Role · Provider

The heavy role, assembled rather than authored.

A provider develops an AI system and places it on the market under its own name. For a high-risk system that is the full Chapter III set — risk management, Annex IV documentation, a quality management system, conformity assessment, CE marking, registration and post-market monitoring. Veritome derives it from one register instead of thirteen documents that disagree.

No card · EU-hosted · 5 minutes to a first classification
Veritome Annex IV technical-file builder — sections assembled from live system data with a hash-sealed export
The reality

Where provider programmes stall.

What we hear

“We have the documents, but they contradict each other.”

What the product does

Thirteen artefacts maintained by hand drift the week after they are written. When the technical file, the risk register and the declaration all read the same record, they cannot disagree.

What we hear

“We did not think Article 25 applied to us.”

What the product does

Putting your name on a high-risk system, substantially modifying one, or repurposing one into high-risk makes you its provider. Plenty of companies are providers without having built a model.

What we hear

“The auditor asked how a decision was reached and we had the outcome, not the reasoning.”

What the product does

A conformity route chosen in a meeting is not a record. Every decision here carries who made it, when, and the article it rests on — hash-chained and exportable.

What you get

One register, thirteen artefacts.

01

Annex IV that assembles itself

Sections built from live system data, edited and approved by a named person, then sealed with a hash. A sealed file is never edited — a change makes a new version.

02

Risk management as a lifecycle

Article 9 wants a continuous iterative process, not a document. Hazards, mitigations and residual rating, revisited as the system changes.

03

The QMS without a second system

Article 17 maps onto the ISO 42001 programme, so the clauses tick from work you already did rather than from a parallel binder.

04

Conformity route, recorded

Annex VI internal control or the third-party route, with the reasoning captured — including which harmonised standards were applied.

05

Annex VIII pre-filled

The Article 49 registration fields, filled from the register, with the gaps named. The portal submission becomes a paste.

06

Post-market monitoring that runs

Article 72 monitoring and Article 73 incident routing, with the reporting deadline computed from the date you knew.

In practice

Three ways companies become providers.

Use case 01

A SaaS company shipping a CV-ranking feature to EU customers.

  • Annex III point 4 — employment. High-risk, and the full provider set applies.
  • Annex IV assembles from the register; the IFU is generated for deployers to receive.
  • Internal-control route under Annex VI, with the standards applied recorded.
  • Registered under Art. 49 before it is placed on the market.
Veritome Annex IV technical-file builder — sections assembled from live system data with a hash-sealed export
Use case 02

A company white-labelling a vendor's scoring model under its own brand.

  • Art. 25(1)(a) — the name on the product makes them the provider.
  • The classification asks the branding question rather than assuming a buyer's role.
  • The vendor's documentation becomes an input, not a substitute for their own file.
  • The duty transfers with the brand, which is the part most teams miss.
Veritome guided classification — the register wizard that walks Article 5, Annex I, Annex III and the Article 6(3) exception
Use case 03

A team fine-tuning an open model for a regulated decision.

  • A substantial modification, or a changed intended purpose, or both — Art. 25(1)(b) and (c).
  • Data governance under Art. 10 covers the fine-tuning set, not only the base model.
  • Accuracy, robustness and cybersecurity evidence under Art. 15 belongs to them now.
  • One register carries both this and their deployer duties for bought tools.
Veritome risk register — portfolio risk KPIs and a severity-by-likelihood heat-map for Article 9 risk management
Also included

The parts a provider reaches for later.

Straight answers

Straight answers for providers.

We only fine-tuned someone else's model. Are we really a provider?

Possibly. Article 25(1) makes a deployer, distributor or importer into a provider of a high-risk system in three cases: putting your name or trademark on it, making a substantial modification to it, or changing its intended purpose so that it becomes high-risk. Fine-tuning can meet the second or third test depending on what changed. The classification asks the questions that decide it rather than leaving you to guess.

What does the provider set actually contain?

For a high-risk system: risk management across the lifecycle (Art. 9), data governance (Art. 10), technical documentation to Annex IV (Art. 11), automatic logging (Art. 12), instructions for use (Art. 13), human oversight design (Art. 14), accuracy, robustness and cybersecurity (Art. 15), a quality management system (Art. 17), conformity assessment (Art. 43), the EU declaration of conformity (Art. 47), CE marking (Art. 48), registration (Art. 49), post-market monitoring (Art. 72) and serious-incident reporting (Art. 73).

Do we need a notified body?

It depends on the route. Most Annex III high-risk systems take the internal-control route of Annex VI, which the provider performs itself. Systems covered by Annex I sectoral legislation, and biometric systems where no harmonised standard has been applied, take the third-party route. The classification records which route applies and why, so the file says how the decision was reached.

How does the technical file get built?

Annex IV sections assemble from the live record — the system description, the development process, the risk-management outputs, the data used, the oversight design, the accuracy and robustness evidence. You edit and approve; you do not start from an empty template. Sealing produces a hash-stamped version, and a sealed document is never edited: a change makes a new version.

When is registration required?

Article 49 requires the provider of an Annex III high-risk system to register it in the EU database before placing it on the market or putting it into service. Veritome pre-fills the Annex VIII fields from the register and tells you which are still missing, so the portal submission is a paste rather than a rediscovery exercise.