AI Governance, Risk & Red Teaming
Visionary · M11 · lesson 11 of 14 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Signing the Article 47 Declaration of Conformity - Personal Accountability
📖
now learning

Signing the Article 47 Declaration of Conformity - Personal Accountability

15 min

It is a Tuesday morning in May 2026. Maya Okafor, Chief AI Risk Officer at Acme, is alone at her desk with the Article 47 EU declaration of conformity for ServiceAssist v1.0 printed in front of her. The Annex IV technical documentation file is closed in a binder to her left. A printed eight-question checklist sits to her right. The pen is uncapped. Thirty minutes pass and the pen does not move. The document is two pages long. The load-bearing sentence, "Acme declares that the high-risk AI system ServiceAssist v1.0 conforms to the requirements of Chapter III Section 2 of Regulation (EU) 2024/1689", sits above a blank signature line, a printed "Maya Okafor, Chief AI Risk Officer," a date, and a place. The legal weight of those three lines is materially heavier than Maya expected when the role was offered. The signature she is about to put down is personal. It survives her tenure at Acme. It is retained for ten years under Article 18. It is the document a market surveillance authority will pull first if ServiceAssist ever appears in an Article 73 incident. It is the document a class-action plaintiff's counsel will pull first in discovery. It is the document the Commission's AI Office will pull first if Article 99(5) misleading-information proceedings are ever opened against Acme. Maya picks up the eight-question checklist and walks through it one item at a time. This lesson is what she walks through, why each question matters, what the signature commits her to, how the "I-don't-have-confidence" escalation path works, and what changes the first time ServiceAssist undergoes a substantial modification.

Article 47 + Article 18 - What the Signature Is and How Long It Lives

Article 47 of Regulation (EU) 2024/1689, the EU AI Act, requires the provider of a high-risk AI system to draw up a written EU declaration of conformity. The declaration is the legal instrument by which the provider states, on the record, that the high-risk AI system in scope conforms with the design, data, transparency, oversight, accuracy, robustness, and cybersecurity requirements set out in Articles 8 through 15. The declaration is signed by a natural person on behalf of the provider. The declaration is retained for ten years from the date the system is placed on the market or put into service per Article 18, alongside the Annex IV technical documentation file that it references. The signed declaration is incorporated as Annex IV §8 of the technical file. CE marking under Article 48 cannot be affixed until the declaration is signed. Article 71 EU database registration cannot reference a declaration that does not exist. The signing moment is the chokepoint where the entire Annex IV file becomes a marketed product.

Article 47(2) prescribes the required content of the declaration with precision. Eight numbered items must appear: (1) the name and address of the provider, including the authorized representative under Article 22 where the provider is established outside the Union; (2) the unambiguous identification of the AI system: name, type or model designation, version, unique identifier; (3) an explicit statement that the system conforms with the EU AI Act and, where applicable, with other Union legislation requiring an EU declaration of conformity; (4) references to the harmonized standards under Article 40 that have been applied, or, where no harmonized standard has been published, references to the common specifications under Article 41 or to other technical solutions adopted to satisfy the requirements; (5) where applicable, the identity and identification number of the notified body that performed the conformity assessment under Annex VII, together with the certificate number; (6) the date the declaration was signed; (7) the place where the declaration was signed; (8) the signature of the natural person authorized to act on behalf of the provider, together with the printed name and role title. Each field is non-negotiable. A declaration missing any item is defective and exposes the provider to Article 99(3) at €15M / 3% of global turnover for an absent valid declaration, compounded by Article 99(5) at €7.5M / 1% if the missing field constitutes misleading information.

The signing is by a natural person: not by the provider as an entity, not by a department, not by a stamp. A single named individual, identified by role with a date and a place, assumes accountability that survives organizational change. If Maya signs today and leaves Acme in 2027, the declaration remains valid on her signature; supervisory authorities still trace findings back to her name; the Article 18 retention keeps her name in the record until 2036 at the earliest. The signature carries weight even after the employment relationship has ended.

