AI Governance, Risk & Red Teaming
Proficient · M9 · lesson 9 of 31 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
CE Marking, Article 47 Declaration of Conformity, Article 71 EU Database Registration
📖
now learning

CE Marking, Article 47 Declaration of Conformity, Article 71 EU Database Registration

15 min

It is a Wednesday in November 2027. Across the conference table sit the General Counsel, the Chief AI Officer, the Quality Director, and a single piece of paper: the Article 47 EU declaration of conformity for Acme.HireRank v2.1. One signature stands between the Annex IV technical file and the EU market. Below the signature line, the printed name of the authorized person: the senior executive who, under several Member-State implementing laws, has personal criminal exposure if the statement on this page turns out to be false. Above the signature, nine fields drawn from Annex V. Once this page is signed, three things happen in sequence: the CE marking is affixed to the system's user interface under Article 48, the Annex VIII data set is uploaded to the Commission-operated EU database under Article 71, and only then, only then, does the system go on the market. This is the operational chokepoint where the Annex IV file becomes a marketed product. Miss any of the three steps, or run them out of order, and the system is on the market unlawfully. This lesson walks the three deliverables, the Annex V content, the Annex VIII database fields, and the six common mistakes that turn a clean Annex IV file into an Article 99(3) finding.

The Three Pre-Market Deliverables - In Order

Article 16 lists the obligations of providers of high-risk AI systems. Three of those obligations, 16(g), 16(h), and 16(i), converge into the final pre-market workflow. They are not interchangeable, and they are not parallel. They run in a strict sequence, each one depending on the prior:

  1. Article 47 EU declaration of conformity. Drafted against Annex V. Signed by the authorized person on behalf of the provider. Becomes Annex IV §8. Triggers the right to apply CE marking.
  2. Article 48 CE marking. Affixed to the system in compliance with Regulation (EC) No 765/2008. For digital-only AI systems, displayed on the user interface. Includes the notified body number adjacent to the CE mark where Annex VII (Module H) was the conformity assessment route.
  3. Article 71 EU database registration. Annex VIII data set uploaded to the Commission-operated central EU database. Required before placing on the market or putting into service.

Only after all three are complete may the system be placed on the market or put into service. Programs that sequence the CE marking before the declaration is signed, or that ship to deployers before the database registration is live, are non-compliant on Article 16(g)/(h)/(i) and on Article 71. The penalty exposure under Article 99(3) at €15M / 3% of global turnover is the headline number. The operational consequence, withdrawal from the market by the national market surveillance authority under Article 79, is the one that ends careers.

The sequencing also matters for the Annex IV technical file. The signed Article 47 declaration becomes Annex IV §8. The Annex VIII data set posted to the database becomes a referenced artifact in the Annex IV §1 general description. The CE marking placement on the user interface is documented in Annex IV §3 monitoring and control. The three pre-market deliverables close the loop on the Annex IV file, and on the Article 17 quality management system that produced it.

Article 47 + Annex V - The EU Declaration of Conformity

The Article 47 declaration is a single legal document. It is short, typically one to three pages in production. It carries a disproportionate amount of legal weight, because it is the document by which the provider personally states, on behalf of a named senior executive, that the high-risk AI system conforms to the requirements of the EU AI Act. Annex V specifies the content with precision. Get one field wrong and the declaration is defective; get the signing wrong and the declaration is void.

Annex V Required Content - Nine Fields

The Annex V content set covers nine numbered items. Each one must appear on the declaration; missing any of them is a defect under Article 47 and triggers Article 99(3) exposure:

