Governance Chain · Chain of Custody

From registration to audit — one attributable chain.

Six stages. Four roles. Every handoff documented, every artifact structured and attributable. This is how governed AI compliance produces a reconstructable record.

EAB structures role separation by design — no single actor can complete the governance cycle alone. Each stage produces a timestamped artifact that the next stage builds on, creating a chain of custody that holds under external scrutiny.

6 stages 4 distinct roles Artifact integrity at every stage
The governance chain

Every stage is gated. Every handoff is documented.

Each stage is gated on the previous one. The output of every stage is a structured, timestamped artifact — not a field in a form.

1
Business Operator

System Registration

The operator registers the AI system through a structured wizard. Business context, deployment scope, affected populations, and intended use — all captured in a defined schema, not free-text fields that drift between audits.

  • System name, version, and deployment context
  • Intended purpose and use-case scope
  • Affected user groups and geographic deployment
  • Initial actor role classification (Provider / Deployer / Both)
Output Artifact
System Profile — Business Draft
State: draft_business
Anchors: Organization, responsible operator, UTC timestamp

Next gate: AI System Owner must complete the technical profile before screening can begin.
Handoff to technical owner
AI System Owner / IT
2
AI System Owner · IT Department

Technical Completion

The AI system owner or IT department adds the technical layer that the law requires to be documented: training data characteristics, model architecture, decision output type, and human oversight provisions.

  • Training data origin and quality controls (Art. 10)
  • Model type, output format, and decision influence
  • Human oversight mechanisms and override capability
  • Performance metrics and known limitations (Annex IV)
Output Artifact
Technical Profile — Complete
State: draft_technical
Anchors: AI system owner, version stamp, technical specification

Next gate: Supervisor must initiate screening. Technical profile is locked from this point.
Supervisor initiates screening session
Compliance Supervisor
3
Compliance Supervisor

Supervisor Screening

The most critical stage. A qualified supervisor initiates the screening session against the obligation profile for the system's risk classification. EAB analyzes the system against Annex III criteria and derives the full obligation set. The supervisor retains override authority — but every bypass is logged with justification.

  • Risk classification against Annex I & III (Art. 6–9)
  • Prohibited practice check (Art. 5)
  • Obligation derivation from classification result
  • Legal version snapshot: CELEX 32024R1689 anchored
  • Supervisor override: logged with reason, never silent
Output Artifact
Screening Result — Sealed
State: approved
Anchors: Risk level, applicable articles, supervisor identity, legal version, UTC timestamp

Immutable: Record is frozen on approval. Re-screening creates a new record — never overwrites.
Obligation set activated for all roles
All Roles
4
All Roles

Obligation Management

The screening result activates a structured obligation set, derived from the risk classification and legal source context. Each obligation is mapped to its article reference, assigned to a role, and tracked independently. The legal source context informs the obligation logic — human responsibility for each obligation remains intact and attributed.

  • Art. 9 — Risk Management System implementation
  • Art. 13 — Transparency obligations per user group
  • Art. 14 — Human oversight provision documentation
  • Art. 17 — Quality Management System policies
  • Art. 43 — Conformity assessment path (if Annex III)
Output Artifact
Obligation Set — Active
State: in progress
Anchors: Screening result, article references, role assignments

Live: Status updates as roles complete obligations and attach evidence.
Evidence attached per obligation
All Roles
5
All Roles

Evidence Collection

Each obligation requires evidence. EAB structures what must be collected — technical documentation, conformity declarations, QMS policies, data governance records, oversight logs. Evidence is attached to the obligation record, not stored separately in a folder that nobody finds at audit time.

  • Technical documentation per Annex IV checklist
  • Data governance records (Art. 10)
  • Human oversight logs and intervention records
  • QMS policies and review cycle documentation
  • Conformity declaration (provider, if Annex III)
Output Artifact
Evidence Package — Attached
State: complete
Anchors: Each document linked to its obligation & article

Frozen: Evidence is sealed when the obligation is marked complete. History is preserved on any update.
Read-only access granted to auditor
Auditor
6
Auditor · Read-Only

Audit Access

External or internal auditors receive a dedicated, read-only workspace. Sealed records, complete decision trails, legal version snapshots, and PDF exports — structured for conformity assessments and supervisory authority reviews, without requiring preparation from your team and without any modification access to live records.

  • Full screening history per AI system
  • Obligation status and evidence per article
  • Legal version in force at each determination
  • PDF export of complete compliance record
  • Supervisor identity and bypass log (if applicable)
Output Artifact
Audit Trail — Frozen
State: auditable
Anchors: All prior stage artifacts, timestamps, role identities

Immutable: No actor can modify records in auditor view. History only grows — never shrinks.
When the law changes

The chain restarts at Stage 3 — automatically.

When incorporated legal source changes are confirmed, EAB analyzes which obligation areas are affected and flags each impacted system for controlled re-screening. A new screening record is created — anchored to the new legal version — while the entire previous chain remains intact. The audit trail is never modified. It only grows.

Re-Screening
↺ Stage 3
Get started

Put your AI systems through the chain.

Available from Professional. The full governance chain activates the moment your first system is registered.

EU-hosted · Anchored to CELEX 32024R1689

Get in Touch
Request More Information

Tell us about your organization and what you’re looking to address. We’ll follow up with the relevant information.