Article 18 retention sits at the back of the signing moment. The declaration is retained for ten years from the date the system ceases to be made available on the market. The retention applies to the declaration itself and to the underlying Annex IV technical documentation file. National market surveillance authorities, the Commission, the AI Office, and notified bodies may request the declaration and the technical file at any point during the retention window. Within statutory response time (typically 15 days, varying by Member State), the provider must produce the signed declaration and the supporting Annex IV evidence. The retention obligation is the reason the signing officer's identity must remain traceable, through HR records, board minutes, AIMS evidence vault entries, for the full ten-year window. The signing is not a moment in time; it is a ten-year commitment to remain identifiable as the person who attested to conformity.

The Eight-Question Check Before the Pen Touches the Page

The CAIRO who signs without walking the eight-question check is rubber-stamping. Rubber-stamping is what surfaces as personal liability when the declaration turns out to be defective. The 2026 L5 practice is a written, retained, named-evidence checklist that the signer completes before the signature goes on the page. Each question has a single binary answer: YES, with named evidence pointer in the AIMS evidence vault, or NO. A single NO halts the signing. Maya's checklist below is the Acme reference pattern; it is the same pattern that every CAIRO signing under Article 47 should adopt before any high-risk system declaration is finalized.

  1. Is the Annex IV technical documentation file current and complete? All nine Annex IV sections present, internally reviewed, signed off by ML Engineering / AI Officer / CAIRO. The Annex IV §6 lifecycle-changes section reflects the pre-determined-change carve-out under Article 43(4). Annex IV §8 is reserved for the Article 47 declaration about to be inserted. (Cross-reference lesson 050 - Building the Annex IV Technical Documentation File.) Evidence pointer: AIMS/TDF/ServiceAssist/v1.0/index.md, last reviewed 2026-05-08 by Maya Okafor.
  2. Has the Article 9 risk-management process been executed? Risk identification, risk analysis, risk evaluation, and risk-mitigation measures documented for the full lifecycle. Residual risks acknowledged and accepted at the appropriate level of governance. The risk-management documentation is current, not last year's snapshot. Evidence pointer: AIMS/RM/ServiceAssist/v1.0/risk-register.xlsx + AIMS/RM/ServiceAssist/v1.0/residual-risk-acceptance-2026-05-06.pdf signed by AIGC.
  3. Is the Article 10 data-governance evidence current? Training, validation, and test data sets meet quality criteria. Data preparation processing, including labelling and cleaning, is documented. Bias examination is performed and documented. Article 10(5) special-categories-data justification is retained where applicable. Data provenance is traceable for the full training corpus. Evidence pointer: AIMS/DG/ServiceAssist/v1.0/data-governance-report.pdf + datasheets-for-datasets entries per corpus.
  4. Has the Article 14 human-oversight design been verified? The system is designed and developed to enable human oversight by natural persons during use. The oversight measures are commensurate with the risks. Output interpretation aids, the ability to disregard, override, or reverse outputs, and the stop / kill-switch capability are documented and tested. Evidence pointer: AIMS/HO/ServiceAssist/v1.0/oversight-design.md + UAT test results 2026-04-22.
  5. Are the Article 15 accuracy, robustness, and cybersecurity claims supported? Accuracy metrics declared in the instructions for use are supported by validation evidence. Robustness against errors, faults, and inconsistencies is demonstrated. Cybersecurity measures appropriate to the threat surface are in place, OWASP LLM Top 10 + MITRE ATLAS adversarial testing evidence retained. Article 15(4) feedback-loop hardening is documented. Evidence pointer: AIMS/Acc-Rob-Sec/ServiceAssist/v1.0/article-15-evidence-pack.pdf.
  6. Is the Article 17 quality management system in place and audited? The QMS is documented in writing through written policies, procedures, and instructions. Conformity assessment procedures, data management procedures, post-market monitoring procedures, and incident reporting procedures are operative. ISO/IEC 42001:2023 Stage 2 certification is current as parallel evidence. Internal audit completed within the last twelve months. Evidence pointer: AIMS/QMS/index.md + ISO 42001 certificate 42001-Acme-2025-001 valid through 2028-07-15.
  7. Has the Article 27 FRIA been filed? For high-risk systems falling within the Article 27 scope (deployers of Annex III systems, public-body deployers, certain financial-sector deployers), the fundamental rights impact assessment has been completed, notified to the national supervisory authority where required, and the FRIA output has been integrated into system design. (Cross-reference lessons 044-048.) Where Acme is the provider and the deployer-side FRIA is separate, evidence of provider-side FRIA support and instructions-for-use coverage is retained. Evidence pointer: AIMS/FRIA/ServiceAssist/v1.0/fria-2026-04-30.pdf + Article 49(2) notification log entry.
  8. Is the CE marking affixed correctly and is the Article 71 registration current? CE marking is integrated into the system's user interface per Article 48(5): visible, legible, accessible from every screen. Notified body identification number is adjacent where Annex VII Module H applied (not applicable to ServiceAssist - Annex VI internal control). Provider identification is adjacent. Article 71 EU database registration is complete with the Annex VIII nine-field information set; Article 78 confidentiality designation is field-by-field and Legal-signed; registration identifier is captured into Annex IV §1. Evidence pointer: AIMS/CE-71/ServiceAssist/v1.0/ce-mark-screenshots.zip + EU-DB-Reg-2026-05-10-ServiceAssist-v1.0.pdf.

