Report a serious incident to the right authority
Veritome resolves the competent authority for the member state, tracks the Art. 73 deadline (2 / 10 / 15 days), runs four-eyes approval, and drafts the notification — you review and send.
Compliance doesn't stop at launch. The Act requires you to keep watching a high-risk system once it's live, and to react fast when something goes wrong.
Article 72 — post-market monitoring
Providers must run a post-market monitoring system: actively collect and review data on how the system performs in the real world, throughout its lifetime, and feed what you learn back into the risk-management system (Art. 9). In Veritome this is a recurring activity — the Post-market monitoring tab on each high-risk system carries the monitoring obligations and their evidence, checkpoints appear on the Calendar as dated, owned events, and what you find feeds the Risk Register.
Article 73 — reporting a serious incident
A serious incident is a death or serious harm to health, a serious and irreversible disruption to critical infrastructure, an infringement of fundamental-rights obligations, or serious harm to property or the environment. The clock is tiered and counted in calendar days from the moment you become aware (Art. 73(2)–(4)):
| Deadline | When it applies |
|---|---|
| 2 days | Widespread infringement, or serious/irreversible disruption of critical infrastructure |
| 10 days | Where a death is involved |
| 15 days | Any other serious incident (report without undue delay, and no later than this) |
To raise one:
- Go to Incidents and click Report serious incident, or open the Incidents tab of a specific system.
- Read the reporting-authority banner: it names the market-surveillance authority for the Member State where the incident occurred, with its designation status and a link to the Commission's list. It defaults to your organisation's country.
- Pick the incident type (the Art. 3(49) categories) — your choice sets the reporting clock; short-clock types show an amber warning.
- Under When & where, enter the incident date & time, the date you became aware (the clock runs from awareness), and the Member State where it occurred.
- Set the causal link footing: established, reasonably likely, or under assessment. The duty to report attaches as soon as a link is reasonably likely — you don't wait for certainty.
- Fill the details (persons affected, categories, what happened, harm) and the response (immediate and corrective actions, whether the system was withdrawn, whether the provider was notified).
- Choose the report type — initial (Art. 73(5)), follow-up or final — and confirm the reporting contact.
- Click Save incident report. This starts the notification countdown, which also lands on your Calendar.
Four-eyes approval and sending
Before the report leaves for the authority, a second person — an admin or compliance manager who did not draft it — reviews and approves it. In the Four-eyes approval card an eligible approver clicks Approve report, which also mints the report into the Evidence ledger. Use the incident copilot if you want Aria to draft the notification, and the authority router to resolve the competent authority and record that a human sent it. A person always reviews and sends — Veritome never submits to a regulator automatically.
Working the register
Incidents lists every serious incident across the estate, ordered by reporting deadline, with KPIs for Total, Open, Short-clock (2 / 10 days) and This month. The status flow runs Reported → Under investigation → Notified to authority → Closed; the countdown is satisfied once the authority is notified. The notification checklist tracks the three things that must be true: provider notified, report approved (four-eyes), authority notified. File a final report to close out the notification, then move the incident to Closed.