VeritomeHelp Centre
/
Browse documentation
Help Centre · 30 articles

Using Veritome

One article per screen, in the order of the rail.

Position
Dashboard
  • Understand the Dashboard
    The first screen: five counts with denominators, your programmes with the next step in each, one action queue, what Aria found, five gated items of work this week, the dates split honestly, and the regulatory updates.
  • How obligation completion is scored
    The completion figure is phase-weighted — implementation carries 45 of 100 points — with priority weighting inside each phase and a hard zero for prohibited systems.
AI systems
  • Register your first AI system
    Add an AI system, answer the guided questions — role, duties, model, prohibited practices, risk, transparency, GDPR — and get a classification with the exact obligations that apply.
  • AI systems: the register and the system record
    The inventory every duty hangs off — four counts, the register filters, list or board, CSV import — and the seven-tab record each system opens onto.
  • Classify a system: the guided flow, screen by screen
    Classification decides your risk tier and role, which decide what you must do. Eight screens and a review — role, Art. 25, GPAI, Art. 5, Annex III, Art. 6(3), Art. 50 and the five GDPR questions.
  • The six-phase compliance journey
    Every system moves through six gate-locked phases — Classify, Scope, Implement, Assess, Register, Monitor — and empty phases never block.
Obligations
  • Scope obligations and assign owners
    After classification, confirm which derived obligations genuinely apply, mark the rest not applicable, put a named owner on each, and settle the Art. 4 literacy duty.
  • Work an obligation: register, drawer, evidence
    Drive obligations from the register or a system record: List, Board or Timeline; filters by domain, framework, scope and system; the drawer's form, evidence and history; the four-eyes rule.
  • Dates and deadlines: the Obligations timeline
    Every dated thing — obligation due dates, periodic reviews, incident clocks, statutory milestones, programme steps — is a row on the Obligations register. The Timeline view buckets them by week, and red means one thing.
  • Data governance: Art. 10 dataset practices per system
    The Data domain of the Obligations register: Art. 10 training, validation and testing data practices for every high-risk system, the deployer's Art. 26(4) input-data duty, and the GDPR rows generated beside them.
  • Transparency notices: Art. 50 disclosure duties
    The Transparency domain of the Obligations register: Article 50 duties for systems that talk to people, read emotions or generate synthetic content — and the notice studio that drafts the wording.
  • Human oversight: Art. 14 measures and the deployer's Art. 26(2) duties
    The Oversight domain of the Obligations register: who can intervene in each high-risk system, how the stop mechanism works, how automation bias is countered — the provider designs the measures, the deployer assigns and equips the people.
  • GPAI disclosures: the Art. 53/55 duties
    For general-purpose model providers: the Documentation domain holds the downstream model documentation, the copyright policy and the training-data summary — and the extra Art. 55 layer when a model carries systemic risk.
  • Steps: Aria drafts, a person approves, then it counts
    Open a step, answer its questions or let Aria draft from what you already have, then approve. Only approval files the record as evidence and creates the control.
Do the work
Controls
Evidence
Policies
  • Policies: what the organisation decided once
    The organisation-scope record register: the Art. 4 literacy programme, the Art. 17 policy pack, the retention policy, the programme steps that produce a policy, and the six policy documents you write and approve.
  • Organisation policies: write, approve, issue
    The six organisation-wide policies the EU AI Act asks a provider for, as clause outlines you write into — guidance is never prefilled, approving issues a version, and an approved policy is never edited in place.
Risks
  • Risks: Art. 9 risks, the heat-map and reviews
    Log and score Art. 9 risks with the seven-step guided wizard, read the heat-map, see which Art. 9, Art. 27 and Art. 55 assessments each system still owes, and complete scheduled reviews that leave a dossier entry.
Suppliers
Incidents
Prove it
Assessments
Audit trail
Academy
  • AI literacy: satisfying Article 4
    Art. 4 binds every provider and deployer since 2 February 2025 — answer the Academy's six questions, complete the programmes they assign, and keep a twelve-month record that counts as evidence.
  • The Academy: your AI literacy record, and when it lapses
    Article 4 binds every person who works with AI, not only the technical roles. Six questions decide which programmes apply to you, the answers are filed as evidence, and the record you earn is valid for twelve months.
Documents
  • Documents: owed, drafted, approved, issued
    The register of every document your frameworks require, counted as instances in four buckets, laid out per system as a matrix, with the Issued archive that keeps every produced version.
  • Documents: every document your frameworks require, one register
    The register of every document you owe — organisation-wide ones as a list, per-system ones as a grid of type against system — with four counts that say where the work actually stands, and an issued archive that never overwrites.
  • Instructions for use: the Art. 13 package
    What a provider's instructions for use must contain under Art. 13(3), how the package is built and handed to deployers, how a deployer receives it, and where it feeds the deployer's own duties.
Reports
Configure
Frameworks
Organisation
  • Invite your team and assign owners
    Add colleagues, pick from six least-privilege roles, keep the org profile that feeds your documents, and assign obligation owners so work is accountable.
  • Plans, billing and upgrades
    Early access is free with 30% off locked in for life; then Classify, Starter (€79), Govern (€199) and Manage (€599), Enterprise by quote; ISO/IEC 42001 and NIST included from Govern, ISO/IEC 27001 at €199 on Govern and included in Manage; annual billing at ten months for twelve, and what happens at a limit.
  • Organisation: profile, members, billing, security and data
    The Configure screen for everything set once: the organisation profile that feeds your documents, members and roles, your own AI literacy standing, billing, SSO, security, data residency, API keys, integrations and notifications.
  • Webhooks: react to compliance events in real time
    Register an HMAC-signed webhook so downstream tools react the moment a system is registered, an obligation changes status, an incident is filed or evidence is verified.
  • Set up SSO and SCIM provisioning
    Connect your identity provider over OIDC for single sign-on, and mint SCIM tokens so your IdP provisions and deactivates users automatically — both Enterprise features, configured by an Admin.
  • API keys and organisation data export
    Create hashed, scoped API keys for programmatic access, generate a sealed export of all organisation data, and file a GDPR erasure request.