regulation10.com

Knowledge base / regulation10.com product guide (EU AI Act)

How evidence and documents map to EU AI Act obligations

Each EU obligation on a system is backed by the module runs and documents you attach to it. When you complete a module or upload a document, the platform links it to the obligation it supports. The evidence export and the obligation status then show, requirement by requirement, which items are covered and which are still open. To close a gap, open the outstanding obligation, run the linked module or attach the requested document, and the status updates on its own.

The mapping exists because the EU AI Act is written as obligations while your organisation produces artefacts, and the two do not line up one-to-one by nature. A regulator asks whether your risk management obligation is met; your organisation holds assessment runs, policies, and test reports. Someone has to connect the two, and doing it by hand in a spreadsheet is exactly the kind of work that rots: it is accurate the week it is made and quietly wrong thereafter. The platform makes the connection at the moment the artefact is created, so the map maintains itself as a side effect of doing the work.

For you, the value shows up in both directions. Looking from obligation to evidence answers the reviewer's question: show me what supports this requirement. Looking from evidence to obligation answers the internal question: what was this run actually for, and what breaks if it is stale? Both directions matter during a conformity assessment, where an assessor works through requirements and expects each one to resolve to concrete, current artefacts without a guided tour.

The closing loop is deliberately short. An open item is not a diagnosis to interpret; it names the module or document that closes it and links you there. This turns compliance work from a research exercise into a queue. Teams that work the queue steadily find the status view converging on complete without a heroic final push, which is the healthiest shape for an audit-facing record to grow in, because it leaves a timeline of steady work in the audit trail rather than a suspicious last-minute flood.

Documents deserve the same care as runs. Uploading a policy against an obligation is a claim that the policy supports it, so attach the document that actually does the supporting, not the nearest PDF. A reviewer who opens one mislinked artefact reads the rest of your record with colder eyes.

One honest boundary. The mapping is a navigational scaffold that organises your evidence against the framework's requirements; it is not a determination that an obligation is legally satisfied. Whether a given run and set of documents amount to compliance is a judgement for you and, where it matters, a qualified adviser. What the platform guarantees is narrower and still valuable: nothing in your record is orphaned, nothing applicable is silently unaddressed, and the state of the whole is visible at a glance rather than discoverable only by audit.

When an artefact goes stale, for example a policy that was revised outside the platform, replace the attachment rather than leaving the old version to speak for you. The link carries your claim about what supports the requirement, so keeping the linked artefact current is part of keeping the claim true. This is informational only and not legal advice: the platform's regulatory content is a scaffold pending qualified-professional review, so confirm any obligation with a qualified adviser before you rely on it.

How evidence and documents map to EU AI Act obligations | regulation10.com