VeritomeHelp Centre
/
Browse documentation
Using Veritome

Report a serious incident to the right authority

Veritome resolves the competent authority for the member state, tracks the Art. 73 deadline (2 / 10 / 15 days), runs four-eyes approval, and drafts the notification — you review and send.

Updated Veritome documentation

Compliance does not stop at launch. The EU AI Act requires you to keep watching a high-risk system once it is live and to react fast when something goes wrong. Incidents (under Do the work) is the register of case files — an operational register, not evidence of anything until a case is closed.

Article 72 — post-market monitoring

Providers must run a post-market monitoring system: actively collect and review data on how the system performs in the real world, throughout its lifetime, and feed what they learn back into the risk-management system (Art. 9). In Veritome that is the Monitor phase — the monitoring obligations and their evidence on each high-risk system, the recurring review on Assessments, and findings that become risks on Risks or, when serious, incidents here. See Post-market monitoring: the Art. 72 plan and the monitoring cycle.

Article 73 — reporting a serious incident

A serious incident (Art. 3(49)) is an incident or malfunction leading to death or serious harm to health, a serious and irreversible disruption of critical infrastructure, an infringement of Union fundamental-rights obligations, or serious harm to property or the environment. The clock is tiered and counted in calendar days, running from the moment the provider establishes a causal link between the system and the incident, or the reasonable likelihood of one, and in any event from awareness (Art. 73(2)–(4)):

DeadlineWhen it applies
2 daysA widespread infringement, or a serious and irreversible disruption of critical infrastructure
10 daysWhere a death is involved
15 daysAny other serious incident — report without undue delay, and no later than this

A data breach in a high-risk system is usually two clocks at once: an EU AI Act serious incident (Art. 73, 2 to 15 days) and a GDPR personal-data breach (GDPR Art. 33, 72 hours to the supervisory authority). The form lets you record which regime, or both.

To raise one:

  1. Press Report serious incident on Incidents, or open a system's Incidents tab.
  2. Read the reporting-authority banner: it names the market-surveillance authority for the Member State where the incident occurred, with its designation status and a link to the Commission's list. It defaults to your organisation's country and warns you when the authority's published address failed its last automated check.
  3. Pick the incident type — your choice sets the reporting clock; the short-clock types carry an amber warning.
  4. Under When and where, enter the incident date and time, the date you became aware, and the Member State where it occurred (Art. 73(1) sends the report to that state's authority).
  5. Set the causal link footing: established, reasonably likely, or under assessment. The duty to report attaches as soon as a link is reasonably likely — you do not wait for certainty.
  6. Fill in the details (persons affected, what happened, the harm) and the response (immediate and corrective action, whether the system was withdrawn, whether the provider was notified).
  7. Choose the report typeinitial, follow-up or final — and confirm the reporting contact.
  8. Save. The notification countdown starts, and the case appears on the register with its day n of N window.

Four-eyes approval and sending

Before the report leaves for the authority, a second person — an Org admin or Compliance manager who did not draft it — reviews and approves it. Approving also files the report in the Evidence hub. The authority router resolves the competent authority (and, for Member States with a distributed model, the sector authority and single point of contact), offers a pre-filled Art. 73 notification letter and a draft email to the authority contact, and records that a person sent it. Aria can draft the notification text. Veritome never submits to a regulator automatically.

Working the register

The register lists every case file across the estate, ordered by reporting deadline, with filters by type and status and a panel for every case still on the Art. 73 clock. The status flow runs Reported → Under investigation → Notified to authority → Closed; the countdown is satisfied once the authority is notified. File a final report to close out the notification, then move the incident to Closed. Case files carry a ten-year retention floor — Veritome's own retention class, aligned to the Art. 18 period for technical documentation.