Each question is answerable as YES only if the named evidence pointer exists, has been reviewed by the CAIRO personally (not delegated), and is producible to a regulator within fifteen days. A YES without named evidence is operationally a NO, the signer is answering from memory rather than documentation, and the signature is rubber-stamping. The checklist itself is retained alongside the declaration in the AIMS evidence vault as part of the signing-due-diligence record.

Signer Identity - Who Signs, Who Authorizes, and the Article 22 Overlay

The Article 47 declaration is signed by a natural person on behalf of the provider. Who that person is, and how their signing authority is established and recorded, is one of the operationally underspecified questions of the EU AI Act. The Regulation leaves the internal-governance choice to the provider. The practical patterns that have emerged across first-wave 2026-2027 deployments are converging on a small set of standard models.

Standard Signing Patterns in 2026 Practice

  • Chief AI Risk Officer (CAIRO). The most common signing role for organizations that have established a dedicated AI risk function. The CAIRO has the authority, the evidence access, and the technical literacy to walk the eight-question check personally. The CAIRO signs against a board-approved AI risk policy and reports to the board AI subcommittee. This is Acme's chosen pattern for ServiceAssist.
  • Chief AI Officer (CAIO). Where the AI function is consolidated under a single executive with both build-side and risk-side authority, the CAIO signs. The pattern is more common in technology providers whose primary product is AI. The CAIO carries higher conflict-of-interest exposure because the same role that builds the system attests to its conformity; mitigations include independent risk review and AIGC challenge before signing.
  • Chief Executive Officer. For smaller providers or for systems judged sufficiently high-impact that the board wants the CEO's name on the page, the CEO signs. The pattern is most personally consequential, CEO personal accountability cascades into D&O coverage discussions and proxy-statement disclosures.
  • General Counsel. Where Legal is the natural keeper of regulatory filings and the GC has been authorized to sign on the provider's behalf for regulatory instruments generally, the GC signs. The pattern requires the GC to acquire AI-specific literacy to walk the eight-question check meaningfully, pure legal-formalism signing without substantive technical understanding is the rubber-stamp failure mode.
  • Authorized representative under Article 22 (for non-EU providers). Where the provider is established outside the Union, Article 22 mandates the appointment of an EU-established authorized representative. The authorized representative carries the signing authority for the EU declaration of conformity. The mandate must be documented in writing, registered with the relevant national authority, and operationally enable the representative to receive correspondence on behalf of the provider. The authorized representative's name and address appear in declaration field 1 alongside the provider's; the signature in field 8 is the representative's.

