FAQ
Setup & Organisation
How does NADOVO work? What is the compliance journey?
NADOVO guides you through EU AI Act compliance in 5 phases. You work through the phases in order:
Phase 1 — Discover: Capture all AI systems in your company (e.g. ChatGPT, Microsoft Copilot, AI-powered HR tools).
Phase 2 — Define: For each AI system, create one or more AI processes — the concrete use case (intended purpose and scope). Based on this intended purpose, NADOVO automatically determines the risk class (under EU AI Act Annex I and III).
Phase 3 — Assess: Evaluate the risks of your AI processes and plan measures for risk mitigation.
Phase 4 — Implement: Foster and document your employees' AI competence (Art. 4 EU AI Act) and implement the necessary measures.
Phase 5 — Monitor: Capture and report AI incidents when something goes wrong.
Important — the core of the NADOVO approach: It is not the AI system that is classified, but the individual AI process (the use case). The intended purpose determines the risk level — the same AI system can be classified differently depending on the application. This is why EU AI Act compliance in NADOVO starts with the process, not the system.
Tip: You do not have to complete all phases at once. Start with Phase 1 and work your way forward step by step. The dashboard shows your progress at all times.
In what order should I proceed?
The recommended order for getting started:
- Add an AI model ("AI Models" module) — first add the models you use to "My models" (select from the catalog or create a custom model). Important: when creating an AI system you can only choose from models you have already added — you cannot add a model from within the AI system wizard. If the model you need is missing, briefly leave the wizard (your draft is preserved), add it in the "AI Models" module and return.
- Create AI system (Phase 1) — enter your AI system and link the model(s). If the model is not yet known or none is set up, select "Model unknown". The wizard guides you through 5 steps.
- Release AI system — set the status to "In operation".
- Create AI process (Phase 2) — describe the use case (intended purpose and scope). NADOVO classifies the process automatically.
- Release AI process — for high-risk processes, you must first perform an assessment (see below).
- Training & measures (Phase 4) — document your employees' AI competence and implement the measures.
- Document AI content (AI Content Register) — capture AI-generated content as evidence and document review and marking under Art. 50 (see AI Content Register).
Important: An AI process can only be released once the linked AI system has the status "In operation". NADOVO will notify you if anything is missing.
What is the difference between AI system, AI process and assessment?
These three elements form the core of NADOVO:
AI system (Phase 1): This is the technology itself — for example "ChatGPT" or "Microsoft Copilot". Here you capture which AI model you are using, where it is hosted, and who is responsible for it.
AI process (Phase 2): This is the concrete use case of an AI system — for example "Customer support via ChatGPT" or "Application pre-screening with an AI HR tool". An AI system can have multiple processes. Key point: it is the process that is classified, not the system — the same AI system can have different risk levels depending on the use case.
Assessment (Phase 3): This is the risk evaluation for a specific AI process. Here you identify risks, define measures, and document how you keep those risks under control.
Relationship: An AI system has one or more AI processes. Each AI process can have an assessment. The three elements are linked — changes to one element can affect the others.
How do I manage my users and roles?
In the "Organisation" module (visible to company admins), the "User management" tab is where you manage your company's user accounts:
- Add user: you invite by email, first and last name; the person receives an email with a sign-up link. New users automatically get the "User" role. The "Invitation language" field sets the language the email is sent in — prefilled with your own interface language. Resending uses the same language as the original invitation.
- Status: Active, Inactive, Pending (open invitation) or Expired. You can deactivate/activate users and resend or revoke invitations.
- Address already taken: an email address that already has access cannot receive a second invitation — the action stops with a notice. Anyone who does open such an invitation is told to sign in instead, or to use "Forgot password"; the existing access stays untouched.
Deactivating, archiving and why there is no deletion: user accounts have three states:
| State | Meaning |
|---|---|
| Active | Sign-in possible |
| Inactive | Sign-in blocked, can be reactivated at any time — during parental leave, for instance |
| Archived | Closed for good, cannot be reactivated |
Archiving is deliberately a two-step action: deactivate first, then archive; a confirmation dialog spells out the consequences beforehand. Archived accounts are hidden by default — the "Show archived" toggle next to the search brings them back into view with an "Archived" badge and no actions. There is no delete: NADOVO is an evidence product, and approvals, qualifications and responsibilities have to stay attributable to a person. That is exactly why archiving retains all evidence and assignments. If someone returns later, simply invite the same email address again — they get a fresh account, and the old history remains separate and intact.
Roles:
- Company Admin — full access including the Organisation and user management
- User — standard access to the company features
What counts against the user limit: only active users. Deactivating and archiving free the seat immediately — so you can invite a stand-in during parental leave, for example. Reactivating checks whether the limit still has room. Open invitations also reserve a seat, so that no more commitments go out than the plan allows; if an invitation expires or you revoke it, the seat is freed again.
A user is not the same as an employee: a user has a login (an account) and counts against your plan limit. The employees in the AI Literacy module come from a separate directory without a login and do not count against the user limit — the same person can be both, but need not be.
In the "Company" tab you also maintain your company profile and the AI Compliance Officer — the person responsible for EU AI Act compliance. Also select your company's country from the list there: it determines which reporting authority is pre-filled for AI incidents (see AI Incidents).
Why can't I sign in?
The sign-in screen names the reason. Four cases occur:
| Message | Meaning | What to do |
|---|---|---|
| Email address or password is incorrect | One of the two is wrong. For security reasons NADOVO deliberately does not say which — otherwise it could be used to check who has an account | Check your entry; if in doubt use "Forgot password" |
| "Your access has been temporarily deactivated." | Your account is set to "Inactive" — it can be reactivated at any time | Contact your company admin |
| "Your access has been deactivated." | The account is archived, that is, closed for good | Contact your company admin; a new invitation can be sent if needed |
| A notice about too many attempts | After five failed attempts NADOVO temporarily blocks sign-in | Wait about 15 minutes, then try again |
I was signed in and suddenly see a deactivation notice: if your account is deactivated or archived during the session, NADOVO shows this explanation along with a log-out button — even after reloading the page. You are no longer signed out without explanation.
More on the account states under "How do I manage my users and roles?".
Where do I see my plan and my limits?
Right below the heading in the "Organisation" module, an info box shows your current plan and how much of the plan limits you use: the number of users and AI systems, each as "current of max" (or "unlimited" if your plan has no limit).
If a limit no longer suffices, contact your administrator or support for an upgrade. What happens when a limit is reached is covered under "Why can't I create a new AI system?".
Which company profile details matter?
Company admins maintain the company profile in the "Organisation" module on the "Company" tab. Three details have a direct effect in the platform:
- Country (selection list): determines which reporting authority is pre-filled for AI incidents (see AI Incidents).