  1. System identification. Name of the AI system, type or model designation, version identifier, any unique identifier (serial number, registration ID) that distinguishes the marketed system from prior or future versions. The identification must be specific enough that the declaration unambiguously attaches to one system instance and not to a family of variants. "Acme.HireRank v2.1, build 2027.10.15.001" is acceptable. "Acme.HireRank (current version)" is not.
  2. Provider identification. Name and address of the provider. Where the provider is established outside the Union, the name and address of the authorized representative appointed under Article 22. The authorized representative requirement is mandatory for non-EU providers and is the natural cross-walk to Article 22's authorized-representative-mandate template.
  3. Statement of conformity. An explicit declaration that the AI system is in conformity with the EU AI Act (Regulation (EU) 2024/1689) and, where applicable, with other Union legislation providing for the issuing of an EU declaration of conformity. This is the load-bearing sentence of the document. The phrasing should be drawn from Annex V's text and reviewed by Legal, "Acme declares that the high-risk AI system identified above conforms to the requirements of Chapter III Section 2 of Regulation (EU) 2024/1689" is the standard pattern.
  4. Annex IV reference. Reference to the Annex IV technical documentation file by identifier, version, and date. The technical file does not get attached to the declaration; it is incorporated by reference. The reference must be specific enough that the Annex IV file in scope at the moment of declaration can be retrieved on regulator inquiry.
  5. Harmonized standards applied. The list of harmonized standards under Article 40 that the provider has applied to establish the presumption of conformity. Where no harmonized standard exists for an article, the declaration cites the common specifications under Article 41 or the technical solution adopted. For the first wave of Annex III deployments through 2027, the harmonized-standard catalog is partial; ISO/IEC 42001:2023, 23894:2023, 5338:2023, and 27001:2022 are common references for the unfilled gaps.
  6. Notified body involvement. Where the conformity assessment was performed under Annex VII (Module H) with notified-body involvement, the name and identification number of the notified body and the certificate number. For Annex III §1 biometric ID systems (the only Annex III category mandatorily on the Module H path) this section is required. For most Annex III §2-§8 deployments under Annex VI internal control, this section reads "Not applicable, conformity assessment performed under Annex VI internal control."
  7. Date of declaration. The calendar date on which the declaration was signed. Must precede the date on which the system is placed on the market or put into service. A declaration signed after market placement is defective and may not be back-dated.
  8. Signature of authorized person. Wet-ink or qualified electronic signature of the natural person authorized to sign on behalf of the provider. The authorized person is named (printed name + role title) below the signature. The authorized person cannot delegate signing to a junior officer; the signing authority is a personal one.
  9. Place of signature. The location at which the declaration was signed. Typically the registered office of the provider. Used by regulators to determine the Member State whose implementing law governs the criminal exposure of the signing officer.

The nine fields are non-negotiable. A declaration missing field 6 (notified body) where Annex VII applied is invalid. A declaration missing field 8 (signature) is not a declaration. A declaration signed after the market-placement date is back-dated and exposes the provider to Article 99(5) at €7.5M / 1% for misleading information in addition to the underlying Article 99(3) for the absent valid declaration.

The Authorized Person - Personal Accountability

The authorized person who signs the Article 47 declaration is not a clerical signatory. The signature carries personal exposure that varies by Member State implementing law but is uniformly material:

  • Personal accountability for the statement of conformity. The signing officer personally states that the system conforms. Where the statement turns out to be false in material respects, the officer can be named in administrative proceedings and, in several Member States (Germany, France, Italy among them), in criminal proceedings under national implementing law.
  • Cannot delegate the signing act. The authorized person can delegate the preparation of the declaration to staff. The signing itself, the act of attaching name and signature, is personal. A document signed "for and on behalf of" a named officer by a delegate is generally not a valid Article 47 declaration unless the delegation is on the public record and the delegate is themselves an authorized officer.
  • Named in the declaration. The printed name and role title of the authorized person appears below the signature line. Anonymous signatures (legible squiggle without printed identification) are defective.
  • Typically the senior executive with AI accountability. Common patterns: Chief AI Officer (where the role exists and carries Annex VII Module H authority); General Counsel (where Legal is the natural keeper of regulatory filings); Chief Operating Officer (where AI deployment is operationally integrated); the legal-entity director on smaller orgs. The board may designate the authorized person through a corporate resolution; the resolution should be retained alongside the declaration.
  • D&O insurance overlay. Directors' and officers' insurance policies in 2026 increasingly carve out coverage for criminal exposure under Member-State AI Act implementation. The authorized person should confirm coverage scope with the broker before signing.

The named-signatory pattern is materially different from the historic CE marking practice for industrial products, where a quality manager often signed routinely. For high-risk AI, the signing authority should be a board-known senior executive whose name appears in proxy statements. The declaration is a personal commitment, not an administrative formality.

Retention and Refresh

Two operational rules close the Article 47 lifecycle. The declaration is retained per Article 18 for ten years from the date the system ceases to be made available on the market. The retention applies to the declaration itself and to the underlying Annex IV technical file that the declaration references. National market surveillance authorities may request the declaration and the technical file at any point during the retention window; the declaration must be producible within the statutory response time (typically 15 days, varying by Member State).

