# Governance Report — AI-assisted rental applicant risk assessment (Decision Support)

_HumanOSE — governance preparation, assurance support and audit-ready evidence. No legal compliance certification._

**Product:** HumanOSE  
**Use Case:** uc\_cx\_a01 (v2)  
**Source system:** causax  
**Language:** EN  
**Data mode:** synthetic  
**Generated at:** 2026-09-04T07:26:50.028Z  
**Report status:** Active  
**Integrity hash:** 0b0e9b5dbc38e7b1…  

> This report is based exclusively on synthetic data (pilot operation). No real personal data.

> This report does not certify legal compliance.

## Executive summary

An AI-assisted process prepares a structured, explained and uncertainty-flagged assessment for the rental decision (completeness of documents, plausibility and risk indicators). The pilot uses synthetic profiles only; the assessment model itself is not implemented in the pilot but is governed.

- **Intended purpose:** Clarified (v2): Automated individual decisions are technically and organizationally excluded; the appeal channel for affected persons is part of the operating concept.
- **Preliminary risk class:** Near high-risk — mandatory human oversight, external legal review recommended
- **Human oversight required:** Yes
- **Governance Readiness:** 2/16 Controls with evidence/reviewed

> Governance Readiness denotes the degree of preparation (evidence in place/reviewed) — it does not certify conformity.

## Use case profile

- **Intended purpose:** Clarified (v2): Automated individual decisions are technically and organizationally excluded; the appeal channel for affected persons is part of the operating concept.
- **Affected groups of persons:** natuerliche\_personen\_mietinteressenten, mitarbeitende\_verwaltung
- **Data sources:** personenbezogen\_selbstauskunft, personenbezogen\_unterlagen\_metadaten, objektdaten
- **AI function:** screening\_support, recommendation
- **Potential impact:** zugang\_essentielle\_leistung, oekonomisch\_personenbezogen, diskriminierungsrisiko\_zu\_pruefen
- **Jurisdiction:** eu-de
- **Source system:** causax
- **Lifecycle state:** Active

## Risk assessment (preliminary)

- **Preliminary risk class:** Near high-risk — mandatory human oversight, external legal review recommended
- **Confidence of the assessment:** medium
- **Ruleset:** v0.1.0
- **Human review required:** Yes

> The risk classification is preliminary and does not replace a legal assessment.

### Reasoning (rule reference)

- R-HIGH-SCREEN-01 — Screening of natural persons affecting access to an essential service (housing) — near high-risk constellation, mandatory human oversight.
- R-ELEV-ECON-01 — Economic impact on natural persons — decision support requires human approval of effective steps.
- R-ELEV-PII-01 — Processing of personal data sources — GDPR principles (purpose limitation, data minimization, data subject rights) must be applied.
- R-LIM-TRANSPARENCY-01 — Generative or recommending AI function — transparency and labeling obligations must be reviewed.

### Open legal questions

- Is access to housing to be classified as an essential private service within the meaning of Annex III of the EU AI Act? External legal review recommended; until clarified it is treated as near high-risk.

### Recommended risk mitigations

- Mandatory human review of every individual-case assessment by a named accountable person.
- Bias review and monitoring of the assessment logic before and during use.
- Establish an appeal/correction channel for affected persons (Incident & Appeal Register).
- Data minimization: process only governance-necessary categories, no copies of raw data.
- Every effective action (booking, decision, notification) is approved by a human.
- Role-based access control and audit events for every access to sensitive objects.
- Label AI-generated content as such; escalation to a human is possible at any time.
- Obtain external legal review before any real use (near high-risk constellation).

### Uncertainty of the assessment

Rule set v0.1 works with internal review heuristics on the EU AI Act, GDPR, Swiss DSG and the UK context. The assessment depends on the completeness of the registry entries and does not replace a legal review.

## Policy & control overview

> The control status documents the review of the evidence — it does not certify conformity.

| Control | Reference | Status | Evidence |
|---|---|---|---|
| Check for prohibited practices | EU AI Act Art. 5 | Open | 0 |
| Risk management system | EU AI Act Art. 9 | Open | 0 |
| Data governance | EU AI Act Art. 10 | Open | 0 |
| Technical documentation (Annex IV-like) | EU AI Act Art. 11 / Annex IV | Open | 0 |
| Record-keeping / logging | EU AI Act Art. 12 | Open | 0 |
| Transparency & labeling | EU AI Act Art. 13 / 50 | Open | 0 |
| Human oversight | EU AI Act Art. 14 | Reviewed (evidence) | 1 |
| Accuracy, robustness, cybersecurity | EU AI Act Art. 15 | Open | 0 |
| Lawfulness of processing | DSGVO Art. 6 | Open | 0 |
| Data minimization | DSGVO Art. 5(1c) | Evidence attached | 1 |
| Data protection impact assessment (DPIA) | DSGVO Art. 35 | Open | 0 |
| Data subject rights | DSGVO Art. 12–22 | Open | 0 |
| Bias monitoring | SysTec Policy AI-BIAS-01 | Open | 0 |
| AI literacy of those involved | EU AI Act Art. 4 | Open | 0 |
| Access control | ISO 27001 A.9 (Referenz) | Open | 0 |
| Audit/evidence chain | SysTec Evidence Standard (ADR-003) | Open | 0 |

### Open gaps

- Check for prohibited practices
- Risk management system
- Data governance
- Technical documentation (Annex IV-like)
- Record-keeping / logging
- Transparency & labeling
- Accuracy, robustness, cybersecurity
- Lawfulness of processing
- Data protection impact assessment (DPIA)
- Data subject rights
- Bias monitoring
- AI literacy of those involved
- Access control
- Audit/evidence chain

## Human oversight

- **Responsible human:** actor\_klaus
- **Reviewer:** actor\_klaus (reviewer)

> Human responsibility remains mandatory; AI does not make automatic decisions about persons.

