VeritomeHelp Centre
/
Browse documentation
Templates & records

Documents: every document your frameworks require, one register

The register of every document you owe — organisation-wide ones as a list, per-system ones as a grid of type against system — with four counts that say where the work actually stands, and an issued archive that never overwrites.

Updated Veritome documentation

Documents answers the question every audit begins with: which documents do our frameworks require from us, and do we have them?

Two sections, because there are two kinds of thing

Organisation-wide documents exist once for the company — your AI governance policy, the Statement of Applicability, the GDPR Art. 30 record of processing, the AI literacy programme, and every record a programme produces while that programme is active. They are a plain list.

Per AI system documents exist once per system. The Annex IV technical file is not one document at 2% — it is one file for each of your systems, each at its own stage. So they render as a grid: document type down the side, your AI systems across the top, one cell per real document. Click a cell to open that system's copy. Past eight systems the grid stops being readable and becomes a picker: one system at a time.

A cell reading n/a is not a gap. It means that system's classification does not require that document — a deployer of a limited-risk chatbot owes no Declaration of Conformity, and showing it as 0% would be inventing work.

Required of you, and everything else

The default tab is Required of you. It is derived, never declared: from the obligations the engine generated off each system's confirmed classification, and from the frameworks your organisation has switched on. All types is one click away — nothing is hidden, it is simply not first.

The four counts

  • Owed — nothing captured yet.
  • Drafted — data captured, nothing signed off.
  • Approved — signed off, no public seal.
  • Issued — sealed, with a fingerprint and a public verify link.

Every document sits in exactly one of the four, and the four add up to the total. There is no "covered" count: that number measured whether we had shipped an editor for a row, which is a fact about Veritome, not about your compliance.

Where a row takes you

A document is a destination, not a drop-down. Every row and every cell opens a page under Documents with its own URL, its own back button and a link you can send to a colleague. The page then decides what opens there:

  • A record with a bespoke editor — the Annex IV file, the Annex V declaration, the Annex VIII sheet, the instructions for use, the FRIA — opens that editor, with a way back to the register.
  • A document produced from a register — the record of processing from processing activities, supplier assessments from suppliers, incident reports from incidents, the literacy programme from training — offers that register as the next step rather than replacing the page with it.
  • A programme record — an ISO or GDPR step's document — opens the step drawer over the document's own page.
  • An organisation policy opens the policy editor.

Inside a per-system document

Opening a document gives you three panes. On the left, its sections — each numbered, with the article it is composed from and how many of that article's fields carry an answer. In the middle, one section at a time: the form for the obligation that section is made of. On the right, what the document is composed from.

The middle pane is the part worth understanding. A section is not a copy of an obligation — it is that obligation. What you type there is saved against the obligation itself, so it completes the obligation and appears in every document composed from it. Two sections of the Annex IV technical file are both made from Art. 11; fill one and the page tells you which other section it just filled. A section with no article beneath it is your own account, written there and nowhere else.

Composition — your data becomes the draft

Veritome composes a draft from the obligation data you have already entered: classification details, checklist answers, form fields, risk records. Composition is deliberately prefill, never overwrite — only genuinely empty fields are seeded, anything you wrote by hand stays yours, and a composed draft is labelled as one.

Issued, and never overwritten

Issuing a finished document computes its fingerprint, writes it into the system's dossier chain-of-custody, and appends one row to the Issued tab at the far right of the register — an archive that only ever grows. Re-issuing appends; it never edits. Each issue carries the retention class stamped at that moment: ten years for the Art. 18 documents (technical file, declaration, dossier entries, generated evidence), six months as the floor for logging records, and current version with history for organisation policies. A statutory floor cannot be clicked away; the absence of one means "kept until the organisation removes it", never "expired". Anyone you hand a document to can check it against the public verify page — see Attach evidence and verify generated documents.

Plans

Tracking is free on every plan — knowing what you owe and how far along you are costs nothing. Producing and sealing documents is a Govern and Manage capability.