Browse documentation
Help Centre · 30 articles
Using Veritome
One article per screen, in the order of the rail.
Position
Dashboard
- Understand the DashboardThe first screen: five counts with denominators, your programmes with the next step in each, one action queue, what Aria found, five gated items of work this week, the dates split honestly, and the regulatory updates.
- How obligation completion is scoredThe completion figure is phase-weighted — implementation carries 45 of 100 points — with priority weighting inside each phase and a hard zero for prohibited systems.
AI systems
- Register your first AI systemAdd an AI system, answer the guided questions — role, duties, model, prohibited practices, risk, transparency, GDPR — and get a classification with the exact obligations that apply.
- AI systems: the register and the system recordThe inventory every duty hangs off — four counts, the register filters, list or board, CSV import — and the seven-tab record each system opens onto.
- Classify a system: the guided flow, screen by screenClassification decides your risk tier and role, which decide what you must do. Eight screens and a review — role, Art. 25, GPAI, Art. 5, Annex III, Art. 6(3), Art. 50 and the five GDPR questions.
- The six-phase compliance journeyEvery system moves through six gate-locked phases — Classify, Scope, Implement, Assess, Register, Monitor — and empty phases never block.
Obligations
- Scope obligations and assign ownersAfter classification, confirm which derived obligations genuinely apply, mark the rest not applicable, put a named owner on each, and settle the Art. 4 literacy duty.
- Work an obligation: register, drawer, evidenceDrive obligations from the register or a system record: List, Board or Timeline; filters by domain, framework, scope and system; the drawer's form, evidence and history; the four-eyes rule.
- Dates and deadlines: the Obligations timelineEvery dated thing — obligation due dates, periodic reviews, incident clocks, statutory milestones, programme steps — is a row on the Obligations register. The Timeline view buckets them by week, and red means one thing.
- Data governance: Art. 10 dataset practices per systemThe Data domain of the Obligations register: Art. 10 training, validation and testing data practices for every high-risk system, the deployer's Art. 26(4) input-data duty, and the GDPR rows generated beside them.
- Transparency notices: Art. 50 disclosure dutiesThe Transparency domain of the Obligations register: Article 50 duties for systems that talk to people, read emotions or generate synthetic content — and the notice studio that drafts the wording.
- Human oversight: Art. 14 measures and the deployer's Art. 26(2) dutiesThe Oversight domain of the Obligations register: who can intervene in each high-risk system, how the stop mechanism works, how automation bias is countered — the provider designs the measures, the deployer assigns and equips the people.
- GPAI disclosures: the Art. 53/55 dutiesFor general-purpose model providers: the Documentation domain holds the downstream model documentation, the copyright policy and the training-data summary — and the extra Art. 55 layer when a model carries systemic risk.
- Steps: Aria drafts, a person approves, then it countsOpen a step, answer its questions or let Aria draft from what you already have, then approve. Only approval files the record as evidence and creates the control.
Do the work
Controls
- Controls: one thing you do, credited across every frameworkWhat a control is, how it links to requirements, why the register starts empty, and why coverage only counts verified proof.
- Overlap credit: done by overlap, never done twiceA record that satisfies a clause in two frameworks is one record. A step whose every requirement is already evidenced elsewhere is marked done by overlap — with the record that did it.
- The Statement of Applicability, generated from what you didThe SoA is a view over your controls and records, not a spreadsheet you fill. Every Annex A control is listed; an exclusion needs a justification sentence.
Evidence
- The Evidence hub: sealed files, links, connectors and freshnessEvery file you hold as proof, fingerprinted and sealed, linked to the obligations it satisfies; upload, generate or connect; and an expiry clock so stale evidence is flagged, not counted.
- Attach evidence and verify generated documentsAttach fingerprinted evidence to obligations and checklist items, and generate the Annex IV, FRIA and declaration documents that each carry a public verify URL.
- OAuth evidence connectors: Drive, SharePoint, GitHub, JiraConnect the tools your proof already lives in over read-only OAuth, then sync recent items in as evidence — deduplicated, link-checked weekly, and attachable to obligations.