Board-Resolution Authorization

The 2026 governance pattern in larger organizations is to require board-resolution authorization before the CAIRO signs the Article 47 declaration. The board (or board AI subcommittee) passes a resolution naming the authorized person, scoping the system categories the authorization covers, setting the appointment duration, naming a back-up officer for incapacity, confirming D&O coverage, and recording the personal-accountability acknowledgement. The resolution is retained alongside the declaration. Three operational reasons: it documents that signing authority was conferred deliberately and at the board level (defending against any later claim that the signer acted outside their authority); it surfaces the personal-accountability conversation between the prospective signer and the board (eyes-open signing); it triggers the D&O coverage review that becomes critical if signing-related liability ever surfaces. Boards that adopt the pattern refresh the resolution annually and on any change of signing officer; the resolution is read into the minutes and retained in the AIMS evidence vault. Acme's board AI subcommittee passed the resolution naming Maya Okafor as authorized person for high-risk AI declarations in the November 2025 board cycle.

Ambiguous Internal Authority - A Failure Mode

One of the recurring 2026 failures is ambiguous internal authority. Multiple executives believe they have the authority to sign. No board resolution is on file. The CAIRO drafts the declaration; the General Counsel countersigns; the CAIO signs separately on a different copy for a different deployment. A regulator inquiry surfaces the inconsistency, the declaration's validity becomes contestable, and the signing officer's accountability becomes diffused across multiple individuals: which, in practice, often means no individual carries it cleanly. The remediation is the board-resolution pattern, a single named primary signer per system category, and a documented back-up succession that activates only on the primary's incapacity. The clarity is operationally important precisely because the personal accountability is real.

Liability Landscape + the "I-Don't-Have-Confidence" Escalation Path

The signing officer's liability landscape combines four overlapping exposures. The first is administrative, Article 99(3) at €15M / 3% of global turnover for the underlying conformity failure where the system on the market does not in fact conform. The second is misleading-information, Article 99(5) at €7.5M / 1% where the declaration itself contains false or misleading statements. The third is personal: under several Member-State implementing laws (Germany, France, Italy among them), the signing officer can be named in administrative proceedings and in some cases in criminal proceedings for false attestation. The fourth is class-action and discovery, the signed declaration is the document plaintiff's counsel pulls first in product-liability or discrimination class-action discovery; the signer's name appears on the record and the signer can be deposed.

The cascading nature of the exposure matters. A signing officer who walks the eight-question check rigorously, retains the named-evidence checklist, and signs in good faith on the basis of documented evidence has a strong defense even if a downstream failure later surfaces, the signer attested to what the evidence at the time supported, not to a future state. A signing officer who rubber-stamped without the check has no comparable defense, the absence of the check is itself the evidence of the failure to exercise reasonable care. The eight-question check is not bureaucracy; it is the affirmative-defense file the signer's counsel will rely on if the signature ever comes under challenge.

The Escalation Path When a Question Answers NO

The signer's most important power is the power to refuse to sign. The L5 governance design assumes this power, builds the escalation path that supports it, and treats the refusal as an operationally normal outcome rather than as a career-ending event. The escalation path that Acme has formalized, and that should be the 2026 reference pattern, runs as follows.

  • Step 1: The signer halts the signing moment. Any NO answer to any of the eight questions halts the signing. The pen does not touch the page. The draft declaration is set aside.
  • Step 2: Written escalation memo to AIGC and to the board AI subcommittee. The signer drafts a short memo (one to two pages) identifying which question or questions answered NO, what evidence was missing or insufficient, what remediation is required, and a recommended remediation timeline. The memo is dated and signed by the prospective signer. Copies go to the AI Governance Committee chair and to the board AI subcommittee chair.
  • Step 3: AIGC review and remediation tasking. The AIGC reviews the memo at its next scheduled meeting (or at an ad-hoc session if urgency warrants). The AIGC either confirms the gap and tasks remediation, or, if the AIGC believes the signer's gap analysis is in error, surfaces the disagreement to the board for resolution. The AIGC cannot override the signer's refusal to sign; only the signer carries the personal accountability, and only the signer can attest.
  • Step 4: Remediation tracked in the AIMS evidence vault. The remediation tasks are logged, owners assigned, evidence pointers updated as remediation completes. The deployment is held, the system is not placed on the market or put into service, until the gaps are closed.
  • Step 5: Re-walk the eight-question check after remediation. Once remediation evidence is in the AIMS vault, the signer re-walks the full eight-question check. If all eight now answer YES with named evidence, the signing proceeds. If any still answers NO, the cycle restarts.
  • Step 6: Documented refusal record. If the signer ultimately determines that the system cannot be brought to a state where the eight-question check can be completed honestly, the refusal is documented as a formal decision. The system is not signed; deployment does not proceed. The refusal record is retained in the AIMS vault as part of the governance audit trail.

