ISMS Copilot

Free tool

AI model documentation completeness checker

Self-score how complete the documentation of one AI system or model is, as a model card, a dataset datasheet, or a technical-documentation file. The areas follow the EU AI Act's Annex IV technical-documentation structure for high-risk systems and Annex XI for general-purpose AI models, read alongside ISO/IEC 42001:2023. You get a completeness heatmap and a prioritised list of what to write next. A starting point for your documentation file, not a conformity assessment.

Structured around EU AI Act (Regulation (EU) 2024/1689) Annex IV and Annex XI and ISO/IEC 42001:2023. Area descriptions are original editorial content; refer to the primary sources for official wording and normative requirements.

This is a self-assessment completeness aid for one model or system, not a certification, audit, conformity assessment, or legal advice. It does not reproduce EU AI Act normative text or ISO/IEC 42001:2023 clause and control titles. Confirm what your specific system legally requires against the primary sources below and, where the EU AI Act applies, the conformity route for your risk tier.

Overall documentation completeness: Not answered

0 of 14 areas answered

Purpose and intended use
Not answered
Data and datasets
Not answered
Model design and performance
Not answered
Risk, oversight, and transparency
Not answered
Lifecycle, security, and provenance
Not answered

What to document first

No weak areas flagged from what you answered. Keep the documentation versioned with the model and reviewed. This is still not a conformity assessment.

Rate each documentation area on how complete and reviewed the written record is today, not on how good the underlying practice is.

Purpose and intended use

Intended purpose and use context

You have written down what the system or model is for, who is meant to use it, in what context, and the conditions, assumptions, and limits of its intended use, including reasonably foreseeable misuse to avoid. (EU AI Act Annex IV(1); Annex XI for GPAI models.)

General description, versions, and acceptable use

A reviewer can follow what the system does and how it is provided (as a product, an API, or an embedded component), which version or release this documentation covers, and any acceptable-use terms or licence attached to it. (Annex IV(1); Annex XI model description.)

Data and datasets

Data sources and provenance

You record where the training, validation, and test data came from, how it was collected or obtained, and the licensing or legal basis under which you use it. (Annex IV(2); Article 10; Annex XI data information.)

Dataset composition and preparation

You document the datasets used to build and evaluate the system: their size and main characteristics, how they were labelled, and the cleaning, filtering, or other preparation applied. (Annex IV(2); Annex XI data curation.)

Data quality and bias examination

You document how data quality and relevance are judged, and how possible biases in the data and their effects on the people the system affects are examined and addressed. (Article 10; Annex XI bias-detection measures.)

Model design and performance

Design choices and architecture

You document the key design decisions, the general logic and method of the system, the model type and main parameters at an appropriate level, and the rationale for the principal choices, without having to disclose trade secrets. (Annex IV(2); Annex XI architecture and parameters.)

Performance metrics and evaluation

You report the metrics used to measure accuracy and performance, why those metrics fit this system, the results on representative data, and how the system was tested and validated. (Annex IV(2), (3), and (4); Annex XI evaluation results.)

Known limitations and expected accuracy

You state the system's known limitations, the conditions under which performance degrades, the level of accuracy users should expect, and any group for which it may perform differently. (Annex IV(3).)

Risk, oversight, and transparency

Risks to people and mitigations

You document the foreseeable risks the system poses to health, safety, fundamental rights, or other people, and the measures taken to identify, evaluate, and reduce them. (Annex IV(5); Article 9.)

Human oversight measures

You document how people can understand, monitor, intervene in, or override the system, and the technical and organisational measures built in to make that oversight effective. (Annex IV(2) and (3); Article 14.)

Information and instructions for users

You give the people deploying or using the system clear instructions: its capabilities and limitations, the conditions required for safe use, and what is expected of a human overseeing it. (Article 13.)

Lifecycle, security, and provenance

Robustness, accuracy, and cybersecurity

You document the measures that keep the system accurate and resilient against errors and adversarial conditions, and that protect the system and its data against cybersecurity threats, consistent with its intended use. (Annex IV(2); Article 15.)

Versioning, change, and post-deployment monitoring

You version the documentation with the system, record the relevant changes made across its lifecycle, and have a plan to monitor how it performs once it is in use. (Annex IV(6) and (9); Article 72; ISO/IEC 42001:2023 lifecycle expectations.)

Third-party components, standards, and resources

You identify the third-party tools, pre-trained or general-purpose models, and other externally-sourced components the system relies on, the standards or alternative solutions you applied, and, for larger models, the computational resources used. (Annex IV(2) and (7); Annex XI computational resources.)

