AI Guide

Notified Body (EU AI Act): The independent certifier behind third-party AI conformity checks

A notified body is an independent conformity assessment organization that an EU member state designates to test and certify certain high-risk AI systems before they reach the market. Only a narrow slice of high-risk AI needs this third-party route; most systems clear the EU AI Act through the provider's own internal control instead. This article explains how bodies get designated, what they check, and what German Mittelstand providers need to know before engaging one.

Key Facts
  • A notified body is an independent conformity assessment body designated by an EU member state's notifying authority and listed in the European Commission's NANDO database under EU AI Act Article 35.
  • Only remote biometric identification systems and high-risk AI embedded as a safety component in an already-regulated product, such as machinery or medical devices, require notified body assessment under Annex VII; most Annex III systems use internal control under Annex VI instead.
  • Germany's draft KI-Marktüberwachungs- und Innovationsförderungsgesetz, approved by the Cabinet in February 2026, designates the Bundesnetzagentur as the national notifying authority, with DAkkS supporting technical accreditation of candidate bodies.
  • Bitkom's 2026 AI study found 85% of German SMEs have no documented inventory of the AI systems they operate, making it hard for many to know in advance whether a notified body review applies to them.
  • Cloud Security Alliance's March 2026 research note found more than half of organizations still lack a systematic AI system inventory, the same gap that leaves notified body capacity planning largely reactive across the market.

Definition: Notified Body (EU AI Act)

A notified body is an independent conformity assessment organization that an EU member state’s notifying authority designates and lists with the European Commission to test, audit, and certify certain high-risk AI systems before they reach the EU market under the EU AI Act.

Core characteristics of notified body

A notified body is the certifying actor, not the process itself: the organization a provider submits documentation to and receives a certificate from.

  • Designated by a national notifying authority and formally notified to the European Commission
  • Listed with a unique identification number in the NANDO database
  • Audits the quality management system and tests the AI system where necessary
  • Issues a certificate that is the legal precondition for CE marking

Notified Body vs. Conformity Assessment

Conformity assessment is the overall procedure a provider completes before market placement; a notified body is one possible actor inside it, not the procedure itself. Most high-risk systems clear assessment through internal control, with no external body involved. A notified body only enters the picture for the narrower set of systems Annex VII routes to third-party review.

Importance of notified body in enterprise AI

Whether a provider needs a notified body determines the timeline and external dependency of reaching market, since scheduling sits outside routine AI compliance work. Bitkom’s 2026 AI study found 85% of German SMEs have no documented AI system inventory, so many cannot yet say whether this path applies to them.

Methods and procedures for notified body

Getting designated, and getting assessed, follows a defined legal sequence.

Designation and accreditation

A conformity assessment body applies to its notifying authority, which verifies Article 31’s independence and competence requirements, usually via accreditation.

  • Body submits an accreditation certificate, or documentary evidence where none exists
  • Notifying authority verifies compliance and notifies the Commission
  • Commission assigns an identification number and adds the body to the NANDO list

Scope of conformity assessment activities

A certificate covers only the AI system types and modules named in its own notification. The body checks technical documentation, audits the quality management system, and tests the system directly where the risk profile warrants it.

Ongoing monitoring and certificate validity

Certification is not one-time. A notified body reassesses the system after any substantial modification and periodically audits the provider’s quality management practices to keep the certificate valid.

Important KPIs for notified body

Providers depending on a notified body track different indicators than those on the internal control route.

Engagement and scheduling metrics

  • Lead time from application to booked audit: target weeks, not months
  • Engagement rate: percentage of Annex VII systems with a body under contract
  • Documentation rework requests per assessment cycle
  • Time from submitted technical file to issued certificate

Strategic capacity risk

Because few bodies hold a full AI Act designation, tracking availability is a board-level risk metric for providers of biometric or product-embedded high-risk AI. Cloud Security Alliance’s March 2026 research note found more than half of organizations still lack a systematic AI system inventory, leaving demand forecasting reactive.

Certificate and audit quality

Teams should track how often a notified body flags documentation gaps versus accepting the file as submitted. Repeated rework signals documentation written for an internal checklist rather than what the body actually tests.

