VeritomeHelp Centre
/
Browse documentation
Programmes

Coverage and the auditor: the matrix, the seat, the pack

Frameworks → Coverage shows every requirement and the workflow assigned to it. Give your auditor a read-only seat and the records; the certificate comes from them, not from us.

Updated Veritome documentation

Frameworks → Coverage is the requirement-by-requirement map for a programme: each catalogue clause, the step assigned to it, the record that step produces, and one of three states — Workflow assigned, addressed in the SoA only, or a gap. A gap is a build failure on our side, not something hidden from you: a test holds every clause in every catalogue claimed by some step, so the column exists to prove the absence of gaps rather than to list them.

"Workflow assigned" is deliberately not "covered". It says a step exists for the clause. Whether the clause is done comes from that step's record being approved, and the programme card and the Controls screen are where that shows.

The auditor's seat

Invite your auditor with the Auditor role under Organisation → Members & roles. An Auditor reads everything — the register, the records, the evidence with its hash chain — and changes nothing. Scope the invitation to the engagement and remove it afterwards; the Audit trail records both.

What to hand over

There is no single "readiness pack" button. What exists is more useful, because each piece is a record with a hash:

  • The readiness report step near the end of each ISO programme — the organisation's own account of Stage 1 readiness, approved like any other record.
  • The sealed Statement of Applicability PDF from Documents.
  • The Coverage matrix as CSV.
  • Per system, the EU AI Act audit bundle from Reports, with a SHA-256 manifest of every document it contains.
  • For NIST AI RMF, the generated profile PDF.

Recording the outcome

Certification is a fact you record, never one the product derives. On the programme card an admin enters the certification body, the certificate reference and the next surveillance audit date; the programme status moves to Certified only by that entry.

Who signs the certificate

Not Veritome. Accredited certification bodies work under ISO/IEC 17021-1, and ISO/IEC 17021-1 §5.2.5 keeps consultancy and certification apart: a certification body may not provide management-system consultancy, and may not certify a system where its own consultancy would compromise its impartiality. We are on the consulting side of that line by design. The certificate comes from an accredited body, on the strength of the evidence you show them — and it attests to the management system, not to conformity with the EU AI Act.