Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How does ShipReady Metrics produce AI-governance evidence?
Updated
Artefacts are collected, a human reviewer can accept one as meeting a control, and the result can be exported or shared as a posture snapshot. That is a recorded human judgement over your own records. It is not legal conformity. Not legal advice.
ShipReady Metrics AI-governance evidence, last verified 10 September 2026 against Articles 11, 12, 17, 18, 19, 21, 47, 73 and 113 of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024) for the evidence types being mapped. ISO/IEC 42001:2023 is a management-system standard, not the regulation. This page is not legal advice, not a filing, and does not start a clock. It does not determine that the Act applies to YOU, that YOU are a provider or a deployer, or that YOUR system is high-risk. This product is not a regulator filing pack, not forensic chain of custody, and does not file with the AI Office.
This is an evidence flow, not a conformity determination
Audience: a compliance owner who has to answer an auditor, a customer, or counsel faster than a shared drive allows, and wants to know exactly what this product can and cannot say on their behalf. This page is not legal advice. It does not start a clock. Nothing here is a determination that the Act applies, that YOU are a provider or a deployer, or that YOUR system is high-risk.
The path is: signed-in app → Compliance, where evidence collection and the obligation map live, with the AI-governance surface — the AI inventory and the AI risk register — under Compliance → AI governance. Evidence in this product means an artefact the organisation supplied, plus a record of who reviewed it and when. It does not mean an assertion by the platform that a legal duty is satisfied. Last verified 10 September 2026. Not legal advice.
- Four kinds of text appear here, and they are labelled: legal requirements of 2024/1689 (only if they apply); Commission and AI Office materials, which are guidance, not the regulation; ISO/IEC 42001:2023, a standard, not a legal substitute for the Act; and ShipReadyMetrics capability, which describes shipped behaviour and never a legal determination.
- The evidence-retention-checklist guide on this site is the Articles 12, 18 and 19 retention-matrix page — what to keep and for how long. The AI-audit-evidence guide on this site is the evidence-request-by-role page — who asks for what, and whether they can compel it. This page is the third question: how the material gets produced and reviewed in the first place.
- The how-shipreadymetrics-supports-ai-governance guide on this site is the wider product map. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
The flow, step by step
Each step says what it produces and what that output is not. The last column is the honest limit, and it is the column worth reading first. Last verified 10 September 2026. Not legal advice.
| Step | What happens | Honest limit | Kind of text |
|---|---|---|---|
| Record the facts on the AI inventory | An administrator registers each AI system and records its declared tier, use case, role, owner, GPAI flags, and which governance artefacts exist. | A boolean says an artefact was recorded. Nothing reads the artefact or judges whether it satisfies Annex IV or any other requirement. | ShipReadyMetrics capability. Not a classification and not an Article 49 registration. |
| Collect the artefact | The document, export, or record itself is attached to the control it relates to, with the organisation as its source. | The product did not produce the underlying artefact and cannot vouch for its accuracy. Garbage attached carefully is still garbage. | ShipReadyMetrics capability. Not forensic chain of custody. |
| Human evidence review | A reviewer looks at a manually supplied row and can accept it as meeting the control. The acceptance is recorded with the reviewer and the date. | This is a human judgement, deliberately. It is not a machine verdict, not an automated test, and not a legal conclusion — and the reviewer's name is attached precisely so that nobody can pretend otherwise. | ShipReadyMetrics capability. Not a conformity determination. |
| Grade coverage over the declared subject set | Obligation coverage is computed across systems the organisation declared high-risk. An empty inventory reads not verified rather than pass, and a full-coverage pass is refused while systems look under-declared. | Honest arithmetic over declarations. If the declared population is wrong, the result is honestly wrong about the wrong population. | ShipReadyMetrics capability. Never a fabricated pass and never a fabricated gap. |
| Export | The AI inventory and governance posture can be exported as documents, as structured data, and as a machine-readable AI bill of materials in CycloneDX form. | An export is portability. It is not an Annex VIII submission, not an Annex IV dossier, and not a filing. | ShipReadyMetrics capability. |
| Share as a posture snapshot | ShipReady Passport publishes a shareable snapshot of recorded posture, aimed at a customer's diligence questionnaire. | A snapshot of what the organisation recorded. Not legal conformity, not a certificate, not CE marking, and not an answer to a reasoned request from an authority. | ShipReadyMetrics capability. |
Which evidence types this flow actually touches
Mapped against the record types on the retention page and the request types on the auditor page. A row that this product only holds a pointer to is marked as such — a pointer is useful, and it is not the artefact. Last verified 10 September 2026. Not legal advice.