Policies
- Policies: what the organisation decided onceThe organisation-scope record register: the Art. 4 literacy programme, the Art. 17 policy pack, the retention policy, the programme steps that produce a policy, and the six policy documents you write and approve.
- Organisation policies: write, approve, issueThe six organisation-wide policies the EU AI Act asks a provider for, as clause outlines you write into — guidance is never prefilled, approving issues a version, and an approved policy is never edited in place.
Risks
- Risks: Art. 9 risks, the heat-map and reviewsLog and score Art. 9 risks with the seven-step guided wizard, read the heat-map, see which Art. 9, Art. 27 and Art. 55 assessments each system still owes, and complete scheduled reviews that leave a dossier entry.
Suppliers
- Suppliers: the value chain, agreements and the IFU handoffThe register of the third parties behind your AI systems, the written agreements Art. 25(4) and GDPR Art. 28 expect, the six-question supplier assessment, and how the Art. 13 instructions for use hand off along the chain.
Incidents
- Report a serious incident to the right authorityVeritome resolves the competent authority for the member state, tracks the Art. 73 deadline (2 / 10 / 15 days), runs four-eyes approval, and drafts the notification — you review and send.
- Post-market monitoring: the Art. 72 plan and the monitoring cycleAfter deployment the work continues: a monitoring plan per high-risk system, recurring reviews on Assessments, and the paper trail that connects field experience back into risk management.
Prove it
Assessments
- FRIA: the fundamental-rights impact assessment, step by stepWho must run an Art. 27 FRIA, what the assessment covers, the Art. 27(3) notification and the Art. 27(4) link to the DPIA, when to revisit it, and how Veritome generates the report per system.
- DPIA overlap: reuse your FRIA where the GDPR meets the EU AI ActArt. 27(4) lets the FRIA draw on the GDPR Art. 35 DPIA and Art. 26(9) sends the instructions for use into it — Veritome shows both routes, maps completed FRIA answers onto the DPIA's four pillars and exports an input pack for your privacy team. None of it counts as coverage.
Audit trail
- The audit trail: every change, hash-chained and anchored dailyWho changed what, when — every mutation in the product writes a line. Lines are chained by hash and anchored once a day, so the trail can be verified, not just read.
- SIEM ingestion: pull the audit logStream the whole tenant audit trail into your SIEM with the since-and-cursor endpoint, know what each entry carries, and verify the daily hash anchors so an altered entry cannot hide.
Academy
- AI literacy: satisfying Article 4Art. 4 binds every provider and deployer since 2 February 2025 — answer the Academy's six questions, complete the programmes they assign, and keep a twelve-month record that counts as evidence.
- The Academy: your AI literacy record, and when it lapsesArticle 4 binds every person who works with AI, not only the technical roles. Six questions decide which programmes apply to you, the answers are filed as evidence, and the record you earn is valid for twelve months.
Documents
- Documents: owed, drafted, approved, issuedThe register of every document your frameworks require, counted as instances in four buckets, laid out per system as a matrix, with the Issued archive that keeps every produced version.
- Documents: every document your frameworks require, one registerThe register of every document you owe — organisation-wide ones as a list, per-system ones as a grid of type against system — with four counts that say where the work actually stands, and an issued archive that never overwrites.
- Instructions for use: the Art. 13 packageWhat a provider's instructions for use must contain under Art. 13(3), how the package is built and handed to deployers, how a deployer receives it, and where it feeds the deployer's own duties.
Reports
- Dossiers, tech docs and the regulator viewThe classification dossier is a hash-linked chain of custody; the regulator view is the 'open the books' surface; the audit bundle is one PDF with a SHA-256 integrity manifest.
- Reports, CSV export and audit bundlesGenerate audience-specific PDF reports, export the obligation matrix as CSV, build a per-system audit bundle, and schedule any template to self-generate on a cadence.
- Annex IV technical documentation, section by sectionWhat the Annex IV technical file must contain, how Veritome composes it from the Art. 9–15 obligations in a guided editor, and how issued versions are hash-sealed and kept for ten years.
