SCRM Supplier Compliance & Risk Management

Home

Regulation (EU) 2024/1689 · staggered application

With an AI model, liability does not stop at whoever built it.

The AI Act spreads duties across the chain: providers, deployers, importers, distributors. Using a system means knowing what you are using – and being able to evidence it.

The AI Regulation classifies systems by risk and attaches duties accordingly. High-risk systems require conformity assessment, technical documentation, logging and human oversight; general-purpose models carry their own transparency duties towards downstream providers.

For Swiss companies the reach is wider than it first appears: among other triggers, it matters whether a system’s output is used in the EU. And beyond that the chain carries on – supply an AI component and your EU customer will ask for documentation.

Where the chain bites

  • Providers placing an AI system on the market under their own name – even when someone else’s model sits inside.
  • Deployers using a system professionally, who must maintain oversight and logs.
  • Suppliers of models, training data and components through information duties to downstream providers.
  • Companies that substantially modify a bought-in system and thereby become providers themselves.

What the chain must supply

Classification
Establish whether a deployed system counts as high-risk – unanswerable without provider information.
Documentation
Obtain and retain technical documentation and instructions for use.
Data provenance
Understand what a model was trained on and what usage rights exist.
Oversight
Organise human oversight and keep logs of use.
Changes
Record the provider’s model and version changes – they can alter the classification.

How SCRM covers it

Provider per AI component

Model, platform and data source as separate records with an owner.

Documents with validity

Documentation and declarations dated, so the version in use at a given time stays provable.

Changes as events

A silent model switch becomes visible instead of passing unnoticed.

Classification recorded

“Not high-risk” is evidence too, with its reasoning.

Frequently asked

Does the AI Act apply to Swiss companies?

Not as domestic law. It bites where, among other triggers, a system’s output is used in the EU – and in practice through customer contracts. Your own position needs case-by-case legal assessment.

What separates a provider from a deployer?

A provider places on the market, a deployer uses. Substantially modifying a bought-in system or offering it under your own name switches the role – with considerably more duties.

How does this relate to ISO/IEC 42001?

The AI Act is law, the standard a management system. A system run to 42001 eases the evidence but does not replace legal assessment.

As of July 2026. Application is staggered; the deadlines in force govern. Not legal advice.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required