governance model AI
01 / 07

Every decision has someone responsible for it.
And every person in charge has their own proof.

The " EU AI Act " doesn't just call for controls—it calls for clarity on who makes decisions, who oversees them, and who is accountable. V-PROOF organizes the " AI governance " into three levels of responsibility and a six-step cycle, and each step leaves a record with a name, date, and digital signature.

Who decides?
02 / 07

Three levels of responsibility. One that monitors from the outside.

Governance works when Each level knows what it decides and what it must be able to demonstrate. V-PROOF documents what happens at each level.

Verify from the outsideAuditor · regulator · clientVerify the evidence without a V-PROOF account and without access to the organization's internal systems.
01 · AccountabilityBoard and ManagementSets the risk appetite, approves the AI policy, and receives reports from Exposure and the evidence team.V-PROOF ’s records: the approved policy, its version, and each report submitted.
02 · DecideAI CommitteeApproves high-risk systems, exceptions, and policy changes. It consists of members from the legal, compliance, DPO, CISO, and business departments.V-PROOF's records: every approval, with the exact wording of the signature.
03 · OperaSystem AdministratorsThey register the system, monitor its operation, and are responsible for its day-to-day use.V-PROOF's records: the inventory, human decisions, and the controls applied.
What does each person do?
03 / 07

Who approves, who carries out, and to whom reports are made.

A reference model that we adapt to the structure of each organization during the assessment.

ActivityBoard & executive managementAI CommitteeSystem AdministratorLegal · DPO · CISOEvidence in V-PROOF
Establishing Risk Appetite and AI PolicyARICSealed policy and version
Maintain the systems inventoryIARCList of each system and the person responsible for it
Classify the risk according to the EU AI ActIARCRisk level and associated obligations
Approve a high-risk systemIA · RCCDeclaration by the Designated Person
Monitor implementation—IA · RCHuman Decisions and Controls Implemented
Manage an incidentIARRDetection, response, and resolution dates
Notify managementIA · RCCExposure , and Evidence Report

A Is accountable · R Implements · C Is consulted · I Is informed

The governance cycle
04 / 07

Six steps. Everyone leaves their proof.

The cycle repeats itself every time a new system is introduced, an existing one is changed, or the policy is revised.

  1. 01InventoryRecord each AI system, its provider, and the person responsible for it
  2. 02ClassifyRisk level according to the “ EU AI Act ” and the obligations it triggers
  3. 03ApproveWritten statement from the designated person, verbatim at the track
  4. 04MonitorControls in progress and recorded human decisions
  5. 05Showsealed , and verifiable by third parties
  6. 06ReviewReport for management and recalculation of on-demand risk
What the regulation requires
05 / 07

Governance is not optional. It's written in the rules.

The frameworks covered at V-PROOF all call for the same thing, in different words: clearly defined roles, human oversight, and the ability to demonstrate it.

EU AI Act · Art. 4AI Literacy

Anyone who uses AI systems must ensure that their staff has the necessary knowledge to do so.

EU AI Act · Articles 14 and 26Human supervision

In high-risk systems, those responsible for deploying them must entrust oversight to individuals with the necessary expertise, training, and authority.

EU AI Act · Art. 26Obligations of the Deployer

Use the system according to the instructions, monitor its operation, maintain records, and report serious incidents.

ISO/IEC 42001 · Clauses 5 and 9Leadership and Review

Management makes the commitment, establishes the policy, and assigns roles; the system is audited and reviewed by management.

NIST AI RMF · Govern FunctionCulture and Responsibilities

Policies, roles, and accountability must be defined before mapping, measuring, and managing risk.

GDPR · Art. 5.2Proactive Responsibility

It is not enough to simply comply: the data controller must be able to demonstrate compliance.

A general overview of the relevant regulations. For your specific situation, please consult your legal advisor.

Global and local
06 / 07

One model for the entire group. Each country's regulations on top of that.

The core governance framework is common (EU AI Act, ISO/IEC 42001, NIST AI RMF, and GDPR), and each subsidiary adds its own local layer, such as the ENS in Spain. Management sees a single, consolidated set of evidence.

How to Get Started
07 / 07

Start by finding out who's making the decisions today.

1 · Assessment. We take stock of your AI systems and identify who is responsible for each one.

2 · Model Design. We define roles, a committee, and a cycle tailored to your organization.

3 · Getting Started. V-PROOF begins tracking every step with its proof.