AI governance. Connected.

Five frameworks.
One connected
workspace.

Understand what applies. Give every action an owner.
Keep the evidence together.

Explore with sample dataNo account needed
A shared foundation for
  • EU AI Act
  • ISO/IEC 42001
  • ISO/IEC 27001
  • GDPR
  • NIST AI RMF
Find Veritome onVeritome on Product HuntVeritome on BetaListVeritome verified on directree
LESS FRAGMENTATION. MORE CLARITY.

Compliance is connected.
Your work should be too.

Move from scattered files and separate checklists to a programme your team can actually run.

01

Understand what applies

Build a system profile once. The requirements relevant to your role, your risk tier and your use case are derived from it — you never assemble the list by hand.

See a system's register
02

Make ownership clear

A requirement becomes work with a name on it: an owner, a due date and a practical definition of done, so nothing sits in the gap between two people who each assumed the other had it.

See the workspace
03

Keep the proof together

Evidence connects to the requirements it supports, and carries the version and review history with it. A certificate that lapses stops counting instead of going on looking green.

See the evidence library
THE WORK, FROM START TO FINISH

One system. A clear next step.

The same recruitment assistant, in each of the six phases the engine puts a system through. Pick a phase to see the screen it is on and the duty it answers.

01 / Classify

Understand the system before the requirements.

Record what it does, who uses it and who is answerable. Role and risk tier fall out of the answers, and the reasoning stays beside the decision rather than in somebody's inbox.

Art. 6(2)
AI systems / Recruitment assistant
Classification
Recruitment assistant
Annex III(4)(a) · employment · shortlisting
High-risk · deployer
System owner
Alex Morgan
Last updated
08.09.2026
Illustrative record · articles are real, the system is not
STRAIGHT ANSWERS

What Veritome will and will not do

Five statements about the product and the law, each with the article, clause or standard behind it.

The dates on every screen are the law's.

Article 5 prohibitions and Article 4 literacy have applied since 02.02.2025; Article 50 transparency since 02.08.2026; the Annex III high-risk obligations apply from 02.12.2027 under the Digital Omnibus deferral. Veritome reads them from one registry, shows them beside each duty, and colours nothing red before its statutory date.

If you owe very little, the check says so.

An organisation that only uses AI tools is found 2 duties by the engine — Art. 4 and Art. 5 — and is told that plainly, with the articles. Registering a system is optional at that point; the free check does not require an account.

No standard is a legal shield today.

No harmonised standard for the EU AI Act has been cited in the Official Journal, so no certificate gives a presumption of conformity. ISO/IEC 42001 is how you build the management system and it is what customers ask for; Veritome labels it voluntary and shows its coverage as coverage, not as compliance.

Certificates come from accredited bodies, not from us.

ISO/IEC 17021-1 §5.2.5 keeps the organisation that helps you build a management system apart from the one that certifies it. Veritome prepares the records, generates the Statement of Applicability and gives your auditor a read-only seat. The certificate is theirs to issue.

Aria proposes. A named person approves.

Aria drafts records, maps requirements and monitors change, and every write lands in its Inbox as a proposal until someone accepts it. The Act requires a natural person to exercise oversight, and an unapproved machine record is worth nothing to an auditor.

TRY IT

Three things the register does that a spreadsheet cannot

All three run on the shipped rules and templates. Switch a framework on and the counts change; tick an Article 25 trigger and a deployer's register becomes a provider's; write a disclosure notice for the one duty that is already in force.

SWITCH A FRAMEWORK ON
  • EU AI ActEU AI ActRegulation (EU) 2024/1689 · statutory · always on69 req
  • GDPRGDPRRegulation (EU) 2016/679 · statutory · always on61 req · 19 steps
  • ISO 42001ISO/IEC 42001ISO/IEC 42001:2023 · voluntary · certifiable by an accredited body65 req · 27 steps
  • ISO 27001ISO/IEC 27001ISO/IEC 27001:2022 · voluntary · certifiable by an accredited body118 req · 25 steps
  • NIST AI RMFNIST AI RMFNIST AI RMF 1.0 · voluntary · no certification exists72 req · 12 steps
Requirements
195
in the frameworks switched on
Programme steps
46
guided records to produce
Done once, counted twice
0
switch on both ISO standards
Point at the EU AI Act
23
steps with a related article — a link, not evidence
BECOME THE PROVIDER BY ACCIDENT · ART. 25
One high-risk system · you bought it, you run it

Tick anything that is true of your organisation. Article 25 makes you the provider of a system you did not build, and the register changes with the role.

