{
  "schemaVersion": "1.0",
  "disclaimer": "Fictional sample template. Not legal advice.",
  "documentControl": {
    "documentTitle": "EU AI Act Annex IV — Technical Documentation",
    "systemName": "",
    "systemVersion": "",
    "providerEntity": "",
    "documentOwner": "",
    "approvers": [],
    "confidentialityLevel": "Internal",
    "effectiveDate": "",
    "revisionHistory": [
      {
        "date": "",
        "version": "v0.1",
        "author": "",
        "summaryOfChange": "Initial draft",
        "approvedBy": ""
      }
    ],
    "scopeStatement": {
      "intendedPurpose": "",
      "boundaries": "",
      "targetUsersOrDeployers": ""
    }
  },
  "annexIv": {
    "1": {
      "title": "General description of the AI system",
      "intendedPurpose": "",
      "providerAndVersioning": {
        "providerName": "",
        "versioningScheme": "",
        "relationshipToPriorVersions": ""
      },
      "contextAndIntegrations": {
        "interactions": "",
        "dependencies": ""
      },
      "softwareFirmwareVersionsAndUpdates": {
        "relevantVersions": "",
        "updateRequirements": ""
      },
      "placingOnMarket": {
        "deliveryModels": [],
        "packagingDetails": ""
      },
      "hardwareEnvironment": {
        "runtimeEnvironment": "",
        "constraints": ""
      },
      "uiAndInstructions": {
        "uiDescription": "",
        "instructionsForUse": ""
      },
      "evidencePointers": [
        { "artifactName": "System overview", "generatedBy": "Product documentation", "integrity": "" }
      ]
    },
    "2": {
      "title": "System elements and development process",
      "developmentMethods": {
        "lifecycle": "",
        "thirdPartyTools": "",
        "rolesAndResponsibilities": ""
      },
      "designSpecifications": {
        "logicSummary": "",
        "keyChoicesAndAssumptions": "",
        "objectives": "",
        "tradeoffs": ""
      },
      "architectureAndComponents": {
        "architectureDiagramRef": "",
        "componentInteractions": "",
        "computeResources": ""
      },
      "dataRequirements": {
        "requirements": "",
        "datasheetReferences": [],
        "provenanceAndPreparation": ""
      },
      "humanOversightAssessment": {
        "oversightGoals": "",
        "interpretabilityMeasures": "",
        "escalationAndOverride": ""
      },
      "predeterminedChanges": {
        "changes": "",
        "evaluationAndApproval": "",
        "continuousCompliance": ""
      },
      "validationAndTesting": {
        "procedures": "",
        "testDatasetReferences": [],
        "metrics": "",
        "discriminatoryImpactAssessment": "",
        "signedReportReferences": []
      },
      "cybersecurityMeasures": {
        "controls": "",
        "threatModelRef": "",
        "accessAndSecrets": ""
      },
      "evidencePointers": []
    },
    "3": {
      "title": "Monitoring, functioning and control",
      "capabilitiesAndLimitations": {
        "capabilities": "",
        "limitations": "",
        "assumptions": ""
      },
      "expectedAccuracy": {
        "overall": "",
        "subgroups": ""
      },
      "unintendedOutcomes": {
        "outcomes": "",
        "riskSources": ""
      },
      "humanOversight": {
        "checkpoints": "",
        "decisionRecords": ""
      },
      "inputDataSpecifications": {
        "typesAndConstraints": "",
        "qualityExpectations": "",
        "invalidInputHandling": ""
      },
      "evidencePointers": []
    },
    "4": {
      "title": "Appropriateness of performance metrics",
      "metricsRationale": {
        "metricsAndWhy": "",
        "limitationsAndMitigations": ""
      },
      "thresholdsAndAcceptance": {
        "thresholds": "",
        "rationale": "",
        "approvedBy": ""
      },
      "evidencePointers": []
    },
    "5": {
      "title": "Risk management system",
      "riskManagementProcess": {
        "identification": "",
        "evaluation": "",
        "mitigation": "",
        "residualRisk": "",
        "verificationLoops": ""
      },
      "operationalLinkages": {
        "riskRegisterRef": "",
        "incidentManagementRef": "",
        "escalationContacts": ""
      },
      "evidencePointers": []
    },
    "6": {
      "title": "Relevant changes through lifecycle",
      "changeCategories": {
        "modelUpdates": "",
        "dataPipelineChanges": "",
        "policyChanges": "",
        "uiChanges": "",
        "retrainingEvents": ""
      },
      "approvalAndValidation": {
        "approvalMatrix": "",
        "validationRequirements": "",
        "rollbackProcedures": ""
      },
      "evidencePointers": []
    },
    "7": {
      "title": "Standards and technical specifications used",
      "harmonisedStandards": {
        "standardsApplied": "",
        "applicabilityNotes": ""
      },
      "ifNone": {
        "solutionsAdopted": "",
        "otherStandards": ""
      },
      "evidencePointers": []
    },
    "8": {
      "title": "EU declaration of conformity",
      "declarationReference": {
        "reference": "",
        "dateOfIssue": "",
        "signatory": ""
      },
      "evidencePointers": []
    },
    "9": {
      "title": "Post-market monitoring system and plan",
      "monitoringObjectives": {
        "objectives": "",
        "signalsTracked": "",
        "thresholdsAndAlerting": ""
      },
      "plan": {
        "ownerAndCadence": "",
        "dataSourcesAndSampling": "",
        "escalationAndRemediation": ""
      },
      "continuousImprovement": {
        "incidentReportingLinkage": "",
        "retrospectives": "",
        "feedbackLoop": ""
      },
      "evidencePointers": []
    }
  },
  "appendices": {
    "integrityModel": {
      "manifestDigests": true,
      "bundleRootHash": true,
      "appendOnlyLedgerAnchor": true,
      "verificationProcedure": [
        "Obtain exported bundle and manifest.",
        "Re-compute SHA-256 digests for each file and compare with the manifest.",
        "Re-compute the bundle root hash and compare with the recorded root hash.",
        "Verify the root hash exists in the audit ledger and matches."
      ]
    }
  }
}
