RRVI™ Repository · Reference Document

Administration Guide

How administrators maintain the EU AI Act Compliance Management System™ throughout its operational lifecycle — from repository integrity to audit-day readiness.

System: EU AI Act Compliance Management System™ Repository: RRVI™ Version: 1.0.2

On this page

  1. 01Purpose
  2. 02Administrator Responsibilities
  3. 03Repository Administration
  4. 04Document Administration
  5. 05Version Management
  6. 06User Administration
  7. 07Backup
  8. 08Periodic Reviews
  9. 09Inspection Preparation
  10. 10Continuous Maintenance
  11. FAQFrequently Asked Questions
01 — Purpose

What this guide governs

This guide describes how administrators maintain the EU AI Act Compliance Management System throughout its operational lifecycle — not just at setup, but continuously, as the regulation phases in, as documents get reviewed, and as the organization changes.

It applies to anyone holding an administrative role over the compliance repository: the Repository Administrator, the AI Governance Owner, and anyone coordinating document reviews, user access, or audit preparation on their behalf.

02 — Administrator Responsibilities

What the Administrator is accountable for

The Administrator shall maintain the system across six areas. Each is covered in detail in its own section below.

01

Maintain repository integrity

02

Manage document versions

03

Coordinate document reviews

04

Manage user access

05

Maintain traceability

06

Prepare the system for audits and inspections

03 — Repository Administration

Keeping the repository itself trustworthy

Before anything else, the repository has to be internally consistent — a crawler, an auditor, or the next administrator should be able to open it and immediately understand its structure without asking you.

Verify

Do not rename controlled documents. A document's filename is part of its identity — traceability records, registers, and prior audit evidence all reference it by name. Renaming breaks the chain even if the content is unchanged.
04 — Document Administration

What every controlled document must carry

Every controlled document in the system shall have all five of the following, without exception:

FieldWhy it matters
Unique identifierLets any register, cross-reference, or audit trail point to exactly one document, unambiguously.
VersionDistinguishes the current controlled state from superseded drafts.
ApprovalRecords who authorized the document to become effective, and when.
Revision historyShows what changed between versions, and why — the difference between a document and a black box.
OwnerNames exactly one accountable person for keeping the document current.
05 — Version Management

What happens at every release

Each release of the compliance system — not just the code, but the documentation set itself — follows the same sequence:

06 — User Administration

The five roles that must be assigned

Administration is not a single job — it is five distinct areas of accountability, and each needs a named person, even in a small organization where one person holds more than one role.

AI Governance Owner
Owns the overall governance posture and policy direction.
AI System Owner
Accountable for a specific AI system's inventory entry and risk classification.
Compliance Owner
Owns the compliance documentation set and its currency.
Internal Auditor
Independently reviews evidence and flags gaps before an external inspector does.
Repository Administrator
Maintains the repository itself — structure, versions, access, backups.
07 — Backup

What must survive a disaster

08 — Periodic Reviews

When the system gets reviewed

Reviews are not optional and not only reactive. The system shall be reviewed:

09 — Inspection Preparation

What "ready" looks like before an inspector asks

Before any inspection — announced or not — verify the following, in this order:

10 — Continuous Maintenance

What stays maintained, always

Administration does not end once the system is set up. Five things stay under continuous maintenance for as long as the system is in use:

01

Repository

02

Documentation

03

Releases

04

Audit records

05

Compliance records

FAQ

Frequently asked questions

Who is responsible for maintaining the compliance repository?

The Repository Administrator, working alongside the AI Governance Owner and Compliance Owner, is responsible for repository integrity, document versions, user access, traceability, and audit readiness.

Can controlled documents be renamed?

No. Controlled documents must never be renamed once issued, since their filename is part of their unique identifier and is referenced by traceability records, registers, and prior audit evidence.

What must every controlled document include?

A unique identifier, a version number, a recorded approval, a revision history, and a named owner.

How often should the system be reviewed?

At minimum annually, and additionally after any regulatory change to the EU AI Act or after major updates to the repository itself.

What roles need to be assigned for administration?

AI Governance Owner, AI System Owner, Compliance Owner, Internal Auditor, and Repository Administrator.

What should be verified before an inspection?

That all modules are complete, registers are current, evidence is available, declarations are approved, and traceability is maintained end to end.

What happens at every version release?

The CHANGELOG and README are updated, a GitHub Release is created, and a Zenodo DOI is published where applicable, so every release remains citable and traceable.