Template preview (excerpt)
One-page Annex IV summary (forwardable)
- Intended purpose:
- Decision(s) supported or automated:
- Human oversight checkpoints:
- Data sources (top 5):
- Monitoring signals & thresholds:
- Logging & retention policy:
5) Risk management system
- Typical harms: disparate impact, unfair denial, fraud/identity errors
- Mitigations + verification evidence (tests, sampling outcomes)
View the worked example
Always-review trigger:
- Any decline recommendation when confidence < 0.65
- Any decision affecting vulnerable customer category (as defined internally)
- Any policy near-miss (blocked or nearly blocked step)
Before you begin
For compliance, risk, product, and ML ops teams shipping agentic Processes into regulated environments.
A system-type Annex IV template for credit underwriting teams: intended purpose, decision boundaries, data governance, human oversight, monitoring, and evidence pointers.
It mirrors how audits actually work: reviewers look for concrete controls and exportable evidence, not legal theory.
When to use this resource
- Your system influences creditworthiness, eligibility, or pricing decisions.
- You need defensible documentation tied to evidence (logs, approvals, evaluations).
- You are preparing a technical documentation package and an evidence pack export drill.
Information to gather
- System description (what decisions are influenced, what is advisory vs automatic).
- Data sources and quality checks (including retention and access controls).
- Evaluation approach (metrics, segment performance checks, thresholds).
- Oversight SOP + monitoring plan + retention policy references.
Review checklist
Use these checks in the review with your system owner. Confirm the applicable requirements and attach evidence for the decisions your team makes.
- Intended purpose and “do not use for” boundaries are explicit.
- Inputs and data sources are listed with governance and quality checks.
- Human oversight triggers and escalation rules are defined.
- Monitoring signals include drift, performance by segment, and incident triggers.
- Logging covers decisions, approvals/overrides, tool calls, and versioning; retention is declared.
- Each section points to evidence that can be exported as a bundle (manifest + checksums).
Operating controls and evidence
- Govern
Policy-as-code checkpoints that block or require review for high-risk actions.
Versioned change control for model/prompt/policy/Process updates.
- Assure
Risk-tiered sampling reviews (baseline + burst during incidents or after changes).
Near-miss tracking (blocked / nearly blocked steps) as a measurable control signal.
- Prove
Configurable retention schedules, integrity verification, and an append-only Audit Trail.
Evidence Room export bundles (manifest + checksums) so auditors can verify independently.
Questions about this resource
Is credit underwriting usually “high-risk” under the EU AI Act?
Many creditworthiness and essential services decision-support uses are commonly treated as high-risk categories, but classification depends on intended purpose and context. Confirm with counsel.
What do reviewers look for first?
Decision boundaries, data governance, monitoring signals and thresholds, oversight triggers, and proof you can export logs and approvals for specific decisions.
How often should Annex IV documentation be updated?
Treat it as living documentation: update on model/policy changes, material Process changes, incidents, and monitoring findings.
What evidence should be attached for underwriting systems?
Segment performance checks, drift reports, threshold change approvals, review queue records, and audit logs tied to decision trace IDs.
Can we keep sensitive data out of exports?
Yes. Use redaction rules and hashed references where appropriate, and document the approach as part of the evidence pack.
Do we need a one-page summary?
It’s not mandatory, but it’s highly effective: it’s what internal reviewers forward, and it helps align stakeholders quickly.
Download file language: English
