Rule reference
This page is documentation, not a worklist. It states which rules each governance gate reads, so a finding raised inside an AI System can be traced back to the rule that produced it. The findings themselves live under Gaps and readiness within each AI System.
Rule index
Every rule the engine can raise, and what it asks.
- STRUCT-01A Use Case names the model that serves it
A Use Case with no AI Model linked cannot be traced to what performs it.
- STRUCT-02A deployed model version carries an approval
A model version in use without an approving review is deployed against the record.
- TRACE-01A model version names the datasets it was built on
Training, testing and monitoring data are recorded as dataset use records.
- TRACE-02A dataset use record states what it was used for
Training, testing or monitoring, stated per model version.
- DATA-01A dataset carries a quality assessment
A dataset used by an approved model version without a quality assessment.
- DATA-02Dataset use and fitness is assessed
The fitness of a dataset for the purpose it is used for is recorded.
- RISK-01An identified risk is assessed and controlled
A risk without a control is identified only.
- RISK-02A control carries verification evidence
A control claimed effective without evidence is a claim, not a control.
- RISK-03A Use Case has its risks assessed
A Use Case with no risk record attached has not been assessed.
- REV-01Review conditions are closed
An approval given subject to conditions holds until the conditions are closed.
- REV-02A periodic review is planned
A system in operation without a planned periodic review drifts unobserved.
- APPR-01An approval is signed by the person who gave it
Part 11 signature, with name, meaning and date.
- MON-01A monitoring signal is answered
An open signal past its response window has no recorded response.
- CE-01A planned modification carries an impact assessment
Controlled evolution without an impact assessment is uncontrolled.
- CE-02A planned modification is authorised before it is implemented
The authorising review is linked to the modification.
- CE-03The controlled evolution declaration is complete
Method, scope, limits and verification are all stated.
- CONF-01The deployed version is recorded
What is running is stated, and matches an approved model version.
- EVID-01Evidence is current
Evidence past its review date no longer supports what it is linked to.
- CLASS-01The AI System is classified
The regulatory classification is answered and dated.
- REPRO-01A model version is reproducible
Code reference, environment and dataset versions are recorded together.
- REPO-01The source repository is connected
A change to a model without a commit reference cannot be traced to code.
- SIG-01A signal is triaged
A signal is acknowledged, and where it is material it opens a modification.
- UDI-01A UDI-DI is assigned
A device placed on the market carries a device identifier.
- UDI-02The UDI record matches the device as placed
Identifier, issuing entity and version agree with the current configuration.
- UDI-03A change that triggers a new UDI-DI has one
A change to the device that alters identification requires a new UDI-DI.
- UDI-04A change within the change plan is recorded against it
Changes inside the plan are traced to the plan, not asserted separately.
- AIACT-04AI literacy measures are recorded
Article 4. Measures for staff and others operating the system on your behalf.
- AIACT-05No prohibited practice is engaged
Article 5. A prohibited practice cannot be placed on the market in any form.
- AIACT-27The fundamental rights impact assessment is complete
Article 27. Owed by the deployers the Act names, before first use.
- AIACT-49The EU database registration is recorded
Article 49. Registration before placing on the market or putting into service.
- FIN-01Credit decisioning is governed
The system affecting creditworthiness carries the governance the sector requires.
- FIN-02Model performance is monitored against a threshold
A stated threshold, and the response when it is breached.
- EMP-01Employment decisions carry a bias audit
A current audit of the system used in recruitment or employment decisions.
- EMP-02Candidate notice is recorded
The notice given to affected persons is held as a record.
- IND-01Safety function performance is verified
The safety-related function is verified against its specification.
- IND-02Operational limits are stated
The conditions in which the system may operate are recorded.
- STATE-01The declared state is supported by the record
A system in operation while blockers are open, or while record completeness stands below the floor, is approved against its own record.
Governance gates
Shared across every industry profile.
| Gate | Purpose | Decided by | Rules read |
|---|---|---|---|
| Development authorisation | Authorises development against a stated intended purpose. | Independent Reviewer | STRUCT-01STRUCT-02 |
| Model approval | Approves an immutable AI Model Version for use. | Independent Reviewer | TRACE-01TRACE-02DATA-01DATA-02 |
| System approval for operation | Approves the complete AI System for operation in a market. | Independent Reviewer | STRUCT-01STRUCT-02APPR-01RISK-01RISK-03REV-02CONF-01 |
| Change authorisation | Authorises a change inside the Controlled Evolution boundaries. | Quality and Regulatory | CE-01CE-02CE-03REV-01RISK-01MON-01 |
| Resumption | Resumes operation after restriction or suspension. | Independent Reviewer | MON-01RISK-01REV-01 |
Profile rules
The industry profile adds rules to the shared set and feeds them into the gates.
Medical device and SaMD
Software placed on the market as a medical device, or as part of one. Carries device classification, the UDI family and, where change is planned, a PCCP.
Financial services
Models used in credit, pricing, trading, fraud or capital decisions. Carries independent validation, challenger comparison and fairness testing.
Employment and HR technology
Systems used in recruitment, selection, promotion or termination. High-risk under Annex III, and subject to bias audit and candidate transparency duties.
Industrial and critical infrastructure
Systems that control or supervise physical process, plant or infrastructure. Carries functional safety, declared operational limits and a human oversight plan.