THE WHOLE INSTRUMENT

Every capability,
in one place.

Veritome is one system, not a suite. Classification, obligation mapping, risk management, the quality system, verifiable documentation, provider–deployer handoff and AI-literacy tracking — all sharing the same engine, the same evidence ledger, the same audit trail.

Classification wizard
ART. 5 · ART. 6 · ANNEX III

A wizard that walks the law, not your gut.

A branching decision tree that mirrors the Act's exact classification logic — prohibited practices first, then Annex I sectoral overlap, then Annex III §1–§8 domains, then Article 6(3) self-exclusion, then Article 6(4) authority notification when the system stays out. Every step is anchored to its article; every answer becomes a Classification record you can re-open without restarting.

  • Prohibited-practice screening (Art. 5) before anything else.
  • Annex III domain picker with conditional flags (biometrics, workplace, GPAI).
  • Art. 6(3) exception wizard with the six criteria, individually argued.
  • Art. 6(4) authority-notification record for self-excluded systems.
  • Aria suggests the answer; you confirm and sign — every decision audited.
Veritome guided classification — the five-step register wizard that walks Article 5, Annex I, Annex III and the Article 6(3) exception
Smart obligation mapping
ENGINE

The right obligations, auto-mapped.

Once a system is classified, the engine reads role + risk tier + Annex III domain + behavioural flags and materialises the exact obligations that apply. A workbench, not a checklist: drag tasks between To-do, In Progress, In Review and Complete. Article-derived deadlines, role-aware filters, evidence at the item level.

  • Conditional logic for biometrics, workplace AI, GPAI, emotion recognition.
  • Role-aware: deployer, provider, importer, distributor — different journeys.
  • Tabs auto-generated from the engine; phase gates lock the next step.
  • Granular checklist auto-tick from backing data (RiskPlan, Annex IV doc, Oversight plan).
Veritome obligation workbench — engine-derived obligations across the six-phase journey, filterable by phase and system with per-item status
Risk management
ART. 9

From risk register to residual sign-off.

A working RiskPlan with item-level controls, inherent and residual scoring, and a sign-off ledger. Mitigations that close items also tick the Art. 9 checklist. Reality wins — delete every risk item and the obligation flips back to NOT_STARTED.

  • Inherent + residual scoring per item, with a heat-map view.
  • Mitigation actions tied to evidence + assignee + due date.
  • Residual-risk sign-off transitions Art. 9 to COMPLETE; the ledger is permanent.
  • Periodic review (Art. 9(8)) scheduled automatically; calendar integration.
Veritome risk register — assessments-required strip, portfolio risk KPIs and a severity-by-likelihood heat-map for Article 9 risk management
Quality management system
ART. 17

QMS that lives where the work happens.

The Art. 17 quality management system is not a Word document — it's the union of every other obligation. Veritome gives you the QMS shape (policies, responsibility allocation, change management, post-market plan, incident reporting) and wires each piece to the live evidence already attached to your obligations.

  • Policies + responsibility matrix maintained inside the platform.
  • Change management triggers re-classification when systems materially change.
  • Post-market monitoring plan and serious-incident reporting workflow.
  • QMS export: a single PDF that references every backing document by hash.
Veritome reports — the organisation compliance report, board summary, audit-preparation pack and incident register generated as sealed PDFs
Verifiable documentation
ANNEX IV · ART. 47 · ART. 49

Documents you can prove.

Annex IV technical files, Fundamental Rights Impact Assessments, EU Declarations of Conformity and Annex VIII registration packs assemble themselves from your live system data. Smart forms with Aria suggestions, evidence at item level, audit trail of who filled what when. Every document is hash-sealed; every dossier carries a public verify URL.

  • Annex IV builder pulls from RiskPlan, oversight plan, training data record.
  • FRIA wizard for Annex III §5 deployers; auto-skipped where not required.
  • EU DoC editor pre-fills from the chosen Art. 43 pathway.
  • Annex VIII export: the EUDB registration sheet, ready to paste.
  • verify.veritome.eu — a regulator or buyer can check the seal without an account.
Veritome Annex IV technical-file builder — eleven sections assembled from live system data with a hash-sealed export
Provider ↔ deployer handoff
ART. 13

Art. 13 IFU exchange, in one click.

When a provider hands a high-risk system to a deployer, the Instructions for Use must travel — system purpose, performance, known limitations, oversight measures, monitoring obligations. Veritome seals the IFU package on the provider side and lets the deployer paste-import it on theirs. Cross-org, cross-account, cryptographically sealed.

  • Provider seals the IFU package; gets a one-time sharing token.
  • Deployer pastes the token; the package imports into their system record.
  • Hash chain links the deployer's copy back to the provider's seal.
  • Audit log on both sides — fields imported, who imported, when.
Veritome Article 13 Instructions-for-Use package — provider identity, intended purpose and the nine required elements for provider-to-deployer handoff
AI literacy programmes
ART. 4

Six role-based programmes, tracked.

Article 4 obliges providers and deployers to ensure a sufficient level of AI literacy across staff. Veritome ships six role-tailored programmes (Executive AI Awareness, Compliance Officer, Technical Team, Deployer Operations, Provider Operations, General Staff AI Literacy), tracks completion per person, and surfaces the org-level percentage your auditor will ask for first.

  • Programmes calibrated to role responsibilities, not generic e-learning.
  • Per-person completion certificates; org-level dashboard for the board.
  • Refresher cadence (annual / on-role-change) tracked and prompted.
  • Certificate hash + verify URL — same trust mechanism as Annex IV docs.
Veritome AI literacy — six role-based training programmes with an organisation literacy score and per-person completion tracking for Article 4