- AI Compliance Officer: the section for the person responsible for compliance with the EU AI Act. Under "Designated person" you select them as an Internal person (employed by the company) or an External person (a consultant/service provider). Not to be confused with the responsible persons for human oversight (per AI process in the assessment, chosen from the qualification register) or the responsible persons for measures (per task, chosen from the employee directory) — those are different roles.
- Four-eyes principle on release: optional governance setting for the AI Content Register — when enabled, the release approver must be a different person than the creator.
- Company logo: appears on the cover pages of all PDF reports (see its own question below).
Can I put my company logo on the PDF reports?
Yes. Administrators upload the logo in the "Organisation" module → "Company" tab (the "Company logo (reports)" field). It then appears on the cover pages of all PDF reports — qualification proofs, AI content proofs and audit-trail exports — above the NADOVO logo.
- Format: PNG or JPEG, max. 1 MB. NADOVO checks the actual file content, not just the file extension — a renamed or corrupted file is rejected.
- Immediate effect: upload, replace and remove take effect immediately, independently of the company settings' "Save" button. Reports already generated do not pick up a changed logo — regenerate the report.
- Remove: via "Remove" (with confirmation); the reports then use the default cover page again.
Not white-label: the NADOVO branding stays on all reports. Your logo appears additionally above it — as the sender of the document.
Where do I change the language, password or appearance (light/dark)?
The "Settings" module is where you manage your personal preferences — in three tabs:
- Profile: first and last name, editable via "Save changes". Your email address can only be changed by support; your role can only be adjusted by administrators.
- Appearance: choose the theme — Light, Dark or System (follows your operating system setting) — and the language of the application (German/English). This is also where you control whether the welcome overview (the 5-phase summary) is shown on every login.
- Security: change your password — at least 8 characters, with an uppercase letter, a lowercase letter and a number.
Do I have to confirm the theme or language with "Save"? No. Everything in the "Appearance" tab is saved automatically as soon as you switch it. Only the name change in the "Profile" tab needs the "Save changes" button.
These settings only apply to your own account. Company-wide details (team, company profile) are maintained by company admins in the "Organisation" module (see above).
A colleague sees a different theme than I do on the same computer — is that correct?
Yes. Light/dark is stored per user account, not per device or browser. When several people share the same computer, each logged-in person sees their own setting — it is applied automatically on login.
New accounts start with "System": the application then follows your operating system's light/dark setting until you make your own choice under "Settings" → "Appearance".
AI Models
What is the difference between AI models and AI systems?
AI models are the underlying models (e.g. GPT-4, Claude, Gemini) — a library you choose from. In the "AI Models" module you define under "My models" which models are used in your company.
AI systems (Phase 1) are the concrete AI systems you actually deploy and must document under the EU AI Act. An AI system references one or more AI models: when creating it, you select the models used in the "AI selection" step — from the models you have already added — and specify each model's "role in the system" (e.g. classifier, generator).
In short: the AI model is the underlying technology, the AI system is your specific use of it.
How do I add AI models? Can I import my own?
The "AI Models" module has two areas:
- Model catalog: a central library of known models curated by NADOVO. With "Select" you add a model to "My models" (or "Select all from {provider}" for all of a provider's models).
- My models: your selected models, grouped by provider.
Using a model that isn't in the catalog? With "Add custom model" you create a company-specific model (name, provider, version, category, description) — it gets the "Custom model" badge.
No matching model yet? If you don't yet know which model is used — or forgot to add it — you can still create the AI system and select the "unknown" model when linking, then add the specific model later.
Note: There is no file import (e.g. JSON) for end users — the catalog is maintained centrally. So you either select from the catalog or add your own models.
AI Systems (Phase 1)
What do the different AI system statuses mean?
| Status | Meaning | What you can do |
|---|---|---|
| Draft | The system is still being edited | Edit, delete or release |
| In operation | The system is active and released | Deactivate or create new version |
| Out of operation | The system is temporarily not in operation | Reactivate |
| Superseded | The system was replaced by a new version | View only, no further editing |
Why can't I create a new AI system — the button is greyed out?
Every plan includes a maximum number of AI systems. Once you reach it, NADOVO disables the "New AI system" button in the overview. Hovering over it shows your current usage: "Limit reached (X of Y AI systems)".
What to do? Either delete an AI system you no longer need — or contact your administrator to upgrade the plan. You can see how many systems your plan allows and how many are in use in the "Organisation" module.
Careful when going via the Compliance Journey: If you open the form through the "Register AI System" menu item (sidebar, DISCOVER phase), the block does not apply upfront — the menu item stays clickable. You can fill in the entire form and the "Limit reached" message only appears when you save; your entries are not kept. It is therefore best to always create new AI systems from the overview, where you can see the limit in advance.
Applies to users too: The same plan limit exists for the number of user accounts, with the same behaviour in the "Organisation" module. Plans without a cap show no limit. Only active users and open invitations are counted there (see User management).
Why can't I release my AI system?
Because a required detail is missing — and the message tells you which one. Instead of a generic "Release failed", NADOVO names the specific field along with the term it appears under in the wizard, for example: "Release not possible. Missing required fields: Location (hosting locations)" — that is step 3 of the AI system wizard.
Add the detail named, save, and release again.
This applies throughout the app: when an action fails — release, status change, deletion, invitation — NADOVO shows the server's specific reason rather than only the fact that something went wrong.
What happens when I deactivate an AI system?
When you deactivate an AI system, NADOVO automatically updates all linked elements:
- AI processes connected to this system are set to "Paused"
- Assessments connected to these processes receive the status "Review required"
The dialog shows you all affected processes up front with name, ID and risk class — with no options to choose from: all of them are paused. That is not a setting but the necessary consequence, because an AI process may only stay released while its AI system is ready for deployment. The success message names the number of processes and assessments affected. The reverse holds too: because a process is paused solely by its system being taken out of operation, putting the system back into operation fully restores the previous state.
If you want to retire a single process for good, do that in the "AI processes" module via Archive — not through the AI system.
Why? When an AI system is no longer in operation, the associated processes cannot continue to run. The EU AI Act regulation requires you to keep your risk assessments up to date — when something on the system changes, the assessments must be reviewed.
What do you need to do?
- If the deactivation is temporary: reactivate the system later. Doing so releases all paused processes of that system again; the associated assessments remain at "Review required" and must be checked again.
- If the deactivation is permanent: archive the processes and, if applicable, create new ones for a replacement system.
What does "Create new version" mean for an AI system?
When something substantial changes on an AI system — for example a different AI model, new infrastructure, or a new data location — you create a new version instead of overwriting the existing system.
Why a new version instead of just editing? The EU AI Act requires that changes are documented traceably (Art. 12). With versioning, the old state is preserved and the change is verifiable at any time — including for auditors and supervisory authorities.
What happens when you create a new version?
