REGISTER / 01
Which AI systems touch our data?
A current register records purpose, provider, owner, role, data use and affected groups.
Turn each AI system into a current, cited evidence record your customers can review, then export a scoped pack without exposing drafts or internal activity.
The customer question
“Please list the AI systems used in your service, their risk classification, transparency controls, and supporting documentation.”
Typical customer security and procurement request
REGISTER / 01
A current register records purpose, provider, owner, role, data use and affected groups.
DECISION / 02
Each role, risk and transparency decision retains the answers, reasoning and legal references.
EVIDENCE / 03
A dated manifest contains selected systems and completed evidence, with internal work excluded.
One maintained record
The customer pack is a controlled view of the governance record your team already maintains, not another spreadsheet created under deadline pressure.
Capture the system, provider, purpose, owner, organisational role, data use and affected groups before evidence gets scattered.
Support reply assistant
Customer operations / Deployer record
Customer-safe by scope
A proof pack is a dated external snapshot, not a mirror of your workspace. You choose the systems; Konformis includes current, completed material and records the contents in a manifest.
Inspect the example packThe separate internal audit package retains the deeper activity and decision record for internal assurance work.
Northstar Labs proof pack
PACK-2026-0718 · GENERATED 18 JUL 2026
Prepared by, snapshot date and selected systems
Purpose, provider, owner, role and status
Results, reasoning and legal references
Article 50 checks and evidence links
Completed versions selected for this review
Plain-language scope and limitations
Remains inside the workspace
Ongoing readiness
Reviews, expiry dates and document versions keep the workspace useful between customer requests. Generate a new external snapshot from the current state when needed.
Evidence review register
4 RECORDS
Provider information
Current
Source captured 08 Jul 2026
Security
Transparency notice
Review due
Due 28 Jul 2026
Product
Human oversight procedure
Final · v1.4
Approved 18 Jul 2026
Operations
Risk classification
Reviewed
Decision version 3 retained
Legal
The internal audit package preserves activity and versions for assurance work; the customer pack includes only the selected completed state.
Staged enforcement
The AI Act is active and applies in stages. The operational task is to know what applies now, prepare the next evidence set, and keep a roadmap for later high-risk requirements.
The Council gave final approval to the AI Omnibus on 29 June 2026. Official Journal publication and entry into force are the remaining formal steps. Confirm publication and the legally operative text before relying on amended dates. This overview is operational guidance, not legal advice.
Article 50 Code of PracticeTwo ways to start
Self-serve workspace
Use the complete workflow for up to 30 AI systems. Inventory, triage, evidence, versioned documents and both export types are available from day one.
Focused setup engagement
A focused working engagement to structure your initial inventory, triage the records and assemble a first procurement-ready evidence pack with your team.
No. It is a structured, point-in-time export of the records and evidence in your workspace. It supports customer review, but it is not legal advice, an audit opinion, or a certificate of compliance.
Draft and in-review documents, user activity, billing details, internal change history, and the internal audit log are excluded. A separate internal audit package is available for assurance work.
The current workflow is designed for EU and UK B2B SaaS companies with roughly 20–200 staff, especially teams where security, product, legal, and operations share AI governance work.
Yes. The public classifier produces a preliminary, shareable result without an account. A workspace adds inventory, evidence tracking, documents, reviews, and exports.
No. Some high-risk application dates moved, while prohibited-practice, AI literacy, GPAI, and transparency duties follow their own stages. Procurement reviews can still require inventory, ownership, risk decisions, and supporting evidence.
The next customer review