Risk factors and controls for notified body

Misjudging whether a notified body is required

The most common error is assuming internal control applies when a system is actually a safety component of a regulated product.

  • Confirm whether the system is a standalone use case or embedded in a regulated product
  • Re-check the routing decision whenever the host product’s own certification changes
  • Document the classification with legal sign-off, not an engineering assumption

Capacity bottleneck and lead times

Designation of AI Act notified bodies has lagged demand, echoing the backlog after the EU Medical Device Regulation’s rollout. Providers that genuinely need Annex VII review should apply for a slot well ahead of any launch date.

Engaging a body outside its notified scope

A certificate is valid only for the system types listed in its own NANDO entry. Engaging a body outside that scope produces a certificate that will not hold up under market surveillance.

Practical example

A 130-employee manufacturer of AI-assisted diagnostic imaging software near Erlangen builds a module that flags suspicious findings in radiology scans, shipped as a safety component inside medical imaging devices already certified under the Medical Device Regulation. Because the module sits inside a regulated product, it needs notified body assessment rather than internal control. The team engaged a notified body already active under that regulation more than a year before launch, anticipating scheduling constraints.

  • Technical documentation covering training data and validation testing shared with the notified body
  • Quality management system audit scheduled months ahead of the target CE marking date
  • Change-control process flagging modifications that require reassessment
  • Joint certification timeline for both regulations tracked by one compliance owner

Current developments and effects

Three developments are shaping how providers plan around notified bodies in 2026.

National designation processes remain slow

Member states are still building notifying authority infrastructure, and few bodies hold a full AI Act designation as of mid-2026.

  • Germany’s draft KI-MIG designates the Bundesnetzagentur as notifying authority, with DAkkS supporting accreditation
  • Established bodies such as TÜV and DEKRA entities are expected to seek AI Act designation
  • The NANDO database remains the only authoritative source for a body’s current status

Capacity bottleneck echoes earlier EU product law rollouts

Industry observers warn that the shortage of accredited AI Act notified bodies mirrors the backlog after the Medical Device Regulation and In Vitro Diagnostic Regulation took effect.

Digital Omnibus postponement does not remove the requirement

The Digital Omnibus pushed most Annex III obligations to December 2027, but Annex VII systems embedded in regulated products still align with their host product’s own certification deadlines, some as early as August 2028.

Conclusion

A notified body is the accredited, independent actor the EU AI Act inserts into the narrow set of assessments that genuinely warrant outside scrutiny, not a universal checkpoint every high-risk system must pass. Knowing whether a system actually needs one decides whether a Mittelstand provider manages an internal documentation project or an external dependency with its own timeline. The designation landscape is still maturing and capacity constraints are real, making early engagement a genuine advantage. Providers that map their exposure now avoid discovering the requirement only once a launch date is at risk.

Frequently Asked Questions

What does a notified body actually check during an assessment?

It reviews technical documentation against Article 11, audits the quality management system, and tests the system where warranted. It issues a certificate only once these checks confirm compliance.

Does our company need a notified body, or can we self-assess?

Most Annex III systems qualify for internal control, where the provider assesses its own compliance. Only remote biometric identification systems and AI embedded in an already-regulated product need a notified body.

What does working with a notified body cost and how long does it take for a Mittelstand company?

Costs include audit and certification fees plus internal time preparing documentation, and totals vary with system complexity. Timelines currently run to several months given limited capacity, so apply well before the intended launch date.

Is there funding support available for notified body costs in the Mittelstand?

Some German digitalization and compliance funding programs, typically run through KfW or state-level schemes, can offset consulting and audit costs tied to certification, though dedicated funding lines remain limited as of 2026.

Do we need our own IT team to interact with a notified body?

No. Most providers combine internal product and legal staff with an external compliance partner. Companies like Superkind that build custom AI agents connected to enterprise systems already document data flows and oversight points as part of the build, giving a review a ready evidence base.

How does a notified body relate to market surveillance authorities like the Bundesnetzagentur?

A notified body certifies a system before it reaches the market; a market surveillance authority monitors compliance afterward and can demand documentation at any time. Passing assessment does not exempt a provider from later scrutiny, and effective AI governance plus strong post-market monitoring keep a system defensible once live.

Building better software Contact us together