How Veritome works

One engine. Six phases. No guesswork.

Under the surface, Veritome runs on an obligation engine — a deterministic, article-by-article model of the EU AI Act that turns a 113-article Regulation into the exact obligations for your systems. Everything on screen is that engine, made walkable in six phases, with the GDPR beside it and the voluntary standards running as programmes on the same register.

Deterministic · Article-anchored · EU-hosted
The engine underneath

A rules engine for the law — not a chatbot guessing at it.

Most tools either hand you a static checklist or ask a language model to improvise your obligations. Veritome does neither. The legal core is a structured, article-by-article model of the Act that reads each system's role, risk tier and characteristics, and returns the precise set of obligations, deadlines and evidence it owes — and nothing it does not.

01

Deterministic, not a guess

The legal core is a rules engine, not a language model. The same inputs always produce the same obligation set — so a decision you explain to an auditor today reads identically tomorrow.

02

Anchored to the article

Every obligation, deadline and control cites the provision it comes from. Nothing is asserted without a reference you can look up in the Regulation itself.

03

Kept current, centrally

When guidance or the law changes, the engine is the single place we update — and every affected system re-derives its obligations. You inherit the change without re-reading 113 articles.

The engine's internal logic is Veritome intellectual property. What we share openly is the outcome — the exact article references behind every obligation — so your record is fully auditable without exposing how the mapping is built.

The EU AI Act path

From first classification to live monitoring, in six phases.

Every system moves through the same journey. Phases are gate-locked — you cannot register a system you have not assessed — and a phase with nothing that applies to your role is passed automatically. The bar at the top of each system shows exactly where it stands.

01

Classify

Know exactly what you are holding.

Answer a short set of questions per system. The engine returns a risk tier — prohibited, high, limited or minimal — anchored to the articles that decide it, plus the Art. 6(3) exception where it applies.

Art. 5Art. 6Annex III
02

Scope

See only the obligations that are actually yours.

Your role (provider, deployer, importer, distributor) and risk tier resolve to the exact obligation set — nothing generic, nothing missing. A deployer of a limited-risk chatbot and a provider of a high-risk system get two different, correct lists.

Art. 16–27Art. 25
03

Implement

Put the controls in place, with the proof attached.

Work each obligation as a guided checklist — human oversight, logging, data governance, technical documentation — attaching evidence as you go. Evidence carries expiry dates, so coverage stays honest over time.

Art. 9–15Art. 26
04

Assess

Run the assessments the Act requires, on the record.

Guided fundamental-rights (FRIA) and conformity assessments, with a sealed report at the end. Where a DPIA already exists under the GDPR, the overlap is mapped so you do not do the same work twice.

Art. 27Art. 43Annex IV
05

Register

Hand the regulator a dossier with every decision traced to its article.

Annex VIII registration fields pre-filled from your system record, a Declaration of Conformity, and a hash-sealed dossier with a public verify URL your auditor can check independently.

Art. 47Art. 49Annex VIII
06

Monitor

Keep the obligations live after go-live, not just at launch.

Post-market monitoring, serious-incident reporting inside the Art. 73 window, scheduled reviews, and a regulatory-change watch that flags when the law — or your obligation set — moves under you.

Art. 72Art. 73
The standards on top

Switch a framework on and it becomes a programme.

The EU AI Act and the GDPR are statutory and always on. ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF are yours to enable, and when you do, each becomes a programme: ordered steps in gated phases, one record per step, credit wherever a requirement is already evidenced by something you did for another framework.

The coverage matrix shows every requirement and what closes it. The Statement of Applicability is generated from the programme. The certificate, for any standard, comes from an accredited body — never from us.

The five frameworks and their crossover
ISO 42001ISO 42001 programme
27 steps · 27 records · 14 shared
01Establish
5 steps · Complete
02Plan
5 steps · In progress
03Support
3 steps · Locked
04Operate
8 steps · Locked
05Evaluate & improve
4 steps · Locked
06Certification audit
2 steps · Locked
Plan · the steps
  1. 01Risk methodology and AI risk assessmentShared recordApproved
  2. 02Risk treatment and Statement of ApplicabilityIn draft
  3. 03AI system impact assessmentPer systemTo do
  4. 04AI objectives and planning to achieve themShared recordTo do
Phases and steps as the product generates them · progress shown is illustrative
Veritome coverage matrix — every requirement of a framework and the step that closes it
Straight answers

What the engine will and will not do

Four questions we are asked on most evaluation calls, answered as the product ships today.

Is the obligation mapping done by an AI model?

No. The mapping is a deterministic rules engine: role, risk tier, Annex III area and behavioural flags resolve to the obligation set, and every obligation cites its article. Aria, the assistant, drafts and proposes; it never decides a classification or files anything.

What happens to the other frameworks?

The EU AI Act and the GDPR are statutory and always on. ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF are voluntary; switch one on and it runs as a programme of ordered steps, with credit wherever a record you already produced satisfies a clause.

Can I skip a phase?

Phases are gate-locked — you cannot register a system you have not assessed — but a phase with no applicable obligations for your role is complete by definition and the journey moves past it.

Is any of this legal advice?

No. Veritome structures the work and cites the law; the judgement calls belong to you and your counsel. Every screen names the article it rests on so that review is possible rather than guesswork.

Want the article-by-article view? Read the EU AI Act guide.