The escalation path's existence is what makes the signer's accountability operationally workable. Without it, the signer is choosing between two unacceptable outcomes, sign in bad faith or veto a deployment the entire organization is depending on. With the escalation path, the signer is choosing between signing with named evidence and triggering a documented remediation cycle that the organization expects and supports. The L5 board's role is to make clear, before any signing moment, that the refusal pathway is a sanctioned governance outcome and that the signer who escalates is acting in the organization's interest, not against it.

Post-Signing Maintenance and the Substantial-Modification Re-Signing Trigger

Signing the declaration is not the end of the obligation; it is the start of a maintenance cycle. The signed declaration attests to conformity at the moment of signing. Conformity must remain true through the lifecycle of the system. Several mechanisms in the EU AI Act work together to maintain, and to test, that ongoing conformity.

Keeping the Annex IV File Current

Annex IV must remain current. The Article 11 documentation obligation is continuous, not point-in-time. As the system evolves through routine updates, configuration changes, performance-tuning, monitoring-instrumented improvements, and data-pipeline refinements, the Annex IV file is maintained in lock-step. The Annex IV §6 lifecycle-changes section captures the pre-determined-change carve-out scope and tracks each change against that scope. The declaration referenced in Annex IV §8 remains valid as long as the changes stay within the pre-determined-change envelope; the moment a change crosses the substantial-modification threshold, the declaration becomes stale and re-signing is triggered.

Article 72 Post-Market Monitoring Anomalies

Article 72 requires the provider to operate a post-market monitoring system that collects, documents, and analyses data on system performance throughout the lifecycle. The PMM is designed to surface anomalies: performance degradation, drift in error patterns, fairness-metric shifts, robustness regressions, cybersecurity events. Anomalies that suggest the system no longer meets the conformity claims in the signed declaration are the trigger for re-conformity assessment and potential re-signing. The signing officer's standing review of the PMM outputs (typically quarterly through the AIGC) is the operational mechanism that keeps the signed declaration honest over the lifecycle.

Article 73 Serious Incidents Must Not Contradict the Declaration

Article 73 requires reporting of serious incidents to the national market surveillance authority within fifteen days (with shorter windows for widespread infringement and incidents involving critical infrastructure). Serious incidents that reflect a failure of the conformity claims in the signed declaration are operationally devastating for the signer. The incident report itself becomes an admission that the declaration's statement of conformity was either inaccurate at signing or has become inaccurate since signing. The maintenance discipline that prevents this failure is the integration of PMM outputs with the change-control gate (lesson 053) and the declaration-refresh trigger; incidents should be surfaced and remediated before they cross the Article 73 reporting threshold.

ISO 42001 and Notified-Body Surveillance Audits

The ISO/IEC 42001:2023 surveillance cycle (annual surveillance audits between the three-year recertification cycles) and, where Annex VII Module H applied, the notified-body surveillance audits both test the operative state of the QMS that produced the signed declaration. Surveillance audit findings that contradict the declaration are signal that the declaration is becoming stale; surveillance audit clean reports are evidence that the declaration's underlying QMS continues to operate as attested. The signing officer's review of surveillance audit reports is part of the post-signing maintenance discipline.

Substantial-Modification Re-Signing Trigger - Article 43(4)

The most consequential post-signing maintenance event is a substantial modification under Article 43(4). A substantial modification, a change that affects the system's compliance with the high-risk requirements or that modifies the intended purpose, invalidates the prior declaration. The provider runs a new conformity assessment (under the same route as the original: Annex VI internal control or Annex VII Module H), produces a refreshed Annex IV technical file, and signs a new Article 47 declaration on behalf of the modified system. The Article 71 database registration is updated with the new declaration reference. The CE marking continues to apply but now references the modified system per the refreshed declaration.

