WHAT THE ARTICLE IS ABOUT
The transparency and reporting obligations of notified bodies
Article 45 establishes what notified bodies must report and to whom. It creates a comprehensive information-sharing framework that enables national authorities, the Commission, and other notified bodies to maintain an accurate picture of conformity assessment activity across the EU — detecting inconsistencies, identifying systemic issues, and maintaining the integrity of the certificate system.
WHAT IT SAYS
Report certificates issued, refused, suspended and withdrawn
- Notified bodies must inform their notifying authority of all certificates they issue, including quality management system approvals and technical documentation assessment certificates
- They must also report all refusals, restrictions, suspensions and withdrawals of certificates — not just successful issuances
- They must report any circumstances that affect the scope or conditions of their notification
- They must report any requests they receive from market surveillance authorities regarding conformity assessment activities
- On request, they must report all conformity assessment activities performed, including cross-border activities and subcontracting arrangements
- Notified bodies must share information with other notified bodies conducting similar assessments — including information on negative assessment results — while maintaining confidentiality
- All information sharing is subject to the confidentiality obligations of Article 78
WHO IS AFFECTED
Notified bodies and the authorities they report to
- All notified bodies designated under the AI Act — reporting obligations apply to all assessment activities
- Notifying authorities who receive and process the reports
- The Commission and other member states who receive notification of significant decisions
- Other notified bodies who receive information on negative assessment results
- Providers indirectly — the information sharing system helps catch inconsistent assessments that might otherwise disadvantage compliant providers
WHAT IT MEANS FOR SMES
Transparency that protects providers from inconsistent treatment
- The negative result sharing obligation is the most practically significant provision for providers: if a notified body refuses to certify a particular type of AI system, other bodies are informed — preventing providers from shopping for a more lenient assessor without addressing the underlying issue
- The reporting requirement also creates accountability: a notified body that issues certificates too liberally or too restrictively will be visible to the system through the pattern of its reports
- Confidentiality is protected: while assessment outcomes are shared between bodies and authorities, commercial details of your AI system are subject to the Article 78 confidentiality obligations
- If you suspect you have been treated inconsistently compared to other providers, the information-sharing framework under this article is the systemic mechanism that should catch this — raise concerns with your notifying authority
Related Articles
- Article 44 — Certificates (the documents whose issuance and withdrawal must be reported)
- Article 38 — Coordination of notified bodies (the broader coordination framework this article feeds into)
- Article 78 — Confidentiality (the protection that applies to all information shared under this article)
- Article 35 — NANDO register (the public-facing output of the information-sharing system)