### Review history

| Timestamp | Reviewer | Decision |
|---|---|---|
| 2026-07-10T11:52:53.672Z | actor\_klaus | Changes required |
| 2026-07-10T11:52:53.706Z | actor\_klaus | Approved by human review |
| 2026-07-10T11:52:53.718Z | actor\_klaus | Approved by human review |

## Evidence summary

- **Evidence chain status:** invalid (suspected tampering)
- **Number of evidence events:** 73
- **Verification passed:** No

> Simulated anchoring (PageCipher integration pending) — marked as a simulation.

| # | Timestamp | Actor | Action | Hash |
|---|---|---|---|---|
| 666 | 2026-09-02T19:07:56.722Z | actor\_system\_humanose | governance\_report\_generated | 4efb8ea00fa9… |
| 674 | 2026-09-02T19:07:58.696Z | actor\_system\_humanose | governance\_report\_generated | e18b35d8602a… |
| 692 | 2026-09-04T04:53:43.241Z | actor\_system\_humanose | governance\_report\_generated | ce672229e052… |
| 696 | 2026-09-04T04:54:26.545Z | actor\_system\_humanose | governance\_report\_generated | 6f8a7c8a6673… |
| 726 | 2026-09-04T05:42:26.500Z | actor\_system\_humanose | governance\_report\_generated | d326a38934ad… |
| 776 | 2026-09-04T06:34:42.919Z | actor\_system\_humanose | governance\_report\_generated | 6dc74c9c68fd… |
| 780 | 2026-09-04T06:34:52.690Z | actor\_system\_humanose | governance\_report\_generated | eba816525367… |
| 796 | 2026-09-04T06:38:09.648Z | actor\_system\_humanose | governance\_report\_generated | 09d47cfc39e4… |
| 832 | 2026-09-04T06:46:59.197Z | actor\_system\_humanose | governance\_report\_generated | 7cf9a8bfcb2e… |
| 898 | 2026-09-04T07:25:02.348Z | actor\_system\_humanose | governance\_report\_generated | 9204e9504d9a… |
| 905 | 2026-09-04T07:25:09.422Z | actor\_system\_humanose | governance\_report\_generated | eb124211e060… |
| 908 | 2026-09-04T07:25:09.504Z | actor\_system\_humanose | governance\_report\_generated | 49d8d8d8c905… |
| 911 | 2026-09-04T07:25:53.755Z | actor\_system\_humanose | governance\_report\_generated | eceee2e99ea0… |
| 939 | 2026-09-04T07:26:05.091Z | actor\_system\_humanose | governance\_report\_generated | 009f109992c1… |

### PageCipher anchor status

- **PageCipher integration status:** Active (HTTP integration with PageCipher)
- **PageCipher anchor status:** 47/73 Anchored
- **PageCipher anchor reference:** pagecipher:2c25260d08b829c022ebab64e1ce89ea
- **Last anchoring attempt:** 2026-09-04T07:26:05.095Z

> The PageCipher anchor proves the integrity and provenance of the evidence — it does not certify legal compliance.

## Open risks & gaps

- 14 open controls without evidence
- Is access to housing to be classified as an essential private service within the meaning of Annex III of the EU AI Act? External legal review recommended; until clarified it is treated as near high-risk.

## Legal notices (disclaimer)

- This report does not certify legal compliance.
- The risk classification is preliminary and does not replace a legal assessment.
- The legal assessment may require a specialized legal review.
- This report serves governance and compliance preparation on an evidence basis. It does not constitute legal advice, certification, or a conformity attestation.
- Human responsibility remains mandatory; AI does not make automatic decisions about persons.

## Appendix

### Control catalog

| Control | Source | Reference |
|---|---|---|
| Check for prohibited practices | eu\_ai\_act | EU AI Act Art. 5 |
| Risk management system | eu\_ai\_act | EU AI Act Art. 9 |
| Data governance | eu\_ai\_act | EU AI Act Art. 10 |
| Technical documentation (Annex IV-like) | eu\_ai\_act | EU AI Act Art. 11 / Annex IV |
| Record-keeping / logging | eu\_ai\_act | EU AI Act Art. 12 |
| Transparency & labeling | eu\_ai\_act | EU AI Act Art. 13 / 50 |
| Human oversight | eu\_ai\_act | EU AI Act Art. 14 |
| Accuracy, robustness, cybersecurity | eu\_ai\_act | EU AI Act Art. 15 |
| Lawfulness of processing | gdpr | DSGVO Art. 6 |
| Data minimization | gdpr | DSGVO Art. 5(1c) |
| Data protection impact assessment (DPIA) | gdpr | DSGVO Art. 35 |
| Data subject rights | gdpr | DSGVO Art. 12–22 |
| Bias monitoring | internal\_policy | SysTec Policy AI-BIAS-01 |
| AI literacy of those involved | ai\_literacy | EU AI Act Art. 4 |
| Access control | security | ISO 27001 A.9 (Referenz) |
| Audit/evidence chain | audit | SysTec Evidence Standard (ADR-003) |

### Generation metadata

- **Generated at:** 2026-09-04T07:26:50.028Z
- **Version:** 0.1.0
- **Language coverage:** 100 %
- **Number of evidence events:** 975
