Case study · EU AI Act, Annex III
01 / 04

A company wants to use AI to screen resumes.
This is how governance works, step by step.

Alba Logística receives hundreds of applications per opening and wants an assistant to review them and propose a shortlist. The final decision is still made by a human. It may seem harmless, but the EU AI Act classifies it as high-risk: Annex III includes the selection of individuals. With support from Merlín Digital Partners in designing the selection process, here is the complete workflow in V-PROOF—from registration to the report for the board—featuring actual screenshots from the platform.

7steps, from registration to the report
88/100risk score · High level
2signatures with verbatim certification
12EU AI Act controls reviewed
Partner Use Case

In collaboration with Merlín Digital Partners, V-PROOF's partner in talent recruitment.

Get to know your partner →

Walkthrough recorded on September 23, 2026, in the platform. The company, individuals, and data are fictional. None of the screenshots are from a customer.

The Seven Steps
02 / 04
01

Register

The assistant is added to the inventory with an owner and a purpose.

Every AI system that the organization builds, purchases, or uses is registered with a reference number, type, business unit, and a designated person responsible. The intended purpose is not just another field: it is a legal concept defined in the EU AI Act (Article 3(12)), and the obligations depend on it.

The assistant is linked to the model it uses and the data it processes, along with its legal basis and retention period.

AI-0100Use casePeople & TalentPersonal data · GDPR 6(1)(b)
02

Sort

Eleven questions. The EU AI Act risk level is calculated as you answer.

Prohibited practice, scope of Annex III, legal effects, personal data, degree of autonomy, third-party provider. With each response, the panel updates the level, score, reasons, and obligations that are triggered.

Result: High, 88 out of 100. Use of Annex III, decisions with significant effects, personal data, third-party provider.

EU AI Act Articles 9 through 15 and 26Art. 27 FRIAArt. 49 RegistryGDPR Art. 35 DPIA
V-PROOF portal · ClassificationPlatform Screen · Demo
CLASSIFICATIONHIGHscore: 88 / 100• Scope of Annex III: employment, workforce management, and access to self-employment.• Makes or substantially influences decisions that have legal effects or thathave a similarly significant impact.• Processes personal data.• A third-party product or service.TRIGGERED OBLIGATIONSEU AI Act Articles 9–15 (provider) and Article 26 (deployer); Article 27 FRIAwhere applicable; Art. 49, Registration.GDPR Articles 5, 6, 13–14, 25, 30, and 32; Article 35 DPIA when the risk is high.GDPR Art. 22: Safeguards for automated decision-making.NIST AI RMF GOVERN-6 / MANAGE-3; ISO 42001 A.10: Supplier Controls.Complete the initial assessment1234
  1. 1Level High, 88 out of 100, calculated with fixed rules from the answers
  2. 2Grounds in Annex III (employment), significant effects, personal data, and a third-party model
  3. 3Requirements: The applicable provisions of the EU AI Act and the GDPR, in conjunction with NIST and ISO 42001
  4. 4Next step: The initial assessment, which determines the level
03

Rate the risks

Probability × impact. No one can type the score by hand.

Each risk is scored before and after the measures are implemented: inherent and residual. Bias against female or older candidates starts at 20 (critical) and decreases to 10 (high), with two mitigation measures: human review of each rejection and a quarterly bias test using anonymized candidate data.

The platform bases its calculations on probability and impact. That way, no one can sugarcoat a risk.

Skew · 20 → 10Privacy · 12 → 6Residual Heat Map
04

Controls

What each framework requires and where the system stands, step by step.

The library includes 76 controls: EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and internal principles. The matrix shows those applicable at the High level, grouped by framework, and every status change is recorded in the audit log.

Four of the organization's policies are enforced through safeguards built into the platform itself: chat filtering, compliance audits, mandatory attestation, and human review.

Art. 14 Human Oversight · ImplementedArt. 10 Data · Partially implementedArt. 27 FRIA · Pending
05

Sequential approval

Two people sign off, one after the other, and each writes down what they have verified.

The assessment initiates a request. The steps are configured as follows: first the AI governance lead, then the data protection officer. Each signature requires an attestation, which is recorded verbatim, and includes conditions: in this case, completing the FRIA before production.

Only the person whose email address is listed in that step can make the decision. If someone else tries to do so, the platform will reject it.