The refresh rule is the cross-walk to Article 43(4) substantial modification. Where a substantial modification is performed on a placed-on-market system, the declaration is invalidated by the change. A new Annex IV technical file is produced (or the existing one is refreshed under §6 lifecycle changes), a new conformity assessment is run, a new Article 47 declaration is signed, and the new declaration replaces the prior one. The Article 71 database registration is updated with the new declaration reference. Failing to refresh the declaration after a substantial modification leaves the system on the market with an invalid declaration, a state that triggers Article 99(3) on its own.

Article 48 - Affixing the CE Marking

Article 48 carries the CE marking obligation from Regulation (EC) No 765/2008 (the general framework for marketing of products) onto the AI Act. The CE marking is the visible signal to deployers and to the market that the provider has satisfied the conformity assessment. The Article 48 requirements unpack into four operational rules:

  • Affixed in compliance with Regulation 765/2008. The CE marking conforms to the form, proportions, and visibility rules of the 765/2008 framework. The marking is the standard "CE" graphic in the established proportions; reductions below the minimum visible size are not permitted.
  • For digital-only AI systems, displayed on the user interface. Article 48(5) is the AI-specific accommodation. AI systems delivered as software (no physical product) display the CE marking on the system's user interface in a location accessible to deployers and to affected persons interacting with the system. Common patterns: an "About" page, a footer accessible from every screen, a system-information modal. The marking must be visible and legible, buried in a 10-page click-through agreement is not compliant.
  • Notified body identification number adjacent, where Annex VII applied. For Annex III §1 biometric ID systems that ran through Annex VII Module H, the notified body's four-digit identification number appears immediately adjacent to the CE marking. The combined "CE 0123" marking communicates that the notified body identified by 0123 was involved in the conformity assessment. For Annex VI internal-control assessments, no notified body number is added.
  • Provider identification adjacent. The provider's name and trade name appear adjacent to the CE marking, with a contact address (or URL) that permits affected persons and deployers to reach the provider for inquiries. For digital-only AI, this is integrated into the same UI element that carries the CE mark.

The CE marking must be visible and legible. The Commission's enforcement posture in 2026-2028 is that hidden, undersized, or low-contrast CE markings are non-compliant; a marking that requires a deployer to actively search for it does not meet the visibility standard. The marketing temptation to bury the CE mark for aesthetic reasons should be resisted at the product-design stage. The mark is also a market signal that the system has passed conformity assessment, visible CE marking on a competitor's system creates a deployer expectation that yours displays the mark too.

Where the same AI system is marketed under multiple branded skins (white-label deployments, OEM relabeling, distributor channels), the CE marking and provider identification follow the system. Article 25 actor classification governs which party places the CE marking: generally the provider of the underlying system, but where a downstream party performs substantial modification under Article 25(1)(b), that downstream party becomes the provider of the modified system and assumes CE-marking responsibility for the modified version.

Article 71 + Annex VIII - EU Database Registration

The Article 71 EU database is a Commission-operated central registry of high-risk AI systems placed on the EU market. It is the public-facing transparency layer of the conformity regime: a regulator and (in part) a public-citizen can query the database to determine what high-risk AI systems are on the market, by what provider, in what Member States, under what high-risk category, with what current status. The database also serves the market surveillance authorities of the Member States by providing a single-source view of high-risk-system deployments across the Union.

Annex VIII - The Registration Information Set

Annex VIII specifies the fields that the provider must enter into the database before placing the system on the market or putting it into service. The fields decompose into nine items:

  • Provider identity. Name, address, and contact information of the provider. Where the provider is established outside the Union, the name, address, and contact information of the authorized representative appointed under Article 22.
  • Trade name and address. The trade name under which the system is marketed (which may differ from the provider's legal name) and the address from which the system is offered.
  • System identification. Name of the AI system, version identifier, type or model designation, and the unique identifier used in the Article 47 declaration. The system identification in the database must match the system identification in the declaration.
  • High-risk category. The Annex III sub-category (or Annex I product category) under which the system is classified. For Annex III, the eight categories (§1 biometrics through §8 administration of justice) and the specific sub-paragraph. For Annex I, the harmonized-product framework that applies. The high-risk-category field is the primary search axis in the database.
  • Member States where placed on the market. The list of Member States in which the system is or is intended to be placed on the market or put into service. The list may cover all 27 (typical for cloud-delivered SaaS) or a subset (typical for region-specific deployments). The list is updated as the deployment footprint changes.
  • Status. Current market status: placed on the market, withdrawn, recalled, or other status code per the Annex VIII status taxonomy. The status field is updated as the lifecycle proceeds.
  • Declaration of conformity reference. Reference to the Article 47 EU declaration of conformity by identifier, version, and date. The declaration itself is not uploaded; the reference links the database entry to the declaration that the provider retains under Article 18.
  • Instructions for use. The Article 13 instructions for use in electronic format. Uploaded to the database in a machine-readable format that deployers and authorities can retrieve. This is the field that gives the database genuine downstream-deployer utility.
  • URL for additional information. A URL on the provider's domain where additional information about the system is available: model card, system card, performance documentation, user guides, support contact. The URL is published in the public-facing portion of the database (see confidentiality below).

