The control status documents the review of the evidence — it does not certify conformity.
Filter by source: All sources · AI literacy · Audit · EU AI Act · GDPR · Internal policy · Security
v0.1.0| ID | Control | Expected evidence | Risk classes | AI functions |
|---|---|---|---|---|
ai_literacy_staff |
AI literacy of those involved EU AI Act Art. 4 |
Evidence of sufficient AI literacy of the persons involved in the deployment. | Near high-risk — mandatory human oversight, external legal review recommended Elevated risk — human review required Limited risk — review transparency obligations | All functions (not restricted) |
| ID | Control | Expected evidence | Risk classes | AI functions |
|---|---|---|---|---|
audit_evidence_trail |
Audit/evidence chain SysTec Evidence Standard (ADR-003) |
Complete, hash-chained evidence trail of the governance-relevant actions. | Near high-risk — mandatory human oversight, external legal review recommended Elevated risk — human review required | All functions (not restricted) |
| ID | Control | Expected evidence | Risk classes | AI functions |
|---|---|---|---|---|
euaia_prohibited_check |
Check for prohibited practices EU AI Act Art. 5 |
Evidence that there is no use falling under the prohibited practices; in case of suspicion, external legal review. | Suspected prohibited practice — immediate human and legal review required Near high-risk — mandatory human oversight, external legal review recommended | All functions (not restricted) |
euaia_risk_management |
Risk management system EU AI Act Art. 9 |
Documented, iterative risk management across the entire lifecycle of the AI system. | Near high-risk — mandatory human oversight, external legal review recommended Suspected prohibited practice — immediate human and legal review required | All functions (not restricted) |
euaia_data_governance |
Data governance EU AI Act Art. 10 |
Evidence of appropriate data governance (relevance, representativeness, error handling of the input data). | Near high-risk — mandatory human oversight, external legal review recommended | All functions (not restricted) |
euaia_technical_documentation |
Technical documentation (Annex IV-like) EU AI Act Art. 11 / Annex IV |
Annex IV-like technical documentation in place, versioned and up to date. | Near high-risk — mandatory human oversight, external legal review recommended | All functions (not restricted) |
euaia_record_keeping |
Record-keeping / logging EU AI Act Art. 12 |
Automatic, traceable event logging (append-only) in place. | Near high-risk — mandatory human oversight, external legal review recommended Elevated risk — human review required | All functions (not restricted) |
euaia_transparency |
Transparency & labeling EU AI Act Art. 13 / 50 |
AI use is made transparent to affected persons; AI-generated outputs are labeled. | Near high-risk — mandatory human oversight, external legal review recommended Elevated risk — human review required Limited risk — review transparency obligations | All functions (not restricted) |
euaia_human_oversight |
Human oversight EU AI Act Art. 14 |
Human oversight plan with a named accountable human and the ability to intervene/override. | Near high-risk — mandatory human oversight, external legal review recommended Suspected prohibited practice — immediate human and legal review required | All functions (not restricted) |
euaia_accuracy_robustness |
Accuracy, robustness, cybersecurity EU AI Act Art. 15 |
Evidence of appropriate accuracy and robustness as well as suitable security measures. | Near high-risk — mandatory human oversight, external legal review recommended | All functions (not restricted) |
| ID | Control | Expected evidence | Risk classes | AI functions |
|---|---|---|---|---|
gdpr_lawfulness |
Lawfulness of processing DSGVO Art. 6 |
Documented legal basis for the processing of personal data. | Near high-risk — mandatory human oversight, external legal review recommended Elevated risk — human review required | All functions (not restricted) |
gdpr_data_minimization |
Data minimization DSGVO Art. 5(1c) |
Evidence that only necessary data categories are processed. | Near high-risk — mandatory human oversight, external legal review recommended Elevated risk — human review required | All functions (not restricted) |
gdpr_dpia |
Data protection impact assessment (DPIA) DSGVO Art. 35 |
DPIA carried out and documented where required. | Near high-risk — mandatory human oversight, external legal review recommended | All functions (not restricted) |
gdpr_data_subject_rights |
Data subject rights DSGVO Art. 12–22 |
Processes for access, rectification, objection and appeal by affected persons in place. | Near high-risk — mandatory human oversight, external legal review recommended Elevated risk — human review required | All functions (not restricted) |
| ID | Control | Expected evidence | Risk classes | AI functions |
|---|---|---|---|---|
bias_monitoring |
Bias monitoring SysTec Policy AI-BIAS-01 |
Bias review and monitoring of the assessment logic documented (in particular for the screening of natural persons). | Near high-risk — mandatory human oversight, external legal review recommended | screening_support |
| ID | Control | Expected evidence | Risk classes | AI functions |
|---|---|---|---|---|
security_access_control |
Access control ISO 27001 A.9 (Referenz) |
Role-based access control and audit logs for sensitive objects in place. | Near high-risk — mandatory human oversight, external legal review recommended Elevated risk — human review required | All functions (not restricted) |