AI Governance, Risk & Red Teaming
Strategic · M15 · lesson 15 of 25 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Establishing the EU AI Act Conformity Assessment Function
📖
now learning

Establishing the EU AI Act Conformity Assessment Function

15 min

The Acme Inc AI Governance Committee meeting on the second Tuesday of May 2026 ended with one slide on the screen. The CAIO presented it. "Our Annex IV technical documentation file for ServiceAssist v1.0 is nine months old. The ML team built it last August before launch. Since then, the system prompt has changed four times, the retrieval index has been re-indexed twice, the safety filter has been retrained, and the model behind it has been rev'd from Claude Sonnet 4 to Claude Sonnet 4.7. Who owns refreshing the TDF? The ML team built it, but nobody on that team is currently accountable for keeping it current. We have a 250-page regulator-grade artefact that documents a system that no longer exists in production, and no permanent function that owns the refresh." The CRO asked the follow-up that triggered a six-month build. "Who owns Article 47 declarations? Who files the Article 71 registration on the next release? Who runs the Article 72 post-market monitoring? Who calls a notified body if we move into Module H? Who decides whether a system-prompt change is an Article 43(4) substantial modification that triggers re-conformity?" The CAIO answered honestly: "Today, nobody. Each of those tasks has been done at least once, but no permanent function owns any of them as ongoing capabilities. We are operating the EU AI Act on a project basis. It does not scale to August 2 2026, and it definitely does not scale to December 2 2027 when the Omnibus VII grace ends for Annex III." Lesson 077 is the L4 rebuild: the Conformity Assessment Function (CAF), the permanent organisational unit that owns the provider-tier EU AI Act obligations (Articles 11, 17, 43, 47, 71, 72, 73) on an ongoing basis, the 10-section CAF charter, the 8-role staffing model, the 5-quarter implementation roadmap, the 8-KPI dashboard, the eight named interfaces, the four common 2026 CAF failures examiners are citing, and a worked Acme Inc 2026 CAF operating model.

Why a Dedicated Conformity Assessment Function in 2026, and Why It Is Not a Project

The Acme slide is not unique. Across 2026 boardrooms, the same realisation is arriving. The provider-tier obligations are not point-in-time tasks. They are continuous capabilities that require continuous accountable ownership. Five regulatory drivers force the issue in 2026 and through 2027.

Driver 1 - Article 11 + Annex IV TDF refresh. Article 11 requires the provider to draw up and keep up to date the technical documentation set out in Annex IV. The Commission's Q&A guidance is explicit: "keep up to date" is an ongoing obligation triggered by any change that materially affects accuracy. Annex IV §1-§9 covers nine sections from system description through performance metrics through risk-management documentation. A nine-month-old TDF for a system that has changed four times since is presumptively non-compliant.

Driver 2 - Article 47 declaration currency. Article 47 requires the provider to issue a written EU declaration of conformity for each high-risk system and to keep it at the disposal of national competent authorities for ten years after placement on the market. The declaration must remain current: re-issuance is required whenever the referenced harmonised standards, the conformity assessment route, or the system characteristics change. Somebody named must own the trigger and the file.

Driver 3 - Article 71 EU database registration. Article 71 establishes the EU database for high-risk AI systems. Providers must register before placement on the market or putting into service. The Commission's 2025 implementing regulation specifies the data points, the currency obligation, and the requirement to register updated versions. Registration is not a one-time event; it recurs with each materially different version.

Driver 4 - Article 72 post-market monitoring. Article 72 requires the provider to establish and document a post-market monitoring system proportionate to the AI system and its risks, covering performance, robustness, and risk indicators on an ongoing basis, with named actions when monitoring identifies non-compliance or new risks. Post-market monitoring is a permanent operational capability with named owners, weekly cadence, and reporting obligations. A project cannot deliver Article 72; only a permanent function can.

Driver 5 - Article 43(4) substantial modification. Article 43(4) requires the provider to re-perform conformity assessment whenever a high-risk AI system undergoes "substantial modification", a change that affects compliance with the requirements or alters the intended purpose. The 2025-2026 Commission guidance has narrowed the practical meaning: a meaningful change to the system prompt, the retrieval architecture, the safety filter, or the foundation model can trigger substantial modification. The judgement is operational, requires deep knowledge of the system and the Annex IV TDF, and recurs with every release. There is no responsible way to operate this regime without a permanent function whose primary remit is exactly this judgement.

