
  • Does ShipReady Passport prove conformity? No. It is a shareable posture snapshot, not legal conformity and not a certificate.
  • Document the assessment, including the decision that no request is expected. This page does not keep YOUR file.

Where this shows up in ShipReady Metrics

The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.

If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and the AI risk register, and can export the inventory and governance posture — including a machine-readable AI bill of materials in CycloneDX form. Evidence collection stores artefacts the organisation supplied, and a human evidence review can accept a manually supplied row as meeting a control. That overlay is a reviewed human judgement, not a machine verdict and not a legal conclusion.

This product is not a regulator filing pack, is not forensic chain of custody, does not respond to authorities on your behalf, does not file with the AI Office, does not register in the EU database, does not issue certifications, does not affix CE marks, and is not a notified body. ShipReady Passport is a shareable posture snapshot, not legal conformity. The obligation map lists frameworks the organisation has marked in-scope. The cyber risk register lives under Security and is a different register.

This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.

Primary sources (last verified 10 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 9, 11, 12, 14, 15, 17, 18, 19, 21, 23, 26, 47, 49, 53, 55, 71, 73, 74, 78 and 113, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 (NIST AI 100-1, January 2023) is guidance, not law. Commission AI Act pages, AI Office materials, and national market-surveillance authority guidance are guidance, not the regulation. These are not a complete world list. Not legal advice.

The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The technical-documentation guide on this site is the Articles 11 and 53 Annex IV/XI/XII page. The evidence-retention-checklist guide on this site is the Articles 12, 18 and 19 retention-matrix page. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The readiness-checklist guide on this site is the deadline-anchored Article 113 self-assessment page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.

Frequently asked questions

Is this legal advice?

No. It is a dated map of what authorities can compel under Regulation (EU) 2024/1689 and what certification auditors ask by practice under ISO/IEC 42001:2023, which is a standard, not the regulation. Whether the Act applies to YOU, which role YOU hold, and how to answer any particular request are legal questions for counsel on your facts. This page does not start a clock.

Is a prepared evidence pack a filing?

No. A regulator request under Article 21 or Article 74 of Regulation (EU) 2024/1689 arrives with its own legal basis, addressee, scope and deadline, and counsel answers it. Assembling documents in advance shortens the response and reduces the chance of an embarrassing gap. It does not pre-answer the request, is not a submission, and does not start or stop a clock. This product is not a regulator filing pack.

Can a market-surveillance authority ask for our source code?

Conditionally, if Article 74 applies. Article 74(14) of Regulation (EU) 2024/1689 grants access to the source code of a high-risk AI system upon a reasoned request and only when both conditions are met: access is necessary to assess conformity with the Chapter III Section 2 requirements, and testing or auditing procedures and verifications based on the data and documentation provided by the provider have been exhausted or proved insufficient. Counsel reads the authentic paragraph before anything is handed over.

Is an ISO 42001 audit the same as a regulator request?

No. An ISO/IEC 42001:2023 certification audit is a voluntary relationship with an accredited certification body auditing a management system against a published standard. A market-surveillance action under Articles 21 and 74 of Regulation (EU) 2024/1689 is a legal power. A certificate is not CE marking, is not an Article 43 conformity assessment, and does not answer a reasoned request. Last verified 10 September 2026.

Does ShipReady Passport prove AI Act conformity?

No. ShipReady Passport is a shareable snapshot of the posture an organisation recorded, useful for a customer's diligence questionnaire. It is not legal conformity, not a certificate, not CE marking, and not an Article 43 conformity assessment. This product does not issue certifications and is not a notified body. A named human still owns the assessment.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.