The signer of the refreshed declaration is not necessarily the same individual as the original signer. If the CAIRO role has changed hands between the original signing and the modification, the new CAIRO signs the refreshed declaration after walking the eight-question check freshly against the modified system. If the original signer remains in role, they sign the refreshed declaration; the prior signature remains on the prior declaration for the prior version, retained per Article 18 for ten years from when that prior version ceased to be available. The signing-officer accountability tracks with each version's declaration; one individual's accountability does not get transferred to a successor in a way that releases the original.

Acme's pattern for ServiceAssist v1.0: the initial declaration is signed by Maya Okafor on May 19, 2026; the substantial modification planned for Q4 2026 (foundation-model swap from Claude 4 to Claude 5, expanding the use-case envelope beyond what the Article 43(4) pre-determined-change carve-out covers) will trigger a refreshed conformity assessment and a fresh Maya Okafor signature on the refreshed declaration, with the eight-question check re-walked against the modified system. Both declarations, v1.0 original and v1.0 substantial-modification, are retained in the AIMS evidence vault.

Common 2026 Signing Failures + the Personal-Accountability Bargain

Six failure modes recur across 2026 signing practice. Each one is preventable with the eight-question check and the board-resolution governance pattern; each one is found in the wild and each one is the kind of failure that surfaces as personal exposure to the signer when the deployment goes wrong downstream.

  • Failure 1 - Rubber-stamp signing without the eight-question check. The signer trusts that the team has done the work, signs in the last 24 hours before a deployment deadline, and does not personally walk the evidence. When the conformity claim is later challenged, the signer has no contemporaneous record of due diligence. The remediation is the mandatory written, retained, named-evidence checklist before the pen touches the page.
  • Failure 2 - Ambiguous internal authority. Multiple executives believe they have signing authority. No board resolution is on file. Different copies of the declaration carry different signatures. Validity becomes contestable. The remediation is the board-resolution pattern with a single named primary signer per system category.
  • Failure 3 - No escalation path documented for refusal. The signer faces a NO answer on one of the eight questions but has no sanctioned pathway to escalate without appearing to obstruct the deployment. The signer signs anyway, against their own judgment. The remediation is the formal six-step escalation path with explicit board-level support for refusal as a normal governance outcome.
  • Failure 4 - Signing while substantial modification is in progress. A substantial modification is being developed in parallel with a declaration signing for the current version; the declaration is signed but is immediately stale because the in-progress modification crosses the carve-out boundary. The remediation is the change-control gate (lesson 053) integration with the signing workflow, no signing on a system that has a pending substantial modification within the planning horizon.
  • Failure 5 - Signer not retained in role long enough for the ten-year evidence trail. The signing officer leaves the organization within a year or two of signing; succession planning has not been done; the trail back to the signer's contemporaneous evidence becomes harder to reconstruct. The remediation is the AIMS evidence vault retention of the signing-due-diligence file (the eight-question check with named pointers) as a self-contained record that does not depend on the signer's continued presence.
  • Failure 6 - Skipping board-resolution authorization where the governance design requires it. The CAIRO signs without the formal board resolution because the deployment is urgent. The signing authority becomes contestable, the D&O coverage review was not triggered, the board-level acknowledgement of personal accountability was not surfaced. The remediation is the hard gate, no signing until the board resolution is on file.