- NADOVO copies all data of the current version into a new draft
- You edit the changed fields in the wizard
- In the last step you see a summary of the changes
- After release, the old version is archived and the new version becomes active. In the AI system's version history the superseded version carries the note "Replaced by version 1.0.1" — while the new version is still a draft it reads "Still in use (will be replaced when version … is approved)"
Where do I find the version history? On the detail page in the "Version history" tab; from the overview, the entry of the same name in the three-dot menu takes you straight there. Each row names the ID and version, the status, date and person — for processes also the approver and the release comment. "View" opens a single version, "Compare" puts two versions side by side (for AI systems and processes).
Looking at an old version? Then a "Superseded version" notice sits at the top with the "Go to current version" button. The breadcrumb navigation above the title ("Overview → ID · Name · version") also takes you back. 5. Linked AI processes are paused and must also be updated
Tip: You do not have to manage version numbers yourself. NADOVO automatically detects what has changed and suggests a suitable version.
AI Processes (Phase 2)
What is a risk class and how is it determined?
The EU AI Act distinguishes four risk levels. In NADOVO the risk class applies to the AI process (the use case), not to the AI system as a whole. Hovering a risk-class badge shows the full designation with its article reference:
| Risk class | Meaning | Examples | Consequence |
|---|---|---|---|
| Unacceptable | Banned AI practices (Art. 5) | Social scoring, manipulative systems | Must not be used |
| High-Risk | High-risk AI in sensitive areas (Art. 6) | Application pre-screening, credit scoring, biometric identification | Strict requirements, mandatory assessment |
| Limited | AI with transparency obligations (Art. 50) | Chatbots, deepfake detection | Transparency requirements |
| Minimal | Low risk | Spam filters, AI-powered search | No special requirements |
Transparency obligations (Art. 50): Regardless of the risk class, transparency obligations apply to AI-generated content (texts, images, chatbots) from 2 August 2026 — you document review and marking in the AI Content Register.
How does NADOVO determine the risk level? Automatically — per process. From your entries (intended purpose and scope), NADOVO recognizes relevant terms and matches them against the official criteria of the EU AI Act regulation (Annex I and III). This immediately produces a classification suggestion — a quick, supporting starting point for your assessment. The expert decision stays with you: you review the suggestion and adjust it if needed.
Can I change the risk level? Yes. If you believe the automatic classification is incorrect, you can override it manually. You can optionally provide a justification, which is documented in the audit trail.
Disclaimer (risk classification): This risk class is an automatically generated suggestion intended to support the assessment. It does not constitute a legally binding classification. The binding classification and the responsibility for it lie with the provider or deployer of the assessed AI system. A professional and legal review of the result is recommended.
Why can't I release my high-risk process?
For AI processes with the risk class "High-Risk" or "Unacceptable", stricter requirements apply. Release is a multi-stage process:
Step 1: Complete the process in the wizard (finish all 5 steps). When you edit it, the wizard opens where you last saved — you don't start over at step 1.
Step 2: Submit the process "For review" — This signals that the process is ready for a risk assessment. The action only appears once you have been through all five wizard steps; before that it reads "Edit" — in the overview as well as on the detail page. If the linked AI system is not ready for deployment, submitting is rejected; the message names the current status and the values allowed for it. (So this surfaces immediately instead of only at release.)
Step 3: Perform the assessment — Go to the "Risk Assessments" area and perform a risk assessment for this process. The assessment includes:
- Identifying risks
- Evaluating likelihood and impact
- Defining measures for risk mitigation
- Creating a Human Oversight Plan
- Carrying out a Fundamental Rights Impact Assessment (FRIA)
Step 4: Approve the assessment — Make sure all mandatory fields are filled in (at least 1 risk, at least 1 measure per risk, Human Oversight Level, all FRIA categories rated).
Step 5: Release the process — Only when the assessment has the status "Approved" can you release the process.
Why so many steps? Art. 9 of the EU AI Act regulation requires that high-risk AI systems undergo a documented risk management process BEFORE they are deployed. The multi-stage release ensures that you can demonstrably meet this requirement.
Processes with low risk (Limited/Minimal): Here a direct release without an assessment is sufficient. NADOVO detects the risk level automatically and adjusts the release process accordingly.
What does the status "Paused" mean for an AI process?
A process is paused automatically when something changes on the linked AI system:
Reason 1 — AI system deactivated: The system was temporarily taken out of operation. As soon as the system is reactivated, you can reactivate the process as well.
Reason 2 — New version of the AI system: A new version of the AI system was released. The old version has been archived, and the process still points to the old version. You need to create a new process version and link the new AI system.
If the process is still a draft, it is simpler: there the AI system field is not locked. When you edit it, NADOVO inserts the current version itself and reports "AI system updated to current version" with the ID and version number; the selection list names the version for every system (e.g. AIS-000004 · Chatbot F (v2.1)). Only for a released process does the field stay locked — there the route is a new process version, so that the basis of the release is not swapped out after the fact.
How do I find out why my process is paused? NADOVO shows you the next step directly in the process overview:
- "Reactivate" — the AI system is in operation again, the process can be reactivated directly
- "Create new version" — the AI system has been superseded by a new version
- "Activate the AI system first" — the AI system is still deactivated
- "New version exists" — a successor version of this process already exists; review and approval happen there
Why can't I click "Activate the AI system first"? This is not a button but a hint: as long as the linked AI system is deactivated, "Reactivate" is not the next step. Activate the AI system first — "Reactivate" then appears as a clickable action.
The state of the AI system at a glance: A marker sits before the name of the linked AI system, in the "AI system" column:
| Marker | Meaning |
|---|---|
| Green dot | "AI system in operation" |
| Red dot | "AI system out of operation" — usually the reason the process is paused |
| "Outdated" tag | The AI system has been superseded by a new version |
The markers describe the AI system, not the process — the process status is in the "Status" column. Hover over a dot to see its meaning.
What happens to my assessment when the process is changed?
When you substantially change an AI process, the associated assessment must be reviewed. NADOVO automatically sets the assessment status to "Review required" in the following cases:
- The risk class has changed (e.g. from "Limited" to "High-Risk")
- The linked AI system has been swapped
- The linked AI system was deactivated — the process is paused and the assessment must be reviewed
What do you need to do? Open the assessment, check whether the risk evaluation is still up to date, and approve it again. If the risk class has changed, you may need to identify additional risks or perform the FRIA.
Note: Assessments still in progress ("In progress") are not changed automatically — they still need to be completed anyway.
If the process is archived, NADOVO archives all assessments of that process too, whatever their previous status. They remain viewable as evidence; editing and approval are no longer possible there. That way no assessment is left in a state it cannot get out of.
Risk Evaluation & Assessment (Phase 3)
What is an assessment and when do I need one?