Omnibus VII context, why 2026 is the buildout year. Omnibus VII (December 2024) deferred Annex III high-risk obligations for new systems to December 2 2027 while keeping Article 5 prohibitions, Article 50 transparency, Article 4 literacy, and GPAI obligations on their original timelines. For organisations with Annex III high-risk AI in production or under development, the CAF must be operational well before December 2 2027 for new systems and immediately for grandfathered or accelerated systems. Organisations that defer CAF establishment past Q4 2026 are running out of runway for the 12-18 month capability buildout the function requires.

CAF vs FRIA-owner. The CAF is the provider-tier function. It owns obligations that arise when the organisation places a high-risk AI system on the EU market or puts it into service as a provider. The FRIA owner is the deployer-tier function. It owns Article 27 fundamental rights impact assessments when the organisation uses a high-risk system as a deployer. Many organisations are both provider and deployer; the CAF and FRIA-owner functions interface but do not merge. The obligations and the evidence trails are different.

Bottom line. The CAF is not a project, not a working group, not a virtual team, and not an additional duty assigned to the AI Platform tech lead. It is a permanent organisational unit with named ownership, dedicated headcount, a board-ratified charter, a multi-year budget, defined deliverables, and a place on the org chart with reporting lines that preserve independence. The L4 leader who stands up the CAF in 2026 will not face the "who owns refreshing the TDF" moment at the November 2027 board meeting.

The Ten-Section CAF Charter the L4 Leader Ratifies with the Board

The CAF charter is the board-ratified document that establishes the function, authorises its scope, and defines its operating model. Ten sections cover everything the function needs to defend its existence at examination, certification, and supervisory conversation.

Section 1 - Purpose. A two-paragraph statement of why the CAF exists, anchored in Articles 11, 17, 43, 47, 71, 72, and 73. Names the regulatory drivers, the scope of provider-tier obligations, and the relationship to the AI Governance Committee. Written in language a board director can read once and understand.

Section 2 - Scope. The CAF covers (a) all high-risk AI systems the organisation places on the EU market as provider (Annex III + Annex I product-safety routes), (b) GPAI models the organisation provides if applicable (Article 53 + 55), (c) the Article 17 QMS for AI, (d) Annex IV TDFs for in-scope systems, (e) Article 47 declarations, (f) Article 71 registrations, (g) Article 72 post-market monitoring, (h) Article 43(4) substantial-modification judgement, (i) notified-body engagement for Module H / Annex VII routes (regulated products with AI safety components). Scope explicitly excludes deployer-tier obligations (Article 26, 27 FRIA) owned by the FRIA-owner function with documented interface.

Section 3 - Authority. CAF is granted authority to (a) require Annex IV TDF inputs from any product team building high-risk AI, (b) approve or block placement on the EU market based on conformity-assessment completeness, (c) determine substantial modification under Article 43(4), (d) commission internal or external audits of conformity evidence, (e) engage notified bodies and regulatory counsel, (f) escalate to AIGC and board AI subcommittee. Names the escalation pathway and AIGC/board override authority.

Section 4 - Reporting line. Head of CAF (Chief Conformity Officer or equivalent) reports substantively to the CRO or CAIO, never to the CIO or any 1L delivery executive. The reporting-line independence test is identical to lesson 073's 2L compliance-function test. If CAF reports to the CIO, the function's authority to block placement collapses under delivery pressure. 2026 supervisory expectation is unambiguous: CAF reports to a risk or compliance executive, with dotted line to CIO for operational coordination only.

Section 5 - Staffing model. Eight-role CAF (detailed below) with named owners, headcount, hiring profiles, and external advisory bench. Specifies rotation policy, literacy training cross-walked to lesson 033, and succession planning for Head of CAF and the four critical roles (technical-file, declaration, registration, post-market).

Section 6 - Deliverables. Named artefacts: (a) Annex IV TDF per in-scope system, refreshed quarterly or on substantial modification; (b) Article 47 declarations, currency-checked monthly; (c) Article 71 registrations, coverage-monitored monthly; (d) Article 72 monitoring plans and dashboards, weekly cadence; (e) Article 17 QMS documentation, annual review; (f) substantial-modification logs and decisions; (g) notified-body engagement records (when Module H applies); (h) annual report to AIGC and board AI subcommittee.

