Work an obligation: register, drawer, evidence
Drive obligations from the register or a system record: List, Board or Timeline; filters by domain, framework, scope and system; the drawer's form, evidence and history; the four-eyes rule.
Once a system is classified, the engine generates the exact set of duties that apply to that system, given its risk tier, your role, its Annex III area, its behavioural flags and its GDPR answers. You never pick obligations from a menu — the engine derives them, so nothing relevant is missed and nothing irrelevant clutters the view.
Where obligations live
Every obligation shows up in two places, and they stay in sync:
- On the system — the Obligations tab of the system record, filtered by phase.
- Across the portfolio — Obligations (under Position), which flattens every obligation on every system into one operational register. Programme steps of organisation scope — an ISO/IEC 42001 policy, a GDPR record — appear here too, as ORG rows beside the per-system ones, so one register holds everything you owe.
The Obligations register
- Narrow the view with the register filters: Domain (Governance & literacy · Risk · Data · Documentation · Transparency & information · Oversight · Monitoring & incidents · Conformity & registration · Supply chain), Framework (EU AI Act, GDPR, and each standard you have enabled) and Scope (Organisation or System). Add a System, a status bucket (All · Overdue · Due this week · In progress · In review · Complete), a search, or My tasks only in the header.
- Choose a layout with List / Board / Timeline. List is the dense, sortable table — sort by clicking a column header (programme phase, title, due date or article). Board is the Kanban; Timeline buckets the same rows by week, overdue first.
- On the Board, drag a card into another column to change its status. The move saves immediately and re-scores the system in the background. A programme step cannot be dragged to its final column — a step is evidenced only by approval in its drawer.
- Select rows in the list to start them together from the bulk bar.
- Click any row or card to open the drawer and do the work.
Two domain filters carry extra tools: Transparency & information shows the notice studio, which drafts Art. 50 wording for the systems that need it; Data shows the GDPR record of processing and data-subject request panels.
Status flow
| Status | Meaning |
|---|---|
| To do | Not started. |
| In progress | Work underway. |
| In review | Submitted for four-eyes sign-off. |
| Complete | Done and evidenced. |
| Not applicable | Scoped out, with a note. Excluded from every figure. |
| Overdue | Any open obligation past its due date. |
Four-eyes on high-risk. If you mark an obligation on a high-risk system complete but you do not hold an approver role (Org admin or Compliance manager), Veritome routes it to In review instead and notifies an approver. The approvals waiting appear on the Dashboard. This keeps a segregation-of-duties trail on the work that matters most.
Inside the drawer
The header carries the status selector, Assigned to and Due date — each saves the moment you change it. Below are three tabs: Form, Evidence and History.
- Form — the guided form or checklist for this obligation, with the article reference inline and a plain-language reading of what it asks.
- Evidence — every record filed against this obligation, with Add evidence to upload a file or record a link.
- History — the audit trail: who changed the status, when evidence was added, every edit.
Some obligations have a dedicated editor — the Annex IV technical documentation, the FRIA, the Art. 43 conformity assessment, the EU Declaration of Conformity, the Annex VIII registration sheet, the Art. 6(3) wizard, the Art. 13 instructions-for-use package. The drawer links to it above the form; the printable ones (the IFU package, the Annex VIII sheet) are read-only references, and the obligation is still completed here.
Smart forms and auto-save
Where an obligation expects structured answers the Form tab renders a smart form: exactly the fields the EU AI Act asks for, with Aria on hand to draft a first pass. Answers auto-save about a second and a half after you stop typing, so there is no Save button to hunt for. Every save recomputes the system's completion figure.
Checklists and per-item evidence
Below the form you work through the obligation's checklist items — each a concrete step, often with its own sub-article reference. For each item you can tick it complete (saved instantly), add notes, and attach evidence — a policy PDF, a test report, a dated screenshot — directly to that item. Evidence is what turns a claim ("we have human oversight") into something an auditor can verify.
When the Regulation lets you reuse work
On six obligations the drawer shows a card headed The Regulation lets you reuse work here. These are the routes the EU AI Act's own text grants: a deployer's fundamental-rights assessment may draw on the GDPR data-protection impact assessment (Art. 27(4)); the deployer shall use the provider's Art. 13 instructions when carrying out that DPIA (Art. 26(9)); an Annex I product's testing and documentation may be integrated into the procedures that legislation already requires (Art. 8(2)); a provider already under a sectoral Union-law quality-management duty may fold Art. 17 into that system (Art. 17(3)); and a financial institution's internal governance rules under Union financial-services law stand in for the quality management system (Art. 17(4), except points (g), (h) and (i)) and for the deployer's monitoring duty (Art. 26(5)).
The card quotes the article, states the condition, and asks you to name what you are relying on. Recording that reliance prefills and explains — it never changes the obligation's status and never counts towards any completion figure or coverage. Whether your organisation truly complies with its own governance rules is not something the product can see; the status stays yours. A voluntary standard such as ISO/IEC 42001 is not sectoral Union law and does not open the Art. 17(3) route.