Role
Compliance officer
Holding the map: which of these instruments reaches your organisation, in which capacity, and on what date.
§ 1 — What you carry
Where the duty attaches
A compliance function rarely occupies one capacity. The same organisation is commonly a deployer of systems it bought, a provider of one it built or rebranded, and the audited organisation when someone comes to look — and the obligations differ in each, including the ones that look like duplicates.
What this page is for is the capacity question, which is the one that decides everything else. Substantially modifying a system you bought can make you its provider; putting your name on it certainly does. The duties that follow are not the ones you were tracking the week before.
Also written as head of compliance, regulatory compliance manager. Everything below is drawn from the obligation dataset by the capacity that binds this role, not by job title — 4 provisions across 1 collection.
§ 3 — Evidence
The artefacts this role owns
Drawn from the evidence column of the provisions above, most widely demanded first. These are what an assessor asks this role to produce.
- 1xA dated residual-risk acceptance decision
- 1xA named oversight assignment, with the competence behind it
- 1xA risk management plan tied to a named system and release
- 1xA suspension decision, or a recorded decision not to suspend
- 1xCybersecurity measures addressing AI-specific attack surfaces
- 1xDeclared accuracy levels and metrics in the instructions for use
- 1xEvidence that post-market data re-entered the process
- 1xFeedback-loop mitigation records for systems that continue to learn
- 1xGovernance that visibly moved after the assessment
- 1xInput-data controls where the deployer supplies the data
- 1xNotification to the market surveillance authority
- 1xReview records from more than one point in the lifecycle
§ 4 — Ahead
What lands next
2 December 2027
2 December 2027
Article 26 — Obligations of deployers of high-risk AI systems
2 December 2027
Article 27 — Fundamental rights impact assessment for high-risk AI systems
2 December 2027
2 August 2028
2 August 2028
Article 26 — Obligations of deployers of high-risk AI systems
2 August 2028
§ 5 — Examined in
Where this is examined
Read from the syllabus entries the provisions above actually carry, not matched by job title. The count is how many of this role's obligations each credential examines, so you can see how much of the role it covers.
- Certified AI Compliance Fundamentals — EU AI Act
Examines 4 of the 4 provisions above, under High-risk obligations and conformity, Roles and duties.
- Certified AI Assurance Public Sector Fundamentals
Examines 2 of the 4 provisions above, under Impact and risk assessment, Public-sector AI use and accountability.
- Certified AI Audit Fundamentals
Examines 2 of the 4 provisions above, under Control identification and testing, Evidence and working papers.
- Certified AI Assurance Employment Fundamentals
Examines 1 of the 4 provisions above, under Notice, transparency, and records.