Section 7 - Decision rights. CAF holds decision rights over (a) Annex IV TDF approval (sign-off authority), (b) Article 47 declaration sign-off (legally-binding signature), (c) Article 43(4) substantial-modification determination (with appeal to Head of CAF and AIGC), (d) Article 71 registration submission, (e) placement-on-market or service-launch hold authority when conformity is incomplete. Names appeal and override pathways.

Section 8 - Interfaces. Named interfaces to (a) FRIA-owner function (Article 27 deployer-tier handoff), (b) MRM / IMV (lesson 068), (c) red-team (lessons 059-066), (d) AI Risk Office (2L integrating function, lesson 073), (e) internal audit (3L), (f) notified bodies (when applicable), (g) regulatory counsel and external advisory bench, (h) EU AI Office (Article 89 information-request response coordination). Each interface specifies handoff artefacts, cadence, and contested-interface escalation.

Section 9 - Performance metrics. The 8-KPI dashboard (detailed below) plus operating cadence (weekly stand-up, monthly AIGC report-out, quarterly board AI subcommittee briefing, ad-hoc on substantial modification or Article 73 serious incident). Names ISO 42001 certification-body external review and internal-audit assurance cycle.

Section 10 - Review cadence. Charter reviewed and re-ratified annually by board AI subcommittee, with material updates ratified by full board. Amended whenever the regulatory perimeter shifts (Omnibus VII implementation, harmonised standards adoption, AI Office guidance, member-state authority designation). Names responsible-counsel review trigger and documentation-archive obligation.

The Eight-Role CAF Staffing Model and Capability Buildout Plan

A mid-size enterprise CAF for an organisation with one to three high-risk AI systems in production runs at eight FTEs; global GPAI providers scale this to 25-40. The L4 leader treats the staffing model as the operating contract, every Article 11/17/43/47/71/72/73 obligation has a named owner; no obligation is orphaned; no role is doubled up where independence is load-bearing.

Role 1 - Head of CAF (Chief Conformity Officer or equivalent). Accountable owner of the function. Reports to CRO or CAIO. Owns the charter, AIGC and board reporting, budget, external bench, strategic posture, and regulator-facing engagements. Hiring profile: 10-15 years compliance or risk leadership with regulated-product or financial-services background; EU AI Act fluency. Direct reports: roles 2-8.

Role 2 - Annex IV technical-file lead. Accountable owner of every Annex IV TDF in the portfolio. Owns authoring methodology, section-by-section content reviews (Annex IV §1-§9), refresh cadence (quarterly + substantial-modification trigger), linkage from TDF to evaluation evidence and FRIA artefacts. Depth role, deep AI/ML competence plus regulatory writing skill. Hiring profile: senior technical writer or regulatory affairs with ML literacy, or senior ML engineer with regulatory training. Supported by 1-2 TDF authors per in-scope system.

Role 3 - Article 47 declaration owner. Accountable owner of the EU declaration of conformity for each in-scope system. Owns legal currency, harmonised-standards mapping (when adopted), conformity-assessment route (self-assessment Article 43(1)(a) or notified-body Annex VII), and the 10-year declaration archive per Article 47. Hiring profile: regulatory affairs with EU CE-marking experience; legal training a plus.

Role 4 - Article 71 EU database registration owner. Accountable owner of the organisation's posture in the EU database. Owns submissions for each new system, version updates, data accuracy, coordination with Commission database operations, and Article 49 / 71 trade-secret protection of sensitive submissions. Hiring profile: regulatory operations with database/portal-submission experience; familiarity with EU Commission digital services. Often combined with role 3 in mid-size CAFs.

Role 5 - Article 43(4) substantial-modification change-control lead. Accountable owner of the substantial-modification regime. Operates change-control intake from product engineering, applies the criteria from Commission guidance, escalates contested cases to Head of CAF and AIGC, tracks re-conformity work that flows from positive determinations. The gatekeeper between engineering velocity and conformity discipline. Hiring profile: deep AI/ML technical competence with regulatory training, or senior regulatory affairs with deep AI literacy.

Role 6 - Article 72 post-market monitoring lead. Accountable owner of the post-market monitoring system across all in-scope high-risk AI. Owns monitoring plan, dashboard architecture (drift, performance, robustness, complaint, bias, near-miss), weekly review cadence, signal triage, action workflow when signals indicate non-compliance, and Article 73 serious-incident escalation. Hiring profile: ML or data engineering with monitoring/observability experience.

