EU AI Act · Assurance Role

EU AI Act Auditor.

Your job is to verify. Not to be handed a folder the night before and told everything is fine.

Without EAB — Today
Documentation assembled the night before your review
No way to verify compliance state at a specific past date
Unclear which legal version was consulted at each decision
Coordinating with client staff just to access records
Evidence may have been added retroactively — no way to tell
Supervisor identity on decisions: often absent or verbal only
The auditor’s position

“A compliance record that required coordination to produce is not a compliance record. It’s a reconstruction.”

EAB Design Principle · Reconstructability without Effort
Your workspace

Everything you need. Nothing you have to ask for.

EAB gives auditors a dedicated, read-only workspace that is completely independent of the organization's day-to-day compliance operations. You access what you need without a single email to the client team — and without any risk of influencing the live system.

Every record in the system is timestamped, frozen on creation, and attributed to a named role. You can query the compliance state of any AI system at any point in time — not just today, but as it was on the date of a specific determination.

Legal version snapshots are attached to every screening result. You can verify not just what was decided, but which version of Regulation (EU) 2024/1689 was in force when the decision was made — and whether the obligation set derived from it was correct under that version.

Auditor Workspace Includes
  • RecordsAll AI systems in the organization
  • HistoryFull screening history per system
  • LegalVersion snapshot per determination
  • TrailSupervisor identity & bypass log
  • EvidenceAttached documentation per obligation
  • ExportPDF per system & compliance cycle
  • AccessRead-only — no write capability at all
What you can verify

Six things an auditor can determine independently.

No interviews. No document requests. No "we'll get that to you." The answers are in the record.

Art. 6–9

Risk Classification

The risk level assigned to each AI system, the articles applied, the legal version in force at classification, and the supervisor who authorized the result — all in one record.

CELEX 32024R1689

Legal Version at Each Decision

Every screening result carries a frozen snapshot of the regulation version consulted. You can verify that the obligation derivation was correct under the law as it stood — not as it stands today.

Decision Trail

Who Decided — and When

Every determination is attributed to a named supervisor with a UTC timestamp. Override and bypass events are logged with justification — the record is never silent about how a decision was reached.

Art. 9–17

Obligation Completion

The full obligation set derived from the screening result, the status of each obligation, and the evidence attached. You can assess whether the organization acted on what the law required — obligation by obligation.

Annex IV

Technical Documentation

Technical records collected during the screening workflow: training data governance, model architecture, human oversight provisions, and performance metrics — structured to the Annex IV checklist.

Re-Screening History

Response to Legal Changes

When the regulation changed, which systems were flagged, when they were re-screened, and what changed in the determination — the complete response timeline, without gaps.

How it works

An audit session, start to finish.

No onboarding call. No document handover. No waiting.

1
Access

You receive auditor access credentials

The organization grants you read-only access to their EAB workspace. No installation, no VPN, no document handover. You log in and the records are there — exactly as the compliance team sees them, minus any write capability.

2
Overview

Review the AI system inventory

The full system inventory is visible: each registered AI system, its risk classification, screening status, and obligation completion state. You can filter by risk level, screening date, or legal change event — without asking anyone.

3
Deep Dive

Inspect individual records

For each system: the complete screening history, the legal version snapshot at each determination, the obligation set with evidence attached, the supervisor decision trail including any bypass events, and the technical documentation. Everything is there. Nothing is summarized.

4
Export

Export what you need

PDF export of the complete compliance record per AI system — or per obligation cycle. The export reflects the frozen state of the record, not the current state. You decide the reference date. The record reconstructs itself.

For your clients

Recommend EAB to the organizations you audit.

If your clients use EAB, your next audit starts the moment you log in — not the moment they finish preparing.

EU-hosted · Anchored to CELEX 32024R1689

Get in Touch
Request More Information

Tell us about your organization and what you’re looking to address. We’ll follow up with the relevant information.