Features

Every capability, in one place.

Veritome is one system, not a suite. Classification, the obligation engine, the frameworks you switch on as programmes, evidence and controls, risk, the quality system, verifiable documentation, provider-to-deployer handoff and AI literacy — sharing one engine, one evidence ledger and one audit trail.

No card · Five frameworks · One register · EU-hosted
Classification

A guided intake that walks the law, not your gut.

The intake mirrors the Act's own order — prohibited practices first, then Annex I, the Annex III areas, the Article 6(3) carve-outs and the Article 25 triggers — plus the five GDPR questions that decide which data-protection duties join the register. Every step is anchored to its article; every answer becomes a classification record you can reopen.

Art. 5Art. 6Annex IIIArt. 25
  • Prohibited-practice screening (Art. 5) before anything else.
  • Annex III area picker with the conditional flags — biometrics, workplace, GPAI.
  • Art. 6(3) exception assessment, the six criteria argued one by one.
  • Art. 6(4) authority-notification record for self-excluded systems.
  • Aria suggests the answer; a named person confirms it. Every decision is audited.
Try the free check
Veritome guided classification — the register wizard that walks Article 5, Annex I, Annex III and the Article 6(3) exception
Obligations

The right obligations, derived — not typed.

Once a system is classified, the rules engine reads role, risk tier, Annex III area and behavioural flags and materialises the obligations that apply. The register is where the work lives: owners, statutory dates, evidence per item, list, board or timeline, filtered by domain, framework, system or scope.

Art. 9–15Art. 16Art. 26Art. 72
  • Deterministic: the same inputs give the same obligations, traceable to the article.
  • Role-aware — deployer, provider, importer and distributor get different, correct lists.
  • Six gated phases from Classify to Monitor; the next step is always visible.
  • Checklists tick from backing data — a risk plan, an Annex IV file, an oversight plan.
How the engine works
Veritome obligations register — engine-derived duties with owners, dates and status
Frameworks as programmes

Switch a standard on and get a path, not a list.

ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF run as programmes: ordered steps in gated phases, each producing a record — the policy, the risk method, the impact assessment, the internal audit. The coverage matrix credits every record to every clause it satisfies, in every framework you have on. The Statement of Applicability is generated from what you did.

ISO 42001 §4–10ISO 27001 A.5–A.8NIST GOVERN–MANAGEGDPR Art. 35
  • Steps ISO/IEC 42001 and 27001 share are one record, done once.
  • Requirement-by-requirement coverage, exportable as CSV for your auditor.
  • GDPR duties join the register per system from five data questions.
  • Voluntary standards are labelled voluntary — the certificate comes from an accredited body.
The five frameworks and their crossover
ISO 42001ISO 42001 programme
27 steps · 27 records · 14 shared
01Establish
5 steps · Complete
02Plan
5 steps · In progress
03Support
3 steps · Locked
04Operate
8 steps · Locked
05Evaluate & improve
4 steps · Locked
06Certification audit
2 steps · Locked
Plan · the steps
  1. 01Risk methodology and AI risk assessmentShared recordApproved
  2. 02Risk treatment and Statement of ApplicabilityIn draft
  3. 03AI system impact assessmentPer systemTo do
  4. 04AI objectives and planning to achieve themShared recordTo do
Phases and steps as the product generates them · progress shown is illustrative
Evidence and controls

Proof filed once, counted everywhere it applies.

Upload it, generate it, or pull it from Google Drive, SharePoint, GitHub or Jira. Every piece of evidence carries a SHA-256 fingerprint and an expiry; lapsing proof drops out of coverage and reminds its owner. Controls are produced by the programmes you run, and each carries the evidence that proves it.

Art. 11Art. 18ISO 42001 A.6
  • One record satisfies every obligation and clause that names it.
  • Freshness: expiry dates, renewal cadence, a nudge before the auditor notices.
  • A hash-chained, daily-anchored audit trail behind every change.
Veritome evidence register — files with fingerprints, the clauses each satisfies, scope and status
Risk management

From risk register to residual sign-off.

A working risk plan with item-level controls, inherent and residual scoring, and a sign-off ledger. Mitigations that close items also tick the Art. 9 checklist. Reality wins: delete every risk item and the obligation flips back to not started.