An assessment is a systematic risk evaluation for an AI process. NADOVO automatically indicates whether an assessment is required:
| Indicator | Meaning | Action |
|---|---|---|
| "Required" | High-risk process — or, regardless of the risk class: the process handles special categories of personal data (Art. 9 GDPR) or personal data hosted outside the EU (Art. 44 ff. GDPR) | Perform and approve the assessment. NADOVO only blocks the process release for high-risk processes though — in the two GDPR cases the assessment is required, but it is not a technical precondition for release |
| "Recommended" | The process handles personal data (hosted inside the EU, without special categories), operates with high autonomy or continuously learns | Assessment is recommended but not mandatory for release |
| "Not required" | Low risk, no special characteristics | No assessment needed |
My assessment shows "Review required" but I cannot edit it — why?
Reviewing an assessment requires the linked AI process to be up to date. If the process is paused, still a draft or archived, the assessment overview shows the non-clickable hint "Update the process first" in the "Next step" column — with the explanation: "Review or approval becomes possible once the linked process has been updated and submitted for review as a new version."
What to do? First create a new version of the process (typically after updating the AI system) and submit it for review. The assessment then becomes editable again.
The "Next step" column tells you what is due in every situation:
| Display | Meaning |
|---|---|
| "Continue" | The assessment is in progress — the wizard opens |
| "Start review" | The assessment needs to be reviewed |
| "Update the process first" | A hint, not a button — the process is blocking the review |
| "Approve" | The assessment is complete and can be approved |
| "Approve process" | The assessment is approved — the process approval is missing |
| "Conformity documented" | Process and risk assessment are approved, all documentation steps are done |
For archived assessments the column stays empty — the status is enough there.
The notice banner on the assessment detail page names the state of the process:
| Process | Notice title | What applies |
|---|---|---|
| suspended | "Process suspended" | Once it is approved again, you can continue working |
| archived | "Process archived" | The assessment can only be viewed |
| superseded | "Process version superseded" | Continue with the assessment of the current process version |
So archived assessments can still be opened and read as evidence. The hint "Update the process first" appears only for a suspended process — for an archived one there is nothing left to update.
Deleting is possible only for assessments with the status "In progress" and is reserved for company admins; whether the linked process is suspended makes no difference. Completed, approved and archived assessments are retained as evidence.
About "Conformity documented": The completion badge also appears in the process overview, likewise for approved processes with no assessment obligation (evaluation "Not required") — their documentation is complete once the process is approved — and in the AI Content Register for released entries. It confirms only that the documentation steps in NADOVO are finished, and does not replace legal advice.
What must be included in an assessment for high-risk processes?
The EU AI Act sets clear requirements for risk management of high-risk AI. NADOVO guides you through the assessment in 6 steps:
Step 1 — Select process: Choose the AI process for which you want to perform the assessment. The process context shown also names the process owner — the same detail appears in the closing summary.
Step 2 — Prohibited practices check (Art. 5): Check whether your AI use falls under one of the eight prohibited practices in Art. 5 of the EU AI Act. For high-risk processes you answer all eight individually (see also the next question).
Step 3 — Identify risks: Capture all relevant risks for your AI use (e.g. discrimination, data protection breach, faulty decisions).
Step 4 — Evaluation and measures: Evaluate each risk by likelihood and impact. Define at least one mitigation measure for each risk.
Step 5 — Human Oversight and FRIA:
- Human Oversight: Set the oversight level (human-in-the-loop / on-the-loop / in-command, Art. 14) and name a responsible person — optionally also a deputy. Only employees with a completed qualification documented in the AI Literacy module can be selected (so the competence of the oversight person required by Art. 26(2) is structurally evidenced). For high-risk processes the responsible person is mandatory. Use the "Notes" field for execution details (e.g. escalation path, how to act on anomalies).
- FRIA (Fundamental Rights Impact Assessment): Evaluate the impact on fundamental rights across 6 categories.
Step 6 — Summary: Review the overall evaluation and accept the residual risk. "Complete Assessment" ends the wizard. Approval is a separate step and happens afterwards via the overview or the detail page — the "Next step" column offers it there. Capturing and approving are deliberately two distinct actions.
Mandatory fields for approval:
- At least 1 risk identified
- For each risk, at least 1 measure defined
- Human Oversight Level set
- All 6 FRIA categories rated
Do I have to complete the whole assessment for a process that is not high-risk?
No. Below high-risk, the EU AI Act requires neither an individual check of the prohibited practices nor a risk assessment — so NADOVO takes you through the same six steps in a shorter form:
- Step 2 (prohibited practices) is already filled in and read-only. A note explains: "Already checked during classification" — the eight practices under Art. 5 were evaluated during the AI process's risk classification, and none apply. You go straight to "Next".
- Step 3 (identify risks) is optional: "Capturing risks is optional here". You can move on without an entry. Adding one still makes sense if you want to document something — for example regarding data protection where personal data is processed.
- Step 4 reports "No risks captured — that is fine" when the list is empty and offers the way back to step 3 without demanding it.
For high-risk processes both stay mandatory: the eight practices are asked individually, and without at least one evaluated risk with a measure you cannot continue.
Two details: Answers you have already recorded are never overwritten — if you filled in step 2 manually, your input stays. And if a process is later reclassified as high-risk, step 2 asks for the eight answers again; results taken over automatically no longer count.
Why can't I select a responsible person for human oversight in the assessment?
Only employees with a documented, completed qualification (Art. 4 EU AI Act) can be selected. First create a qualification in the AI Literacy module — internal measure, external proof or experience assessment — and complete it. The person then appears in the selection for the responsible person and the deputy.
If there is no qualified employee yet, Step 5 shows a corresponding hint. This is how NADOVO ensures the oversight person demonstrably has the competence required by Art. 26(2). (This does not apply to measure owners in the "Measures" module — no qualification is needed there.)
What does "Review required" mean for an assessment?
This status means that something has changed in the context and you need to check whether your risk evaluation is still current.
Possible triggers:
- The linked AI system was deactivated (the process is paused)
- The linked AI system was swapped
- The risk class of the process has changed
What do you need to do?
- Open the assessment
- Check whether the identified risks and measures still apply
- Adjust the evaluation if needed
- Approve the assessment again
The review starts at step 1, not at the end: because the context has changed, the Art. 5 check and the evaluations have to be confirmed in the new context — so you go through the wizard again from the beginning.
Versioning
Why are there versions, and what do the numbers mean?
NADOVO uses version numbers (e.g. 1.0.0, 1.1.0, 2.0.0) to document changes to AI systems and AI processes traceably. This matters because the EU AI Act requires changes to AI systems to be documented and retained for at least 10 years (Art. 12).
You do not need to worry about the version numbers. NADOVO automatically detects what has changed and suggests a suitable version number. You can simply accept the suggestion.
If you're curious — here's how the logic works:
| Change | Example | Version number |
|---|---|---|
| Substantial change | Different AI model, different role, different infrastructure | 1.0.0 → 2.0.0 |
| Minor change | New responsible person, updated description | 1.0.0 → 1.1.0 |
| Minimal change | Correction in the name, notes updated | 1.0.0 → 1.0.1 |
Can I still edit a released AI system or process?
No — and that is by design. A released element represents a reviewed and documented state. If you want to make changes, create a new version:
- Click "Create new version" in the action menu
- NADOVO creates a copy as a draft
- Edit the desired fields
- In the last wizard step you see a summary of the changes
- Release the new version
The old version is archived automatically. All changes are documented in the audit trail.
Why can't I just overwrite? If an auditor or supervisory authority wants to trace how your AI system was configured 2 years ago, the old state must be available. Versioning makes that possible at any time.
Phase 4 — AI Literacy & Measures
Is training mandatory? What does the EU AI Act require?
A specific training course is not legally required. Article 4 of the EU AI Act expects companies to foster their employees' AI competence ("AI literacy") — the 2026 Digital Omnibus amendment softened the originally stricter wording ("ensure a sufficient level of AI competence"). So it is about demonstrably fostered competence, not a mandatory training.
In NADOVO you document this competence in the "AI Literacy" module (IMPLEMENT phase) — an evidence register under Art. 4. You record qualifications via three equivalent routes (internal measure, external proof or experience assessment); the AI Act prescribes no particular format — neither certificates nor exams. What matters is that you can evidence the competence — from 2 August 2026 supervisory authorities can request proof.
What you should do:
- Foster the AI competence of everyone who works with AI systems — e.g. via training, briefings or guidelines
- Document this in the "AI Literacy" module
- Evidence it, depending on the route, through the entry itself, an uploaded document or a substantiated assessment
How do I manage my employees' AI competence?
You document and evidence your employees' AI competence in the "AI Literacy" module. Each entry is a qualification and is recorded via one of three equivalent routes — the input fields adapt to the chosen qualification type:
- Internal Measure — a training, briefing or e-learning your company conducts itself. The entry is the evidence; optionally with a format (e.g. in-person, online). Can be planned and marked completed afterwards.
- External Proof — a document issued by a third party (certificate, attestation, degree). Applies to exactly one employee, and the proof file is mandatory — it is the evidence. Counts as completed immediately.
- Experience Assessment — a qualified person in your company assesses the competence from practical work, with a function and a reason (self-assessment is not possible). Counts as completed immediately.
Attaching a document: You can upload a file with every entry — PDF, PNG, JPG or WebP, max. 5 MB (mandatory for an external proof, optional otherwise). NADOVO checks the actual file content, not just the file extension: a renamed or corrupted file is rejected with a message and not stored — upload the original file in that case, or export it again. Entry and document are created together: if the file is rejected, no entry is created either.
Employees without a user account: the people in this module come from a separate employee directory and do not need a NADOVO account. When recording, you type the name — already-added employees are suggested, new ones you create with first and last name directly in the dialog.
Status: "Planned" and "Completed" follow from how you record the entry; "Overdue" is calculated automatically when the date of a planned internal measure has passed. Completed entries can additionally be archived (status "Archived" — see its own question below).
Overview, completing and editing: the overview has a filter row — search plus the Qualification, Type, Employee and Status filters — and sortable columns. A paperclip icon next to the title shows that an entry has a document attached; clicking it opens the document directly in the preview ("Open document"). The actions are available via the menu at the end of the row. Administrators complete a planned internal measure via the action menu with "Quick complete": there you choose which employees attended; anyone missing can optionally be removed from the entry (if people remain open, the entry stays "Planned"). Without administrator rights you instead mark participants individually in the detail dialog (the "Participants" tab). The employees of an entry can also be edited there afterwards. You can reuse an existing entry as a template.
What is an experience assessment?
When a person is demonstrably competent without a training course or certificate (e.g. years of practical work with AI systems), a qualified person in your company — such as a manager or the compliance lead — can assess that competence. You provide the function of the assessing person and a reason; this makes the assessment robust towards authorities. Self-assessment is not possible — the assessing and the assessed person must be different.
Why is my external proof immediately "Completed"?
External proofs and experience assessments document an already existing qualification — there is nothing left to carry out. Their date (issue or assessment date) therefore cannot lie in the future. Only the internal measure has a "Planned" state, because it still has to take place.
How do I create a proof (PDF) of AI competence?
Two ways — both produce a PDF under Art. 4:
- Single entry: for a completed qualification, via the action menu "Report (PDF)" — with all the entry's details, the participating employees and the audit trail.
- Overall proof: via the "Qualification proof (PDF)" entry in the three-dot menu at the top right of the overview (administrators only, and only when the list is not empty). Beforehand you choose the scope — all or selected employees; the chosen scope is stated in the PDF. The report lists the records per employee with their respective status ("Completed on …" / "Open"). It covers only active entries — archived ones are not included (use the single-entry report for those).
This lets you evidence AI competence to an authority, customer or auditor in one place.
Can I delete or archive a completed qualification?
Delete: no. Completed qualifications are compliance evidence under Art. 4 EU AI Act — to keep your register complete, they cannot be deleted, only archived. Planned entries (not yet carried out) can be deleted by administrators.
Archiving (administrators only, via the action menu or the detail dialog):
- A confirmation dialog points out that the action cannot be undone — there is no restore. So check the entry for completeness beforehand.
- An archived entry is read-only: it can no longer be edited, completed or deleted.
- The single proof (PDF) is available; archived entries are not included in the overall proof.
Where do I find archived qualifications? They are hidden in the overview by default — select "Archived" in the status filter to show them.
How do I document risk-mitigation measures (Phase 4)?
In the "Measures" module you track the risk-mitigation measures — i.e. implementing the measures defined in the assessment (Phase 3).
- Origin: measures are derived automatically from risk assessments or created manually ("New task"). Measures derived from assessments are linked to the corresponding risk and process; manually created tasks are not linked to any process.
- Fields: title, type (technical, organizational, human oversight), description, responsible person, due date.
- Responsible person: chosen from the employee directory (maintained in the AI Literacy module) — the person needs no user account of their own and no documented qualification (unlike human oversight in the assessment). The field is optional.
- Status: each measure moves through Planned → Active → Completed. "Active" covers both — currently being introduced and running continuously (e.g. a measure that applies as long as the process is active). You change the status via the action menu (⋮) — for manual and assessment measures; every change is recorded in the audit trail.
- Overview: sortable columns (default: nearest due date on top, overdue in red) and multi-select filters (measure, process, responsible, due date, status). The measure type is shown in the detail dialog and the export.
- Archive instead of delete: completed measures can be archived by administrators (final, read-only); after that they cannot be deleted. Planned and active measures remain deletable. Archived measures are hidden by default — select "Archived" in the status filter to show them.
- Export: measures can be exported as CSV/JSON or to tools such as Trello, Teams Planner or Jira.
