Delegation of Authority Matrix Validator
Regime

EU AI Act: what it asks of an approval matrix

For a company with EU or UK operations: the human oversight and deployer duties that apply when an AI system acts in a decision, and the right to an explanation.

Quoted when the company has EU or UK operations.

Named, not quoted, beside it: the UK Corporate Governance Code provision on risk management and internal control.

EU AI Act: every clause cited, quoted

4 of the 43 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

EU AI Act Art. 12 Record-keeping (logs)

High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system, ensuring a level of traceability appropriate to the intended purpose; logging capabilities for biometric remote-identification AI systems include the period of each use, the reference database against which input data has been checked, the input data for which the search led to a match, and the natural persons involved in the verification.

What an auditor asks to see: Logging capability design evidence; Log-retention policy aligned with the intended purpose
Where matrices usually fall short: Insufficient logging to reconstruct system operation; Logs not retained over the system lifetime
Source: EU AI Act
EU AI Act Art. 14 Human oversight

High-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of automation bias, correctly interpret the output, decide not to use the output or override or reverse it, intervene in operation, and stop the system.

What an auditor asks to see: Human-oversight design (UI, controls, alerts); Oversight-personnel training and authority
Where matrices usually fall short: Oversight is nominal (e.g. cannot stop the system in practice); No training for oversight personnel
Source: EU AI Act
EU AI Act Art. 26 Obligations of deployers of high-risk AI systems

Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for at least 6 months (longer where required); inform workers/representatives where used in the workplace; carry out a DPIA where required under GDPR; and where a deployer is a public authority, register the system in the EU database.

What an auditor asks to see: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable; Workforce information for workplace deployment
Where matrices usually fall short: Deployer not following IFU; No human-oversight assignment; Logs deleted before 6 months
Source: EU AI Act
EU AI Act Art. 86 Right to explanation of individual decision-making

A deployer must, at the request of an affected person who has been subject to a decision the deployer took on the basis of the output of an Annex III high-risk AI system other than one listed under Annex III point 2, and which produces legal effects or similarly significantly affects that person in a way they consider to have an adverse impact on their health, safety or fundamental rights, provide clear and meaningful explanations of the role of the AI system in the decision-making procedure and of the main elements of the decision taken. The duty does not apply where Union or national law provides an exception or restriction, and applies only to the extent the right is not otherwise provided for under Union law.

What an auditor asks to see: A documented procedure for receiving and answering explanation requests, with an owner and a response time; Explanation templates per decision type, covering both the role of the AI system in the procedure and the main elements of the decision; A register of requests received and the explanations given; An analysis of which deployed systems fall within Art.86, including which decisions produce legal or similarly significant effects; The recorded assessment of any Union or national law exception relied on, and of any overlap with a right already provided elsewhere in Union law
Where matrices usually fall short: No inbound channel at all, so the right exists on paper and cannot be exercised; An explanation of how the model works in general, rather than the role it played in this decision and the main elements of that decision; The duty assumed to sit with the provider, when Art.86 addresses the deployer; A data protection access response reused unchanged, which answers a different question and omits the role of the system in the decision procedure
Source: EU AI Act