Governance & evidence
Documentation & evidence generation
Compliance is ultimately proved on paper. The document generator produces the records the law requires from your registered systems, assessments and organisation profile, so the documentation reflects your actual configuration rather than a template.
Transcript
Compliance is ultimately proved on paper. This is where the documentation the law requires is generated from the data you have already entered.
The AI Act's Article 11 requires technical documentation before a high-risk system is placed on the market, and Annex 4 sets out exactly what it must contain: the system's general description, its development process, its monitoring and control, and its risk management.
Generating a document calls the platform's engine against your real system records. This is a genuine document being written now, not a template being opened.
The result is populated from your configuration: your systems, your assessments, your organisation profile. Ten document types are produced per system, each answering a specific article.
The System Card answers the AI Act's Articles 11 and 12. The Human Oversight Plan answers Article 14. The Data Governance Framework answers Article 10. The Declaration of Conformity answers Article 47, and must be kept for ten years.
Review and edit every draft before you rely on it. The platform produces the evidence. You remain the accountable party for what it says.
On Enterprise, downloading a document as a PDF signs it in the same step. No separate action, no extra setting to find.
The signature ties this exact download to a snapshot of the organisation's tamper-evident audit trail at this moment. A verification link appears immediately, ready to share with a regulator or auditor.
Opening it checks two things independently: that the signature itself is valid, and that the audit trail behind it is currently intact. The same check anyone holding this link could run, with no login required.
Why this is required
Article 11 requires technical documentation to be drawn up before a high-risk system is placed on the market, and kept up to date. Annex IV sets out precisely what it must contain: a general description of the system, a description of its elements and development process, detailed information on monitoring, functioning and control, the risk management system, and changes made through its lifecycle.
Article 47 requires a written, machine-readable EU declaration of conformity for each high-risk system, kept for ten years after the system is placed on the market or put into service. Article 48 governs CE marking, and Article 49 requires registration in the EU database before market placement.
Article 17 requires providers to operate a quality management system documented through written policies, procedures and instructions, covering regulatory compliance strategy, design control, testing, data management, risk management and post-market monitoring.
On the data protection side, the same principle produces different artefacts: Article 30 records of processing, Article 28 processor registers, Article 33 breach records and Article 15-22 request logs.
The point of generating these from live data is that documentation which is maintained by hand diverges from reality almost immediately, and stale documentation is worse than none: it is evidence of a control that was not operating.
What EuroCompliant does
Ten document types are generated per system, each mapped to an article of the AI Act: AI System Card (Articles 11-12), Risk Assessment Report (Article 6), Technical Documentation (Annex IV), Audit Log (Article 12), Human Oversight Plan (Article 14), Data Governance Framework (Article 10), Instructions for Use (Article 13), Quality Management System (Article 17), EU Declaration of Conformity (Article 47) and CE Marking Guide (Article 48).
Organisation-wide documents cover the other enabled frameworks: GDPR and UK GDPR records and registers, CCPA notices and inventories, ISO/IEC 42001 policy and statement of applicability, NIST AI RMF governance, and DORA ICT risk and resilience documentation.
Drafts are pre-filled from your data and exportable as Markdown or PDF.
On Enterprise, PDF exports can be cryptographically signed and tied to the organisation's tamper-evident audit trail (see Evidence & Audit). Each signed PDF carries a verification link anyone can use to confirm the document has not been altered since it was generated, independently of your login.
Walking through it
Complete the system record first
The generator can only describe what you have told it. Thin system records produce thin documentation.
Open /systems →Generate the drafts
Select a system for its Annex IV set, or a framework for organisation-wide records.
Open /compliance-docs →Review and edit every draft
Generated documentation is a starting point that reflects your data. You remain the accountable party for what it says. Read it before you rely on it.
Regenerate after material changes
The AI Act's Article 11 requires the documentation to be kept up to date, so a model change, purpose change or new data source should trigger a refresh.
The law
Technical documentation
Drawn up before market placement, kept up to date, containing the Annex IV information.
Technical documentation contents
General description, development process, monitoring and control, risk management, and lifecycle changes.
EU declaration of conformity
A written, machine-readable declaration per system, retained for ten years after market placement.
Quality management system
Documented written policies and procedures covering compliance strategy, design control, testing, data and risk management.
Records of processing activities
A written record of processing, available to the supervisory authority on request.
Frequently asked
Is generated documentation legally sufficient on its own?
It is a substantiated draft, not a signature. The platform assembles the Annex IV structure and fills it from your records, which removes the mechanical work, but you must review it for accuracy and completeness, and you remain accountable for its contents.
How long do we keep these?
Article 18 requires providers to keep the technical documentation, quality management system documentation and conformity assessment records for ten years after the system is placed on the market. Article 47 sets the same period for the declaration of conformity.
What does a signed PDF prove?
That the specific bytes a regulator or auditor holds are exactly what the platform generated, and that this organisation's audit trail was intact at the moment of generation, not that the underlying content is legally correct. It is an integrity guarantee, not a legal attestation; you remain responsible for reviewing what the document actually says.
Related guides
Compliance checklists
How Articles 9 to 15 become tracked, owned, evidenced work rather than a document nobody reads.
Evidence vault & audit trail
Turning completed checklist items into artefacts a regulator can inspect, and the logging duties behind Articles 12 and 26.
Records of processing (RoPA)
The Article 30 record: the foundational GDPR document, and usually the first thing requested in an investigation.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial