Dossiers, tech docs and the regulator view
The classification dossier is a hash-linked chain of custody; the regulator view is the 'open the books' surface; the audit bundle is one PDF with a SHA-256 integrity manifest.
Compliance you cannot show is not compliance. The dossier is where Veritome turns your obligation work into the record an authority asks for — a classification record, the Annex IV technical documentation, a regulator view you can export for your own records, and a hash-sealed audit bundle.
Every dossier document is a working draft you prepared for your own review — the first time you export one, you acknowledge exactly that. It is not a Veritome attestation or a submission to any authority. Have qualified counsel confirm legal sufficiency before you rely on anything here.
The classification dossier (chain of custody)
The classification dossier is the running record of every decision about a system's risk tier — who decided, what they submitted, who approved it.
- Open the system and press Dossier in the header.
- If none exists yet, Create dossier opens the record and starts the trail. A system registered through the guided flow already has one, with a sealed first entry.
- New entry — pick an entry type (initial classification, tier change, periodic review, …), fill the guided form and submit.
- A second person reviews each submitted entry: Approve adds it to the chain; Reject returns it with a written reason. Neither can be undone.
Each entry is hash-linked to the one before it: every approved entry stores its own fingerprint plus the previous entry's (the first is the genesis entry). Alter any entry and the chain no longer verifies. The header shows Dossier opened, Total entries, Last reviewed, Next review due and Chain integrity; Verify chain → recomputes the fingerprints and either confirms the chain is intact or names the entry where it broke. Each entry carries a public Verify link a third party can open without an account. Completed reviews append their own entries here, so the trail grows with the routine work — see Risks: Art. 9 risks, the heat-map and reviews.
Article 11 and Annex IV — technical documentation
Providers of high-risk systems must draw up technical documentation before placing the system on the market and keep it up to date; Annex IV lists what it must contain. You do not retype any of it — Veritome composes it from the obligation data already entered on the system's risk-management, data-governance, technical-documentation and oversight obligations, and the editor shows which obligation feeds each section. See Annex IV technical documentation, section by section.
Article 47 — the EU Declaration of Conformity
Before a high-risk system is placed on the market, the provider draws up an EU declaration of conformity (Art. 47, the content of Annex V) and affixes the CE marking (Art. 48). The declaration is kept for ten years after placing on the market (Art. 18). Its editor is a prescribed form — every field cites the Annex V point it answers — reached from the Art. 47 obligation or from Documents. See Declaration of Conformity, CE marking and Annex VIII registration.
The regulator view
The regulator view is the "open the books" surface — everything an authority would want, in one place. From the system header press Regulator view. It opens with the phase attestations table (each phase with its status, obligation count and completion), then every obligation laid out by area with its article reference, status, checklist detail, verifier, verification date and attached evidence. The foot of the page carries the hash-sealed compile timestamp and the public verify mark. Cmd/Ctrl+P prints a clean A4 PDF; Annex VIII export → in the header opens the pre-filled registration sheet.
The audit bundle and its SHA-256 integrity manifest
The audit bundle is one merged PDF for a system: a cover sheet, every completed obligation form, the risk management report and the classification dossier. Build it from the Reports page (the Compliance audit bundle card). Its last page is an integrity manifest: a table listing every source document with its position, name, byte size and the SHA-256 hash of the exact bytes that went into the bundle — the chain-of-custody record for the package, so an auditor can confirm nothing was swapped after assembly.