Step 1 · AI governance Step 2 · DPOApproved · 2 of 2
V-PROOF Portal · ApprovalsPlatform Screen · Demo
Decide · Intake Approval · AI-0100 · Assistant toresume screeningStep 1 · AI governance lead · david@vproof.ioDecisionApproveCertification*I confirm that the initial assessment, the risk register, and the matrix ofthe CV screening assistant's controls have been reviewed and that theThe system can switch to pilot mode with human review of each rejection.It is recorded verbatim in the decision log and the audit log.CommentRequirement: Complete the FRIA (Art. 27) prior to production.CancelRecord: Approved1234
  1. 1Nominal step Only the person whose email address appears in the step can decide
  2. 2Decision: The one for that step, in the established order
  3. 3Mandatory attestation to approve: what was verified, recorded verbatim
  4. 4Requirement: Complete the FRIA (Art. 27) prior to production
06

Seal the evidence

The bias report is uploaded with its cryptographic fingerprint and is linked to verifiable evidence.

Evidence is a document that proves something: a bias report, a safety test, or a record. When it is uploaded, the platform calculates its cryptographic fingerprint, which is the same as the one obtained by calculating it externally: it is the file's fingerprint, not a copy.

With a V-Seal®, that fingerprint is recorded as verifiable cryptographic evidence. An auditor later verifies that the document has not been altered, without accessing the platform or the content. The sealing is recorded and explicitly confirmed before it is completed.

Cryptographic fingerprintV-Seal®Verifiable without access
V-PROOF Portal · EvidencePlatform Screen · Demo
Linked to V-Seal b122ccfc19e3e5987f61c349304b25041106e6a3f452e0708e9bcd5bbdd83971.Update+ Add by referenceSearch through the evidence…Type: AllSearch2 rowsEVIDENCETYPEFINGERPRINTproofCOLLECTEDVALIDUNTILSupplier Security Review (Sealing)(example of the seed)AI-0100 · Resume Screening Assistantproof fromsafetyb122ccfc19e3…sealed·Sept. 232026View sealEditDeleteproof 's Q3 2026 Bias Report,resume screeningAI-0100 · Resume Screening AssistantReport onbias967758f9c1ff…WITHFINGERPRINTMarch 312027Sept. 232026OpenCreateV-Seal®LinksealedEditDelete1234
  1. 1Link: The evidence is linked to its V-Seal®
  2. 2Hash The cryptographic hash of the file, which is calculated outside the platform
  3. 3Status: sealed, or fingerprint only, awaiting seal
  4. 4seal Record the fingerprint as verifiable evidence using V-Seal®
07

Report

For the auditor, the complete report. For the board, one page.

Four reports: the system profile, the model profile, the compliance report by framework, and the executive summary, which includes indicators, the most significant risks, pending approvals, and open incidents.

Behind it all is the audit log: every action, including who did it, when, and what happened before and after. No one can edit or delete those rows, not even an administrator.

System profileCompliance by FrameworkExecutive SummaryExportable Log
At the end of the tour
03 / 04

What the platform now knows about the assistant.

Inventory

AI-0100 registered, with a designated person in charge, purpose, associated form, and system record.

Data

Candidate resumes: personal data, legal basis under GDPR Article 6(1)(b), retention period of 12 months.

Level

High under the EU AI Act, Annex III, employment. Determined by the initial assessment: 88 out of 100.

Risks

Two open issues with mitigations: bias (residual 10) and privacy (residual 6).

Controls

Twelve EU AI Act controls evaluated, along with their status and the supporting evidence.

Approval

Two signatures with verbatim attestation and one condition: FRIA prior to production.

Evidence

Bias report with an SHA-256 hash, sealed with V-Seal®, and verifiable by a third party.

Traceability

Each previous step is recorded in the audit log, showing the before and after states, with no way to delete.

In plain terms
04 / 04

What a person continues to do today.

We'd rather tell you this before you discover it in the demo. The platform records, audits, and seals; it does not replace the decision-maker's judgment.

The status of the checks is set by a person; only code checks are evaluated automatically during each analysis.
Approvers do not receive a notification; they see the pending items when they log in to the portal.
Evidence is sealed manually, item by item, by the V-Seal® operator.
The risk score is recalculated when you click "Recalculate," not on its own.
Alerts are raised manually; chat filter blocks do not trigger them yet.
Reports are generated on demand; there are no scheduled deliveries.

Which AI systems does your organization have that haven't been registered yet?

Executive-led assessment: inventory, classification according to the EU AI Act, evidence gaps, and a plan to address them in your actual processes.