Contract/document AI assistance · uc_cx_d04
← Back to use case · Back to dashboard
Elevated risk — human review required · not applicable: 0
| ID | Control | Expected evidence | Status | Evidence |
|---|---|---|---|---|
euaia_record_keeping |
Record-keeping / logging EU AI Act Art. 12 · EU AI Act |
Automatic, traceable event logging (append-only) in place. | Open | 0 |
euaia_transparency |
Transparency & labeling EU AI Act Art. 13 / 50 · EU AI Act |
AI use is made transparent to affected persons; AI-generated outputs are labeled. | Evidence attached | 1 |
gdpr_lawfulness |
Lawfulness of processing DSGVO Art. 6 · GDPR |
Documented legal basis for the processing of personal data. | Open | 0 |
gdpr_data_minimization |
Data minimization DSGVO Art. 5(1c) · GDPR |
Evidence that only necessary data categories are processed. | Open | 0 |
gdpr_data_subject_rights |
Data subject rights DSGVO Art. 12–22 · GDPR |
Processes for access, rectification, objection and appeal by affected persons in place. | Open | 0 |
ai_literacy_staff |
AI literacy of those involved EU AI Act Art. 4 · AI literacy |
Evidence of sufficient AI literacy of the persons involved in the deployment. | Open | 0 |
security_access_control |
Access control ISO 27001 A.9 (Referenz) · Security |
Role-based access control and audit logs for sensitive objects in place. | Open | 0 |
audit_evidence_trail |
Audit/evidence chain SysTec Evidence Standard (ADR-003) · Audit |
Complete, hash-chained evidence trail of the governance-relevant actions. | Open | 0 |