AI Incidents (Phase 5)
What is an AI incident and when do I have to report it?
An AI incident is an event in which an AI system leads to harm or malfunction — for example discriminatory decisions, data protection breaches, or faulty outcomes with real-world effects.
Reporting deadlines under EU AI Act (Art. 73) — each from discovery of the AI incident:
| Severity | Reporting deadline | Example |
|---|---|---|
| Critical | 2 days | AI system causes significant harm to health or safety |
| Serious | 15 days | AI system systematically makes discriminatory decisions |
| Minor | No reporting obligation | Isolated error without larger effects |
NADOVO shows the remaining reporting deadline as a color-coded indicator so you don't miss a deadline.
How do I report an AI incident to the authority?
For reportable AI incidents (serious/critical), NADOVO supports you with the reporting workflow in the AI incident detail:
- Responsible authority pre-filled: based on your company's country, NADOVO automatically suggests the responsible market surveillance authority (e.g. the Bundesnetzagentur for Germany) — with name, website, reporting portal, email, phone and, where applicable, a note. Prerequisite: the country is selected from the list in the "Organisation" module ("Company" tab) — if it is missing, the AI incident report points this out and links directly to the settings.
- The place of the AI incident is decisive (Art. 73): the pre-fill follows the company's registered office as a practical starting point. What matters, however, is the authority of the member state where the AI incident occurred — which is why the "Authority / Recipient" field can be freely overwritten (see the next question).
- Prepare the report: choose a reporting method (e.g. email, reporting portal, phone) — the authority's contact details are filled in accordingly. You can copy the prepared notification text or open it as an .eml file; you record the authority's case number in the AI incident.
- Report first, then resolve: a reportable AI incident (serious/critical) must be reported before it can be resolved — the "Resolution" tab is locked until then.
- Optional "Provider informed on": in addition to the authority, you can record when you informed the provider of the AI system (Art. 26(5)).
AI incidents with the "Minor" severity generally have no reporting obligation.
What statuses does an AI incident have — and how do I close it?
An AI incident moves through a simple model: New → Resolved → Archived, plus Cancelled for an abort.
Reporting is a marker, not a status. Once the authority has been notified, the deadline column shows "Authority notified" instead of the countdown (the notification date appears on hover). The AI incident stays in the "New" status until you resolve it.
How to close an AI incident:
- Resolve: in the "Resolution" tab you choose "With measures" (root cause plus corrective and preventive actions) or "Without measures" (e.g. a false alarm — with a mandatory reason). For reportable AI incidents this is only possible after reporting (see the previous question).
- Archive: resolved AI incidents can be archived. They then disappear from the default overview but remain reachable via the "Archived" status filter.
How do I delete an AI incident? You can't — AI incidents are evidence and cannot be deleted. Instead of deleting, you cancel an AI incident that has not yet been reported and is unresolved (with a mandatory reason). It receives the "Cancelled" status, is retained as a record, and the action is documented in the audit trail.
Where does the authority data come from — and can I change the suggested authority?
The authority data (name, website, reporting portal, email, phone) comes from a directory of market surveillance authorities per country maintained centrally by NADOVO. It is continuously updated — treat the pre-fill as a vetted starting point, not as conclusive legal advice. If there is no dedicated entry for your country (yet), NADOVO shows an EU fallback ("national market surveillance authority") — so reporting is never blocked, and you can add the recipient manually.
Change it? Yes. The "Authority / Recipient" field can be freely overwritten — important when the AI incident occurred in a different member state than your registered office (Art. 73).
Good to know: the recipient saved with a report is a snapshot. Later updates to the directory do not change reports that have already been documented.
AI Content Register
What is the AI Content Register and why do I need it?
From 2 August 2026, the transparency obligations of Art. 50 EU AI Act apply: AI-generated content must be marked under certain conditions — and anyone relying on an exemption must be able to prove it if challenged.
The AI Content Register (its own item in the main navigation) is where you capture every relevant AI-generated piece of content as audit-proof evidence — linked to the generating AI process, reviewed by a human, documented in the immutable audit trail (10 years).
Depending on the content type, an entry serves one of two purposes:
- Review evidence (text only): AI-generated texts on matters of public interest must be marked — unless a human has reviewed them and takes editorial responsibility (Art. 50(4)). The register entry proves exactly that: who reviewed, when, and who is accountable.
- Marking evidence (image, audio, video, dialogue): Here the entry documents that and how you fulfilled the marking obligation — or why an exemption applies.
Important: The register is precautionary evidence — there is no legal obligation to keep such a register. But when an authority, competitor or customer asks "Is this AI? And where does it say you reviewed it?", you have the proof at the click of a button.
When does AI content have to be marked — and when not?
That depends on the content type. The release dialog ("Review & release") guides you through the decision per type and explains the legal situation at the moment of the decision:
Text: First the classification: does the text inform the public about a matter of public interest? If "No" (e.g. product copy, internal memo), there is no marking obligation — your classification is documented as evidence. If "Yes": with confirmed content review and editorial responsibility taken, the review exemption under Art. 50(4) applies — no marking needed, the entry is your proof. Without human review, marking is mandatory.
Image / audio / video: The deepfake question: could the content appear real to viewers (persons, places or events depicted realistically)? Yes → marking is mandatory (label text and placement are documented). No (obviously artificial) → no marking obligation, the choice is documented.
Dialogue (chatbots, voice/phone assistants): must generally be marked — users or callers must recognise they are interacting with an AI (Art. 50(1)). Exception only where the AI use is obvious.
Where marking is required, you must confirm before release: "The marking is applied to the content." This confirmation is logged as its own audit-trail event — the evidence that marking actually happened.
Note: Violations of Art. 50 carry fines (up to EUR 15 million or 3% of global turnover). The register does not take the marking obligation off your hands — it documents your decisions so you can prove them at any time.
How do I create an AI content entry?
Via "New AI content entry" in the AI Content Register. Three required fields are enough: content type (text, image, audio, video or dialogue), title and the generating AI process. Everything else is optional: type of use (fully AI-generated, AI-assisted, AI-edited), reference (URL or storage location — can be added until release) and notes.
Two ways:
- Manually: fill in the form — always available.
- Metadata upload (JSON): paste the metadata block returned by your AI tool or drop it as a file — the fields fill in automatically (see the next question).
The entry is saved as a draft. Review, release and marking are deliberately not part of capture — they happen together via "Review & release" in the list.
AI process not inventoried yet? Then select the option "AI process not inventoried". The entry documents this fact, the release is not blocked — and via the process filter such inventory gaps stay visible, so you keep track of which processes you should still inventory in Phases 1 and 2.
What is the metadata prompt and how does the JSON upload work?
The fastest way into the register — tool-independent, without a plugin or API connection:
- Copy the prompt: In the capture dialog, select the AI process under "Metadata prompt" and click "Copy prompt".
