Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Article 31

CurrentFrom 2 Aug 2025

Maintain the Governance, Independence, Resources and Competence Required of an AI Notified Body

Applies to Notified Body.

Actors
Notified Body
Themes
Risk & AssuranceSecurity & Resilience

Tracker Guidance

Maintain the organisational, quality, resource, process, independence, confidentiality, insurance, competence and cybersecurity arrangements required to perform AI conformity assessments with integrity and impartiality.

Official text

Article 31Official source
1. A notified body shall be established under the national law of a Member State and shall have legal personality. 2. Notified bodies shall satisfy the organisational, quality management, resources and process requirements that are necessary to fulfil their tasks, as well as suitable cybersecurity requirements. 3. The organisational structure, allocation of responsibilities, reporting lines and operation of notified bodies shall ensure confidence in their performance, and in the results of the conformity assessment activities that the notified bodies conduct. 4. Notified bodies shall be independent of the provider of a high-risk AI system in relation to which they perform conformity assessment activities. Notified bodies shall also be independent of any other operator having an economic interest in high-risk AI systems assessed, as well as of any competitors of the provider. This shall not preclude the use of assessed high-risk AI systems that are necessary for the operations of the conformity assessment body, or the use of such high-risk AI systems for personal purposes. 5. Neither a conformity assessment body, its top-level management nor the personnel responsible for carrying out its conformity assessment tasks shall be directly involved in the design, development, marketing or use of high-risk AI systems, nor shall they represent the parties engaged in those activities. They shall not engage in any activity that might conflict with their independence of judgement or integrity in relation to conformity assessment activities for which they are notified. This shall, in particular, apply to consultancy services. [Excerpt - see official source for complete provision]

Excerpt stored at a complete legal-unit boundary. See the official source for the full provision.

Sub-obligations

These are independently assessable parts of the parent requirement.

  1. Article 31(1)-(3)

    Current

    Maintain Appropriate Organisation, Quality Management, Processes and Cybersecurity

    Tracker Guidance

    Maintain legal personality and an organisational structure, allocation of responsibilities, reporting lines, quality arrangements, resources, processes and suitable cybersecurity that support confidence in conformity-assessment performance.

    Official text

    Article 31(1)-(3)Official source
    1. A notified body shall be established under the national law of a Member State and shall have legal personality. 2. Notified bodies shall satisfy the organisational, quality management, resources and process requirements that are necessary to fulfil their tasks, as well as suitable cybersecurity requirements. 3. The organisational structure, allocation of responsibilities, reporting lines and operation of notified bodies shall ensure confidence in their performance, and in the results of the conformity assessment activities that the notified bodies conduct.
  2. Article 31(4)-(6)

    Current

    Safeguard Independence, Objectivity and Impartiality in AI Conformity Assessment

    Tracker Guidance

    Remain independent of assessed providers and other economically interested operators, prevent conflicts arising from design, development, marketing, use or consultancy, and document procedures that safeguard impartiality.

    Official text

    Article 31(4)-(6)Official source
    4. Notified bodies shall be independent of the provider of a high-risk AI system in relation to which they perform conformity assessment activities. Notified bodies shall also be independent of any other operator having an economic interest in high-risk AI systems assessed, as well as of any competitors of the provider. This shall not preclude the use of assessed high-risk AI systems that are necessary for the operations of the conformity assessment body, or the use of such high-risk AI systems for personal purposes. 5. Neither a conformity assessment body, its top-level management nor the personnel responsible for carrying out its conformity assessment tasks shall be directly involved in the design, development, marketing or use of high-risk AI systems, nor shall they represent the parties engaged in those activities. They shall not engage in any activity that might conflict with their independence of judgement or integrity in relation to conformity assessment activities for which they are notified. This shall, in particular, apply to consultancy services. 6. Notified bodies shall be organised and operated so as to safeguard the independence, objectivity and impartiality of their activities. Notified bodies shall document and implement a structure and procedures to safeguard impartiality and to promote and apply the principles of impartiality throughout their organisation, personnel and assessment activities.
  3. Article 31(7); Article 78

    Current

    Protect Confidentiality and Professional Secrecy in Notified-Body Activities

    Tracker Guidance

    Maintain documented procedures so staff, committees, subsidiaries, subcontractors and associated external personnel protect confidential information and professional secrecy, subject to lawful disclosure requirements.

