VeritomeHelp Center
/
Help center
Help center

Using Veritome

By what you do: classify, work obligations, evidence, reports.
22 ARTICLES
01
Classify a system: risk tier, role and the wizard steps
Classification decides your risk tier and role — which together decide how much you must do. Here are the five wizard steps and how the derogation works.
02
Scope obligations and assign owners
After classification, confirm which derived obligations genuinely apply, mark the rest not applicable, put a named owner on each, and settle your Art. 4 literacy duty.
03
Work an obligation: board, checklists, evidence, owners
Drive obligations from the Kanban workbench or a system tab: change status, work the four-eyes flow, fill auto-saving smart forms, tick checklist items with notes and evidence.
04
The six-phase compliance journey
Every system moves through six gate-locked phases — Classify, Scope & literacy, Implement, Assess, Register, Monitor — and empty phases never block.
05
How the compliance score is calculated
The score is phase-weighted — implementation carries 45 of 100 points — with priority weighting inside each phase and a hard zero for prohibited systems.
06
Risk register, Art. 9 risks and review schedules
Log and score Art. 9 risks with the guided wizard, run Art. 27 FRIAs, and complete scheduled reviews that leave a tamper-evident entry in the regulator dossier.
07
Ask Aria: what the assistant can and can't do
Aria answers EU AI Act questions using your compliance context, runs on EU-hosted Mistral, drafts first passes, and never submits anything to a regulator on its own.
08
Supply chain: instructions for use and pre-market checks
How the Art. 13 IFU hands off from provider to deployer, and the Art. 23 importer and Art. 24 distributor checks — all on the system's Supply chain tab.
09
The Evidence hub: coverage, uploads, connectors and freshness
Read coverage and gaps across the portfolio, upload hash-deduplicated files, pull proof in with read-only OAuth connectors, and track expiry so stale evidence is flagged.
10
Attach evidence and verify generated documents
Attach hash-sealed evidence to obligations, and generate Annex IV, FRIA and Declaration of Conformity documents that each carry a public verify URL.
11
Report a serious incident to the right authority
Veritome resolves the competent authority for the member state, tracks the Art. 73 deadline (2 / 10 / 15 days), runs four-eyes approval, and drafts the notification — you review and send.
12
AI literacy: satisfying Article 4
Art. 4 applies to every provider and deployer since 2 Feb 2025 — match staff to role-based programmes, enrol and track them, and issue certificates that flow through as evidence.
13
Dossiers, tech docs and the regulator view
The classification dossier is a hash-linked chain of custody; the regulator view is the 'open the books' surface; the audit bundle is one sealed PDF with a SHA-256 integrity manifest.
14
Reports, CSV export and audit bundles
Generate audience-specific PDF reports, export the compliance matrix as CSV, build a per-system audit bundle, and schedule any template to self-generate on a cadence.
15
The compliance calendar and deadlines
The calendar aggregates every dated obligation, review, incident clock and statutory milestone — filter it, subscribe to a live feed, and complete reviews from it.
16
Quality Management (QMS): ISO/IEC 42001 controls and Art. 17
Stand up an AI management system on the ISO/IEC 42001 Annex A control catalog, track control status across four lifecycle groups, and let completed controls tick your Art. 17 checklists automatically.
17
Data Governance: Art. 10 dataset practices per system
The portfolio view of Article 10: training/validation/testing data provenance, representativeness, bias controls and residency for every high-risk system, with completion rolled up per system.
18
Transparency notices: Art. 50 disclosure duties
Track the Article 50 duties for systems that talk to people, read emotions, or generate synthetic content — chatbot disclosure, deepfake labelling, emotion-recognition notification — and generate the notices.
19
Human oversight: Art. 14 measures and the deployer's Art. 26(2) duties
Record who can intervene in each high-risk system, how the stop mechanism works, and how automation bias is countered — the provider designs the measures, the deployer assigns and equips the people.
20
Post-market monitoring: the Art. 72 plan and the monitoring cycle
After deployment the work continues: a monitoring plan per high-risk system, recurring reviews on the calendar, and the paper trail that connects field experience back into risk management.
21
Regulatory watch: track changes, decide, and leave a trail
Delegated acts, guidance, harmonised standards and national implementation — logged by your team in a change register: assess relevance, record the decision, and turn planned actions into scheduled reviews.
22
GPAI disclosures: the Art. 53/55 workspace
For general-purpose model providers: downstream model documentation, the copyright policy, the training-data summary — and the extra Art. 55 layer when a model carries systemic risk.