Browse documentation
Help Centre · 8 articles
Templates & records
FRIA, Annex IV, DoC, AI policy, SoA — what each is and how the step produces it.
01Generate documents: five builders, one registerEvery document your frameworks require has one editor, chosen by its kind — composed, prescribed, structured, policy or generated — and is produced from the obligation data you already entered, never typed twice.02Annex IV technical documentation, section by sectionWhat the Annex IV technical file must contain, how Veritome composes it from the Art. 9–15 obligations in a guided editor, and how issued versions are hash-sealed and kept for ten years.03FRIA: the fundamental-rights impact assessment, step by stepWho must run an Art. 27 FRIA, what the assessment covers, the Art. 27(3) notification and the Art. 27(4) link to the DPIA, when to revisit it, and how Veritome generates the report per system.04Declaration of Conformity, CE marking and Annex VIII registrationThe provider's Art. 47 declaration in the Annex V field set, the Art. 48 CE marking, and registering in the EU database with Veritome's pre-filled Annex VIII copy-out sheet — nothing is submitted to any authority for you.05Documents: every document your frameworks require, one registerThe register of every document you owe — organisation-wide ones as a list, per-system ones as a grid of type against system — with four counts that say where the work actually stands, and an issued archive that never overwrites.06DPIA overlap: reuse your FRIA where the GDPR meets the EU AI ActArt. 27(4) lets the FRIA draw on the GDPR Art. 35 DPIA and Art. 26(9) sends the instructions for use into it — Veritome shows both routes, maps completed FRIA answers onto the DPIA's four pillars and exports an input pack for your privacy team. None of it counts as coverage.07Organisation policies: write, approve, issueThe six organisation-wide policies the EU AI Act asks a provider for, as clause outlines you write into — guidance is never prefilled, approving issues a version, and an approved policy is never edited in place.08Instructions for use: the Art. 13 packageWhat a provider's instructions for use must contain under Art. 13(3), how the package is built and handed to deployers, how a deployer receives it, and where it feeds the deployer's own duties.