Art. 9Art. 9(8)
  • Inherent and residual scoring per item, with a heat-map view.
  • Mitigation actions tied to evidence, an assignee and a due date.
  • Residual-risk sign-off completes Art. 9; the ledger is permanent.
  • Periodic review (Art. 9(8)) scheduled automatically.
Veritome risk register — portfolio risk KPIs and a severity-by-likelihood heat-map for Article 9 risk management
Quality management system

A QMS that lives where the work happens.

The Art. 17 quality management system is not a Word document — it is the union of every other obligation. Veritome gives you the shape (policies, responsibility allocation, change management, post-market plan, incident reporting) and wires each piece to the live evidence already attached to your obligations. Run ISO/IEC 42001 as a programme and the same records count there too.

Art. 17ISO 42001 §5–9
  • Policies and the responsibility matrix maintained inside the product.
  • Change management triggers re-classification when a system materially changes.
  • Post-market monitoring plan and serious-incident reporting workflow.
  • One PDF that references every backing document by hash.
Veritome reports — the organisation compliance report, board summary and audit-preparation pack as sealed PDFs
Verifiable documentation

Documents you can prove.

Annex IV technical files, fundamental-rights impact assessments, EU declarations of conformity and Annex VIII registration sheets assemble themselves from your live system data. Smart forms with Aria suggestions, evidence at item level, an audit trail of who filled what and when. Every document is hash-sealed; every dossier carries a public verify URL.

Annex IVArt. 27Art. 47Annex VIII
  • Annex IV builder pulls from the risk plan, the oversight plan and the training-data record.
  • FRIA for Annex III deployers, with the DPIA overlap mapped so nothing is asked twice.
  • Declaration of Conformity pre-filled from the chosen Art. 43 pathway.
  • Annex VIII export: the EU-database registration sheet, ready to paste.
  • A public verify link — a regulator or buyer checks the seal without an account.
Open a sample dossier
Veritome Annex IV technical-file builder — sections assembled from live system data with a hash-sealed export
Provider to deployer handoff

The Art. 13 instructions for use, exchanged and sealed.

When a provider hands a high-risk system to a deployer, the instructions for use must travel — purpose, performance, known limitations, oversight measures, monitoring duties. Veritome seals the package on the provider side and lets the deployer import it on theirs. Cross-organisation, cryptographically sealed.

Art. 13Art. 26
  • The provider seals the package and gets a one-time sharing token.
  • The deployer pastes the token; the package imports into their system record.
  • The hash chain links the deployer's copy back to the provider's seal.
  • An audit log on both sides — fields imported, who imported, when.
Veritome Article 13 instructions-for-use package — provider identity, intended purpose and the required elements for provider-to-deployer handoff
AI literacy

Role-based programmes, tracked and filed as evidence.

Article 4 obliges providers and deployers to ensure a sufficient level of AI literacy across staff. Veritome ships six role-based programmes, tracks completion per person and surfaces the organisation-level figure your auditor asks for first.

Art. 4
  • Programmes calibrated to role responsibilities, not generic e-learning.
  • A record of completion per person; an organisation-level view for the board.
  • Refresher cadence — annual, or on a change of role — tracked and prompted.
  • Each record carries a hash and a verify URL, the same mechanism as the dossier.
Veritome AI literacy — six role-based training programmes with per-person completion tracking for Article 4
Straight answers

Questions buyers ask about the product

Four answers, each true of the product as shipped today.

Is Veritome one product or a suite of modules?

One product. Classification, the obligations register, the framework programmes, evidence, risk, the QMS, the documents, the IFU handoff and AI literacy share one engine, one evidence ledger and one audit trail. A record filed once is counted everywhere it applies.

Which frameworks does Veritome cover?

The EU AI Act is the spine and the GDPR sits beside it — both statutory and always on. ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF are voluntary and run as programmes you switch on. Coverage is shown requirement by requirement in one matrix.

Does Veritome file anything with a regulator?

No. It prepares the artefacts — the Annex VIII registration sheet, the Declaration of Conformity, the dossier with its verify URL — and you make the submission. Nothing is filed on your behalf and nothing here is legal advice.

Where does the data live?

In the EU. The application and database run on Hetzner in Germany, object storage in Falkenstein, and Aria runs on Mistral in Paris. The sub-processor register names every supporting service.