When companies picture an audit, many imagine an unannounced inspection with a briefcase and a clipboard. In practice, an EU AI Act audit usually looks different: a request for evidence — with a deadline for when it needs to be ready. That's exactly where it gets tight for many companies. Not because the AI systems themselves are a problem, but because the evidence is scattered: a bit in emails, a bit in a spreadsheet, a bit in the head of whoever ran the rollout back then.
Who actually audits – and when?
Market surveillance under the EU AI Act is carried out by the responsible national authorities. A review can be triggered by a specific cause – such as a complaint or a reported incident – or happen as part of general spot checks, similar to other regulated areas. What matters: the request to produce evidence typically comes with relatively little lead time. There's practically no time left to start documenting once the request has already arrived.
The evidence companies are likely to need
The exact scope depends on the individual case, but the following items come up in most situations:
What stands out: almost none of these items can be cleanly produced after the fact, on the day of the request. A risk classification justified retroactively reads very differently from one documented from the start.
Our tip: Test yourself: could you produce all seven items from the table above for your most important AI system today, with no lead time? If not, you know exactly where the next step is.
Why "we'll document that when it comes up" doesn't work
The natural instinct is to treat documentation as something you can produce on demand. The problem: by the time a request arrives, the demand is already there – and the typical deadline rarely leaves enough time to make up for months or years of missing documentation. Companies that misclassified a system, or never documented it at all, risk not just fines, but also an otherwise uncritical system suddenly facing heightened scrutiny – simply because traceability can no longer be reconstructed after the fact.
How companies actually prepare
Here too: it doesn't have to be a huge project if you start early enough.
1. Build a register. Capture every AI system in use in one place – the foundation for everything else.
2. Prioritize high-risk systems. Assemble complete technical documentation under Annex IV for these first, including data quality and fairness assessment.
3. Keep evidence centralized and export-ready. Document governance decisions, training records, and incident history so they can be assembled in hours, not weeks, when needed.
Our tip: Once a year, simulate an "audit fire drill" internally – have someone on the team assemble the evidence for one system as if the request were arriving tomorrow. Gaps show up before they get expensive.
Frequently asked questions about EU AI Act audits
Who conducts EU AI Act audits?
The responsible national market surveillance authorities. Reviews can be triggered by a specific cause (e.g. a complaint) or occur as part of general checks.
What penalties apply for missing documentation?
The EU AI Act provides for significant fines, with the exact amount depending on the individual case and the severity of the violation. The specific consequences should be reviewed legally if in doubt.
How much time is there to prepare, typically?
Requests for evidence usually come with a relatively short deadline. Documentation started only after the request arrives can rarely be fully caught up within that window.
Does this apply to companies with only minimal-risk systems too?
The scope of evidence obligations depends on the risk class. Regardless, since February 2025, any company using AI systems must be able to demonstrate compliance with the AI literacy obligation under Article 4.
The best time to prepare evidence isn't the day the request arrives
Audit preparation is, at its core, not a legal topic but an organizational one: evidence is best created when an AI system is introduced – not only once someone asks for it. Structure that once, and in a real audit situation, all that's left to do is export it.
That's exactly where SimpleAct comes in: capture AI systems, classify them by risk, attach complete documentation – and produce an export-ready audit trail when needed. All in one place, instead of scattered across emails, spreadsheets, and institutional memory.
This article is for general information purposes only and does not constitute legal advice. Procedures, deadlines, and fine ranges can vary depending on the individual case and national implementation. If in doubt, we recommend a legal review.
About SimpleAct: SimpleAct is a European compliance platform that helps companies structure their AI system documentation under the EU AI Act. From capturing systems, through risk assessment, to an export-ready audit trail – all in one place.
Tags
Kamill | SimpleAct
Author · SimpleAct Team