Your role: Deployer
Deployer register
Deployer of a high-risk system
12
obligations
  1. Art. 4AI literacy — all staff dealing with AI
  2. Art. 5Prohibited practices screening
  3. Art. 26(1)Use system per provider's instructions for use
  4. Art. 26(2)Assign human oversight person(s)
  5. Art. 26(5)Monitor operation; suspend & notify on serious risk
  6. Art. 26(9)Use Art. 13 information for the GDPR Art. 35 DPIA
  7. Art. 26(4)Input data relevance — when deployer controls input
  8. Art. 26(6)Retain automatically generated logs — at least 6 months
  9. Art. 73Report serious incidents to provider and authority within 15 days
  10. Art. 26(11)Inform affected persons of high-risk AI decisions
  11. Art. 86Right to explanation of individual decision-making
  12. Art. 26(12)Deployer — cooperate with competent authorities
Computed by the engine’s applicability rules over the seeded obligation set. Nothing here is applied to an account; the real intake asks nine questions.
WRITE THE DISCLOSURE NOTICE · ART. 50 · IN FORCE
Art. 50 · in force since 02.08.2026
What you owe →
Disclosure notice generator
You are talking to Aria, an AI system that answers questions about your AI systems. It is not a person. Type agent at any time to reach a human. Answers can be wrong; important decisions are checked by a person.
Art. 50(1) disclosure · Art. 50(2) marking in the full toolOpen the generator →
Built for accountability

Assistance you can inspect.
Decisions you own.

Good governance needs clear records, visible limits, and people who remain in control.

Trust & accountability →
01

Sources alongside the work

A recommendation arrives with the article it rests on, so you can judge the basis before you act on it rather than after.

02

Human approval stays central

Aria drafts and proposes. A named person files, and the record says which of the two happened — because whether an organisation truly complies is not a fact this product can see.

03

A record of what changed

The owner, the version and the review context stay with the evidence, so an auditor opening a March obligation reads March's document.

Questions

The things people ask before they sign up

What is Veritome?

Veritome is compliance software for European organisations that use or build AI systems. It keeps one register of every AI system you have, works out which obligations each one carries under EU AI Act, ISO 42001, ISO 27001, GDPR and NIST AI RMF, records who owns each obligation and what evidence closes it, and drafts the documents those obligations call for. It is a tool for doing and recording the work — it does not certify you, audit you, or make a compliance determination on your behalf.

Which regulations and standards does Veritome cover?

5: EU AI Act, ISO 42001, ISO 27001, GDPR and NIST AI RMF. The EU AI Act (Regulation (EU) 2024/1689) and the GDPR are binding EU law. ISO/IEC 42001 and ISO/IEC 27001 are voluntary standards, certifiable only by an accredited certification body. The NIST AI Risk Management Framework is a voluntary United States framework with no legal status in the EU. Veritome runs each as its own programme and shows where work on one genuinely counts toward another.

Do the EU AI Act's rules apply to me if I only use AI, not build it?

Yes. The Act attaches duties to four operator roles, and a deployer — an organisation using an AI system in a professional capacity — carries its own set under Article 26, including human oversight, monitoring, input data quality, and notifying workers before an AI system is used in the workplace. One organisation can hold different roles for different systems. Veritome derives the duty set per system from the role you record against it.

When do the EU AI Act obligations actually start?

They are staged. The prohibited-practice rules in Article 5 and the AI-literacy duty have applied since 02.02.2025. The Article 50 transparency duties became applicable on 02.08.2026. Regulation (EU) 2026/1744, the Digital Omnibus on AI, deferred the standalone Annex III high-risk obligations to 02.12.2027 and the Annex I embedded high-risk obligations to 02.08.2028. The date that binds you depends on what your systems are, not on when you started.

What does Veritome actually produce?

A register of your AI systems with a recorded classification for each; the obligation set that follows from that classification, with an owner and a status per obligation; an evidence library where one record can close obligations under more than one framework, with the basis for each reuse stated; and generated documents — Annex IV technical files, fundamental rights impact assessments, declarations of conformity, Annex VIII registration sheets — hash-sealed with a public verification URL. A generated document records work you did. It is not a regulatory determination and not certification.

Is Veritome a certification body or a substitute for legal advice?

No, to both. Veritome is not a certification body, a notified body, an accredited auditor or an authorised representative, and nothing it produces constitutes certification under any standard. Certification against ISO/IEC 42001 or ISO/IEC 27001 is granted only by an accredited certification body following its own audit. The software does not give legal advice; the classification and the conclusions remain yours, and material decisions warrant qualified professional advice.