The Personal-Accountability Bargain

The 2026 pattern in CAIRO and CAIO hiring and retention practice is to formalize the personal-accountability bargain before the role is accepted. The signing officer increasingly negotiates, contractually, a defined set of protections in exchange for the personal accountability they will carry. The standard elements of the bargain:

  • Contractual indemnification. The employer indemnifies the signing officer for liability arising from signed declarations except for liability arising from the signer's own bad faith or gross negligence. The indemnification scope is defined in writing in the employment contract or in a separate side letter referenced from the employment contract.
  • D&O insurance coverage with AI-specific scope confirmed. The D&O policy explicitly covers Article 47 signing liability. The signing officer reviews the policy with the broker, including any Member-State criminal-exposure carve-outs, before accepting the signing role. Annual coverage reviews are written into the engagement.
  • Board ratification of signing authority. The board passes the authorizing resolution before the first signing. The resolution surfaces the personal-accountability conversation between the signer and the board, making explicit that the board understands and supports the signing officer's role.
  • Standing access to evidence and to refusal. The signer has standing, unconstrained access to the underlying Annex IV evidence, to the AIGC, and to the board AI subcommittee. The signer's right to refuse to sign is documented as a governance norm; refusal does not trigger employment-side consequences absent bad-faith or capricious refusal patterns.
  • Succession planning. A back-up signer is named and trained. The signing-due-diligence checklist pattern is portable across signers so that a successor can pick up the discipline without learning curve.

The bargain is, in practical effect, the operating model that allows the signing role to be filled. CAIROs and CAIOs who sign without the bargain in place are increasingly rare in 2026: the personal exposure is too material, the D&O carve-outs are too sharp, and the precedent of personal naming in early enforcement actions is sufficient to make unprotected signing an unattractive proposition. Boards that want competent signers are learning to put the bargain in place.

Worked Example - Acme CAIRO Signs ServiceAssist v1.0, and the Cross-Walk Reference

Pulling the lesson together through the Acme worked example. Maya Okafor, CAIRO at Acme, is signing the Article 47 declaration for ServiceAssist v1.0 in Q2 2026. ServiceAssist is an Annex III §4 employment-context system used internally for candidate-screening across Acme's 12,000-person workforce, with the conformity assessment performed under Annex VI internal control. Maya's signing sequence:

  1. Pre-signing, board resolution in place. The Acme board AI subcommittee passed the authorizing resolution naming Maya as authorized person for high-risk AI declarations in November 2025; D&O coverage confirmed by the broker with explicit Article 47 signing scope; succession plan names the Acme General Counsel as back-up signer for cases of incapacity.
  2. Pre-signing, eight-question check walked with named evidence. Maya completes the written checklist over a thirty-minute desk session. All eight questions answer YES with named evidence pointers in the AIMS evidence vault. The checklist is dated, signed by Maya, and saved as AIMS/Sign-DD/ServiceAssist/v1.0/8q-check-2026-05-19.pdf alongside the draft declaration.
  3. Signing, declaration is executed. The declaration is signed on May 19, 2026, place: Acme registered office, San Francisco (with the EU authorized representative under Article 22, Acme EU GmbH in Munich, referenced in field 1 alongside Acme Inc. for the non-EU provider record). The signed declaration is incorporated as Annex IV §8 of the ServiceAssist v1.0 technical file.
  4. Post-signing - CE marking and Article 71 registration. The CE marking is integrated into the ServiceAssist UI footer and on the About / Compliance page. Article 71 EU database registration is completed with the Annex VIII nine-field information set and field-by-field Article 78 confidentiality designation. ServiceAssist v1.0 is placed in service across Acme's EU operations on May 26, 2026.
  5. Maintenance, quarterly AIGC review of PMM and surveillance. The CAIRO walks PMM outputs, surveillance audit findings, and incident logs each quarter to confirm the conformity claims remain supported.
  6. Q4 2026 substantial-modification refresh. The planned Claude 4 → Claude 5 foundation-model swap crosses the Article 43(4) substantial-modification threshold. Maya re-walks the eight-question check against the modified system, signs a fresh Article 47 declaration on November 8, 2026, updates the Article 71 registration, and retains both v1.0 declarations in the AIMS vault, original under retention through 2036 from initial placement; refreshed under retention through 2036+ from modification placement.