What goes into AI documentation, and which rule asks for it

AI documentation is not one document. Three sources shape what a complete record holds: the EU AI Act's Annex IV (the technical documentation a high-risk system needs under Article 11), its Annex XI (what a general-purpose AI model provider documents under Article 53), and ISO/IEC 42001:2023 (the management system that keeps the documentation maintained). The areas in this checker map to those, grouped by documentation domain. The mapping below is our plain-English summary of the requirement structure, not a reproduction of the text.

Documentation domainWhat a complete record holdsPrimary anchor
Purpose and intended useWhat the system is for, who uses it and in what context, its version and acceptable use, and the misuse it is not for.EU AI Act Annex IV(1); Annex XI model description
Data and datasetsWhere the training, validation, and test data came from, how the datasets were built and labelled, and how quality and bias were examined.EU AI Act Annex IV(2), Article 10; Annex XI data information
Model design and performanceThe key design choices and architecture, the metrics and evaluation results, and the known limitations and expected accuracy.EU AI Act Annex IV(2)-(4); Annex XI architecture and evaluation
Risk, oversight, and transparencyThe risks to people and their mitigations, the human-oversight measures, and the instructions given to the people who use the system.EU AI Act Annex IV(5), Articles 9, 13, 14
Lifecycle, security, and provenanceRobustness and cybersecurity measures, versioning and post-deployment monitoring, and the third-party components and standards relied on.EU AI Act Annex IV(2), (6), (7), (9), Articles 15, 72; ISO/IEC 42001:2023

Primary sources

  • EU AI Act, Regulation (EU) 2024/1689 Annex IV (technical documentation for high-risk systems, Article 11), Annex XI (general-purpose AI model documentation, Article 53), and Articles 9, 10, 13, 14, 15, and 72. (checked 2026-06-25)
  • ISO/IEC 42001:2023, Artificial intelligence management system The international AI management system standard whose data, transparency, and lifecycle expectations the same documentation supports. Full text is published by ISO and national standards bodies. (checked 2026-06-25)

Jurisdiction: EU (Regulation (EU) 2024/1689) and international (ISO/IEC 42001:2023). The EU AI Act binds providers and deployers of in-scope AI systems placed on or used in the EU market; ISO/IEC 42001 is a voluntary international standard.

Important

This tool gives a structured self-assessment to orient the documentation of a single AI model or system. It is not legal advice, not an audit, and not a conformity assessment. Whether the EU AI Act applies to your system, and which obligations follow, depends on your system's risk classification and your role (provider, deployer); some requirements, including the full conformity-assessment route for high-risk systems, are not captured by this questionnaire. Confirm your obligations against the primary sources and, where needed, a competent adviser.

FAQ

How is this different from your EU AI Act risk checker?

The risk checker answers a prior question: what risk tier is your AI system under the EU AI Act (prohibited, high-risk, limited, minimal), and what role obligations follow. This checker assumes you already have documentation duties and scores how complete the documentation itself is. Use the risk checker first; use this once you are writing the technical-documentation file.

How is this different from your ISO 42001 readiness checker?

The ISO 42001 readiness checker scores your organisation-wide AI management system against the management-system clauses 4 to 10. This checker scores the documentation of one specific model or system at the artifact level (its model card, dataset datasheet, and technical file). The two are complementary: the management system is how documentation like this gets produced and kept current.

Does a high score mean my system is EU AI Act compliant?

No. This is a self-assessment of documentation completeness for one system. EU AI Act conformity for a high-risk system depends on the actual content of the documentation, the conformity-assessment route, and other obligations that a questionnaire cannot determine. Treat the result as a drafting aid, not a compliance statement.

We only build a general-purpose AI model. Is this still useful?

Yes. The areas reflect Annex XI as well as Annex IV, so the data, architecture, evaluation, compute, and acceptable-use areas line up with what a general-purpose AI model provider documents under Article 53. The same areas also match ordinary model-card and dataset-datasheet practice, so the tool is useful even where the Act does not apply to you.

Are these the official Annex IV or ISO clause headings?

No. We deliberately do not reproduce EU AI Act normative text or ISO/IEC 42001:2023 clause and control titles. Each area is our own plain-English description, anchored only by the Annex or Article number. Consult the primary sources for the official wording.

Do you store my answers?

No. Scoring runs entirely in your browser. There is no form gate; the JSON and CSV exports and the printable report are generated locally on your device.

By ISMS Copilot.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.