Role 7 - Notified-body liaison (Module H regulated industries only). Accountable owner of the notified-body relationship for AI systems within Annex I product-safety routes (medical devices, automotive, machinery) requiring Annex VII Module H conformity assessment. Owns selection (lesson 078), audit-prep, surveillance audits, findings-closure cycle, and renewal. Many CAFs hold this role latent, only regulated-industry CAFs staff it permanently.

Role 8 - Quality management system (Article 17) lead. Accountable owner of Article 17 QMS documentation, management-review cycle, CAPA workflow, internal-audit programme for the QMS, document-control discipline, and ISO 42001 certification preparation and surveillance. Hiring profile: ISO management-system experience (ISO 9001, 27001, 13485) plus AI literacy.

Capability buildout plan. Five components. (a) Skills assessment, gap analysis between current capability and the eight-role profile. (b) Hiring sequence, Head of CAF first (Q1); technical-file lead (early Q2); post-market monitoring and substantial-modification leads (Q2-Q3); declaration owner and registration owner (Q3); QMS lead and notified-body liaison (Q3-Q4); 3-6 month time-to-fill per role. (c) Training programme: Article 4 literacy plus role-specific deep training cross-walked to lesson 033; EU AI Act article-by-article walk-throughs, Annex IV TDF authoring workshops, conformity-assessment route training, ISO 42001 awareness. (d) External advisory bench: pre-cleared regulatory counsel, notified bodies, consulting firms with conformity-assessment experience, academic experts; established Q1 alongside Head of CAF hire; annual relationship reviews. (e) Tooling stand-up: document-management for TDF library, version-control for declarations, change-management for substantial-modification regime, monitoring/observability stack for Article 72, GRC platform integration connecting CAF to AI Risk Office, internal audit, and AIGC.

The Five-Quarter CAF Implementation Roadmap and Operating Cadence

The L4 leader who ratifies the CAF charter in Q1 2026 runs a five-quarter implementation roadmap that takes the function from chartered to fully operational by Q1 2027, in time for the December 2 2027 Omnibus VII Annex III deadline and well before substantial-modification cycles begin to accumulate.

Q1 2026 - Charter, foundational staffing, tooling. Board AI subcommittee ratifies CAF charter. Head of CAF hired and onboarded. Technical-file lead hire initiated. External advisory bench (regulatory counsel, notified-body shortlist) established. Document-management system provisioned. AI Risk Office handoff defined. AIGC reporting cadence agreed. Q1 deliverable: signed charter, staffed Head of CAF, tooling provisioned, scope inventory of in-scope high-risk AI systems completed.

Q2 2026 - First complete Annex IV TDF + first Article 47 declaration. Technical-file lead onboarded. First end-to-end Annex IV TDF authored for the most consequential in-scope system (Acme.ServiceAssist v1.0). Section-by-section against Annex IV §1-§9. Source-evidence trail established with linkages to evaluation reports, red-team findings, FRIA artefacts, model and system cards. Declaration owner hired late Q2. First Article 47 declaration drafted, legal-reviewed, signed. Q2 deliverable: TDF v1 + declaration v1; TDF authoring playbook documented.

Q3 2026 - First Article 71 registration + Article 72 dashboard live. Registration owner hired. EU database registration submitted for the Q2 system. Post-market monitoring lead hired. Article 72 plan documented; dashboard stood up with drift, performance, robustness, complaint, bias, near-miss panels. Weekly review cadence initiated. Substantial-modification change-control lead hired late Q3. Q3 deliverable: registered system in EU database; live post-market monitoring dashboard with two months of operating data.

Q4 2026 - Surveillance posture, ISO 42001 prep. QMS lead hired. Article 17 QMS documentation completed and approved by Head of CAF and AIGC. Internal audit (3L) performs assurance review of CAF operations; remediation tracked. ISO 42001 certification body engaged for stage-1 readiness assessment (lesson 075). Notified-body liaison hired if Module H in scope. Substantial-modification regime stress-tested with one full cycle. Q4 deliverable: ISO 42001 stage-1 readiness; audit findings closed; substantial-modification regime exercised.

Q1 2027 - First substantial-modification cycle + ISO 42001 certification. First real substantial-modification cycle navigated end-to-end: change identified, criteria applied, decision logged, re-conformity executed, TDF refreshed, declaration re-issued, registration updated, monitoring plan amended. ISO 42001 certification audit completed; certificate issued. CAF reports first full-year KPI performance to board AI subcommittee. Q1 2027 deliverable: ISO 42001 certificate; first substantial-modification cycle evidence package; first annual board report.

