# Governance Report — Claims/accounting decision support

_HumanOSE — governance preparation, assurance support and audit-ready evidence. No legal compliance certification._

**Product:** HumanOSE  
**Use Case:** uc\_cx\_c03 (v1)  
**Source system:** causax  
**Language:** EN  
**Data mode:** synthetic  
**Generated at:** 2026-09-04T08:14:48.726Z  
**Report status:** Provisionally classified  
**Integrity hash:** 46a80b896e2ba584…  

> This report is based exclusively on synthetic data (pilot operation). No real personal data.

> This report does not certify legal compliance.

## Executive summary

Plausibility indicators, categorization suggestions and anomalies for claims and bookings.

- **Intended purpose:** Support for case handling — every effective booking/decision is approved by a human.
- **Preliminary risk class:** Elevated risk — human review required
- **Human oversight required:** Yes
- **Governance Readiness:** 0/8 Controls with evidence/reviewed

> Governance Readiness denotes the degree of preparation (evidence in place/reviewed) — it does not certify conformity.

## Use case profile

- **Intended purpose:** Support for case handling — every effective booking/decision is approved by a human.
- **Affected groups of persons:** natuerliche\_personen\_mieter, dienstleister
- **Data sources:** personenbezogen\_schadensmeldungen, buchungsdaten
- **AI function:** classification, recommendation
- **Potential impact:** oekonomisch\_personenbezogen
- **Jurisdiction:** eu-de
- **Source system:** causax
- **Lifecycle state:** Provisionally classified

## Risk assessment (preliminary)

- **Preliminary risk class:** Elevated risk — human review required
- **Confidence of the assessment:** high
- **Ruleset:** v0.1.0
- **Human review required:** Yes

> The risk classification is preliminary and does not replace a legal assessment.

### Reasoning (rule reference)

- R-ELEV-ECON-01 — Economic impact on natural persons — decision support requires human approval of effective steps.
- R-ELEV-PII-01 — Processing of personal data sources — GDPR principles (purpose limitation, data minimization, data subject rights) must be applied.
- R-LIM-TRANSPARENCY-01 — Generative or recommending AI function — transparency and labeling obligations must be reviewed.

### Recommended risk mitigations

- Every effective action (booking, decision, notification) is approved by a human.
- Data minimization: process only governance-necessary categories, no copies of raw data.
- Role-based access control and audit events for every access to sensitive objects.
- Label AI-generated content as such; escalation to a human is possible at any time.

### Uncertainty of the assessment

Rule set v0.1 works with internal review heuristics on the EU AI Act, GDPR, Swiss DSG and the UK context. The assessment depends on the completeness of the registry entries and does not replace a legal review.

## Policy & control overview

> The control status documents the review of the evidence — it does not certify conformity.

| Control | Reference | Status | Evidence |
|---|---|---|---|
| Record-keeping / logging | EU AI Act Art. 12 | Open | 0 |
| Transparency & labeling | EU AI Act Art. 13 / 50 | Open | 0 |
| Lawfulness of processing | DSGVO Art. 6 | Open | 0 |
| Data minimization | DSGVO Art. 5(1c) | Open | 0 |
| Data subject rights | DSGVO Art. 12–22 | Open | 0 |
| AI literacy of those involved | EU AI Act Art. 4 | Open | 0 |
| Access control | ISO 27001 A.9 (Referenz) | Open | 0 |
| Audit/evidence chain | SysTec Evidence Standard (ADR-003) | Open | 0 |

### Open gaps

- Record-keeping / logging
- Transparency & labeling
- Lawfulness of processing
- Data minimization
- Data subject rights
- AI literacy of those involved
- Access control
- Audit/evidence chain

## Human oversight

- **Responsible human:** Oversight assignment pending — a final responsible human must be named before approval.
- **Reviewer:** —

> Human responsibility remains mandatory; AI does not make automatic decisions about persons.

### Review history

No review decisions recorded yet.

