# Governance Report — KI-gestützte Skill-Match-Empfehlung (HumanX OIS)

_HumanOSE — governance preparation, assurance support and audit-ready evidence. No legal compliance certification._

**Product:** HumanOSE  
**Use Case:** uc\_humanx\_skillmatch (v1)  
**Source system:** humanx-ois  
**Language:** EN  
**Data mode:** synthetic  
**Generated at:** 2026-09-04T05:51:25.287Z  
**Report status:** Provisionally classified  
**Integrity hash:** 824e763593b9d766…  

> This report is based exclusively on synthetic data (pilot operation). No real personal data.

> This report does not certify legal compliance.

## Executive summary

HumanX OIS schlägt anhand des Capability Graph erklärte Kandidat:innen für Rollen/Projekte vor — mit Unsicherheit und Pflicht zur menschlichen Prüfung.

- **Intended purpose:** Entscheidungsunterstützung für die menschliche Auswahl — ausdrücklich keine automatische Zuweisung oder Beschäftigungsentscheidung.
- **Preliminary risk class:** Near high-risk — mandatory human oversight, external legal review recommended
- **Human oversight required:** Yes
- **Governance Readiness:** 0/15 Controls with evidence/reviewed

> Governance Readiness denotes the degree of preparation (evidence in place/reviewed) — it does not certify conformity.

## Use case profile

- **Intended purpose:** Entscheidungsunterstützung für die menschliche Auswahl — ausdrücklich keine automatische Zuweisung oder Beschäftigungsentscheidung.
- **Affected groups of persons:** natuerliche\_personen\_mitarbeitende
- **Data sources:** personenbezogen\_capability\_profile
- **AI function:** recommendation
- **Potential impact:** beschaeftigung\_rolle
- **Jurisdiction:** eu-de
- **Source system:** humanx-ois
- **Lifecycle state:** Provisionally classified

## Risk assessment (preliminary)

- **Preliminary risk class:** Near high-risk — mandatory human oversight, external legal review recommended
- **Confidence of the assessment:** medium
- **Ruleset:** v0.1.0
- **Human review required:** Yes

> The risk classification is preliminary and does not replace a legal assessment.

### Reasoning (rule reference)

- R-HIGH-EMPLOY-01 — Impact on employment or role assignment — proximity to Annex III (employment context) must be reviewed.
- R-ELEV-PII-01 — Processing of personal data sources — GDPR principles (purpose limitation, data minimization, data subject rights) must be applied.
- R-LIM-TRANSPARENCY-01 — Generative or recommending AI function — transparency and labeling obligations must be reviewed.

### Open legal questions

- Is there an Annex III constellation in the employment context? External legal review recommended.

### Recommended risk mitigations

- Mandatory human review of every individual-case assessment by a named accountable person.
- No automatic decision with impact on persons — the system proposes, the human decides.
- Data minimization: process only governance-necessary categories, no copies of raw data.
- Role-based access control and audit events for every access to sensitive objects.
- Label AI-generated content as such; escalation to a human is possible at any time.
- Obtain external legal review before any real use (near high-risk constellation).

### Uncertainty of the assessment

Rule set v0.1 works with internal review heuristics on the EU AI Act, GDPR, Swiss DSG and the UK context. The assessment depends on the completeness of the registry entries and does not replace a legal review.

## Policy & control overview

> The control status documents the review of the evidence — it does not certify conformity.

| Control | Reference | Status | Evidence |
|---|---|---|---|
| Check for prohibited practices | EU AI Act Art. 5 | Open | 0 |
| Risk management system | EU AI Act Art. 9 | Open | 0 |
| Data governance | EU AI Act Art. 10 | Open | 0 |
| Technical documentation (Annex IV-like) | EU AI Act Art. 11 / Annex IV | Open | 0 |
| Record-keeping / logging | EU AI Act Art. 12 | Open | 0 |
| Transparency & labeling | EU AI Act Art. 13 / 50 | Open | 0 |
| Human oversight | EU AI Act Art. 14 | Open | 0 |
| Accuracy, robustness, cybersecurity | EU AI Act Art. 15 | Open | 0 |
| Lawfulness of processing | DSGVO Art. 6 | Open | 0 |
| Data minimization | DSGVO Art. 5(1c) | Open | 0 |
| Data protection impact assessment (DPIA) | DSGVO Art. 35 | Open | 0 |
| Data subject rights | DSGVO Art. 12–22 | Open | 0 |
| AI literacy of those involved | EU AI Act Art. 4 | Open | 0 |
| Access control | ISO 27001 A.9 (Referenz) | Open | 0 |
| Audit/evidence chain | SysTec Evidence Standard (ADR-003) | Open | 0 |

### Open gaps

- Check for prohibited practices
- Risk management system
- Data governance
- Technical documentation (Annex IV-like)
- Record-keeping / logging
- Transparency & labeling
- Human oversight
- Accuracy, robustness, cybersecurity
- Lawfulness of processing
- Data minimization
- Data protection impact assessment (DPIA)
- Data subject rights
- AI literacy of those involved
- Access control
- Audit/evidence chain

## Human oversight

- **Responsible human:** Oversight assignment pending — a final responsible human must be named before approval.
- **Reviewer:** —

> Human responsibility remains mandatory; AI does not make automatic decisions about persons.