The CAF operating cadence (steady-state from Q1 2027 onward). Five cadences run continuously. (a) Weekly internal stand-up: Head of CAF plus role leads, 60-minute Tuesday meeting, agenda covers TDF refresh status, declaration currency, registration coverage, post-market signals open/closed, substantial-modification pipeline, notified-body matters, ISO 42001 surveillance status. (b) Monthly AIGC report-out: 30-minute slot at the AI Governance Committee, KPI dashboard reviewed, escalations logged, decisions sought on substantial-modification edge cases and resource asks. (c) Quarterly board AI subcommittee briefing: 60-90 minute deep-dive with the board AI subcommittee, KPI trends reviewed, regulatory landscape update, material risks and incidents discussed, strategic posture confirmed. (d) Ad-hoc on substantial modification (Article 43(4)), the substantial-modification change-control lead convenes a focused review within 5 business days of a candidate change identification, with decision and re-conformity-work scoping completed within 15 business days. (e) Ad-hoc on serious incident (Article 73): the post-market monitoring lead and Head of CAF coordinate the Article 73 notification (15-day clock for serious incidents) with the AI Incident Response Policy owner (lesson 025), legal counsel, and external regulatory advisors.

The Eight-KPI CAF Dashboard and the Interface Architecture

What does not get measured does not get governed. The L4 leader publishes an 8-KPI dashboard for the CAF that the AIGC and the board AI subcommittee track at every cadence point. Each KPI maps to a specific Article obligation and has a defined target, a definition, and an escalation threshold.

KPI 1 - TDF refresh latency. The maximum age of any Annex IV technical documentation file in the in-scope portfolio, measured in days since last full review. Target: <= 90 days. Escalation threshold: > 120 days triggers AIGC notification; > 180 days triggers board AI subcommittee notification. Maps to Article 11. The Acme Inc 9-month TDF that triggered the rebuild would have scored 273 days, multiple escalation thresholds breached.

KPI 2 - Declaration-currency rate. The percentage of in-scope systems whose Article 47 declaration of conformity reflects the current production state (no material drift between declaration and production system, verified by quarterly review). Target: >= 95%. Escalation: < 90% triggers AIGC. Maps to Article 47.

KPI 3 - Article 71 registration coverage. The percentage of in-scope high-risk AI systems that are currently registered in the EU database with current data. Target: 100% (no system goes to market or service without registration). Escalation: any non-coverage gap triggers immediate Head of CAF action. Maps to Article 71.

KPI 4 - Substantial-modification cycle time. The median number of business days from identification of a candidate substantial modification under Article 43(4) to completion of the re-conformity work and re-issuance of dependent artefacts (Annex IV TDF refresh, Article 47 declaration re-issuance, Article 71 registration update). Target: <= 30 business days for self-assessment route; <= 90 business days for notified-body route. Escalation: 1.5x target triggers AIGC. Maps to Article 43(4).

KPI 5 - Article 72 post-market signals open/closed. The count of open monitoring signals (drift exceedance, performance degradation, robustness failure, complaint, bias indicator, near-miss) versus closed within target SLA. Target: 100% of signals triaged within 5 business days; 100% of severity-1 signals closed within 30 business days. Escalation: any aged severity-1 triggers AIGC. Maps to Article 72.

KPI 6 - Notified-body finding closure rate. The percentage of notified-body audit findings closed within agreed remediation timelines. Target: 100% within agreed window. Escalation: any overrun triggers AIGC and Head of CAF response plan. Maps to Annex VII Module H (when applicable). Lesson 078 covers the engagement playbook.

KPI 7 - ISO 42001 surveillance preparedness score. The CAF's self-assessed readiness score against the ISO 42001 Annex A controls (A.3 leadership, A.4 organisational structure, A.5 policy, A.6 resources, A.10 system lifecycle), expressed as a percentage of controls with current evidence at audit-ready quality. Target: >= 90%. Escalation: < 80% triggers AIGC. Maps to ISO 42001 certification posture (lesson 075).

KPI 8 - Article 73 serious-incident reporting timeliness. The percentage of serious incidents (per Article 3 definition) reported to the relevant market surveillance authority within the Article 73 timeline (15 days for serious incidents; 2 days for malfunctions causing serious harm; 10 days for serious and widespread infringements). Target: 100%. Escalation: any late report triggers board AI subcommittee notification and lessons-learned review. Maps to Article 73 (lesson 025 covers the incident response policy).

