AI governance & evidence intelligence
AI governance you can put in front of an auditor.
Bring AI systems, applicable obligations and supporting evidence into one governed record. E-ARI helps governance, risk and compliance teams see what applies, what is evidenced and what needs attention.
Northstar Applicant Screener
highRecruitment · deployer
Rank job applicants for recruitment shortlisting.
Employment, workers management and access to self-employment
Matched phrase: “recruitment”
Confirm applicability: inspect the open questions
- Does an Article 6(3) derogation apply — narrow procedural task, improving a completed human activity, detecting patterns without replacing human judgement, or preparatory work — and has that assessment been documented?
- Is it used to recruit or select, or to make or materially influence decisions on terms, promotion, termination, task allocation or monitoring?
The governance workflow
One record, from discovery to evidence.
Identify AI tools in imported records. Register their purpose and ownership. Follow the applicable duties through to the evidence and documents your reviewers need.
Northstar Applicant Screener
A system becomes a governed record.
- Purpose
- Rank job applicants for recruitment shortlisting.
- Sector
- Recruitment
- Operator role
- deployer
- Decision owner
- To be assigned
Synthetic registry fields · discovery covers the sources you import.
- AI system registry
- Shadow AI discovery
- Vendor risk questionnaires
Predictive evidence readiness
See evidence gaps before the deadline.
E-ARI projects future evidence readiness from your recorded collection history and the obligations ahead. See which workstreams need attention, the assumptions behind the projection and when collection should begin.
Measure progress that supports obligations.
Track artifact collection and, when snapshot history exists, the net rate of obligations evidenced. More uploads do not necessarily mean more coverage.
Know when a forecast is premature.
With insufficient history, E-ARI provides collection priorities instead of an unsupported projection. Scenario bands expose uncertainty in the observed pace.
AT THE OBSERVED COLLECTION RATE
5 / 10
candidate duties projected to lack evidence
Scenario range 5–9 · conditional projection
- Artifacts / month
- 2.0
- History / months
- 7.2
- Projection basis
- raw
Inspect the scenario inputs
Fixed fictional scenario as of 2026-09-09; deadline 2027-12-02, read from the platform timeline. Tier-and-role candidates, not a confirmed determination of applicability. Policy uploads only; no existing evidence links or measured obligation-clearance history. The projection is conditional on the observed pace: not a probability or a compliance verdict, and no customer forecast or measured accuracy is implied.
- AI_ACT_ART_26_5_INCIDENT · Reporting serious incidents by deployers
- AI_ACT_ART_27 · Fundamental rights impact assessment (FRIA) for deployers
- AI_ACT_ART_25 · Responsibilities along the value chain
- AI_ACT_ART_26_5_MONITOR · Monitoring high-risk AI systems operated by deployers
- AI_ACT_ART_74 · Cooperation with market surveillance authorities
- AI_ACT_ART_5_CSAM · Prohibited: AI producing child sexual abuse material (from 2 Dec 2026). A deployer is caught only where they use the system for that purpose — Art.5(1a)(b)
- AI_ACT_ART_5_NCII · Prohibited: AI generating or manipulating non-consensual intimate imagery of identifiable people (from 2 Dec 2026). A deployer is caught only where they use the system for that purpose — Art.5(1a)(b)
- AI_ACT_ART_26 · Obligations of deployers of high-risk AI systems
- AI_ACT_ART_4A_2 · Special-category data processed for bias detection outside the high-risk provider case — deployers of high-risk systems, and providers and deployers of other AI systems and models
- AI_ACT_ART_49_3 · EU database registration — deployer duties where applicable. Timing unsettled: Art.49 was not among the provisions the Omnibus deferred, yet the Commission states the Annex III rules apply from 2 Dec 2027 and the database is not yet reachable
Independent verification
A record your reviewer can verify.
Sealed exports bind artifacts to a signed manifest. Independent verification checks their integrity. Audit Replay recomputes the assessment from its sealed inputs, outside E-ARI.
Verification proves a record is intact and reproducible — not that it is compliant or correct.
Inside the verification chain
Canonical manifests, SHA-256 artifact hashes and Ed25519 signatures bind the bundle. A public append-only transparency log supplies inclusion and consistency proofs. The independent CLI implements the published specification and can run offline.
Read the specification pathsIllustration: the verifier’s offline replay output, using the worked example from the published scoring spec. It is not a live result and contains no information about your own assessment.
Illustrative transcript from the published scoring example. Use the verifier to run a check yourself.
Rules, evidence, human judgement
Deterministic where it matters. Assisted where it helps.
Published rules determine scores and risk tiers. AI assists with explanation, evidence extraction and drafting. Human review remains part of the governance process.
Explore the scoring instruments
SCORING v5.6· VERSIONED METHODOLOGY
Reproducible findings
Inspect the inputs, rule trace and method version.
Traceable support
Follow an obligation back to the supporting clause.
Contextual drafting
Generate explanations and documents for review.
Accountable decisions
Record human determinations and finalise artifacts.
High-risk — by presumption. PROVISIONAL — confirm before relying on this. The rule engine matched 1 Annex III area: Employment, workers management and access to self-employment (Annex III(4)), on the phrase "cv screening". Article 6(2) makes a listed system high-risk BY PRESUMPTION; Article 6(3) lets the provider rebut it — narrow procedural task, improving a completed human activity, detecting patterns without replacing human judgement, or preparatory work — and that assessment must be documented. Nothing in a one-line question can show it was made.
Articles cited: Annex III(4) · Art.6(2) · Art.6(3)Full answerEvidence infrastructure
Evidence connected to the way you work.
Upload documents, send artifacts through the API or configure collection tools. Each path converges on the same evidence ingestion rules.
Your evidence sources
Documents · CI / API push
Pull connectors · runtime capture
Shared ingestion
Validation · SHA-256 integrity
Deduplication · provenance
Governed evidence
Vault · clause support
Control states · exports
Connector maturity is stated individually; experimental connectors remain experimental. Runtime capture records configured traffic and does not enforce runtime policy. Write-scoped API access requires Enterprise.
Enterprise evaluation
Evaluate the platform with the facts in view.
Review our security posture, processing disclosures, methodology and published plans. Discuss your organisation’s requirements before deciding how to deploy E-ARI.
Certification status, hosting locations and sub-processors are set out in full on the Security page.
Before you decide
Questions that matter.
What does E-ARI bring together?
AI system registration, rule-based classification, obligation mapping, evidence, vendor questionnaires and AI literacy records. Governance teams can review generated FRIA and technical documentation and assemble submission packs from the system record. Feature availability follows the published plans.
Does a supported obligation mean we are compliant?
No. Evidence coverage identifies supporting clauses and records; it does not establish that every legal requirement is satisfied in practice. Classification can require a recorded human determination, generated documents require review, and the organisation remains responsible for its decisions.
Can our auditors verify the output independently?
Yes. The public verifier checks sealed bundles, and the independent CLI can verify them offline. Audit Replay recomputes an assessment from its sealed inputs. These checks establish integrity and reproducibility, not legal correctness or certification.
How are AI models used?
Rules determine readiness scores and risk tiers. Models assist with narrative, clause extraction and document drafting. Processing locations, providers and current safeguards are described on the security and data-processing pages.
How should we evaluate E-ARI for our organisation?
Start with the interactive examples and published methodology, then discuss your systems, evidence sources and procurement requirements with us. Self-service assessment and published plans are available. Connector maturity and security limitations are disclosed before you commit.
From governance to evidence
Put your AI governance to the test.
Explore the evidence workflow, inspect the verification path and discuss what your organisation needs to establish a defensible record.