A guided intake that walks the law, not your gut.
The intake mirrors the Act's own order — prohibited practices first, then Annex I, the Annex III areas, the Article 6(3) carve-outs and the Article 25 triggers — plus the five GDPR questions that decide which data-protection duties join the register. Every step is anchored to its article; every answer becomes a classification record you can reopen.
- Prohibited-practice screening (Art. 5) before anything else.
- Annex III area picker with the conditional flags — biometrics, workplace, GPAI.
- Art. 6(3) exception assessment, the six criteria argued one by one.
- Art. 6(4) authority-notification record for self-excluded systems.
- Aria suggests the answer; a named person confirms it. Every decision is audited.
The right obligations, derived — not typed.
Once a system is classified, the rules engine reads role, risk tier, Annex III area and behavioural flags and materialises the obligations that apply. The register is where the work lives: owners, statutory dates, evidence per item, list, board or timeline, filtered by domain, framework, system or scope.
- Deterministic: the same inputs give the same obligations, traceable to the article.
- Role-aware — deployer, provider, importer and distributor get different, correct lists.
- Six gated phases from Classify to Monitor; the next step is always visible.
- Checklists tick from backing data — a risk plan, an Annex IV file, an oversight plan.
Switch a standard on and get a path, not a list.
ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF run as programmes: ordered steps in gated phases, each producing a record — the policy, the risk method, the impact assessment, the internal audit. The coverage matrix credits every record to every clause it satisfies, in every framework you have on. The Statement of Applicability is generated from what you did.
- Steps ISO/IEC 42001 and 27001 share are one record, done once.
- Requirement-by-requirement coverage, exportable as CSV for your auditor.
- GDPR duties join the register per system from five data questions.
- Voluntary standards are labelled voluntary — the certificate comes from an accredited body.
Proof filed once, counted everywhere it applies.
Upload it, generate it, or pull it from Google Drive, SharePoint, GitHub or Jira. Every piece of evidence carries a SHA-256 fingerprint and an expiry; lapsing proof drops out of coverage and reminds its owner. Controls are produced by the programmes you run, and each carries the evidence that proves it.
- One record satisfies every obligation and clause that names it.
- Freshness: expiry dates, renewal cadence, a nudge before the auditor notices.
- A hash-chained, daily-anchored audit trail behind every change.
From risk register to residual sign-off.
A working risk plan with item-level controls, inherent and residual scoring, and a sign-off ledger. Mitigations that close items also tick the Art. 9 checklist. Reality wins: delete every risk item and the obligation flips back to not started.
- Inherent and residual scoring per item, with a heat-map view.
- Mitigation actions tied to evidence, an assignee and a due date.
- Residual-risk sign-off completes Art. 9; the ledger is permanent.
- Periodic review (Art. 9(8)) scheduled automatically.
A QMS that lives where the work happens.
The Art. 17 quality management system is not a Word document — it is the union of every other obligation. Veritome gives you the shape (policies, responsibility allocation, change management, post-market plan, incident reporting) and wires each piece to the live evidence already attached to your obligations. Run ISO/IEC 42001 as a programme and the same records count there too.
- Policies and the responsibility matrix maintained inside the product.
- Change management triggers re-classification when a system materially changes.
- Post-market monitoring plan and serious-incident reporting workflow.
- One PDF that references every backing document by hash.
Documents you can prove.
Annex IV technical files, fundamental-rights impact assessments, EU declarations of conformity and Annex VIII registration sheets assemble themselves from your live system data. Smart forms with Aria suggestions, evidence at item level, an audit trail of who filled what and when. Every document is hash-sealed; every dossier carries a public verify URL.
- Annex IV builder pulls from the risk plan, the oversight plan and the training-data record.
- FRIA for Annex III deployers, with the DPIA overlap mapped so nothing is asked twice.
- Declaration of Conformity pre-filled from the chosen Art. 43 pathway.
- Annex VIII export: the EU-database registration sheet, ready to paste.
- A public verify link — a regulator or buyer checks the seal without an account.
The Art. 13 instructions for use, exchanged and sealed.
When a provider hands a high-risk system to a deployer, the instructions for use must travel — purpose, performance, known limitations, oversight measures, monitoring duties. Veritome seals the package on the provider side and lets the deployer import it on theirs. Cross-organisation, cryptographically sealed.
- The provider seals the package and gets a one-time sharing token.
- The deployer pastes the token; the package imports into their system record.
- The hash chain links the deployer's copy back to the provider's seal.
- An audit log on both sides — fields imported, who imported, when.
Role-based programmes, tracked and filed as evidence.
Article 4 obliges providers and deployers to ensure a sufficient level of AI literacy across staff. Veritome ships six role-based programmes, tracks completion per person and surfaces the organisation-level figure your auditor asks for first.
- Programmes calibrated to role responsibilities, not generic e-learning.
- A record of completion per person; an organisation-level view for the board.
- Refresher cadence — annual, or on a change of role — tracked and prompted.
- Each record carries a hash and a verify URL, the same mechanism as the dossier.
Questions buyers ask about the product
Four answers, each true of the product as shipped today.
Is Veritome one product or a suite of modules?
One product. Classification, the obligations register, the framework programmes, evidence, risk, the QMS, the documents, the IFU handoff and AI literacy share one engine, one evidence ledger and one audit trail. A record filed once is counted everywhere it applies.
Which frameworks does Veritome cover?
The EU AI Act is the spine and the GDPR sits beside it — both statutory and always on. ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF are voluntary and run as programmes you switch on. Coverage is shown requirement by requirement in one matrix.
Does Veritome file anything with a regulator?
No. It prepares the artefacts — the Annex VIII registration sheet, the Declaration of Conformity, the dossier with its verify URL — and you make the submission. Nothing is filed on your behalf and nothing here is legal advice.
Where does the data live?
In the EU. The application and database run on Hetzner in Germany, object storage in Falkenstein, and Aria runs on Mistral in Paris. The sub-processor register names every supporting service.







