User Manual
EU AI Act Compliance Management System™
Repository: RRVI™
Version: 1.0.2
1. Purpose
This User Manual explains how organizations use the EU AI Act Compliance Management System to establish, maintain and continuously improve compliance with Regulation (EU) 2024/1689.
The manual is intended for organizations acting primarily as AI Deployers.
2. Intended Audience
This manual is intended for:
- Company Directors
- Compliance Officers
- AI Governance Owners
- AI System Owners
- Internal Auditors
- External Auditors
- Regulatory Inspectors
3. Repository Structure
The repository contains ten compliance modules.
Each module contains seven controlled documents.
Policy
Procedure
Work Instruction
Checklist
Register
Evidence
Declaration
Total:
- 10 Modules
- 70 Controlled Documents
4. Compliance Lifecycle
The Compliance Management System follows the same lifecycle for every module.
``` Policy ↓
Procedure ↓
Work Instruction ↓
Checklist ↓
Register ↓
Evidence ↓
Declaration ```
Every declaration shall be supported by objective evidence.
5. Getting Started
Before using the Compliance Management System:
- identify all AI systems;
- appoint an AI Governance Owner;
- create the repository;
- publish Version 1.0;
- establish document control.
6. Completing Module 01 — AI System Inventory
Objective
Identify every AI system used by the organization.
Complete:
- Policy
- Procedure
- Work Instruction
- Checklist
- Register
- Evidence
- Declaration
The AI Inventory becomes the foundation for every other module.
7. Completing Module 02 — Risk Classification
Objective
Determine the EU AI Act risk category for every AI system.
Update the Risk Classification Register whenever new AI systems are introduced.
8. Completing Module 03 — AI Literacy
Objective
Ensure personnel have sufficient AI Literacy appropriate to their role.
Maintain evidence of completed awareness and training activities.
9. Completing Module 04 — Prohibited Practices
Objective
Verify that no prohibited AI practices are implemented.
Document assessments and retain supporting evidence.
10. Completing Module 05 — High-Risk Assessment
Objective
Determine whether any AI system qualifies as High-Risk under the EU AI Act.
Document conclusions and supporting rationale.
11. Completing Module 06 — Technical Documentation
Objective
Maintain complete technical documentation for applicable AI systems.
Review documentation after significant technical changes.
12. Completing Module 07 — Human Oversight
Objective
Assign responsible human operators and define oversight mechanisms.
Document review, approval and override responsibilities.
13. Completing Module 08 — Data Governance
Objective
Document data sources, ownership, classification and quality.
Review whenever datasets or processing activities change.
14. Completing Module 09 — Logging & Monitoring
Objective
Maintain operational logs and monitoring records.
Ensure logs are protected and retained according to policy.
15. Completing Module 10 — Incident Reporting
Objective
Identify, investigate and resolve AI-related incidents.
Maintain complete incident records and corrective actions.
16. Annual Review
At least once every year:
- review all Policies;
- review all Procedures;
- review Registers;
- update Evidence;
- renew Declarations.
17. Internal Audit
Use:
- AUDIT_PLAN.md
- INSPECTION_GUIDE.md
- COMPLIANCE_MATRIX.md
- DOCUMENT_TRACEABILITY_MATRIX.md
Verify that every module remains complete and consistent.
18. Regulatory Inspection
During an inspection:
- Present README.md.
- Present DOCUMENT_INDEX.md.
- Demonstrate each module.
- Present Registers.
- Present Evidence.
- Present Declarations.
- Demonstrate traceability.
19. Document Control
Every document shall be:
- version controlled;
- reviewed periodically;
- approved;
- retained;
- traceable.
20. Continuous Improvement
The Compliance Management System shall be updated whenever:
- legislation changes;
- AI systems change;
- incidents occur;
- audits identify improvements;
- new organizational risks emerge.
Version
1.0.2
Prepared by
your compliance officer
your organization
Generate Your Firm's Pack →