EUAICheck is an educational simulator. We are not a law firm and have no affiliation with any official body.
EUAICheck is an independent educational simulator. This content is informational and does not constitute legal advice.
How to prepare your EU AI Act audit: practical guide for SMEs
Updated: September 2026 - Regulation (EU) 2024/1689
EU AI Act compliance is not a one-time event - it is an ongoing process. For SMEs just starting out, the question is not 'when to start' (it is now for obligations already in force) but 'where to start'. This practical guide provides a 5-step method applicable to any company.
Step 1: Inventory all your AI systems
Before any classification, you need to know what you use. Review:
- SaaS software with AI features (CRM, ATS, ERP, marketing tools)
- External AI model APIs (OpenAI, Anthropic, Google, Mistral)
- Internal tools developed in-house with AI components
- Chatbots and virtual assistants on your site or internally
- Content generation tools (text, image, video) used for your communications
Don't forget tools used informally by your teams. An employee who uses ChatGPT to write client emails engages the company's liability under Article 50.
Step 2: Classify each system under the EU AI Act
For each identified system, determine its risk level:
- Unacceptable risk (prohibited): does your system engage in subliminal manipulation, emotion recognition, social scoring?
- High risk: is your system used in HR, healthcare, education, finance, justice or critical infrastructure?
- Limited risk: does your system interact with humans (chatbot) or generate published content?
- Minimal risk: your system does not fall into any of the preceding categories
EUAICheck can help you classify your main system in 17 questions. This free educational simulator provides an initial orientation before consulting a specialist.
Step 3: Prioritise actions according to the timeline
Not all obligations apply at the same time. Prioritise your actions:
- Immediate (already in force): verify absence of prohibited practices, display AI notice on your chatbots, train your teams on AI literacy
- Before December 2027: technical documentation, risk management, EU AI Office registration for high-risk systems
- Ongoing: maintain logs, monitor performance, report incidents
Step 4: Build the required documentation
Documentation is at the heart of EU AI Act compliance. For high-risk systems, Annex IV details what is required:
- System description: purpose, architecture, capabilities, limitations
- Training data: origin, selection criteria, anti-bias measures
- Performance metrics: error rates, bias tests, performance by subgroup
- Risk management system: identified risks, mitigation measures
- Human oversight procedure: who validates, according to which criteria, with what authority
Article 4 requires deployers to ensure that their employees using AI systems have a sufficient level of AI literacy. In practice:
- Train direct users of AI systems on their capabilities and limitations
- Explain potential biases and how to identify them
- Document training conducted (date, content, participants)
- Include AI literacy in onboarding programmes
Start by classifying your system
17 questions to understand your risk level and priority obligations. Free educational simulator.
Start the simulator