AI governance model
01 / 07

Every decision has an owner.
And every owner, their own proof.

He EU AI Act It doesn't just ask for controls: it asks to know who decides, who supervises, and who is responsible. V-PROOF orders the AI governance in three levels of responsibility and a six-step cycle, and each step leaves a record with name, date and verifiable evidence.

Who decides?
02 / 07

Three levels of responsibility. One that verifies from the outside.

Governance works when each level knows what it decides and what it must be able to demonstrate. V-PROOF keeps a record of what happens at each level.

External Verification Auditor · regulator · client Checks evidence without a V-PROOF account and without access to the organization's internal systems.
01 · Accountability Board and executive management Sets the risk appetite, approves the AI policy and receives the exposure and evidence report. What V-PROOF records: the approved policy, its version, and each report submitted.
02 · The AI ​​Committee decides on and approves high-risk systems, exceptions, and policy changes. It is comprised of legal, compliance, DPO, CISO, and business representatives. What V-PROOF records: each approval, with the signatory's verbatim attestation.
03 · Operators System owners Register the system, monitor its operation, and are accountable for its daily use. What V-PROOF records: inventory, human decisions, and applied controls.
Who does what
03 / 07

Who approves, who executes, and who is informed.

A reference model that we adapt to the structure of each organization during the assessment.

Activity Board & executive management AI Committee System owner Legal · DPO · CISO Evidence in V-PROOF
Set risk appetite and AI policy A R I C Sealed policy and version
Maintain the systems inventory I A R C List of each system and the person responsible for it
Classify the risk according to the EU AI Act I A R C Risk level and associated obligations
Approve a high-risk system I A · R C C Attestation by the designated owner
Monitor implementation — I A · R C Human decisions and applied controls
Manage an incident I A R R Detection, response, and resolution dates
Notify management I A · R C C Exposure and evidence report

A. Is accountable · R. Executes · C. Is consulted · I. Is informed

The governance cycle
04 / 07

Six steps. Each one leaves its own evidence.

The cycle repeats itself every time a new system is introduced, an existing one is changed, or the policy is revised.

  1. 01 Inventory and record each AI system, its provider, and its responsible party
  2. 02 Classify Risk Level according to the EU AI Act and obligations it triggers
  3. 03 Approve Written attestation by the designated owner, recorded verbatim
  4. 04 Monitor controls in execution and recorded human decisions
  5. 05 Provide cryptographic evidence verifiable by third parties
  6. 06 Review Report for management and recalculation of risk on demand
What the regulation requires
05 / 07

Governance is not optional. It is written into the rules.

The frameworks V-PROOF covers all ask for the same thing, in different words: clearly defined roles, human oversight, and the ability to demonstrate it.

EU AI Act · Art. 4 AI Literacy

Providers and deployers of AI systems must ensure their staff have sufficient AI literacy.

EU AI Act · Articles 14 and 26 Human oversight

In high-risk systems, those responsible for deploying them must entrust oversight to individuals with the necessary expertise, training, and authority.

EU AI Act · Art. 26 Deployer obligations

Use the system according to the instructions, monitor its operation, maintain records, and report serious incidents.

ISO/IEC 42001 · Clauses 5 and 9 Leadership and review

Management makes the commitment, establishes the policy, and assigns roles; the system is audited and reviewed by management.

NIST AI RMF · Govern Function Culture and accountability

Policies, roles, and accountability must be defined before mapping, measuring, and managing risk.

GDPR · Art. 5.2 Accountability

It is not enough to simply comply: the data controller must be able to demonstrate compliance.

A general overview of the relevant regulations. For your specific situation, please consult your legal advisor.

Global and local
06 / 07

One model for the whole group. The standard for each country, too.

The core governance framework is common (EU AI Act, ISO/IEC 42001, NIST AI RMF, and GDPR), and each subsidiary adds its own local layer, such as the ENS in Spain. Management sees a single, consolidated set of evidence.

How to Get Started
07 / 07

Start by finding out who's making the decisions today.

1 · Assessment. We take stock of your AI systems and identify who is responsible for each one.

2 · Model Design. We define roles, a committee, and a cycle tailored to your organization.

3 · Getting Started. V-PROOF begins tracking every step with its proof.