### Review history

No review decisions recorded yet.

## Evidence summary

- **Evidence chain status:** invalid (suspected tampering)
- **Number of evidence events:** 33
- **Verification passed:** No

> Simulated anchoring (PageCipher integration pending) — marked as a simulation.

| # | Timestamp | Actor | Action | Hash |
|---|---|---|---|---|
| 464 | 2026-09-02T18:31:04.533Z | actor\_system\_humanose | governance\_report\_generated | 6afdc90d269d… |
| 466 | 2026-09-02T18:31:05.084Z | actor\_system\_humanose | governance\_report\_generated | d490ca2afe0b… |
| 468 | 2026-09-02T18:31:05.593Z | actor\_system\_humanose | governance\_report\_generated | 73297288128d… |
| 470 | 2026-09-02T18:31:06.096Z | actor\_system\_humanose | governance\_report\_generated | fd00cb8e50d5… |
| 472 | 2026-09-02T18:31:06.548Z | actor\_system\_humanose | governance\_report\_generated | 2b9f33050b3b… |
| 474 | 2026-09-02T18:31:07.044Z | actor\_system\_humanose | governance\_report\_generated | d056ac2470dc… |
| 476 | 2026-09-02T18:31:07.567Z | actor\_system\_humanose | governance\_report\_generated | 4f2d4dc3276a… |
| 478 | 2026-09-02T18:31:08.052Z | actor\_system\_humanose | governance\_report\_generated | 6b6cedbd5543… |
| 630 | 2026-09-02T19:07:44.194Z | actor\_system\_humanose | governance\_report\_generated | 4c1ca9313352… |
| 632 | 2026-09-02T19:07:44.708Z | actor\_system\_humanose | governance\_report\_generated | 3a0d05fced89… |
| 634 | 2026-09-02T19:07:45.229Z | actor\_system\_humanose | governance\_report\_generated | 9608608dd348… |
| 724 | 2026-09-04T05:40:58.208Z | actor\_system\_humanose | governance\_report\_generated | 838989e59b3a… |
| 742 | 2026-09-04T05:49:53.221Z | actor\_system\_humanose | governance\_report\_generated | 3fc933c2865c… |
| 748 | 2026-09-04T05:50:38.905Z | actor\_system\_humanose | governance\_report\_generated | 2562883fc11e… |

### PageCipher anchor status

- **PageCipher integration status:** Active (HTTP integration with PageCipher)
- **PageCipher anchor status:** 29/33 Anchored
- **PageCipher anchor reference:** pagecipher:86ae890eb0f5b94713ac5a91368567b0
- **Last anchoring attempt:** 2026-09-04T05:50:38.909Z

> The PageCipher anchor proves the integrity and provenance of the evidence — it does not certify legal compliance.

## Open risks & gaps

- 15 open controls without evidence
- Human approval pending
- Is there an Annex III constellation in the employment context? External legal review recommended.

## Legal notices (disclaimer)

- This report does not certify legal compliance.
- The risk classification is preliminary and does not replace a legal assessment.
- The legal assessment may require a specialized legal review.
- This report serves governance and compliance preparation on an evidence basis. It does not constitute legal advice, certification, or a conformity attestation.
- Human responsibility remains mandatory; AI does not make automatic decisions about persons.

## Appendix

### Control catalog

| Control | Source | Reference |
|---|---|---|
| Check for prohibited practices | eu\_ai\_act | EU AI Act Art. 5 |
| Risk management system | eu\_ai\_act | EU AI Act Art. 9 |
| Data governance | eu\_ai\_act | EU AI Act Art. 10 |
| Technical documentation (Annex IV-like) | eu\_ai\_act | EU AI Act Art. 11 / Annex IV |
| Record-keeping / logging | eu\_ai\_act | EU AI Act Art. 12 |
| Transparency & labeling | eu\_ai\_act | EU AI Act Art. 13 / 50 |
| Human oversight | eu\_ai\_act | EU AI Act Art. 14 |
| Accuracy, robustness, cybersecurity | eu\_ai\_act | EU AI Act Art. 15 |
| Lawfulness of processing | gdpr | DSGVO Art. 6 |
| Data minimization | gdpr | DSGVO Art. 5(1c) |
| Data protection impact assessment (DPIA) | gdpr | DSGVO Art. 35 |
| Data subject rights | gdpr | DSGVO Art. 12–22 |
| Bias monitoring | internal\_policy | SysTec Policy AI-BIAS-01 |
| AI literacy of those involved | ai\_literacy | EU AI Act Art. 4 |
| Access control | security | ISO 27001 A.9 (Referenz) |
| Audit/evidence chain | audit | SysTec Evidence Standard (ADR-003) |

### Generation metadata

- **Generated at:** 2026-09-04T05:51:25.287Z
- **Version:** 0.1.0
- **Language coverage:** 100 %
- **Number of evidence events:** 753
