VeritomeHelp Centre
/
Browse documentation
Programmes

Overlap credit: done by overlap, never done twice

A record that satisfies a clause in two frameworks is one record. A step whose every requirement is already evidenced elsewhere is marked done by overlap — with the record that did it.

Updated Veritome documentation

The reason to run five frameworks in one register is that they ask for the same things in different words. Veritome gives credit across them in two ways — and refuses to in a third, which is worth knowing.

One record, two programmes

Some templates are placed in two programmes: the clause 4–10 records ISO/IEC 42001 and ISO/IEC 27001 share — context, interested parties, roles, risk, objectives, change, competence, communication, documented information, operational control, monitoring, internal audit, management review, corrective action. Such a record has an information-security section alongside its AI-management questions. Complete the step once and it is complete in both. Nothing is copied; there is one record, and approving it re-plans the sibling programme.

Done by overlap

A step whose every requirement for its framework is already credited — by an EU AI Act obligation you completed with verified evidence, or by an approved step in another programme — is marked Done by overlap, and the drawer names the records that did it. Partial credit does not close a step: if one of its requirements is uncovered, the step stays open and says which requirement is missing.

Where the credit comes from

Credit is read from the one coverage function the Controls screen and the Coverage matrix use. Two sources feed it:

  • Your controls — a control with verified evidence credits every requirement it is linked to.
  • Your EU AI Act journey — an engine obligation with verified evidence is folded in as if it were a control, so the crosswalk credits the ISO/IEC 42001 requirements it maps to without you minting a control per obligation.

That crosswalk runs one way: the EU AI Act journey credits the standards. No programme record files evidence against an EU AI Act obligation, and the drawer's Related links credit nothing in either direction. There is one definition of "covered" in the product, so the programme card, the matrix and the control never disagree.

What is not credit: the Act's own reuse routes

The EU AI Act itself says, in six places, that work you have already done counts — Art. 27(4) lets a fundamental-rights impact assessment draw on the GDPR DPIA; Art. 26(9) says a deployer uses the provider's instructions for use in that DPIA; Art. 8(2), Art. 17(3), Art. 17(4) and Art. 26(5) let documentation, quality management and monitoring sit inside procedures other Union law already requires. Veritome shows those routes on the obligation and prefills from them. They never count toward coverage, a percentage or the Statement of Applicability, and they never change an obligation's status: whether your internal governance rules genuinely reach the Act's requirement is not a fact the product can see, so you declare reliance and the status stays yours. See DPIA overlap.

What this means for effort

The number of steps a programme skips depends on what you have already done. The programme card shows it; this help centre deliberately does not quote a figure, because yours will differ.