AI Act compliance

AI Act compliance: from complex requirements to a practical roadmap

The EU AI Act introduces clear requirements for developing, placing on the market and using AI systems. The obligations that apply to your organization depend on your role within the AI value chain, whether you are a developer, manufacturer, provider or user. And on the risk classification of the AI system. These responsibilities apply throughout the entire lifecycle of the AI system.

Kiwa helps organizations translate the requirements of the EU AI Act into a practical and actionable roadmap. Providing you insight into your obligations, understand your risk profile and identify the steps needed to achieve demonstrable AI Act compliance.

AI Act compliance

From AI Act requirements to practical AI compliance. Why this remains a challenge for many organizations.

What does this mean for your organization?

The EU AI Act requires more than simply understanding regulatory requirements. Organizations must translate AI Act obligations into governance structures, internal processes, risk management practices and appropriate technical measures.

For many organizations, this transition from legislation to practical implementation is where the real challenge begins. Without a structured approach, uncertainty, delays and compliance risks can arise, making it difficult to demonstrate conformity with the EU AI Act.

Kiwa helps organizations break down this complexity. Through a structured approach, we translate the requirements of the EU AI Act into clear and manageable steps for your organization. In doing so, we help you work towards trustworthy AI systems and demonstrable AI Act compliance.

Who is it for?

Developers of AI systems or models

You develop AI systems or models and need to demonstrate compliance with AI Act requirements relating to risk management, data governance, robustness, transparency and technical documentation.

Manufacturers Integrating AI into products

You incorporate AI into CE-marked or CE-regulated products and must integrate AI compliance requirements into existing conformity assessment procedures and technical documentation.

Deployers of AI systems

You use AI within your organization and are responsible for assessing suitability, ensuring compliant use and monitoring AI systems in a responsible and demonstrable manner.

Deployer or provider? Your role may not be what you think.

Many organizations consider themselves users of AI. Under the EU AI Act, however, that is not always the case. AI systems are frequently configured, customized, integrated into products or embedded in business processes. As a result, an organization that sees itself as a deployer may, under certain circumstances, also be classified as a provider, with a different set of legal obligations.

Determining the correct role is one of the first and most important steps towards AI Act compliance. Your role directly influences the requirements that apply to governance, risk management, technical documentation, monitoring and conformity assessment.

Kiwa helps organizations establish their role under the EU AI Act and translate the resulting obligations into clear and manageable actions. This enables you to work systematically towards trustworthy AI systems and demonstrable AI Act compliance.

Creating trust, driving progress

Why Kiwa?

The EU AI Act follows a risk-based approach. The obligations that apply to your organization depend on both your role within the AI value chain and the risk classification of the AI system. Only once these factors are understood can you determine the appropriate path toward AI Act compliance.

In practice, this initial phase is often the most challenging. Organizations need insight into their AI systems, responsibilities, risks, governance structures, documentation requirements and technical controls. Without a clear framework, fragmentation, delays and uncertainty can hinder compliance efforts.

Kiwa helps organizations tackle this complexity in a structured way. Combining regulatory expertise with deep knowledge of AI and compliance, we translate the requirements of the EU AI Act into concrete and manageable actions.

✓ Notified Body perspective

✓ Practical translation of regulatory requirements

✓ ARION: A proven structured methodology

As a notified body, Kiwa sees firsthand where organizations encounter challenges. The ARION methodology was developed by Kiwa specifically to help organizations navigate these challenges through a practical, logical and structured approach.

Understanding applicable AI Act requirements

AI Act requirements translated into governance, processes and responsibilities

Embedding requirements into technical and organizational measures

Supporting demonstrating compliance and audit readiness

Working with AI

EU AI Act compliance: From complexity to clarity

The European AI Act fundamentally changes how organizations develop, deploy, govern and demonstrate responsible use of AI. The obligations that apply depend on role, risk, and context and require a structured approach.

Through the ARION methodology, Kiwa brings clarity and structure to this complexity. Rather than an abstract framework, ARION provides a practical roadmap that guides organizations from initial understanding to demonstrable and audit-ready AI compliance.

As a notified body, Kiwa has firsthand insight into the challenges organizations face when translating AI Act requirements into practice. ARION was developed to provide structure and clarity where organizations need it most: a logical, step-by-step approach grounded in real-world practice.

Ready to start your AI compliance journey?

The ARION methodology consists of five interconnected stages that together create a complete path toward AI Act compliance.

    AI Inventory

    Systematically identify and define all AI systems within your organization that fall within the scope of the EU AI Act. This creates a formal and verifiable foundation for scope determination, risk classification and future conformity assessment activities.

    Role & Risk

    Determine your organization's legal role under the AI Act and classify each AI system according to the appropriate risk category. This step establishes which obligations apply and which conformity assessment pathway must be followed.

    Integration & Implementation

    Implement and anchor the technical and organizational requirements of the AI Act at system level and across the development, validation and operational environment, ensuring that demonstrable conformity can be established.

    Objective Assessment

    Have the AI system and related technical and organizational measures objectively assessed by an independent third party to evaluate compliance and prepare for formal conformity assessment.

    Notified Body & Compliance

    Formalize AI Act compliance by following the appropriate conformity assessment procedure with a designated, AI-ready notified body, enabling demonstrable market access and regulatory acceptance.