The nine fields are mandatory. The registration is performed by the provider through the Commission-operated database interface. Authentication is via the EU Login system; the registering account is tied to the provider organization, and registration actions are auditable.

Public-Facing Visibility and Trade-Secret Protection

Article 71(5) governs the visibility of database content. Certain fields are public-facing for transparency purposes: provider identity, system identification, high-risk category, Member States, status, and (typically) the URL for additional information. Other fields are accessible only to competent authorities, the Commission, the AI Office, and (in limited cases) the public on request: typically the detailed instructions for use, certain technical specifications, and the declaration reference.

The provider may invoke confidentiality protection under Article 78 for content that constitutes a trade secret, intellectual property, or other commercially sensitive information. The confidentiality claim must be specific (not blanket) and supported by reasoning at the moment of registration. Authorities retain access regardless of the confidentiality designation; the protection limits public visibility, not regulatory access.

Common mistakes in the confidentiality designation include: marking the entire registration as confidential (regulators will reject), claiming trade-secret status on information that is already in the provider's public marketing material (the claim fails the secrecy requirement), and failing to claim confidentiality on genuinely sensitive content (the content goes public and cannot be retracted). The L3 practice is a deliberate field-by-field confidentiality review at the time of registration, signed off by Legal.

Article 49 - The Annex III Carve-Out Registration Path

Article 6(3) (introduced through Recitals 53-55 and operationalized through Article 6(3)) provides a carve-out from high-risk classification for systems that fall within an Annex III category but perform only narrow procedural tasks, improve the result of previously completed human activity, detect decision-making patterns without replacing the human, or perform a preparatory task for a high-risk assessment. The carve-out is self-asserted by the provider and is a high-leverage tool for systems whose Annex III tag is technical but whose actual function is benign.

Article 49(2) creates a separate registration obligation for self-asserted Article 6(3) carve-outs. Providers (and in some cases deployers) who self-assert the carve-out must register the system in a dedicated section of the EU database with the Annex VIII information set adapted to the carve-out context. The self-assertion must be documented with reasoning that survives regulator review; an unjustified Article 6(3) claim that is later overturned exposes the provider to having placed an unregistered high-risk system on the market.

The Article 49 registration pathway is operationally distinct from the Article 71 high-risk registration: same database, different section, different field set, different confidentiality posture. Programs running both high-risk Annex III systems (Article 71 path) and Article 6(3) carve-out systems (Article 49 path) maintain separate registration records for each.

The Q4 2027 Deployment Workflow - End-to-End

For an Annex III §4 employment system reaching the Dec 2, 2027 stand-alone applicability date under the post-Omnibus-VII timeline, the end-to-end Q4 2027 deployment workflow integrates the three pre-market deliverables with the broader Annex IV / Article 17 / notified-body lifecycle:

  1. Annex IV technical file v1.0 finalized. All nine Annex IV sections complete, internally reviewed, signed off by ML Engineering / AI Officer / Chief AI Risk Officer. §6 lifecycle-changes section reflects the pre-determined-change carve-out per Article 43(4). §8 reserved for the Article 47 declaration to be inserted post-signature.
  2. Annex VII Module H assessment closed (if notified body applied). For Annex III §1 biometric ID systems, the notified body has completed Stage 2 audit, issued the Module H certificate, and provided the certificate number. For most Annex III §2-§8 deployments running under Annex VI internal control, this step is the internal-control sign-off.
  3. ISO 42001 Stage 2 certificate (parallel). The Article 17 quality management system has cleared ISO/IEC 42001:2023 Stage 2 certification with the ISO certificate as parallel evidence to the AI Act QMS obligation.
  4. Article 47 declaration signed by authorized person. The declaration is drafted against Annex V, reviewed by Legal, signed by the named authorized person (Chief AI Officer or General Counsel typical), dated, and retained. The signed declaration is inserted into Annex IV §8.
  5. CE marking integrated into system UI. The CE marking (with notified body number adjacent where Module H applied; with provider identification adjacent) is integrated into the system's user interface, typically a footer accessible from every screen and an "About / Compliance" page. The product-engineering integration is tested and shipped.
  6. Article 71 database registration completed. The Annex VIII data set is entered into the Commission-operated EU database. The confidentiality designation is reviewed field-by-field. The instructions for use are uploaded in electronic format. The URL for additional information is verified live. The registration is confirmed and the registration identifier captured.
  7. Deployment proceeds. Only now, with declaration signed, CE mark live, database registration confirmed, may the system be placed on the market or put into service. Deployer onboarding begins, Article 26 deployer obligations attach, Article 72 post-market monitoring activates, Article 73 serious-incident reporting infrastructure is live.