| Evidence type | What the product holds | Duty it relates to | Kind of text | Last verified |
|---|---|---|---|---|
| Technical documentation, the Annex IV dossier | A recorded flag that the dossier exists for a system, the collected file if the organisation attaches it, and a review record if a human accepted it. | Articles 11 and 18(1)(a) of 2024/1689 — draw it up, keep it up to date, keep it at the disposal of national competent authorities for 10 years. | Legal requirements, only if they apply. This product does not write the dossier and is not the system of record for it. | 10 September 2026 |
| Quality-management-system documentation | Policies and their owners in the policies library, plus collected artefacts. | Articles 17 and 18(1)(b) of 2024/1689. | Legal requirements, only if they apply. An ISO/IEC 42001:2023 certificate does not discharge Article 17, and neither does a policy library. | 10 September 2026 |
| Automatically generated logs | A recorded flag that record-keeping and event logging exist for a system. The logs themselves live in your systems. | Articles 12, 19 and 26(6) of 2024/1689 — the capability, and keeping logs for a period appropriate to the intended purpose of at least six months. | Legal requirements, only if they apply. This product does not store or retain YOUR logs. | 10 September 2026 |
| Risk-management records | The AI risk register's per-risk status over the declared high-risk inventory, plus collected artefacts. | Article 9 of 2024/1689 — a continuous, documented, maintained risk-management process across the lifecycle. | Legal requirement, only if it applies. A register is one artefact inside such a process, not the process. | 10 September 2026 |
| Human-oversight and ownership records | The owner assigned to each system and the recorded human-oversight artefact. | Articles 14 and 26(2) of 2024/1689. | Legal requirements, only if they apply. Assigning an owner is not Article 14 compliance. | 10 September 2026 |
| Conformity records: the EU declaration of conformity, notified-body documents, EU-database registration | Organisation attestations that these exist, graded by standalone lenses. | Articles 47, 18(1)(c)–(e), 49 and 71 of 2024/1689. | Legal requirements, only if they apply. An attestation is never the platform asserting conformity, and this product does not register in the EU database or issue certifications. | 10 September 2026 |
| Incident records | Incidents the organisation classified and recorded, with any corrective action it entered. | Articles 3(49), 55(1)(c) and 73 of 2024/1689 — the definition, the GPAI duty to the AI Office, and the high-risk reporting duty on 15-day, two-day and 10-day outer caps. | Legal requirements, only if they apply. Recording an incident is not a report, is not a determination that YOUR event is reportable, and does not start a clock. The AI-incident-reporting guide on this site is that page. | 10 September 2026 |
| Transparency records under Article 50 | Per-characteristic triggers and measures recorded against each system. | Article 50 of 2024/1689. | Legal requirement, only if it applies. Recording a measure is not a finding that the disclosure is adequate. | 10 September 2026 |
| The management-system evidence a certification auditor asks for | Policies, ownership, review dates, and collected artefacts in one place. | ISO/IEC 42001:2023 audit practice, including the Statement of Applicability the standard asks for and no article of the Act requires. | Standard and industry practice, not a legal requirement of the Act. An accredited certification body issues the certificate, not a dashboard. | 10 September 2026 |
Legal requirement versus guidance versus ShipReady capability
The table below labels each text, so that an accepted control is never read as a legal conclusion. Last verified 10 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/1689 Articles 11, 12, 17, 18, 19 and 47 | Legal requirements — the documentation, the logging capability, the quality-management system, the retention periods, and the EU declaration of conformity, only if they apply. | Does not claim any collected artefact satisfies them and does not determine that they bind YOU. |
| Regulation (EU) 2024/1689 Articles 21 and 74 | Legal requirements and powers — information and documentation on a reasoned request, log access, and market-surveillance access to documentation and data sets. | Does not answer a request, does not decide its scope, and is not a regulator filing pack. |
| Regulation (EU) 2024/1689 Articles 55(1)(c) and 73 | Legal requirements — GPAI serious-incident reporting to the AI Office without undue delay, and high-risk serious-incident reporting on 15-day, two-day and 10-day outer caps, only if they apply. | Does not file, does not determine that YOUR event is reportable, and does not start a clock. |
| ISO/IEC 42001:2023 | Best practice / standard. Documented information and management-system evidence. Not a legal substitute for the Act. | Does not issue or substitute for a certificate from an accredited certification body. |
| European Commission AI Act pages and AI Office materials | Commission materials. Guidance, not the regulation. | Does not treat Commission material as rewriting an article or a retention period. |
| This product's evidence collection, review overlay, exports, and Passport | ShipReadyMetrics capability. Collected artefacts, recorded human review, portable exports, and a shareable posture snapshot. | Not legal conformity, not a certificate, not CE marking, not forensic chain of custody, and not a regulator filing pack. A named human still owns the assessment. |
What to do now
As of last verification on 10 September 2026, the documentation and record duties this page maps against sit on the Article 113 residual application of 2 August 2026, with Article 113(c) keeping Article 6(1) and the corresponding obligations on 2 August 2027, and Chapter V GPAI duties applying since 2 August 2025 under Article 113(b), except Article 101. The list below is operational preparation, not a determination that any of it binds YOU.
