# PIPE FISH LABS — ENTERPRISE RESOURCES & AUDIT TEMPLATES # Document: EU AI Act Annex IV Compliance Readiness Checklist # Version: 2.4 (Current with 2026 EU AI Act Enforcement Standards) # Organization: PipeFish Labs (https://pipefishlabs.io) # License: Free Enterprise Resource (Distribution Allowed) ================================================================================ EU AI ACT HIGH-RISK SYSTEM COMPLIANCE CHECKLIST (ANNEX IV REQUIREMENT) ================================================================================ SECTION 1: SYSTEM IDENTIFICATION & RISK CLASSIFICATION -------------------------------------------------------------------------------- [ ] 1.1 Document intended purpose, target deployment sector, and affected personas. [ ] 1.2 Identify whether system falls under Annex III high-risk classification (Biometrics, Critical Infrastructure, Employment/HR, Credit Scoring, Law Enforcement). [ ] 1.3 Maintain an up-to-date System Architecture Diagram showing model endpoints, data pipelines, external APIs, and MCP (Model Context Protocol) tool servers. SECTION 2: RISK MANAGEMENT SYSTEM (ARTICLE 9) -------------------------------------------------------------------------------- [ ] 2.1 Implement continuous risk assessment throughout model lifecycle. [ ] 2.2 Conduct residual risk evaluation and document mitigation measures. [ ] 2.3 Test for potential bias, adversarial prompt injection, and hallucination vectors. [ ] 2.4 Maintain post-market monitoring framework with feedback loops to engineering team. SECTION 3: DATA GOVERNANCE & PROVENANCE (ARTICLE 10) -------------------------------------------------------------------------------- [ ] 3.1 Verify data lineage, training set provenance, and licensing compliance. [ ] 3.2 Implement automated data validation routines for bias and gap detection. [ ] 3.3 Enforce zero-data-retention policies for sensitive enterprise inputs. [ ] 3.4 Establish cryptographic data hashing for training and evaluation datasets. SECTION 4: TECHNICAL DOCUMENTATION & EXPLAINABILITY (ARTICLE 11 & ANNEX IV) -------------------------------------------------------------------------------- [ ] 4.1 Produce machine-readable Annex IV technical documentation package. [ ] 4.2 Document model architecture, weights versioning, hyper-parameters, and fine-tuning logs. [ ] 4.3 Implement step-by-step explainability logs for high-consequence decision steps. [ ] 4.4 Provide human-readable summary for system operators and compliance auditors. SECTION 5: AUTOMATED RECORD-KEEPING & AUDIT TRAILS (ARTICLE 12) -------------------------------------------------------------------------------- [ ] 5.1 Enable tamper-evident logging of input prompts, tool calls, and output states. [ ] 5.2 Store logs in immutable append-only storage with cryptographic timestamps. [ ] 5.3 Retain audit logs for minimum 6-month statutory requirement (or client SLA). [ ] 5.4 Ensure automated log export compatibility with standard SIEM/SOAR platforms. SECTION 6: HUMAN OVERSIGHT & OVERRIDE CONTROLS (ARTICLE 14) -------------------------------------------------------------------------------- [ ] 6.1 Implement "Human-in-the-Loop" (HITL) pause & override mechanisms for critical state handoffs. [ ] 6.2 Provide real-time operator notification for low-confidence agent decisions. [ ] 6.3 Ensure operators have single-click emergency kill-switch capability. [ ] 6.4 Document operator training and intervention protocols. SECTION 7: CYBERSECURITY, ACCURACY & ROBUSTNESS (ARTICLE 15) -------------------------------------------------------------------------------- [ ] 7.1 Conduct penetration testing specifically targeting LLM agent tool interfaces. [ ] 7.2 Implement mTLS authentication between autonomous agents and internal microservices. [ ] 7.3 Enforce automated secret rotation using HashiCorp Vault. [ ] 7.4 Verify system resilience against denial-of-service and payload tampering attacks. ================================================================================ Need Assistance Fulfilling This Checklist? PipeFish Labs offers complete EU AI Act Annex IV technical audit preparation and automated compliance infrastructure. Book a Complimentary Audit Session: https://pipefishlabs.io/book-a-demo-contact/?intent=audit Contact Engineering: pipefish.labs@gmail.com ================================================================================