What a mixed estate does to a spreadsheet.
One register, a role per system.
Three estates that hold both roles.
A SaaS company shipping an AI feature and running bought tools internally.
- Provider for the shipped feature: Annex IV, conformity, CE, Art. 49 registration.
- Deployer for the CV screener HR bought: Art. 26 oversight, logs, worker notice.
- One register, one audit trail, two obligation sets that never mix.
- Art. 4 literacy spans both, because it attaches to the organisation.
A consultancy reselling a partner's model under its own brand.
- Art. 25(1)(a) makes them the provider of the branded system.
- They remain a deployer of everything else they use internally.
- The partner's documentation is an input to their file, not a substitute.
- The role change is recorded with its date and reasoning.
A manufacturer importing a component model and embedding it in a product.
- Importer duties under Art. 23 for what crosses the border.
- Provider duties for the finished product placed under their own name.
- The ten-year Art. 23(5) retention runs alongside the provider file.
- Both sets derive from the same register rather than two programmes.
The parts a mixed estate reaches for.
Straight answers for a mixed estate.
Can one organisation really be a provider and a deployer at once?
Yes, and most are. Role attaches to a system, not to a company. You are a deployer of the vendor tools you use and a provider of anything you build or brand. The register holds a role per system and derives each obligation set independently, so neither journey contaminates the other.
What changes when a system moves from deployer to provider?
Everything about that system's duty list. Article 25(1) triggers on branding, substantial modification, or a change of intended purpose into high-risk. At that point the provider set — risk management, Annex IV, the QMS, conformity assessment, CE marking, registration and post-market monitoring — attaches to you, and the original provider's obligations for that system fall away.
Do we pay for both roles?
Plans follow the roles your estate actually holds, and the pricing page states it in full. What matters here is that holding both roles does not mean running two products: it is one register, one audit trail and one evidence base.
How do we stop the two journeys from confusing people?
The obligation engine is the single source of what applies. A deployer system never shows an Annex IV tab; a provider system never shows a worker-notification duty it does not have. Nobody has to remember which rules belong to which system, because the screens for that system only carry its own.
What if we are not sure which role a system holds?
That is the normal starting position and the reason the check exists. Eight questions for most systems — including the branding and modification questions that decide Article 25 — produce the role, the risk class and the obligations, each citing the article it rests on.


