Regulatory readiness map · Evidence operating model
High-risk AI obligations create a proof burden.
Guardian helps risk, compliance, AI governance, and ML platform teams preserve the operational evidence behind high-risk AI systems, without replacing legal review or conformity assessment.
Proof burden memo
The EU AI Act does not only ask for policies. It asks teams to show how systems were governed, monitored, reviewed, documented, and corrected over time. Most readiness gaps appear after deployment — when monitoring, incident handling, and evidence maintenance are not yet part of day-to-day operations.
Preserve what happened. Reconstruct what matters. Export what you can defend.
Guardian is the evidence operating model for that work — linking operational signals, human oversight, policy mapping, a traceable evidence trail, and export-ready records above the tools you already run.
Obligation → evidence map
Illustrative map for one in-scope system. Counsel confirms your specific obligations.
| Obligation area | What teams may need to show | Evidence Guardian helps preserve | Source systems | Readiness state |
|---|---|---|---|---|
| Risk management | Risk measures, review triggers, follow-up | Threshold events, risk reviews, escalations | Monitoring, ticketing | Linked |
| Data governance | Data quality, lineage, governance decisions | Quality metrics, drift signals, notes | MLOps, data platform | Active |
| Technical documentation | System description tied to production | Versioned docs linked to runs and changes | Model registry, change logs | Open |
| Logging and traceability | Who did what, when, on which output | Timestamped intake, custody trail | API intake, webhooks | Linked |
| Human oversight | Oversight procedures and interventions | Reviewer sign-off, escalation history | Review workflow, incidents | Active |
| Accuracy, robustness, and cybersecurity | Performance and resilience in operation | Metrics, robustness tests, security events | Observability, security tooling | Open |
| Post-market monitoring | Ongoing behaviour after deployment | Baselines, alert history, review outcomes | Monitoring, Guardian dossier | Verified |
| Serious incident evidence | Documentation when serious incidents occur | Incident register, remediation, notification | Ticketing, incident workflow | Active |
8 obligation areas · illustrative · not a legal checklist
Evidence operating model
Six record types that form the dossier for one in-scope system — not a dashboard screenshot.
| ID | Record | What it holds | Status |
|---|---|---|---|
| EVP-01 | AI System Record | In-scope system identity, owners, and operating context | Core |
| EVP-02 | Version Record | Model, policy, and configuration versions linked to production | Core |
| EVP-03 | Evidence Events | Captured signals with source, timestamp, and normalized payload | Active |
| EVP-04 | Human Review | Oversight actions, sign-off, and reviewer identity | Active |
| EVP-05 | Incident + Corrective Action | Open items, root cause, remediation, and resolution trail | Linked |
| EVP-06 | Register-backed Export + Retention | Point-in-time evidence packet with retention boundary | Verified |
Supporting objects
Policies · Owners · Source Connectors — linked across every record type above.
From obligation to dossier
| ID | Step | Output |
|---|---|---|
| MAP-01 | Identify obligation | Obligation area mapped to in-scope system |
| MAP-02 | Map evidence source | Source systems and intake channels registered |
| MAP-03 | Capture operational signal | Event received with timestamp and source ID |
| MAP-04 | Link owner and policy | Custody handler and policy reference attached |
| MAP-05 | Review and preserve custody | Review actions and transfers recorded |
| MAP-06 | Export evidence packet | Reconstructable bundle for review |
Scope boundaries
Common questions
Guardian supports evidence readiness and auditability workflows. It does not provide legal advice, determine legal classification, certify compliance, or replace sector-specific conformity assessment.
Build a first evidence baseline through the Readiness Sprint, then run the operating model in Guardian.