## Evidence summary

- **Evidence chain status:** invalid (suspected tampering)
- **Number of evidence events:** 50
- **Verification passed:** No

> Simulated anchoring (PageCipher integration pending) — marked as a simulation.

| # | Timestamp | Actor | Action | Hash |
|---|---|---|---|---|
| 842 | 2026-09-04T06:47:25.290Z | actor\_system\_humanose | governance\_report\_generated | 8e182576e9d1… |
| 848 | 2026-09-04T06:47:41.209Z | actor\_system\_humanose | governance\_report\_generated | 9cc20acb2cc3… |
| 940 | 2026-09-04T07:26:05.129Z | actor\_system\_humanose | governance\_report\_generated | 3a9692555d05… |
| 954 | 2026-09-04T07:26:17.617Z | actor\_system\_humanose | governance\_report\_generated | b5cae4622b6f… |
| 961 | 2026-09-04T07:26:44.318Z | actor\_system\_humanose | governance\_report\_generated | 281d21d9c94c… |
| 972 | 2026-09-04T07:26:49.825Z | actor\_system\_humanose | governance\_report\_generated | c17c1ea05244… |
| 987 | 2026-09-04T07:27:12.937Z | actor\_system\_humanose | governance\_report\_generated | 73ee183e2333… |
| 1010 | 2026-09-04T07:27:52.609Z | actor\_system\_humanose | governance\_report\_generated | e6d17df607dc… |
| 1052 | 2026-09-04T07:39:11.578Z | actor\_system\_humanose | governance\_report\_generated | 18c63587f871… |
| 1054 | 2026-09-04T07:39:12.074Z | actor\_system\_humanose | governance\_report\_generated | 1ab889b82ffc… |
| 1066 | 2026-09-04T07:39:25.876Z | actor\_system\_humanose | governance\_report\_generated | abb4eb0bd822… |
| 1074 | 2026-09-04T07:39:53.073Z | actor\_system\_humanose | governance\_report\_generated | 14f2f688c376… |
| 1078 | 2026-09-04T07:39:54.066Z | actor\_system\_humanose | governance\_report\_generated | 55dfdb578993… |
| 1196 | 2026-09-04T08:14:13.619Z | actor\_system\_humanose | governance\_report\_generated | b72b60f745dd… |

### PageCipher anchor status

- **PageCipher integration status:** Active (HTTP integration with PageCipher)
- **PageCipher anchor status:** 45/50 Anchored
- **PageCipher anchor reference:** pagecipher:4d4872c2390f17ea55a1318100abf149
- **Last anchoring attempt:** 2026-09-04T08:14:13.624Z

> The PageCipher anchor proves the integrity and provenance of the evidence — it does not certify legal compliance.

## Open risks & gaps

- 8 open controls without evidence
- Human approval pending

## Legal notices (disclaimer)

- This report does not certify legal compliance.
- The risk classification is preliminary and does not replace a legal assessment.
- The legal assessment may require a specialized legal review.
- This report serves governance and compliance preparation on an evidence basis. It does not constitute legal advice, certification, or a conformity attestation.
- Human responsibility remains mandatory; AI does not make automatic decisions about persons.

## Appendix

### Control catalog

| Control | Source | Reference |
|---|---|---|
| Check for prohibited practices | eu\_ai\_act | EU AI Act Art. 5 |
| Risk management system | eu\_ai\_act | EU AI Act Art. 9 |
| Data governance | eu\_ai\_act | EU AI Act Art. 10 |
| Technical documentation (Annex IV-like) | eu\_ai\_act | EU AI Act Art. 11 / Annex IV |
| Record-keeping / logging | eu\_ai\_act | EU AI Act Art. 12 |
| Transparency & labeling | eu\_ai\_act | EU AI Act Art. 13 / 50 |
| Human oversight | eu\_ai\_act | EU AI Act Art. 14 |
| Accuracy, robustness, cybersecurity | eu\_ai\_act | EU AI Act Art. 15 |
| Lawfulness of processing | gdpr | DSGVO Art. 6 |
| Data minimization | gdpr | DSGVO Art. 5(1c) |
| Data protection impact assessment (DPIA) | gdpr | DSGVO Art. 35 |
| Data subject rights | gdpr | DSGVO Art. 12–22 |
| Bias monitoring | internal\_policy | SysTec Policy AI-BIAS-01 |
| AI literacy of those involved | ai\_literacy | EU AI Act Art. 4 |
| Access control | security | ISO 27001 A.9 (Referenz) |
| Audit/evidence chain | audit | SysTec Evidence Standard (ADR-003) |

### Generation metadata

- **Generated at:** 2026-09-04T08:14:48.726Z
- **Version:** 0.1.0
- **Language coverage:** 100 %
- **Number of evidence events:** 1197
