Start with risk classification
Every other documentation requirement flows from where your system sits on the Act's risk tiers. A system misclassified as limited-risk when it's actually high-risk isn't just non-compliant—it's missing the entire audit trail regulators will expect to see.
Risk classification isn't a one-time exercise either: a system's classification can change as its use case, deployment context or autonomy expands, so it needs to be revisited alongside every material change to how the system is used.