- Append it to the generation: Attach the prompt to your request in the AI tool (e.g. ChatGPT, Claude, Copilot) — the tool returns the content plus a structured metadata block (JSON).
- Upload: Drag the JSON block into the capture dialog, paste it, or choose the file — the fields fill in automatically. Validation is rule-based; if something is wrong you get a specific list of errors.
Important — the review stays human: The upload only fills in the capture data (content and AI use); uploaded details are marked as "self-declared" by the AI tool. Review, classification, editorial responsibility and marking arise exclusively through your action in the platform — no AI evaluates anything automatically here. That is exactly what makes the evidence credible.
Can I change or delete a released AI content entry?
No — and that is by design. An entry moves through the lifecycle Draft → Released → Archived. On release it becomes an immutable evidence snapshot; the reference (URL/storage location) is also fixed at that point — release is the last chance to add or correct it.
If the content changes: Use "Duplicate". NADOVO creates a new draft with the capture data — classification, review, marking and release are deliberately not carried over; each version goes through its own release process. With the option "Replaces the original", the original entry is automatically archived when the new one is released ("superseded by") — without a gap in the chain of evidence.
Deleting: Released and archived entries cannot be deleted (only archived) — they are evidence. Company admins can delete drafts; this too is logged in the audit trail.
What if the linked AI process changes? If the process is archived or a newer version exists, the entry shows an info badge — the released entry stays valid as a snapshot; there is no retroactive effect.
What is the four-eyes principle on release?
Optionally, you can require that the release approver is a different person than the creator of the entry. Company admins enable the setting "Four-eyes principle on release" in the "Organisation" module on the "Company" tab.
Default: off — small teams are not slowed down. Enable the principle if your internal governance requires a separate review or you want to further harden the evidence.
How do I prove, if challenged, that content was reviewed and marked?
In two ways:
Audit trail (10 years): Every relevant event — capture, JSON upload (self-declared), editing, release, marking confirmation, reference change, duplication, archiving — is logged immutably with person and timestamp.
AI Content Evidence Report (PDF): For every released or archived entry, the action menu ("Report (PDF)") generates a password-protected PDF report (AES-256) with the entry data and the audit-trail excerpt — ideal for providing clean proof to an authority, customer or auditor. For the whole register, the "Full register proof (PDF)" entry in the three-dot menu at the top right of the overview produces a report over all entries with an overview by status and marking.
Thanks to the link to the AI process, a single document can prove: which system generated the content, in which use case, and who reviewed it.
Audit Trail & Documentation
What does NADOVO document automatically?
NADOVO automatically logs all changes to your AI systems, processes, assessments, training, AI incidents, and AI content entries. You don't have to document anything manually.
What is recorded:
- Who changed what, and when
- Which fields were changed (old and new value)
- Releases and approvals
- Status changes (including automatic ones, e.g. through cascading)
- Risk classifications and changes to them
Retention: 10 years, as required by EU AI Act Art. 12.
Export: You can export the audit trail as PDF (read-only), CSV or JSON at any time.
Where do I find the audit trail?
You find the audit trail directly on each element — there is no separate audit module. Open an AI system, a process, an assessment, a training or an AI incident and choose "Audit trail" from the three-dot menu at the top right. All the other actions of the detail page live there too (edit, release, status changes, delete) — the title row stays clear. The dialog shows the full change history (who, what, when; old and new value) and can be exported as PDF (read-only), CSV or JSON.
From the overview as well — via the same three-dot menu, sitting at the far right behind the main action. Six modules have it: AI System Inventory, AI Processes, Risk Assessments, AI Incidents, AI Literacy and the AI Content Register. In the last two, the same menu also holds the respective register proof. Measures are the only module without an audit trail — neither in the overview nor as a choice in the change report.
Note: The "Audit trail" entry is only visible to company admins. The three-dot menu appears at all only when there are actions available for the current status and role.
As a PDF this becomes the change report — see Reports & Evidence.
Reports & Evidence
Where do I find my reports again?
The "Reports & Evidence" menu item (at the top of the navigation, administrators only) gathers all reports in one place: change report, AI content proof and qualification proof. Before generating, you see how many entries the report will cover.
The log is not a download archive. The page records which report was generated when and by whom — number, type, subject, time and person. The documents themselves are not stored: save a generated PDF wherever you want to keep it. You can generate it again at any time, which produces a new report number.
Do I have to generate reports through this module? No. The entry points in the specialist modules remain, and both routes produce the same document. The only difference is context: in the specialist module the subject is already set, in the reports module you choose it in the dialog.
Why don't I see the menu item? Only users with the administrator role may generate reports and view the audit trail.
What is in the change report (audit trail)?
The change report is the PDF version of the audit trail — the full change history of an element with person, time, and old and new value.
- Report number: every report carries a number in the form
CHG-PROC-000021— on the cover page, in every page header and in the end marker. That makes it citable towards an authority or auditor. - Always complete: the report contains all entries of the chosen selection, not just the ones currently on screen. Page 2 states this explicitly as "all N of N".
- Narrow it down via object and period: the search in the dialog is only a screen aid and does not shrink the report. The object list names ID and label, with the most recent entry on top; long labels are truncated and shown in full when you hover over them.
- Six modules are available: AI System Inventory, AI Processes, Risk Assessments, AI Incidents, AI Literacy and the AI Content Register. Measures are missing because that module keeps no audit trail.
Besides PDF, CSV and JSON are available.
What are the downloaded files called?
All reports and exports follow the same pattern: a name, the ID for single-entry reports, then date and time.
qualification-proof-TRN-000012-2026-07-30-1042.pdfWhich name a download carries:
| Download | File name starts with |
|---|---|
| Change report (audit trail) | audit-trail- plus the module, e.g. audit-trail-process, audit-trail-asset, audit-trail-ai-content |
| Qualification proof, single / register | qualification-proof- / qualification-register- |
| AI content proof, single / register | ai-content-proof- / ai-content-register- |
| Measure export | measures-, and for the tool formats measures-trello-, measures-planner-, measures-jira- |
The change report's file is still called audit-trail-… — the report title inside the PDF reads "Change report (audit trail)", the file name is independent of it.
Thanks to the timestamp, two exports of the same data never overwrite each other and stay clearly identifiable in your file storage. The identifiers are deliberately English and independent of your interface language — so the same report is named identically for everyone in a shared folder.
Can I put my company logo on the reports?
Yes — see company logo on the PDF reports in the Setup & Organisation section. The logo appears on the cover pages of all PDF reports, above the NADOVO logo.
Relationships & Automations
Why do status values change automatically?
NADOVO ensures that your compliance documentation stays consistent. When something changes on an AI system, the linked processes and assessments must be reviewed — this is a requirement of the EU AI Act (Art. 9, Risk Management).
