How Veritome works

One engine.
Six phases. Zero guesswork.

Under the surface, Veritome runs on a proprietary compliance obligation engine — a deterministic model of the EU AI Act that turns a 113-article Regulation into the exact obligations for your systems. Everything you see on screen is that engine, made walkable in six clear phases.

The engine underneath

A rules engine for the law — not a chatbot guessing at it.

Most tools either hand you a static PDF checklist or ask a language model to improvise your obligations. Veritome does neither. The legal core is a proprietary obligation engine: a structured, article-by-article model of the EU AI Act that reads each system's role, risk tier and characteristics, and returns the precise set of obligations, deadlines and evidence it owes — and nothing it doesn't.

It is the single source of truth across the whole product. Every tab, score, document and reminder you see is derived from it — which is why a classification you defend to a regulator today reads identically a year from now.

Deterministic, not a guess

The legal core is a rules engine, not a language model. The same inputs always produce the same obligation set — so a decision you defend to an auditor today reads identically tomorrow.

Anchored to the Article

Every obligation, deadline and control cites the exact provision it comes from. Nothing is asserted without a reference you can look up in the Regulation itself.

Kept current, centrally

When guidance or the law changes, the engine is the single place we update — and every affected system re-derives its obligations. You inherit the change without re-reading 113 articles.

The engine's internal logic is Veritome intellectual property. What we share openly is the outcome — the exact article references behind every obligation — so your compliance is fully auditable without exposing how the mapping is built.

The compliance journey

From first classification to live monitoring, in six phases.

Every system moves through the same journey. Phases are gate-locked — you can't register a system you haven't assessed — and empty phases are skipped automatically when they don't apply to your role. The bar at the top of each system shows exactly where it stands.

01

Classify

Know exactly what you're holding.

Answer a short set of questions per system. The engine returns a risk tier — prohibited, high, limited or minimal — anchored to the specific articles that decide it, plus the Art. 6(3) high-risk exception where it applies.

Art. 5 · Art. 6 · Annex III
02

Scope

See only the obligations that are actually yours.

Your role (provider, deployer, importer, distributor) and risk tier resolve to the exact obligation set — nothing generic, nothing missing. A deployer of a limited-risk chatbot and a provider of a high-risk system get two different, correct lists.

Art. 16–27 · role × risk
03

Implement

Put the controls in place, with the proof attached.

Work each obligation as a guided checklist — human oversight, logging, data governance, technical documentation — attaching evidence as you go. Evidence carries expiry dates, so coverage stays honest over time.

Art. 9–15 · Art. 26
04

Assess

Run the assessments the Act requires, on the record.

Guided fundamental-rights (FRIA) and conformity assessments, with a sealed report at the end. Where a DPIA already exists under the GDPR, the overlap is mapped so you don't do the same work twice.

Art. 27 · Art. 43 · Annex IV
05

Register

Hand the regulator a dossier that holds up.

Annex VIII registration fields pre-filled from your system record, a Declaration of Conformity, and a hash-sealed dossier with a public verify URL your auditor can check independently.

Art. 49 · Art. 47 · Annex VIII
06

Monitor

Stay compliant after go-live, not just at launch.

Post-market monitoring, serious-incident reporting inside the Art. 73 window, scheduled reviews, and a live regulatory-change watch that flags when the law — or your obligation set — moves under you.

Art. 72 · Art. 73 · post-market