4 min read729 wordsv1.0.2.0Last Updated: 1 Aug 2026 Audit & Evidence
EU AI Act: Art. 11 (Technical documentation), Art. 17 (QMS), Art. 72 (Post-market monitoring)
ISO 42001: A.4 (AI risk management), A.7 (AI system performance), A.10 (AI governance)
NIST AI RMF: GOVERN-1.3 (Documentation), MAP-2.1 (Context), MEASURE-3 (Monitoring)
NIST AI 600-1: §2.10 (Intellectual Property), §2.12 (Value chain)
Required Artefact Catalogue
| Artefact |
Standard |
Frequency |
Owner |
Storage |
| System Card |
EU AI Act Art. 11, NIST AI RMF GOVERN-1.3 |
Per model version |
ML Eng |
NestVault365 / Git |
| Model Card |
EU AI Act Art. 11, ISO 42001 A.7.1 |
Per model version |
ML Eng |
NestVault365 / Git |
| Data Sheet |
EU AI Act Art. 10, ISO 42001 A.9.2 |
Per dataset version |
Data Eng |
NestVault365 / Git |
| Risk Register |
EU AI Act Art. 9, ISO 42001 A.4.1 |
Quarterly update |
Risk Owner |
NestVault365 / Jira |
| Treatment Plan |
EU AI Act Art. 9, ISO 42001 A.4.2 |
Per risk |
Risk Owner |
NestVault365 / Jira |
| TEVV Report |
EU AI Act Art. 15, ISO 42001 A.7.2 |
Per release |
ML Eng |
NestVault365 / CI |
| Adversarial Test Report |
EU AI Act Art. 15, NIST AI 600-1 |
Quarterly + per release |
Red Team |
NestVault365 |
| Drift Monitoring Report |
EU AI Act Art. 72, ISO 42001 A.7.3 |
Monthly |
ML Platform |
NestVault365 / Grafana |
| Incident Reports |
EU AI Act Art. 20/73, ISO 42001 A.6.2 |
Per incident |
IR Lead |
NestVault365 / Jira |
| Post-Market Monitoring Plan |
EU AI Act Art. 72 |
Annual review |
Product / ML Eng |
NestVault365 |
| Supply-Chain SBOM |
EU AI Act Art. 25, SLSA, ISO 42001 A.8 |
Per model version |
ML Platform |
NestVault365 / CI |
| QMS Records |
EU AI Act Art. 17, ISO 42001 A.10 |
Continuous |
Quality |
NestVault365 / QMS |
| Conformity Assessment |
EU AI Act Art. 43 |
Pre-market + periodic |
Legal / Quality |
NestVault365 |
System Card Template (EU AI Act Annex IV)
| Section |
Content |
| 1. Identification |
System name, version, provider, intended purpose, deployment context |
| 2. Risk Classification |
Prohibited / High-risk (Annex III ref) / Limited / Minimal |
| 3. Architecture |
Components, data flows, model types, integration points |
| 4. Training Data |
Sources, volumes, preprocessing, bias assessment, provenance, licensing |
| 5. Model Details |
Architecture, framework, hyperparameters, training compute, hardware |
| 6. Performance |
Accuracy, robustness, fairness, latency, throughput (with CIs) |
| 7. Risk Assessment |
Summary of risk register; residual risks accepted with justification |
| 8. Human Oversight |
Mechanisms, escalation paths, fallback procedures |
| 9. Monitoring & Logging |
Metrics collected, retention, alerting thresholds |
| 10. Incident Response |
IR plan reference; serious incident notification procedure |
| 11. Supply Chain |
Third-party components, SBOM references, SLSA levels |
| 12. Conformity |
Assessment route (self / notified body); certificate reference |
| 13. Post-Market |
Monitoring plan; update/decommission criteria |
Primary source: EU AI Act Annex IV. EUR-Lex
Model Card Template (Mitchell et al. / Google Model Cards)
| Section |
Content |
| Model Details |
Name, version, architecture, framework, licence, date, contact |
| Intended Use |
Primary uses, out-of-scope uses, user demographics |
| Factors |
Relevant groups, environments, evaluation conditions |
| Metrics |
Per-factor performance (accuracy, F1, fairness, robustness) with 95% CIs |
| Evaluation Data |
Datasets, splits, preprocessing, known limitations |
| Training Data |
Sources, size, preprocessing, known biases, licensing |
| Quantitative Analyses |
Per-factor breakdowns, intersectional, adversarial robustness |
| Ethical Considerations |
Bias, privacy, safety, environmental impact |
| Caveats |
Known failure modes, monitoring needs, update cadence |
| Package |
Contents |
Format |
| Technical Documentation (Art. 11) |
System card, model cards, data sheets, architecture diagrams, risk register, test reports |
PDF + machine-readable (JSON/YAML) |
| QMS Evidence (Art. 17) |
QMS manual, procedures, records, internal audit reports, management review minutes |
PDF |
| Post-Market Monitoring (Art. 72) |
Plan, drift reports, incident summaries, update logs |
PDF + JSON |
| Supply Chain (Art. 25) |
SBOMs, SLSA attestations, supplier assessments, contracts |
PDF + SBOM (SPDX/CycloneDX) |
Evidence Integrity & Storage
| Requirement |
Implementation |
| Immutability |
Write-once storage (NestVault365 / S3 Object Lock / Git signed commits) |
| Tamper Evidence |
SHA256 hashes recorded in transparency log (Rekor / custom) |
| Access Control |
Role-based (Legal, Quality, ML Eng, Auditors); audit trail on every access |
| Retention |
10 years post-decommission (EU AI Act); longer if sectoral law requires |
| Disclosure |
Encrypted transfer via NestVault365; auditor gets time-limited access token |
Citation Register