What conformity assessment is
Conformity assessment is the procedure by which a provider demonstrates that a high-risk system meets the Articles 8 to 15 requirements, before it is placed on the market or put into service.
The concept is borrowed wholesale from EU product safety law rather than invented for AI, which is useful context: anyone who has taken a medical device or a piece of machinery to market recognises the whole apparatus, and the vocabulary of notified bodies, declarations of conformity and CE marking is the same vocabulary.
What is genuinely new is applying it to software whose behaviour is statistical rather than deterministic, and which can change after it ships. That mismatch produces most of the awkwardness in this part of the Act: a conformity assessment is a point-in-time judgement about a system that may not stay the same.
The Act's answer is the substantial modification concept, which forces reassessment when the system changes in ways that matter, and post-market monitoring, which keeps the provider looking. Both are covered below.
One clarification first: this is a provider obligation. A deployer of a purchased high-risk system does not carry out conformity assessment.

