Free · private in your browser · about 8 minutes

EU AI Act Technical Documentation Evidence Mapper

Take one AI system and mark what evidence you can actually locate for each area in Annex IV. You will leave with a practical preparation list—not a compliance verdict.

0 of 9 mapped
01System identity and intended purpose

What Annex IV asks for: Describe the system, its provider and version, intended purpose, users, foreseeable misuse, and how it interacts with other systems.

Evidence to locate: System card, version record, owner list, intended-use statement, instructions, and interaction map.

Where VeriTrooper may contribute

A VeriTrooper system card and configuration snapshot may contribute, but they will not cover every organizational or legal requirement.

02System elements and development process

What Annex IV asks for: Explain the design, architecture, development methods, data requirements, validation approach, and relevant third-party components.

Evidence to locate: Architecture notes, component inventory, data card, preparation records, test protocol, and dependency records.

Where VeriTrooper may contribute

SitRep may document source readiness; Scout may capture a bounded test protocol, results, limitations, and exclusions.

03Monitoring, functioning, and control

What Annex IV asks for: Document how the system’s operation is monitored and how people can interpret, supervise, or control it.

Evidence to locate: Logging design, human-oversight procedure, alert rules, operating instructions, access controls, and escalation path.

Where VeriTrooper may contribute

Watchtower may contribute monitoring scope, flagged-answer records, and cycle history for a defined workflow.

04Metric selection and performance evidence

What Annex IV asks for: Explain why the chosen performance metrics are appropriate and record the system’s measured performance and limitations.

Evidence to locate: Metric rationale, test set, item-level results, threshold record, failure analysis, and subgroup or condition breakdowns.

Where VeriTrooper may contribute

Scout may contribute item-level outcomes, chosen metrics, limitations, and exclusions for document-grounded answers.

05Risk management record

What Annex IV asks for: Connect identified risks to evaluation, controls, residual risk, and ongoing review.

Evidence to locate: Risk register, hazard analysis, control mapping, test evidence, residual-risk decision, and accountable signoff.

Where VeriTrooper may contribute

VeriTrooper evidence can support a risk review; it does not make the risk decision or replace accountable signoff.

06Lifecycle changes and version history

What Annex IV asks for: Record relevant changes to the system and how those changes affect earlier testing, documentation, and decisions.

Evidence to locate: Change log, model and prompt versions, corpus versions, release approvals, and re-review triggers.

Where VeriTrooper may contribute

Configuration snapshots and repeated Watchtower cycles may help establish what changed and when.

07Standards and specifications

What Annex IV asks for: Identify harmonized standards or common specifications applied, including where they were not fully applied.

Evidence to locate: Standards register, clause mapping, applicability decisions, implementation records, and documented exceptions.

Where VeriTrooper may contribute

A VeriTrooper package may be mapped into a reviewer’s framework, but the reviewer decides whether the evidence is sufficient.

08EU declaration of conformity

What Annex IV asks for: Include the applicable declaration of conformity when one is required.

Evidence to locate: Signed declaration, product and provider identifiers, referenced legislation and standards, and controlled approval copy.

Where VeriTrooper may contribute

VeriTrooper does not issue declarations or certifications. This item remains with the responsible provider and qualified reviewers.

09Post-market monitoring plan

What Annex IV asks for: Document how performance, incidents, changes, and emerging risks will be monitored after deployment.

Evidence to locate: Monitoring plan, owners, indicators, review cadence, incident process, thresholds, and corrective-action records.

Where VeriTrooper may contribute

Watchtower may contribute scheduled test cycles and exception history within its defined monitoring scope.

Primary sources

Start with the rule itself.

Article 11 requires technical documentation for high-risk AI systems to be prepared before the system is placed on the market or put into service and kept up to date. Annex IV sets out the information that documentation should contain.

The European Commission’s current implementation page explains the amended timetable. The classification question still belongs with qualified legal and assurance professionals.

Last reviewed September 9, 2026. The prompts are a plain-English preparation aid and do not reproduce every legal detail or determine whether the Act applies to your system.

Read the field note behind this mapper →