Organisation policies: write, approve, issue
The six organisation-wide policies the EU AI Act asks a provider for, as clause outlines you write into — guidance is never prefilled, approving issues a version, and an approved policy is never edited in place.
Some documents exist once for the organisation and are written, not composed: the policies. Veritome holds six as policy documents — a clause outline per type, an editor that autosaves as you write, and an approval that issues a version.
The six policies
| Policy | Anchor |
|---|---|
| AI governance policy | Art. 17(1)(a) — the strategy for regulatory compliance the quality management system starts from. |
| Roles, responsibilities and RACI | Art. 17(1)(m) — the accountability framework: who is responsible for what. |
| Record-retention and documentation-control policy | Art. 18 — what is kept, for how long, and who controls the documents. |
| GPAI copyright compliance policy | Art. 53(1)(c) — a GPAI model provider's policy for Union copyright law, including text-and-data-mining reservations. |
| Authorised representative mandate | Art. 22 / Art. 54 — the written mandate a non-EU provider gives its EU representative. |
| Value-chain written agreement | Art. 25(4) — the agreement with third parties supplying tools, services, components or processes for a high-risk system. |
They appear in Documents under organisation-wide and in Policies beside the programme records; each opens at its own URL.
Guidance is guidance, never text
Each clause carries the catalogue's suggested content beside an empty field. That suggestion is never copied into the policy. A policy somebody approved without writing is worse than an empty one, and prefilling our wording is exactly how that happens — the person clicks approve on words nobody in the organisation has thought about. You write every clause; the outline tells you what a clause is for.
Approval issues a version
A policy can be approved only when every clause carries the organisation's own words. Approval computes the hash of the clause text and appends the version to the Issued archive, where it stays readable under that hash. An approved policy is not edited in place: making a change reopens it as a new version, and the version already approved is still there in the archive, with its date, for anyone who relied on it.
Download as Word
Every policy can be downloaded as a Word document (.docx) on the Veritome policy template — a title page with the document-control table and the frameworks the policy addresses, a table of contents, the clauses as numbered sections in the order of the outline, the definitions, a framework crosswalk built from the policy's own references, the review-and-approval table and the version history from the Issued archive, with a running header and footer. It carries exactly the clauses as written: a clause not yet written appears as a bracketed placeholder, never as the guidance, and a draft says so on its title page. The download is on every plan where document generation is; the file's SHA-256 travels in the response header so a copy can be matched to the version it came from.
What this is not
Policies are not the programme records. The AI policy that ISO/IEC 42001 asks for, the ISMS scope, the privacy governance policy — those are steps in their programmes, produced through the step drawer and approved there. The six above are the EU AI Act's own organisation-level documents, and they have no programme step to point at, which is why they have a home of their own.