A company wants to use AI to screen resumes.
This is how governance works, step by step.
Alba Logística receives hundreds of applications per opening and wants an assistant to review them and propose a shortlist. The final decision is still made by a human. It may seem harmless, but the EU AI Act classifies it as high-risk: Annex III includes the selection of individuals. With support from Merlín Digital Partners in designing the selection process, here is the complete workflow in V-PROOF—from registration to the report for the board—featuring actual screenshots from the platform.
In collaboration with Merlín Digital Partners, V-PROOF's partner in talent recruitment.
Walkthrough recorded on September 23, 2026, in the platform. The company, individuals, and data are fictional. None of the screenshots are from a customer.
Register
The assistant is added to the inventory with an owner and a purpose.
Every AI system that the organization builds, purchases, or uses is registered with a reference number, type, business unit, and a designated person responsible. The intended purpose is not just another field: it is a legal concept defined in the EU AI Act (Article 3(12)), and the obligations depend on it.
The assistant is linked to the model it uses and the data it processes, along with its legal basis and retention period.
Sort
Eleven questions. The EU AI Act risk level is calculated as you answer.
Prohibited practice, scope of Annex III, legal effects, personal data, degree of autonomy, third-party provider. With each response, the panel updates the level, score, reasons, and obligations that are triggered.
Result: High, 88 out of 100. Use of Annex III, decisions with significant effects, personal data, third-party provider.
- 1Level High, 88 out of 100, calculated with fixed rules from the answers
- 2Grounds in Annex III (employment), significant effects, personal data, and a third-party model
- 3Requirements: The applicable provisions of the EU AI Act and the GDPR, in conjunction with NIST and ISO 42001
- 4Next step: The initial assessment, which determines the level
Rate the risks
Probability × impact. No one can type the score by hand.
Each risk is scored before and after the measures are implemented: inherent and residual. Bias against female or older candidates starts at 20 (critical) and decreases to 10 (high), with two mitigation measures: human review of each rejection and a quarterly bias test using anonymized candidate data.
The platform bases its calculations on probability and impact. That way, no one can sugarcoat a risk.
Controls
What each framework requires and where the system stands, step by step.
The library includes 76 controls: EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and internal principles. The matrix shows those applicable at the High level, grouped by framework, and every status change is recorded in the audit log.
Four of the organization's policies are enforced through safeguards built into the platform itself: chat filtering, compliance audits, mandatory attestation, and human review.
Sequential approval
Two people sign off, one after the other, and each writes down what they have verified.
The assessment initiates a request. The steps are configured as follows: first the AI governance lead, then the data protection officer. Each signature requires an attestation, which is recorded verbatim, and includes conditions: in this case, completing the FRIA before production.
Only the person whose email address is listed in that step can make the decision. If someone else tries to do so, the platform will reject it.
- 1Nominal step Only the person whose email address appears in the step can decide
- 2Decision: The one for that step, in the established order
- 3Mandatory attestation to approve: what was verified, recorded verbatim
- 4Requirement: Complete the FRIA (Art. 27) prior to production
Seal the evidence
The bias report is uploaded with its cryptographic fingerprint and is linked to verifiable evidence.
Evidence is a document that proves something: a bias report, a safety test, or a record. When it is uploaded, the platform calculates its cryptographic fingerprint, which is the same as the one obtained by calculating it externally: it is the file's fingerprint, not a copy.
With a V-Seal®, that fingerprint is recorded as verifiable cryptographic evidence. An auditor later verifies that the document has not been altered, without accessing the platform or the content. The sealing is recorded and explicitly confirmed before it is completed.
- 1Link: The evidence is linked to its V-Seal®
- 2Hash The cryptographic hash of the file, which is calculated outside the platform
- 3Status: sealed, or fingerprint only, awaiting seal
- 4seal Record the fingerprint as verifiable evidence using V-Seal®
Report
For the auditor, the complete report. For the board, one page.
Four reports: the system profile, the model profile, the compliance report by framework, and the executive summary, which includes indicators, the most significant risks, pending approvals, and open incidents.
Behind it all is the audit log: every action, including who did it, when, and what happened before and after. No one can edit or delete those rows, not even an administrator.
What the platform now knows about the assistant.
AI-0100 registered, with a designated person in charge, purpose, associated form, and system record.
Candidate resumes: personal data, legal basis under GDPR Article 6(1)(b), retention period of 12 months.
High under the EU AI Act, Annex III, employment. Determined by the initial assessment: 88 out of 100.
Two open issues with mitigations: bias (residual 10) and privacy (residual 6).
Twelve EU AI Act controls evaluated, along with their status and the supporting evidence.
Two signatures with verbatim attestation and one condition: FRIA prior to production.
Bias report with an SHA-256 hash, sealed with V-Seal®, and verifiable by a third party.
Each previous step is recorded in the audit log, showing the before and after states, with no way to delete.
What a person continues to do today.
We'd rather tell you this before you discover it in the demo. The platform records, audits, and seals; it does not replace the decision-maker's judgment.
Which AI systems does your organization have that haven't been registered yet?
Executive-led assessment: inventory, classification according to the EU AI Act, evidence gaps, and a plan to address them in your actual processes.
