EU AI Act · Annex III · Risk Screening

Annex III Risk Screening

Choose the screening profile for your sector. The evaluation accounts for the regulatory overlaps between the EU AI Act, NIS2, and DORA, and shows the action required for your specific infrastructure setup.

1. Does your company operate in an explicitly regulated high-risk sector? Financial services, healthcare, HR, critical infrastructure, and the public sector are considered core regulatory sectors under the EU AI Act.
2. Do you use AI systems in operational decision-making processes? Credit scoring, candidate selection, diagnosis, and plant control are typical use cases with heightened regulatory relevance.
3. Do you use external data sources for your AI systems? Web scraping, third-party APIs, news feeds, and external LLM inputs raise the requirements for data-source validation.
4. Do you maintain a complete inventory of your AI systems as required by the EU AI Act? A structured inventory forms the documentary basis for meeting the reporting obligations.
5. Has your company designated a dedicated AI Act officer? A clear assignment of internal review processes strengthens governance and simplifies external audits.
6. Is your company subject to NIS2 or DORA? CERTavia provides the infrastructure evidence for the regulatory overlaps of these frameworks.
1. Do you use AI for credit scoring, fraud detection, or risk modeling? These applications are explicitly classified as high-risk under Annex III.
2. Does your system draw on external APIs, market data, or news feeds? Every external domain is a relevant data source under Art. 50 requirements and raises validation needs.
3. Have you already created an inventory of your high-risk AI systems? A structured inventory forms the documentary basis for meeting the reporting obligations.
4. Are you implementing DORA and NIS2 in parallel? CERTavia provides the infrastructure evidence for these regulatory overlaps.
1. Does your company use AI for diagnostics, patient triage, or image analysis? These systems fall within the scope of Annex III No. 2.
2. Are external literature databases, clinical data APIs, or classification systems connected? ICD, SNOMED, and comparable medical knowledge bases raise the validation requirements for data sources.
3. Is the conformity assessment dossier for Annex III prepared? An auditor reviews the machine-readable evidence of data-source integrity as a core part of the conformity documentation.
4. Has an internal or external auditor for Art. 50 already been designated? A clear assignment of review processes strengthens governance and simplifies external audits.
1. Does your system support HR decisions such as candidate selection or employee evaluation? AI systems in this area fall under Annex III No. 4 classification.
2. Does the matching algorithm use external data sources? LinkedIn, job boards, and external skills databases raise the requirements for data-source validation.
3. Do enterprise customers already request evidence of your AI Act compliance status? Under Art. 28, enterprise customers review the compliance status of all software vendors in their supply chain.
4. Have you already officially classified your applicant management system as high-risk? Complete documentation forms the audit-ready basis for evidencing the classification decision.
1. Does your company operate facilities or systems that fall under critical-infrastructure regulation or NIS2? Energy, water, transport, health, finance, and digital infrastructure are classic critical-infrastructure sectors with elevated security requirements.
2. Do AI systems in your organization control or monitor operational infrastructure or critical decision processes? Predictive maintenance, network anomaly detection, and automated control-room support fall within the scope of Annex III No. 3.
3. Do your systems access external data sources, APIs, or network services? Every external domain is a potential attack surface and a relevant data source under Art. 50.
4. Is there a current information security management system (ISMS) in place? NIS2 requires critical-infrastructure operators to maintain a documented ISMS. The CERTavia evidence complements the ISMS with machine-readable infrastructure proof.
5. Have suppliers or third parties already been reviewed for infrastructure compliance? NIS2 Art. 21 and DORA require critical-infrastructure operators to review their supply chain — including technical infrastructure evidence from third parties.
1. Do you offer AI-powered features in your SaaS product to business customers in the EU? As a provider, you carry your own obligations under Art. 28 of the EU AI Act — regardless of where your company is registered.
2. Are your AI features used by customers in regulated high-risk domains (e.g. finance, HR, healthcare)? The high-risk classification depends on the customer's use case — not on your own industry.
3. Do enterprise customers or procurement teams already request evidence of your AI Act compliance status? A cryptographically signed infrastructure evidence record speeds up vendor-assessment processes and shortens sales cycles.
4. Does your product use external data sources, third-party APIs, or LLM services? Every external domain is a data source subject to validation under Art. 50. As a provider, you are responsible for the integrity of these sources.
5. Have you produced an AI policy or technical documentation within the meaning of Art. 11 of the EU AI Act? Technical documentation evidences the conformity decision — CERTavia provides the machine-readable infrastructure component for it.
Frequently asked questions

Questions about the quick assessment and Annex III

What's the difference between this quick assessment and the domain scan?

The quick assessment checks, based on sector and use case, whether your AI system falls under the high-risk obligations of the EU AI Act (Annex III) — a regulatory classification, not a technical measurement. The domain scan checks your domain's technical infrastructure against 80+ parameters and delivers the cryptographically signed evidence for Art. 50 of the EU AI Act. The two tools complement each other.

Is this an official certification?

No. Neither the quick assessment nor the domain scan is an official certification within the meaning of the EU AI Act. The quick assessment provides an estimate of your regulatory exposure. The domain scan provides technical infrastructure evidence — directly usable as an attachment to your conformity assessment dossier. More in the glossary →

What happens if my AI system or infrastructure changes?

If your AI system changes (new features, new sector), you should re-run the quick assessment — the regulatory classification can change. If your infrastructure changes (hosting, DNS, TLS), we recommend a new domain scan, since a SOVP evidence record documents the state at the time of the check.