Every decision has someone responsible for it.
And every person in charge has their own proof.
The " EU AI Act " doesn't just call for controls—it calls for clarity on who makes decisions, who oversees them, and who is accountable. V-PROOF organizes the " AI governance " into three levels of responsibility and a six-step cycle, and each step leaves a record with a name, date, and digital signature.
Three levels of responsibility. One that monitors from the outside.
Governance works when Each level knows what it decides and what it must be able to demonstrate. V-PROOF documents what happens at each level.
Who approves, who carries out, and to whom reports are made.
A reference model that we adapt to the structure of each organization during the assessment.
| Activity | Board & executive management | AI Committee | System Administrator | Legal · DPO · CISO | Evidence in V-PROOF |
|---|---|---|---|---|---|
| Establishing Risk Appetite and AI Policy | A | R | I | C | Sealed policy and version |
| Maintain the systems inventory | I | A | R | C | List of each system and the person responsible for it |
| Classify the risk according to the EU AI Act | I | A | R | C | Risk level and associated obligations |
| Approve a high-risk system | I | A · R | C | C | Declaration by the Designated Person |
| Monitor implementation | — | I | A · R | C | Human Decisions and Controls Implemented |
| Manage an incident | I | A | R | R | Detection, response, and resolution dates |
| Notify management | I | A · R | C | C | Exposure , and Evidence Report |
A Is accountable · R Implements · C Is consulted · I Is informed
Six steps. Everyone leaves their proof.
The cycle repeats itself every time a new system is introduced, an existing one is changed, or the policy is revised.
- 01InventoryRecord each AI system, its provider, and the person responsible for it
- 02ClassifyRisk level according to the “ EU AI Act ” and the obligations it triggers
- 03ApproveWritten statement from the designated person, verbatim at the track
- 04MonitorControls in progress and recorded human decisions
- 05Showsealed , and verifiable by third parties
- 06ReviewReport for management and recalculation of on-demand risk
Governance is not optional. It's written in the rules.
The frameworks covered at V-PROOF all call for the same thing, in different words: clearly defined roles, human oversight, and the ability to demonstrate it.
Anyone who uses AI systems must ensure that their staff has the necessary knowledge to do so.
In high-risk systems, those responsible for deploying them must entrust oversight to individuals with the necessary expertise, training, and authority.
Use the system according to the instructions, monitor its operation, maintain records, and report serious incidents.
Management makes the commitment, establishes the policy, and assigns roles; the system is audited and reviewed by management.
Policies, roles, and accountability must be defined before mapping, measuring, and managing risk.
It is not enough to simply comply: the data controller must be able to demonstrate compliance.
A general overview of the relevant regulations. For your specific situation, please consult your legal advisor.
One model for the entire group. Each country's regulations on top of that.
The core governance framework is common (EU AI Act, ISO/IEC 42001, NIST AI RMF, and GDPR), and each subsidiary adds its own local layer, such as the ENS in Spain. Management sees a single, consolidated set of evidence.
Start by finding out who's making the decisions today.
1 · Assessment. We take stock of your AI systems and identify who is responsible for each one.
2 · Model Design. We define roles, a committee, and a cycle tailored to your organization.
3 · Getting Started. V-PROOF begins tracking every step with its proof.