Overview of automatic status changes:
| What you do | What NADOVO does automatically | Why |
|---|---|---|
| Deactivate AI system | Processes → Paused, Assessments → Review required | System no longer in operation, processes cannot continue |
| Archive process | All assessments of the process → Archived | The process is at the end of its lifecycle; the evaluations stay viewable as evidence |
| Reactivate AI system | All paused processes → Released again | System is in operation again |
| Release new version of AI system | Old processes → Paused | Old system was replaced, processes must be moved to the new version |
| Risk class of a process changes | Assessment → Review required | Risk evaluation was based on the old risk class |
| Link a new AI system in the process | Assessment → Review required | Risk evaluation was based on the old system |
Rule of thumb: When NADOVO changes a status automatically, the platform shows you the next step directly in the overview. Just follow the hints.
How do I filter the overviews — and why don't I see archived entries?
The overviews for AI systems, AI processes, Risk Assessments, the AI Content Register, the AI incidents, AI Literacy and the measures share the same filter bar. All filters start empty so their labels stay readable; only your selection narrows the list. The order of the filters mirrors the overview's columns.
The "Next step" filter (AI systems, AI processes, Risk Assessments, AI Content Register) turns the overview into a work queue: you filter by what is actually due — such as "Edit", "Submit", "Approve", "Start review", "Review & release" in the content register, or "Conformity documented". The options adapt dynamically: only steps that actually occur in your list are offered. The AI incident overview has a "Reporting obligation" filter instead (Reported / Required / None); AI Literacy filters by Type, Employee and Status; the measures by Process, Responsible, Due date and Status.
Waiting hints are deliberately not filter values. States such as "Update the process first", "Activate the AI system first" or "New version exists" appear in the column but cannot be filtered — they describe waiting on something else, not a step you can work through.
Why are archived entries missing? With no selection in the status filter, the overview shows everything except the respective end state:
| Overview | Hidden by default | How to show them |
|---|---|---|
| AI processes | "Archived" | Select "Archived" in the status filter |
| Risk Assessments | "Archived" | Select "Archived" in the status filter |
| AI Content Register | "Archived" | Select "Archived" in the status filter |
| AI systems | "Superseded" | Select "Superseded" in the status filter |
| AI incidents | "Cancelled" and "Archived" | Select the respective value in the status filter |
| AI Literacy | "Archived" | Select "Archived" in the status filter |
| Measures | "Archived" | Select "Archived" in the status filter |
Deactivated AI systems, by contrast, are visible by default — they are not an end state but await a decision. Likewise resolved AI incidents stay visible by default; only "Cancelled" and "Archived" are hidden.
In what order are entries shown — and can I sort them myself?
Default order: without your own sorting, the most recently created entries appear at the top — usually by creation date, in the "AI Literacy" module by the date of the qualification, and for AI incidents by the discovery date.
Sort them yourself: click a column header to sort by that column; a second click reverses the direction. An arrow icon next to the header shows the active sort.
Computed columns such as "Next step", "Reporting obligation", "Deadline" or "Models", as well as the actions column, cannot be sorted.
Adjusting the column width: In all seven overviews the name column can be made wider or narrower. Hover over the column divider to the right of the heading — a double-line symbol appears and the cursor turns into a double arrow — then drag. A double-click on it fits the column to the longest entry automatically. The width you set is remembered per overview on this device.
Note for the Risk Assessments: for a new version of an assessment, the order counts the creation date of the new version — which is why an assessment with an older ID can appear at the top. Use the "Assessment ID" column header to sort by ID instead.
How do AI system, process and assessment relate to each other?
The three elements are linked hierarchically:
AI system (e.g. "ChatGPT")
|
|-- In operation, v1.2.0
|
+-- AI process (e.g. "Customer support")
| |
| |-- Released, v1.0.0
| |
| +-- Assessment (risk evaluation)
| |-- Approved
|
+-- AI process (e.g. "Content creation")
|
|-- Draft, v1.0.0Rule: An AI system must be "In operation" before linked processes can be released. For high-risk processes, an assessment must additionally be approved before the process can be released.
Changes flow top-down: When the AI system changes, processes and assessments are updated automatically. The reverse is not true — a change to the assessment has no impact on the AI system.
Help & Support
What are "Known issues" and where do I find them?
Under Help & Support, the "Documentation" section shows four tiles: Getting started, Modules, FAQ and "Known issues" (slightly highlighted in red). Clicking "Known issues" opens a window listing all currently known problems — each entry with a title, the affected area, a date, a short description, a status and, where available, a workaround.
We maintain this list so you can immediately see whether a behaviour is already known and being worked on — no need to report it separately.
What do the statuses mean?
- In analysis — we're currently analysing the cause; no workaround yet.
- Workaround — a workaround is available that you can use until the fix is released (see the entry).
- Once an issue is resolved, the entry disappears from the list.
My problem is listed — what should I do? Nothing further — we know about it and are working on it. If a workaround is shown, you can use it until the fix is released. No need to report it again.
My problem is NOT listed? Please report it via Help & Support → "Report bug" so we can look into it.
Note: If the list is empty, you'll see "There are no known issues at the moment." — nothing is currently known.
How do I send feedback or a suggestion?
On the Help & Support page, below the documentation tiles, there are two tabs: "Feedback" (selected by default) and "Report bug". For ideas, requests and suggestions, use the "Feedback" tab.
How to fill in the form:
- Category (required) — Improvement suggestion, New feature, Usability or Other.
- Subject (required) — a short headline (at least 3 characters).
- Description (required) — what we should improve, as precisely as possible (at least 10 characters).
- Affected module (optional) — e.g. Discover, Assess, Implement, Monitor, Dashboard or Settings.
- Priority — Low, Medium (default) or High.
- Screenshot (optional) — PNG, JPG or WebP, max. 5 MB.
Click "Send feedback" and your message goes straight to our team; a short confirmation appears. "Cancel" clears the form again.
How do I report a bug?
If something doesn't work as expected, first check the "Known issues" (see above) — if your problem is already listed, we're aware of it. Otherwise, report it on the Help & Support page via the "Report bug" tab.
How to fill in the form:
- Error category (required) — Display error, Functional error, Data loss, Performance or Other.
- Subject (required) — a short headline (at least 3 characters).
- Steps to reproduce (required) — what you did, step by step (at least 10 characters).
- Expected behavior (optional) — what should have happened instead.
- Affected module (required) — which area the error occurs in.
- Severity (required) — Cosmetic, Functional (default) or Critical.
- Screenshot / Screen recording (optional) — PNG, JPG or WebP, max. 5 MB.
- Browser / Device (optional) — e.g. "Chrome 120, macOS".
Click "Report bug" to send the report to our team; a short confirmation appears. The more precise the steps and screenshot, the faster we can reproduce and fix the issue.
As of July 2026