- Declaration of Conformity, CE marking and Annex VIII registrationThe provider's Art. 47 declaration in the Annex V field set, the Art. 48 CE marking, and registering in the EU database with Veritome's pre-filled Annex VIII copy-out sheet — nothing is submitted to any authority for you.
Configure
Frameworks
- Quality Management (QMS): ISO/IEC 42001 controls and Art. 17The organisation-wide AI management system workspace under Frameworks → ISO/IEC 42001: the Annex A control catalogue, the QMS profile, the Statement of Applicability, and the tick-only sync into every Art. 17 checklist.
- Regulatory watch: track changes, decide, and leave a trailDelegated acts, guidance, harmonised standards and national implementation — a change register on Frameworks → Changes: assess relevance, record the decision, and turn planned actions into scheduled reviews.
- Frameworks: switch a standard on, and see what it asksThe Configure screen for the regimes your organisation is run against: the five toggles, the Programme cards, the Coverage matrix, every requirement row, and the regulatory-change register.
- Programmes: a standard as a path, not a listSwitch a framework on and it becomes a programme — ordered steps in gated phases, each producing a record. The standards stop being a checklist you tick and become work you do once.
- Phases and gates: why the next step is lockedEach programme runs in phases; a phase is locked until the one before it is complete. The same rule the EU AI Act journey uses, applied to the standards — plus the GDPR bucket that sits outside the path.
- Coverage and the auditor: the matrix, the seat, the packFrameworks → Coverage shows every requirement and the workflow assigned to it. Give your auditor a read-only seat and the records; the certificate comes from them, not from us.
- EU AI Act — roles, tiers, dates, and the Article 25 trapThe statutory core. Obligations attach by your role for each system and its risk tier; most high-risk duties apply from 2 December 2027; Article 25 can make a deployer the provider.
- GDPR for AI systems — where the Act meets data protectionPersonal data through a running AI system brings the GDPR into the same register: lawful basis, transparency, DPIA, Art. 22, processor terms, transfers — per system from five questions, plus an organisation-wide programme.
- ISO/IEC 42001 — the management system, and why it is not a legal shieldThe AI management-system standard as a programme from Stage 1 to Stage 2. Genuinely useful, certifiable by an accredited body — and not a presumption of conformity with the EU AI Act.
- ISO/IEC 27001 — 93 controls as themes, one management systemInformation security, modelled as one management system with ISO/IEC 42001 where the clauses are the same. The 93 Annex A controls are worked as four guided theme records, not empty rows.
- NIST AI RMF — a profile, not a certificateThe US framework a counterparty may ask for: Govern, Map, Measure, Manage. Veritome produces the profile document from approved records; there is no certification to obtain.
Organisation
- Invite your team and assign ownersAdd colleagues, pick from six least-privilege roles, keep the org profile that feeds your documents, and assign obligation owners so work is accountable.
- Plans, billing and upgradesEarly access is free with 30% off locked in for life; then Classify, Starter (€79), Govern (€199) and Manage (€599), Enterprise by quote; ISO/IEC 42001 and NIST included from Govern, ISO/IEC 27001 at €199 on Govern and included in Manage; annual billing at ten months for twelve, and what happens at a limit.
- Organisation: profile, members, billing, security and dataThe Configure screen for everything set once: the organisation profile that feeds your documents, members and roles, your own AI literacy standing, billing, SSO, security, data residency, API keys, integrations and notifications.
- Webhooks: react to compliance events in real timeRegister an HMAC-signed webhook so downstream tools react the moment a system is registered, an obligation changes status, an incident is filed or evidence is verified.
- Set up SSO and SCIM provisioningConnect your identity provider over OIDC for single sign-on, and mint SCIM tokens so your IdP provisions and deactivates users automatically — both Enterprise features, configured by an Admin.
- API keys and organisation data exportCreate hashed, scoped API keys for programmatic access, generate a sealed export of all organisation data, and file a GDPR erasure request.