- Attach artefacts to systems, not to topics. Every request an auditor or authority makes names a system, and a topic-shaped folder gets re-sorted under time pressure.
- Make the reviewer visible on every accepted row. An acceptance with no name attached is indistinguishable from a machine verdict, and that is exactly the confusion worth avoiding.
- Leave not verified where nothing was assessed. A surface that turns silence into a pass is worse than no surface, because it removes the prompt to do the work.
- Keep the logs where they are. This product records that logging exists; retention of the logs themselves is an Article 19 or Article 26(6) question for whoever controls them. The evidence-retention-checklist guide on this site is that page.
- Decide in advance that a Passport link answers a customer questionnaire and never an authority. The AI-audit-evidence guide on this site is the evidence-request-by-role page, and counsel answers a reasoned request.
Checklist
This is a question list, not a determination that the Act applies to YOU. Walk the legal questions with counsel.
- For each control that reads met, can you name the artefact behind it and the human who accepted it?
- Does an accepted control mean a legal duty is satisfied? No. It is a recorded human judgement over the organisation's own records.
- Is anything reading as a pass where nothing was actually assessed? The surfaces should read not verified instead.
- Are the artefacts attached to the systems they belong to, or piled by document type?
- Do you know which records this product does not hold — the logs, the Annex IV dossier itself, the signed declaration of conformity — and where those actually live?
- Is ShipReady Passport being used with customers rather than offered to a regulator? It is a posture snapshot, not legal conformity.
- Does exporting an AI bill of materials submit anything anywhere? No. It is portability, not an Annex VIII submission and not a filing.
- Document the assessment, including which evidence you decided not to collect and why. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.
If you already have a session: signed-in app → Compliance holds evidence collection, the evidence review overlay, and the obligation map, and Compliance → AI governance holds the AI inventory and the AI risk register with their exports, including a CycloneDX AI bill of materials. Marking in-scope is not applicability. A named human still owns the assessment.
This product is not a regulator filing pack, is not forensic chain of custody, does not file with the AI Office, does not file with a market-surveillance authority, does not register in the EU database, does not issue certifications, does not affix CE marks, and is not a notified body. ShipReady Passport is a shareable posture snapshot, not legal conformity. The cyber risk register lives under Security and is a different register from the AI risk register.
This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.
Primary sources (last verified 10 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. Product claims describe shipped behaviour. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 9, 11, 12, 14, 17, 18, 19, 21, 26, 47, 49, 50, 55, 71, 73, 74 and 113 and Annex IV, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. ISO/IEC 42001:2023 is a management-system standard, not the regulation. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. These are not a complete world list. Not legal advice.
The EU AI Act overview on this site is the pillar page. The evidence-retention-checklist guide on this site is the Articles 12, 18 and 19 retention-matrix page. The AI-audit-evidence guide on this site is the evidence-request-by-role page. The technical-documentation guide on this site is the Articles 11 and 53 Annex IV/XI/XII page. The AI-incident-reporting guide on this site is the Articles 3(49), 55 and 73 page. The how-shipreadymetrics-supports-ai-governance guide on this site is the product map. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a dated description of how evidence is collected and reviewed in this product, set beside the record duties in Regulation (EU) 2024/1689 and ISO/IEC 42001:2023, which is a standard, not the regulation. Whether those duties apply to YOU, and whether any evidence satisfies them, are legal questions for counsel on your facts. This page does not start a clock.
Does an accepted control constitute legal conformity?
No. A control reads as met because the organisation supplied an artefact and, where a review overlay applies, a named human accepted it. That is a recorded human judgement over the organisation's own records. It is not a conformity determination, not CE marking, not an Article 43 conformity assessment, and not a legal opinion. Where nothing was assessed the surfaces read not verified rather than pass.
Is this a regulator filing pack?
No. A request under Article 21 or Article 74 of Regulation (EU) 2024/1689 arrives with its own legal basis, addressee, scope and deadline, and counsel answers it. This product assembles and reviews material in advance, which shortens the response and exposes gaps early. It does not submit anything, does not file with the AI Office, does not file with a market-surveillance authority, and does not start or stop a clock.
Is the evidence forensically sound?
No. This is not forensic chain of custody. Artefacts are supplied by the organisation, attached to controls, and reviewed by a named human with a date. That is a compliance record, useful for audits and diligence. Where a legal or forensic standard of custody matters — an investigation, litigation, or a serious-incident file — that is a separate discipline with separate tooling.
Can we send ShipReady Passport to a market-surveillance authority?
It is not built for that. ShipReady Passport is a shareable snapshot of recorded posture, designed to answer a customer's diligence questionnaire. It is not legal conformity, not a certificate, and not a response to a reasoned request under Article 21 or Article 74 of Regulation (EU) 2024/1689. Counsel decides what goes to an authority and in what form.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.