Cross-Walk to Frameworks and Adjacent Provisions

The signing moment sits at the intersection of multiple frameworks. The L5 cross-walk reference:

  • EU AI Act Articles. Article 8-15 (the substantive conformity requirements attested in the declaration); Article 16 (provider obligations); Article 17 (QMS); Article 18 (10-year retention); Article 22 (authorized representative for non-EU providers); Article 27 (FRIA for high-risk deployment); Article 43 (conformity assessment) and 43(4) (substantial modification); Article 47 (the declaration itself); Article 48 (CE marking); Article 71 (EU database registration); Article 72 (post-market monitoring); Article 73 (serious-incident reporting); Article 99(3) at €15M / 3% and Article 99(5) at €7.5M / 1% (the penalty exposure framework).
  • Annexes. Annex IV §8 (declaration incorporation); Annex V (declaration content per Article 47(2)); Annex VI (internal control conformity assessment); Annex VII Module H (notified-body conformity assessment); Annex VIII (database registration fields).
  • ISO standards. ISO/IEC 42001:2023 Annex A.3 (leadership signature and personal accountability), the standards-side parallel to the Article 47 signing model; ISO/IEC 23894:2023 (risk management) for question 2 evidence; ISO/IEC 5338:2023 (lifecycle) for question 1 evidence; ISO/IEC 27001:2022 (information security) for question 5 cybersecurity evidence.
  • NIST AI RMF. Govern function (the leadership and accountability layer that makes the signing role workable); Manage function (the lifecycle maintenance discipline that keeps the signed declaration honest).
  • SR 11-7 parallel. The Federal Reserve SR 11-7 model risk management framework's attestation pattern, model owners and model validators sign off on model conformity within the bank's MRM governance, is the closest U.S. financial-sector analogue. CAIROs and CAIOs operating across both regimes treat the Article 47 signing moment and the SR 11-7 attestation moment as parallel disciplines.
  • OWASP LLM Top 10 + MITRE ATLAS. Question 5 cybersecurity evidence references these frameworks as the adversarial-testing evidence base for Article 15 robustness and cybersecurity claims.

Key Takeaways

  • The signature is personal and survives organizational change. A natural person signs on behalf of the provider; the signature is retained for ten years per Article 18 alongside the Annex IV file; supervisory authorities trace findings back to the named signer.
  • Article 47(2) prescribes the required content. Provider name and address (with Article 22 authorized representative for non-EU); system identification; conformity statement against Articles 8-15; standards / specifications applied; notified body identity and certificate number (where applicable); date; place; signature with printed name and role.
  • The eight-question check is the affirmative-defense file. Annex IV TDF currency; Article 9 risk management; Article 10 data governance; Article 14 human oversight; Article 15 accuracy / robustness / cybersecurity; Article 17 QMS; Article 27 FRIA; CE marking + Article 71 registration. Each YES requires named-evidence pointer; one NO halts the signing.
  • Signer identity follows a small set of standard patterns. CAIRO, CAIO, CEO, General Counsel, or Article 22 authorized representative. Board-resolution authorization establishes scope, succession, and D&O coverage confirmation; ambiguous internal authority is a recurring failure mode.
  • Liability is administrative + misleading-information + personal + discovery. Article 99(3) at €15M / 3% for underlying failure; Article 99(5) at €7.5M / 1% for misleading-information signing; Member-State personal sanction in some jurisdictions; class-action and discovery exposure naming the signer.
  • The "I-don't-have-confidence" escalation path is sanctioned governance. Six-step pathway from signing-halt → written memo to AIGC and board → AIGC review and remediation tasking → AIMS-tracked remediation → re-walk of the eight-question check → deployment proceeds (or documented refusal record).
  • Substantial modification under Article 43(4) triggers re-signing. Refreshed Annex IV file, re-run conformity assessment, fresh Article 47 declaration signed against the modified system, Article 71 registration updated. The signer of the refreshed declaration is not necessarily the original signer; per-version accountability is retained.
  • The personal-accountability bargain shapes signing-officer retention. Contractual indemnification, D&O coverage with AI-specific scope, board ratification of authority, standing access to evidence and refusal, and succession planning are increasingly contractual prerequisites for accepting the CAIRO / CAIO signing role in 2026, and increasingly the operating model that lets the signing system function at all.