The workflow is sequential, not parallel. Each step depends on the prior. The most common failure mode is shipping the system to early-access deployers before step 6 (database registration) is complete, the early-access deployment is technically a market placement and is non-compliant on Article 71. The fix is to gate early-access access behind the registration confirmation.

Multi-Member-State deployment is handled at step 6. The database registration includes all Member States in which the system is or is intended to be placed on the market. A single declaration (step 4) covers the EU as a unit; a single CE marking (step 5) covers all Member States; the database registration (step 6) names each Member State explicitly. Adding a new Member State to the deployment footprint after initial registration is an update to the database registration, not a new declaration or CE marking.

Six Common Mistakes - The Pattern Library

Six failure modes recur across the first-wave 2027 deployments. Each one is preventable with a deliberate pre-market review. Each one is found in the wild and is the kind of finding that turns a clean Annex IV file into an enforcement letter.

  • Mistake 1 - Missing signature of the authorized person. The declaration is drafted, reviewed, dated, and never signed, or signed by a delegate without authority. The mistake is most common in fast-moving deployments where the AI Officer drafts the declaration and the General Counsel is asked to sign in the last 24 hours; the signing is delayed past the market-placement date or skipped. The remediation is a hard gate at step 4 of the deployment workflow: no CE marking integration (step 5) until the signed declaration is in hand.
  • Mistake 2 - CE marking not visible. The CE marking is buried in a footer requiring scroll-to-bottom, hidden behind an "About" menu three clicks deep, or rendered in low-contrast text against the same-color background. The mistake is most common where the product-design team treats the CE mark as a compliance artifact rather than as a market-facing signal. The remediation is product-design integration at the wireframing stage and a visibility test (can a deployer find the CE mark in under 30 seconds without prompting?) before deployment.
  • Mistake 3 - Database registration after deployment. The system is shipped to deployers before the Article 71 registration is complete, on the theory that "registration is administrative paperwork." This is wrong. The registration is a precondition to market placement, not a follow-up to it. Shipping before registration is non-compliant on Article 71 and on Article 16(i). The remediation is the strict sequence: declaration → CE marking → database registration → deployment, with deployment-blocked status until step 6 confirms.
  • Mistake 4 - Incomplete Annex V content on the declaration. One of the nine Annex V fields is missing or defective. Most common: the harmonized standards field (field 5) cites "ISO 42001, pending publication of harmonized variant" instead of the actual reference standards applied; or the notified body field (field 6) is left blank where Annex VII applied; or the system identifier (field 1) is generic. The remediation is a checklist review of all nine fields against Annex V text, signed off by Legal, before the authorized person signs.
  • Mistake 5 - No refresh on substantial modification. A substantial modification under Article 43(4) is performed on a placed-on-market system, but the Article 47 declaration is not refreshed and the Article 71 registration is not updated. The system continues on the market with an invalid declaration and an out-of-sync registration. The remediation is integration of the change-control gate (Article 43(4)) with the pre-market deliverables: a substantial-modification disposition automatically triggers declaration refresh and database update as part of the re-conformity sequence.
  • Mistake 6 - Weak Article 71 confidentiality claims. Confidentiality is either over-claimed (the entire registration marked confidential, which fails Commission review) or under-claimed (genuine trade-secret content goes public and cannot be retracted). The remediation is a deliberate field-by-field confidentiality review at registration time, with Legal sign-off on each claim and the underlying reasoning documented for the regulator-inquiry response file.