Interface architecture, eight named interfaces operationalised in procedures. (a) FRIA-owner: when Acme is provider and deployer, the FRIA owner consumes the Annex IV TDF as FRIA input, and the CAF receives FRIA findings into the post-market monitoring plan. Quarterly joint review. (b) MRM / IMV (lesson 068), CAF consumes MRM validation reports as primary evidence in Annex IV §6 (performance) and §7 (risk management). Per-cycle handoff. (c) Red-team (lessons 059-066), CAF consumes red-team reports as Annex IV §6/§7 evidence for robustness and security. Per-engagement handoff. (d) AI Risk Office (lesson 073, 2L), CAF reports KPIs into the consolidated view and consumes AI Risk Office register entries as triggers. Weekly signal exchange. (e) Internal audit (3L), assurance over the CAF's operation (framework, not model evaluations); annual engagement plus issue-driven. (f) Notified body (when applicable), liaison manages relationship; surveillance-audit cycles on body's schedule. (g) Regulatory counsel and external bench: ad-hoc on interpretive questions, substantial-modification edge cases, Article 89 information-request responses, serious-incident communications. (h) EU AI Office (Article 89), Head of CAF coordinates response to information requests from AI Office and national competent authorities; process documented in Article 17 QMS.

Common 2026 CAF Failures and the Acme Inc Worked Operating Model

The 2026 supervisory conversations and the early ISO 42001 certification audits have surfaced four recurring CAF failure modes. The L4 leader designs the function with explicit controls for each.

Failure 1 - Treating CAF as a project. The most common 2026 failure. An organisation launches a "conformity assessment project" with a six-month timeline, delivers the initial artefacts (TDF, declaration, registration), declares victory, and disbands the team. Six months later the TDF is stale, the declaration is misaligned with production, no one is monitoring Article 72 signals, and the substantial-modification regime is operating informally if at all. The remedy: charter the CAF as a permanent function from day one; fund it on a multi-year budget; staff it with named headcount; report on it permanently at the AIGC and board AI subcommittee.

Failure 2 - Reporting to the CIO. The second most common failure. The CAF reports to the CIO because "AI lives in IT." The CIO is the 1L delivery executive for AI; reporting compliance and conformity to delivery is the classic 2L breach (lesson 073). Under release-cycle pressure, the CAF cannot block a launch when conformity is incomplete. The remedy: the Head of CAF reports substantively to the CRO or CAIO, with a dotted line to the CIO for operational coordination only. The substantive reporting line carries the independence weight.

Failure 3 - No notified-body bench established before first substantial modification. An organisation in a regulated industry (medical devices, automotive, machinery) does not establish a notified-body relationship until a substantial modification or new high-risk launch triggers the need. Notified bodies have lead times of 6-18 months for new engagements; an organisation that begins searching when it needs the audit is going to miss its launch window. The remedy: notified-body selection and onboarding is a Q1-Q2 CAF deliverable for any organisation with regulated-industry exposure, regardless of whether a Module H route is currently active. Lesson 078 covers the engagement playbook.

Failure 4 - Article 71 registration treated as a one-time event. An organisation registers a system in the EU database at launch and never updates the registration as the system evolves. The registration's currency obligation under Article 71 + the implementing regulation is recurring; each version of the system that materially differs requires an updated registration. The remedy: the Article 71 registration owner runs a monthly currency check across the registered portfolio, mapped to release cadence; the substantial-modification change-control lead notifies the registration owner whenever a determination triggers re-registration.

Acme Inc 2026 CAF, worked operating model. The rebuild that followed the May 2026 AIGC meeting produced the structure below.

Reporting line. Head of CAF reports substantively to the Chief AI Officer (CAIO), with a dotted line to the Chief Risk Officer (CRO) for risk-integration. The CAIO reports to the CEO. The CAF is part of the 2L AI Risk Office structurally but operates as a distinct unit with its own charter, budget, and headcount.