    Official text

    Article 31(7)Official source
    7. Notified bodies shall have documented procedures in place ensuring that their personnel, committees, subsidiaries, subcontractors and any associated body or personnel of external bodies maintain, in accordance with Article 78, the confidentiality of the information which comes into their possession during the performance of conformity assessment activities, except when its disclosure is required by law. The staff of notified bodies shall be bound to observe professional secrecy with regard to all information obtained in carrying out their tasks under this Regulation, except in relation to the notifying authorities of the Member State in which their activities are carried out.
    Article 78Official source
    1. The Commission, market surveillance authorities and notified bodies and any other natural or legal person involved in the application of this Regulation shall, in accordance with Union or national law, respect the confidentiality of information and data obtained in carrying out their tasks and activities in such a manner as to protect, in particular: (a) the intellectual property rights and confidential business information or trade secrets of a natural or legal person, including source code, except in the cases referred to in Article 5 of Directive (EU) 2016/943 of the European Parliament and of the Council (1); (b) the effective implementation of this Regulation, in particular for the purposes of inspections, investigations or audits; (c) public and national security interests; (d) the conduct of criminal or administrative proceedings; (e) information classified pursuant to Union or national law. 2. The authorities involved in the application of this Regulation pursuant to paragraph 1 shall request only data that is strictly necessary for the assessment of the risk posed by AI systems and for the exercise of their powers in accordance with this Regulation and with Regulation (EU) 2019/1020. They shall put in place adequate and effective cybersecurity measures to protect the security and confidentiality of the information and data obtained, and shall delete the data collected as soon as it is no longer needed for the purpose for which it was obtained, in accordance with applicable Union or national law. [Excerpt - see official source for complete provision]

    Excerpt stored at a complete legal-unit boundary. See the official source for the full provision.

  4. Article 31(8)-(9)

    Current

    Maintain Proportionate Assessment Procedures and Appropriate Liability Insurance

    Tracker Guidance

    Use assessment procedures that take account of provider size, sector, structure and system complexity while preserving required rigour, and maintain appropriate liability insurance unless the statutory public-liability exception applies.

    Official text

    Article 31(8)-(9)Official source
    8. Notified bodies shall have procedures for the performance of activities which take due account of the size of a provider, the sector in which it operates, its structure, and the degree of complexity of the AI system concerned. 9. Notified bodies shall take out appropriate liability insurance for their conformity assessment activities, unless liability is assumed by the Member State in which they are established in accordance with national law or that Member State is itself directly responsible for the conformity assessment.
  5. Article 31(10)-(11)

    Current

    Maintain Sufficient Professional Competence and Qualified Personnel

    Tracker Guidance

    Maintain professional integrity and sufficient internal administrative, technical, legal and scientific expertise to perform and oversee conformity-assessment activities, including evaluation of externally performed work.

    Official text

    Article 31(10)-(11)Official source
    10. Notified bodies shall be capable of carrying out all their tasks under this Regulation with the highest degree of professional integrity and the requisite competence in the specific field, whether those tasks are carried out by notified bodies themselves or on their behalf and under their responsibility. 11. Notified bodies shall have sufficient internal competences to be able effectively to evaluate the tasks conducted by external parties on their behalf. The notified body shall have permanent availability of sufficient administrative, technical, legal and scientific personnel who possess experience and knowledge relating to the relevant types of AI systems, data and data computing, and relating to the requirements set out in Section 2.
  6. Article 31(12); Article 38

    Current

    Participate in Notified-Body Coordination and Remain Current on Relevant Standards

    Tracker Guidance

    Participate directly or through representation in required coordination activities and standardisation work, or otherwise ensure current awareness of relevant standards.

    Official text

    Article 31(12)Official source
    12. Notified bodies shall participate in coordination activities as referred to in Article 38. They shall also take part directly, or be represented in, European standardisation organisations, or ensure that they are aware and up to date in respect of relevant standards.
    Article 38Official source
    1. The Commission shall ensure that, with regard to high-risk AI systems, appropriate coordination and cooperation between notified bodies active in the conformity assessment procedures pursuant to this Regulation are put in place and properly operated in the form of a sectoral group of notified bodies. 2. Each notifying authority shall ensure that the bodies notified by it participate in the work of a group referred to in paragraph 1, directly or through designated representatives. 3. The Commission shall provide for the exchange of knowledge and best practices between notifying authorities.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Article 31: Maintain the Governance, Independence, Resources and Competence Required of an AI Notified Body | EU AI Act Library