Template
EU AI Act Article 16 - Provider Obligations Template
Article 16 is where the provider's operational duties are gathered together. The point is not only to have technical documentation, but to show that the provider can keep required materials available, keep logs, take corrective action, and cooperate with authorities when needed.
Technical contribution: Evidence-backed scaffold
Who supplies what
What Article 16 expects, what the template can add, and what your team still owns
This page structures the provider-side written record for Article 16. It does not replace the actual organizational duties or approvals that the law places on the provider.
| Article 16 expects | What the template can add | What your team still has to write | Practical output to keep |
|---|---|---|---|
| Documentation keeping under Articles 16 and 18 | A section shell for technical documentation, QMS records, and retained conformity records. | Describe how these materials are kept available for 10 years after the system is placed on the market or put into service. | A documentation-keeping note. |
| Automatically generated logs under Articles 16 and 19 | Prompts for log retention and retrieval. | Record which automatically generated logs are under provider control and how they are kept for at least six months or longer if another law requires it. | A log-retention note. |
| Corrective actions and duty of information under Article 20 | Prompts for corrective-action handling and notification duties. | Record how the provider brings the system into conformity, when withdrawal, disabling, or recall is used, and who is informed without undue delay. | A corrective-action procedure summary. |
| Cooperation with competent authorities under Article 21 | A place to state how requests, documentation, and log access are handled. | Describe the actual cooperation path used by the provider, including how information is supplied in an easily understood language and how access to logs is granted where they are under provider control. | A short authority-cooperation note. |
| Registration, declaration, marking, and related provider duties | Cross-links to conformity and declaration sections. | Record which provider-side duties are completed elsewhere in the package and who approves them. | A cross-reference note inside the package. |
| CE marking under Article 48 | A place to record how the marking is applied or made digitally accessible. | Record where the CE marking appears, whether it is digital, and whether notified-body identification must accompany it. | A CE-marking note. |
| Registration under Article 49 | A place to record the registration route where it applies. | Record whether registration applies, which register is used, and the retained reference for the relevant AI system. | A registration note. |
Manual fields
What your team still adds to Article 16
The template can structure the provider-obligations section, but it cannot supply your retention process, corrective-action workflow, or authority response path.
| What you add | Why it is required | Practical format to use |
|---|---|---|
| Documentation keeping process | Articles 16 and 18 require the provider to keep documentation and related records available. | A short note naming the repository, versioning control, and 10-year retention path. |
| Log-retention and retrieval process | Articles 16 and 19 require automatically generated logs to be kept where they are under provider control. | A short note naming the logs kept, retention period, and retrieval path. |
| Corrective-action and notification workflow | Article 20 requires corrective action and duty-to-inform when non-conformity or risk appears. | A step-by-step internal escalation and notification note. |
| Authority cooperation contact path | Article 21 requires cooperation with competent authorities and access to logs where applicable. | A named contact and escalation path, plus the documentation and log-access route. |
| Cross-reference to conformity and declaration work | Article 16 sits alongside the conformity and declaration duties. | A short note linking to the related sections in the package. |
| CE-marking record | Article 48 requires the provider to affix CE marking in the required form. | A short note naming where the CE marking appears and how it is accessed. |
| Registration record | Article 49 requires registration where that article applies. | A short note naming the register, reference, and responsible owner. |
FAQ
Frequently asked questions
What is the Article 16 - Provider Obligations template page for?
This page explains what the Article 16 - Provider Obligations template section usually needs to cover inside an EU AI Act package, which parts can be supported by structured evidence, and which parts remain owned by the provider, deployer, or legal reviewer.
Does this Article 16 - Provider Obligations template page create a complete EU AI Act package?
No. It is one section-level guide. A review-ready package still needs the selected role and scope, the other applicable article-level sections, linked technical evidence, owner completion, and final human review.
What evidence should be linked to the Article 16 - Provider Obligations template section?
Use evidence that is current, traceable to the relevant system version, and connected to real runs, retained records, or approved procedures. A weak package relies only on narrative text; a stronger package links the narrative to reproducible artifacts.
Who should review the Article 16 - Provider Obligations template section before handoff?
The technical owner should confirm the system facts and evidence links, while compliance or legal reviewers confirm whether the section is sufficient for the selected EU AI Act role, scope, and conformity path.