Staffing. 8 FTEs across the eight roles. Head of CAF (SVP-level, hired in Q1 2026). Annex IV technical-file lead (Director-level, hired early Q2 2026, supported by 1 technical-file author). Article 47 declaration owner (Senior Manager, hired late Q2 2026, role combined with Article 71 registration owner). Article 43(4) substantial-modification change-control lead (Director, hired late Q3 2026). Article 72 post-market monitoring lead (Director, hired Q3 2026, supported by 1 monitoring engineer). Article 17 QMS lead (Senior Manager, hired Q4 2026). Notified-body liaison not staffed permanently, Acme is not currently in a Module H route; the role is held latent in the charter with a 6-month activation pathway if a regulated-industry expansion is approved.

Q1-Q4 2026 milestones executed. Q1: charter ratified at board AI subcommittee on 14 May 2026; Head of CAF onboarded by 1 June 2026; tooling provisioned by 30 June. Q2: Annex IV TDF v1 for Acme.ServiceAssist v1.0 completed by 15 August 2026; Article 47 declaration v1 signed by Head of CAF on 25 August 2026. Q3: Article 71 EU database registration for ServiceAssist completed on 12 October 2026; Article 72 post-market monitoring dashboard live on 5 November 2026 with daily drift, weekly performance, monthly fairness reviews. Q4: ISO 42001 stage-1 readiness completed in December 2026; substantial-modification regime stress-tested in a tabletop exercise using a hypothetical retrieval-architecture change to ServiceAssist; internal audit (3L) performs assurance review of CAF in January 2027.

KPI baseline at year-end 2026. TDF refresh latency: 38 days (target <= 90; on track). Declaration-currency rate: 100% (only one in-scope system). Article 71 registration coverage: 100%. Substantial-modification cycle time: not yet measured (no real cycle completed). Article 72 post-market signals open/closed: 4 signals raised, all closed within SLA, 0 severity-1. Notified-body findings: N/A. ISO 42001 surveillance preparedness: 78% (improvement plan in place targeting 90% by audit). Article 73 serious-incident reporting timeliness: 100% (1 minor incident reported on day 9 of the 15-day clock).

Regulatory cross-walk. The Acme CAF operating model satisfies multiple frameworks. EU AI Act: Article 11 (TDF), Annex IV technical-file lead; Article 17 (QMS), Article 17 QMS lead and Head of CAF; Article 25 (responsibilities along the value chain), interface with vendor management; Article 43 (conformity assessment), Head of CAF as accountable owner; Article 43(4) (substantial modification), change-control lead; Article 47 (declaration of conformity), declaration owner; Article 50 (transparency), interfaces with the product team; Article 71 (EU database), registration owner; Article 72 (post-market monitoring), monitoring lead; Article 73 (serious incident reporting), monitoring lead coordinating with AI Incident Response Policy owner. NIST AI RMF: Govern 1.1 (organisational policies), Article 17 QMS; Govern 1.5 (ongoing monitoring), Article 72 process; Govern 2.1 (roles), eight-role staffing; Govern 3.1 (workforce competence), capability buildout; Govern 4.1 (organisational commitment), board ratification; Govern 5.1 (legal compliance), Head of CAF authority; Map 1 (context), TDF §1-§3; Map 2 (categorisation), Annex III tier mapping; Map 5 (impacts), FRIA interface; Manage 1.1 (prioritising risks), post-market signal triage; Manage 1.3 (responding), change-control workflow; Manage 2.1 (mitigating risks), re-conformity work; Manage 4.3 (continuous improvement), annual charter review. ISO 42001: A.3 (leadership), Head of CAF and CAIO; A.4 (organisational structure), eight-role design and reporting lines; A.5 (policy), Article 17 QMS documentation; A.6 (resources), multi-year budget; A.10 (system lifecycle), Article 11/43/47/71/72 lifecycle coverage. SR 11-7: governance pillar: board accountability, named ownership, documented authorities, written framework.

Penalty exposure. The CAF is the function that prevents the penalty events. Article 99(3) EUR 15M / 3% of worldwide annual turnover applies to failures of Article 11 (TDF), Article 17 (QMS), Article 26 (deployer obligations, when Acme is also a deployer), Article 43 (conformity assessment), Article 47 (declaration of conformity), Article 71 (database registration), and Article 72 (post-market monitoring). Article 99(4) EUR 15M / 3% applies to operator and notified-body specific failures (when Acme is operating under notified-body assessment). Article 99(5) EUR 7.5M / 1% applies to misleading or incomplete information supplied to the Article 71 EU database or to market surveillance authorities under Article 89 information requests. The L4 leader who stands up the CAF in 2026 with the operating model above has positioned the organisation to defend against each penalty tier with documented evidence of compliance capability and continuous operation. The leader who deferred, who is still discovering the orphaned TDF at the November 2027 board meeting, is positioned for Article 99(3) at first instance and Article 99(5) at second instance if the deficient artefacts make it into a regulatory submission.

