Every decision has an owner.
And every owner, their own proof.
He EU AI Act It doesn't just ask for controls: it asks to know who decides, who supervises, and who is responsible. V-PROOF orders the AI governance in three levels of responsibility and a six-step cycle, and each step leaves a record with name, date and verifiable evidence.
Three levels of responsibility. One that verifies from the outside.
Governance works when each level knows what it decides and what it must be able to demonstrate. V-PROOF keeps a record of what happens at each level.
Who approves, who executes, and who is informed.
A reference model that we adapt to the structure of each organization during the assessment.
| Activity | Board & executive management | AI Committee | System owner | Legal · DPO · CISO | Evidence in V-PROOF |
|---|---|---|---|---|---|
| Set risk appetite and AI policy | A | R | I | C | Sealed policy and version |
| Maintain the systems inventory | I | A | R | C | List of each system and the person responsible for it |
| Classify the risk according to the EU AI Act | I | A | R | C | Risk level and associated obligations |
| Approve a high-risk system | I | A · R | C | C | Attestation by the designated owner |
| Monitor implementation | — | I | A · R | C | Human decisions and applied controls |
| Manage an incident | I | A | R | R | Detection, response, and resolution dates |
| Notify management | I | A · R | C | C | Exposure and evidence report |
A. Is accountable · R. Executes · C. Is consulted · I. Is informed
Six steps. Each one leaves its own evidence.
The cycle repeats itself every time a new system is introduced, an existing one is changed, or the policy is revised.
- 01 Inventory and record each AI system, its provider, and its responsible party
- 02 Classify Risk Level according to the EU AI Act and obligations it triggers
- 03 Approve Written attestation by the designated owner, recorded verbatim
- 04 Monitor controls in execution and recorded human decisions
- 05 Provide cryptographic evidence verifiable by third parties
- 06 Review Report for management and recalculation of risk on demand
Governance is not optional. It is written into the rules.
The frameworks V-PROOF covers all ask for the same thing, in different words: clearly defined roles, human oversight, and the ability to demonstrate it.
Providers and deployers of AI systems must ensure their staff have sufficient AI literacy.
In high-risk systems, those responsible for deploying them must entrust oversight to individuals with the necessary expertise, training, and authority.
Use the system according to the instructions, monitor its operation, maintain records, and report serious incidents.
Management makes the commitment, establishes the policy, and assigns roles; the system is audited and reviewed by management.
Policies, roles, and accountability must be defined before mapping, measuring, and managing risk.
It is not enough to simply comply: the data controller must be able to demonstrate compliance.
A general overview of the relevant regulations. For your specific situation, please consult your legal advisor.
One model for the whole group. The standard for each country, too.
The core governance framework is common (EU AI Act, ISO/IEC 42001, NIST AI RMF, and GDPR), and each subsidiary adds its own local layer, such as the ENS in Spain. Management sees a single, consolidated set of evidence.
Start by finding out who's making the decisions today.
1 · Assessment. We take stock of your AI systems and identify who is responsible for each one.
2 · Model Design. We define roles, a committee, and a cycle tailored to your organization.
3 · Getting Started. V-PROOF begins tracking every step with its proof.