Cross-Walks - The Multi-Framework Anchor

The three pre-market deliverables sit at the intersection of multiple frameworks. The cross-walk table below is the L3 reference for how the Article 47 / 48 / 71 workflow anchors against EU AI Act articles, harmonized standards, and adjacent regulations:

  • EU AI Act Articles. Article 16(g) declaration of conformity obligation; Article 16(h) CE marking obligation; Article 16(i) registration obligation; Article 22 authorized representative for non-EU providers; Article 25(1)(b) downstream substantial-modification transfer of provider status; Article 25(2) original-provider cooperation; Article 43 conformity assessment routes (Annex VI internal control vs. Annex VII Module H); Article 43(4) substantial-modification re-conformity trigger; Article 47 EU declaration of conformity; Article 48 CE marking placement; Article 49 Article 6(3) carve-out registration; Article 49(2) deployer registration for §5(b)/§5(c) deployers; Article 71 EU database registration; Article 78 confidentiality protection; Article 18 ten-year retention; Article 79 market surveillance and withdrawal.
  • Annexes. Annex IV §8 incorporates the signed Article 47 declaration; Annex V specifies the nine declaration content fields; Annex VI internal control conformity assessment; Annex VII Module H notified-body conformity assessment; Annex VIII specifies the nine database registration fields.
  • Adjacent EU regulation. Regulation (EC) No 765/2008 governs the CE marking form, proportions, and placement rules. Regulation (EU) 2024/1689 is the AI Act itself. The Digital Omnibus VII (provisional political agreement May 7, 2026) shifted the stand-alone Annex III applicability to Dec 2, 2027, the date the workflow above is anchored against. The MDR and IVDR overlays apply for Annex I embedded products where the AI system is a safety component of a medical device or in-vitro diagnostic, with the Aug 2, 2028 Annex I applicability date.
  • ISO standards. ISO/IEC 42001:2023 (AIMS), the Article 17 QMS evidence; declaration field 5 typically cites 42001 where no harmonized standard exists. ISO/IEC 23894:2023 (risk management), declaration field 5 reference for Article 9 RMS. ISO/IEC 5338:2023 (AI lifecycle), declaration field 5 reference for Article 11 documentation lifecycle. ISO/IEC 27001:2022 (information security), declaration field 5 reference for Article 15 cybersecurity.
  • NIST AI RMF. Govern function (organizational policies enabling the signing authority); Manage function (substantial-modification trigger flowing back to re-conformity); the declaration / CE mark / database trio is the production-readiness checkpoint that anchors the Govern-Manage handoff.
  • OWASP and MITRE. The declaration field 5 harmonized-standards references typically cite OWASP LLM Top 10 and MITRE ATLAS as the cybersecurity evidence base for Article 15. The cross-walk is operational where the conformity assessment depends on adversarial-testing evidence.

Key Takeaways

  • Three pre-market deliverables, in strict sequence. Article 47 declaration → Article 48 CE marking → Article 71 database registration → market placement. Out-of-sequence shipment is non-compliant.
  • Annex V specifies nine declaration fields. System ID, provider ID (with Article 22 authorized representative for non-EU), conformity statement, Annex IV reference, harmonized standards, notified body where Annex VII applied, date, signature of authorized person, place of signature. Missing any field is a defect.
  • The authorized person carries personal accountability. Signing officer is named, cannot delegate the signing act, and has criminal exposure in several Member States under national implementing law. D&O coverage scope should be confirmed before signing.
  • Retention is ten years per Article 18. Declaration and Annex IV file retained for ten years from system end-of-life. Producible to authorities within statutory response time on request.
  • Substantial modification refreshes the declaration. A substantial modification under Article 43(4) invalidates the prior declaration; a new declaration is signed and the Article 71 registration is updated.
  • CE marking must be visible and legible. Digital-only AI displays the mark on the user interface, visible without hunting. Notified body number adjacent where Annex VII applied. Provider identification adjacent.
  • Article 71 database is Commission-operated. Annex VIII nine-field information set, mandatory before market placement, with public-facing visibility for some fields and Article 78 confidentiality available for trade-secret content.
  • Article 49 path for Article 6(3) carve-outs. Self-asserted carve-outs register in a separate section of the same database with adapted field set.
  • Six common mistakes. Missing signature; CE marking not visible; database registration after deployment; incomplete Annex V content; no refresh on substantial modification; weak Article 71 confidentiality claims. Each preventable with a deliberate pre-market review.
  • This is the production-readiness checkpoint. The Annex IV file becomes a marketed product through Article 47 + 48 + 71. Sequence matters. Signatures matter. Visibility matters. Get the three deliverables right and the deployment goes clean.