Key Takeaways

  • The Conformity Assessment Function is a permanent organisational unit, not a project. EU AI Act Articles 11, 17, 43, 47, 71, 72, and 73 each impose continuous capability requirements; the CAF is the named function that owns each obligation on an ongoing basis. By contrast, the FRIA-owner function (Article 27) owns deployer-tier obligations. Many organisations are both provider and deployer; both functions exist with documented interface.
  • The 10-section CAF charter covers purpose, scope, authority, reporting line (to CRO or CAIO, never to CIO), staffing model, deliverables, decision rights, interfaces, performance metrics, and review cadence. The charter is ratified at board AI subcommittee level annually with material updates ratified by the full board.
  • The 8-role CAF staffing model for a typical mid-size enterprise: Head of CAF; Annex IV technical-file lead; Article 47 declaration owner; Article 71 EU database registration owner; Article 43(4) substantial-modification change-control lead; Article 72 post-market monitoring lead; Notified-body liaison (Module H regulated industries only); Article 17 QMS lead. Global GPAI providers scale to 25-40 FTE; minimum viable CAF is 4-5 with double-hatting.
  • The 5-quarter implementation roadmap: Q1 charter ratification + staffing + tooling stand-up; Q2 first complete Annex IV TDF + Article 47 declaration; Q3 first Article 71 registration + Article 72 post-market dashboard live; Q4 surveillance posture + ISO 42001 stage-1 readiness; Q1 of year 2 first substantial-modification cycle navigated end-to-end + ISO 42001 certification audit.
  • The CAF operating cadence: weekly internal stand-up; monthly AIGC report-out; quarterly board AI subcommittee briefing; ad-hoc on substantial modification (Article 43(4), within 5 business days of identification) or serious incident (Article 73, 15-day clock for serious incidents).
  • The 8-KPI CAF dashboard: TDF refresh latency (<= 90 days); declaration-currency rate (>= 95%); Article 71 registration coverage (100%); substantial-modification cycle time (<= 30 / 90 business days); Article 72 post-market signals open/closed within SLA; notified-body finding closure rate (100% within window); ISO 42001 surveillance preparedness score (>= 90%); Article 73 incident reporting timeliness (100%).
  • Eight named interfaces: FRIA-owner (deployer-tier handoff), MRM/IMV (validation evidence into TDF), red-team (adversarial evidence into TDF), AI Risk Office (2L integration), internal audit (3L assurance), notified body (when applicable), regulatory counsel and external advisory bench, EU AI Office (Article 89 information requests). Each interface has named artefacts, cadence, and escalation pathway.
  • Four common 2026 CAF failures: (1) treating CAF as a project rather than permanent function; (2) reporting to CIO rather than CRO/CAIO (independence breach); (3) no notified-body bench established before first substantial modification (6-18 month lead times); (4) Article 71 registration treated as one-time event rather than recurring with each version.
  • The Acme Inc 2026 CAF worked example: 8-FTE structure with Head of CAF reporting to CAIO with dotted line to CRO; Q1 charter ratification; Q2 Annex IV TDF v1 + Article 47 declaration v1 for Acme.ServiceAssist v1.0; Q3 Article 71 registration + Article 72 dashboard live; Q4 ISO 42001 stage-1 readiness + tabletop substantial-modification exercise; first full year KPI baseline established with TDF refresh latency at 38 days against 90-day target.
  • One operating model satisfies multiple frameworks. EU AI Act Articles 11, 17, 25, 26, 27, 43, 47, 50, 71, 72, 73 + Annex IV §1-§9 + Annex VII Module H + NIST AI RMF Govern 1.1/1.5/2.1/3.1/4.1/5.1, Map 1/2/5, Manage 1.1/1.3/2.1/4.3 + ISO 42001 A.3/A.4/A.5/A.6/A.10 + SR 11-7 governance pillar. Article 99(3) EUR 15M / 3% exposure for Article 11 + 17 + 26 + 43 + 47 + 71 + 72 failures; Article 99(4) EUR 15M / 3% for notified-body specific; Article 99(5) EUR 7.5M / 1% for misleading information to the Article 71 database or Article 89 information requests.