How it works

Progressio.ai maps your documentation to each applicable EU AI Act requirement for High-Risk AI systems, assesses whether the evidence supports it, and shows the resulting evidence position.

From regulatory requirement to evidenced position

Progressio.ai performs automated, evidence-based, requirement by requirement conformity assessments against Articles 9, 10, 11, 12, 13, 14, 15, 17 and 18 of the EU AI Act.

Conformity is evidenced, not assumed

A requirement by requirement conformity assessment evaluates whether each applicable requirement of the EU AI Act can be objectively supported by evidence, not whether a policy, process, or document merely exists.

The real risk is false confidence.
Believing an area is strong when the evidence is incomplete, inconsistent, or missing is often more dangerous than knowing there is a gap.

Every assessment turns evidence into a defensible conformance baseline

Submitted materials are mapped to applicable regulatory requirements, assessed for sufficiency and consistency, and translated into a clear view of strengths, partial coverage, and evidence gaps.

Evidence Mapping

Map submitted evidence to each applicable requirement.

Conformity Assessment

Evaluate each requirement using objective evidence.

Gap Analysis

Identify where evidence is incomplete, inconsistent, or missing.

Prioritized Remediation

Focus corrective action by regulatory significance and effort.

Baseline Conformance Report

Establish a traceable snapshot for future reassessment.

Continuous Reassessment

Measure how the evidenced position changes over time.

Every requirement receives an evidence state

Evidenced

Objective evidence sufficiently supports the applicable requirement.

Partial

Evidence exists but is incomplete, inconsistent, or insufficient.

Evidence Gap

Evidence is missing or does not support the applicable requirement.

The most dangerous gap is the one you believe does not exist.
Auditors and regulators focus on whether claims can be substantiated, not how confident the organisation feels about them.

Built to prevent false confidence

Conformity assessments fail when fluent language substitutes for evidence. Progressio.ai evaluates every requirement against structured evidence, not a reassuring narrative.

01

Specialised assessment models

Purpose-built text models evaluate evidence against each requirement. General-purpose language models are not used to decide conformance.

02

Deterministic requirement graph

Documentation and the regulatory framework are decomposed into a navigable graph of fully covered, non-overlapping atomic requirements. Assessment runs as a deterministic evaluation against that structure.

03

Tier-1 error minimisation

We train the system on continuously evolving synthetic organisations that are diversified across all applicable domains. We do not train on any customer inputs, as their data is only in transit. Errors are minimised by priority. Tier 1 is false confidence: treating a requirement as evidenced when evidence is missing or insufficient. Tier 2 covers remaining assessment errors.

Where language models fit. After the assessment is complete, a general-purpose language model articulates remediation guidance in clear, human-readable form. It does not determine evidence states, map requirements, or decide conformance.

What each area really requires

Expand any Article to see the specific assessment focus, evidence typically involved, and findings that often reveal hidden exposure.

Assessment focus

Establishes whether a documented, continuous risk management system exists throughout the lifecycle of the High-Risk AI System.

Typical evidence

  • Risk Management Policy
  • Risk Register
  • Hazard Analysis
  • Validation & verification records
  • Monitoring procedures
  • CAPA records

Common findings

  • Risks identified but not systematically evaluated
  • Residual risks not documented
  • Mitigation effectiveness cannot be evidenced
  • Monitoring disconnected from risk management

Assessment focus

Evaluates whether data governance processes support the quality and suitability of data used throughout the AI lifecycle.

Typical evidence

  • Data Governance Policy
  • Dataset documentation
  • Data quality assessments
  • Bias assessments
  • Data lineage records
  • Validation procedures

Common findings

  • Incomplete data governance controls
  • Missing evidence of bias assessment
  • Data provenance cannot be evidenced
  • Dataset changes insufficiently documented

Assessment focus

Evaluates whether technical documentation sufficiently explains how the AI system was designed, developed, validated, and maintained.

Typical evidence

  • Technical documentation
  • System architecture
  • Development records
  • Validation documentation
  • Configuration records
  • Version history

Common findings

  • Documentation incomplete or outdated
  • Technical decisions lack supporting evidence
  • Traceability between development and documentation missing
  • Documentation inconsistent across versions

Assessment focus

Assesses whether appropriate logging and record keeping enable traceability throughout the AI system lifecycle.

Typical evidence

  • Logging procedures
  • Audit logs
  • Event records
  • Operational logs
  • Change history
  • Retention procedures

Common findings

  • Logging insufficient for traceability
  • Critical events not retained
  • Retention rules inconsistently applied
  • Audit trail incomplete

Assessment focus

Evaluates whether users receive the information necessary to understand intended use, limitations, assumptions, and operating conditions.

Typical evidence

  • User documentation
  • Instructions for use
  • Operational guidance
  • User warnings
  • Limitations documentation
  • Deployment documentation

Common findings

  • User instructions incomplete
  • System limitations insufficiently communicated
  • Operational assumptions undocumented
  • Human responsibilities unclear

Assessment focus

Assesses whether appropriate human oversight mechanisms enable effective intervention throughout operation of the AI system.

Typical evidence

  • Human oversight procedures
  • Operational roles
  • Escalation procedures
  • Training records
  • Override procedures
  • Operational guidance

Common findings

  • Oversight responsibilities unclear
  • Human intervention mechanisms not evidenced
  • Escalation procedures incomplete
  • Operator training insufficiently evidenced

Assessment focus

Evaluates whether the AI system achieves appropriate levels of accuracy, robustness, and cybersecurity throughout its intended lifecycle.

Typical evidence

  • Test results
  • Validation reports
  • Robustness testing
  • Performance monitoring
  • Cybersecurity assessments
  • Vulnerability management

Common findings

  • Performance claims unsupported
  • Robustness testing incomplete
  • Security controls insufficiently evidenced
  • Ongoing performance monitoring absent

Assessment focus

Assesses whether an appropriate quality management system governs the development, deployment, and maintenance of the AI system.

Typical evidence

  • Quality management procedures
  • Process documentation
  • Internal audit records
  • CAPA documentation
  • Management reviews
  • Process metrics

Common findings

  • Quality processes inconsistently implemented
  • Internal audits incomplete
  • Corrective actions not tracked
  • Quality objectives insufficiently evidenced

Assessment focus

Evaluates whether required documentation and evidence are retained appropriately and remain available for regulatory review.

Typical evidence

  • Document retention policy
  • Retention records
  • Archive procedures
  • Access controls
  • Evidence repository
  • Retention logs

Common findings

  • Required documentation unavailable
  • Retention periods inconsistently applied
  • Archived evidence incomplete
  • Evidence cannot be readily retrieved