How do companies maintain compliance evidence over ten years?
The AI Act requires companies to retain compliance documentation for 10 years - providers must keep technical documentation and quality management records, while importers and authorised representatives retain certificates and declarations.
Under the EU AI Act, companies are legally required to retain specific compliance documentation for 10 years after a high-risk AI system or a general-purpose AI model is placed on the market or put into service.
Depending on the company's specific role in the AI value chain, the evidence that must be kept for this 10-year period includes:
- Providers: the system's technical documentation, documentation concerning the quality management system, records of changes approved by notified bodies, certificates/decisions issued by notified bodies, and the EU declaration of conformity.
- Importers: a copy of the certificate issued by the notified body, the instructions for use, and the EU declaration of conformity.
- Authorised representatives: the EU declaration of conformity, the technical documentation, and applicable certificates.
How companies practically maintain this evidence
Because documentation naturally becomes outdated as soon as AI systems, vendors, or use cases evolve, companies cannot treat this 10-year retention as a one-time static filing exercise. As noted by compliance platforms like Aigolex, "static documents fail the moment reality changes".
To ensure that their compliance evidence remains accurate and "always-ready" over a decade, companies implement structured, continuous operational processes that:
- Centralize evidence by deployment: documentation is mapped and centralized according to specific operational "workspaces" and real-world "deployments" (how the AI is actually used, by whom, and for what purpose), rather than just keeping files on abstract AI models. This repository includes system descriptions, risk assessments, and logs tracking human oversight and monitoring controls.
- Continuously monitor for changes: companies must actively monitor their AI assets, their vendors, and their operational perimeters for any changes over time.
- Utilize alerts and flags: to prevent compliance failures after the initial assessment, companies rely on systems that flag when a change in the AI's usage dictates that risk levels or regulatory obligations must be updated, and issue alerts when the underlying compliance documentation needs to be refreshed.