# Governance Report — AI-assisted support / recommendations

_HumanOSE — governance preparation, assurance support and audit-ready evidence. No legal compliance certification._

**Product:** HumanOSE  
**Use Case:** uc\_cx\_f06 (v1)  
**Source system:** causax  
**Language:** EN  
**Data mode:** synthetic  
**Generated at:** 2026-09-04T06:39:46.784Z  
**Report status:** Draft  
**Integrity hash:** 50c413aa39946006…  

> This report is based exclusively on synthetic data (pilot operation). No real personal data.

> This report does not certify legal compliance.

## Executive summary

Assistance for inquiries and recommendation building blocks for case handling — with AI labeling and escalation to humans.

- **Intended purpose:** Relief in support — no binding commitments made by AI.
- **Preliminary risk class:** —
- **Human oversight required:** No
- **Governance Readiness:** —

> Governance Readiness denotes the degree of preparation (evidence in place/reviewed) — it does not certify conformity.

## Use case profile

- **Intended purpose:** Relief in support — no binding commitments made by AI.
- **Affected groups of persons:** anfragende\_personen
- **Data sources:** anfragetexte\_synthetisch, wissensbasis
- **AI function:** generation, recommendation
- **Potential impact:** operativ
- **Jurisdiction:** eu-de
- **Source system:** causax
- **Lifecycle state:** Draft

## Risk assessment (preliminary)

Use case is not yet classified — controls are only available after the risk classification.

## Policy & control overview

> The control status documents the review of the evidence — it does not certify conformity.

Use case is not yet classified — controls are only available after the risk classification.

## Human oversight

- **Responsible human:** Oversight assignment pending — a final responsible human must be named before approval.
- **Reviewer:** —

> Human responsibility remains mandatory; AI does not make automatic decisions about persons.

### Review history

No review decisions recorded yet.

## Evidence summary

- **Evidence chain status:** invalid (suspected tampering)
- **Number of evidence events:** 5
- **Verification passed:** No

> Simulated anchoring (PageCipher integration pending) — marked as a simulation.

| # | Timestamp | Actor | Action | Hash |
|---|---|---|---|---|
| 10 | 2026-07-10T11:52:53.658Z | actor\_lilli | use\_case.drafted | 0b1a68962967… |
| 690 | 2026-09-04T04:53:38.489Z | actor\_system\_humanose | governance\_report\_generated | 482455eb4dcd… |
| 728 | 2026-09-04T05:42:44.938Z | actor\_system\_humanose | governance\_report\_generated | 19cde699040e… |
| 730 | 2026-09-04T05:42:49.712Z | actor\_system\_humanose | governance\_report\_generated | 0aaef938da83… |
| 806 | 2026-09-04T06:39:18.417Z | actor\_system\_humanose | governance\_report\_generated | bb90d8a6c457… |

### PageCipher anchor status

- **PageCipher integration status:** Active (HTTP integration with PageCipher)
- **PageCipher anchor status:** 4/5 Anchored
- **PageCipher anchor reference:** pagecipher:39f6c2564b39ad07d8dc2c5807227f6a
- **Last anchoring attempt:** 2026-09-04T06:39:18.422Z

> The PageCipher anchor proves the integrity and provenance of the evidence — it does not certify legal compliance.

## Open risks & gaps

No open items recorded.

## Legal notices (disclaimer)

- This report does not certify legal compliance.
- The risk classification is preliminary and does not replace a legal assessment.
- The legal assessment may require a specialized legal review.
- This report serves governance and compliance preparation on an evidence basis. It does not constitute legal advice, certification, or a conformity attestation.
- Human responsibility remains mandatory; AI does not make automatic decisions about persons.

## Appendix

### Control catalog

| Control | Source | Reference |
|---|---|---|
| Check for prohibited practices | eu\_ai\_act | EU AI Act Art. 5 |
| Risk management system | eu\_ai\_act | EU AI Act Art. 9 |
| Data governance | eu\_ai\_act | EU AI Act Art. 10 |
| Technical documentation (Annex IV-like) | eu\_ai\_act | EU AI Act Art. 11 / Annex IV |
| Record-keeping / logging | eu\_ai\_act | EU AI Act Art. 12 |
| Transparency & labeling | eu\_ai\_act | EU AI Act Art. 13 / 50 |
| Human oversight | eu\_ai\_act | EU AI Act Art. 14 |
| Accuracy, robustness, cybersecurity | eu\_ai\_act | EU AI Act Art. 15 |
| Lawfulness of processing | gdpr | DSGVO Art. 6 |
| Data minimization | gdpr | DSGVO Art. 5(1c) |
| Data protection impact assessment (DPIA) | gdpr | DSGVO Art. 35 |
| Data subject rights | gdpr | DSGVO Art. 12–22 |
| Bias monitoring | internal\_policy | SysTec Policy AI-BIAS-01 |
| AI literacy of those involved | ai\_literacy | EU AI Act Art. 4 |
| Access control | security | ISO 27001 A.9 (Referenz) |
| Audit/evidence chain | audit | SysTec Evidence Standard (ADR-003) |

### Generation metadata

- **Generated at:** 2026-09-04T06:39:46.784Z
- **Version:** 0.1.0
- **Language coverage:** 100 %
- **Number of evidence events:** 809
