Antefacts

Standards

What an obligation asks for, and what in the method answers it.

Read from the obligation inward, which is the direction an assessor works in. Four frameworks: the EU AI Act as amended by Regulation (EU) 2026/1744, ISO/IEC 42001:2023, ISO/IEC 23894:2023 and NIST AI RMF 1.0.

This is not a claim of conformity. Using the method makes no party compliant with anything. Where a framework asks for evidence about how an AI system was tested, the method produces that evidence in a form a technical assessor can check without trusting whoever produced it. That is the whole claim.

EU AI Act

Regulation (EU) 2024/1689, high-risk provisions

High-risk requirements and provider obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. The notified body designation framework was not deferred and has applied since August 2025. Our note on the deferral.

ObligationWhat it requiresWhat the method contributes
Art 15(3)Accuracy levels and the relevant accuracy metrics declared in the instructions for useThe metric, sample size, interval method and every numeric constant are sealed before data exists. The declared figure becomes one a third party can reproduce rather than one the provider asserts. It is never described as proved.
Art 15(4), 15(5)Resilience to errors and to adversarial exploitationHeld-back test data with one-way exposure states and canary probing, so contamination of the test set, the failure that silently inflates a robustness figure, is detectable rather than assumed absent.
Art 11, Annex IVTechnical documentation demonstrating complianceThe evidence package is assembled to be examined directly. Annex IV(2)(g), validation and testing procedures with metrics and logs, is answered by pre-registration, run record and result together. Annex IV(4), appropriateness of the metrics, by the pre-registered analysis plan.
Art 12, Art 19Automatic logging over the system’s lifetime; log retentionAn append-only, hash-chained, independently timestamped record with roots published where we do not control them. Retention periods remain the provider’s obligation.
Art 17(1)(d), (e)Examination, test and validation procedures before, during and after development; technical specifications appliedThe lifecycle fixes the order of operations. The pre-registration is the specification, sealed before submissions open.
Art 20, Art 72Corrective action; post-market monitoringDeviations from plan are recorded and published rather than absorbed. Every result carries a replication status stating whether it can still be reproduced, which is the question post-market monitoring keeps asking.
Art 31Notified body independence and integrityArticle 31 asserts independence at the level of the body. The method makes it checkable at the level of each evaluation: our commercial relationship with every subject disclosed on the pre-registration, countersigned by the party whose decision it is, no score where a subject is a competitor, and standing to contest for anyone named.
Art 43, Annex VI, VIIConformity assessment by internal control or by notified body assessment of QMS and technical documentationThe method is input to Annex VII point 4, the technical documentation assessment. It is not a conformity assessment procedure and must not be presented as one.
Art 21Demonstrate conformity on reasoned requestThe package is designed to be handed over and re-checked without our cooperation.
ISO/IEC 42001

AI management system, 2023

Clause or controlWhat it requiresWhat the method contributes
A.6.2.4 AI system verification and validationObjective evidence that verification and validation were performedThe whole method. The process integrity certificate goes further and is machine-checked: the stated procedure is the procedure that ran.
A.6.2.8 AI system recording of event logsEvent logs recordedThe ledger, hash-chained and externally timestamped.
A.6.2.7 AI system technical documentationTechnical documentation maintainedThe evidence package, PDF/A-3b with the machine-readable bundle embedded.
A.7.4 Quality of data for AI systems; A.7.5 Data provenanceData quality and provenance establishedHeld-back data custody, exposure state and contamination detection for the scoring inputs we hold.
A.10.2 Allocation of responsibilities; A.10.3 Suppliers; A.10.4 CustomersResponsibilities allocated across suppliers and customersRoles, separation of duties and the neutrality disclosure, including the countersignature that stops the interested party grading its own relationship.
9.1 Monitoring, measurement, analysis and evaluationDetermine what is monitored and how results are evaluatedFixed before the fact by pre-registration rather than after.
9.2 Internal auditAudit programme and evidenceAudit evidence that does not depend on trusting the auditee.
10.2 Nonconformity and corrective actionNonconformities recorded and acted onDeviation records, published rather than absorbed.
NIST AI RMF

AI Risk Management Framework 1.0

SubcategoryWhat it saysWhat the method contributes
MAP 2.3Scientific integrity and TEVV considerations documented, including experimental design, data collection and selection, and construct validationThis is pre-registration described without the word. The method supplies it with a hash commitment and an independent timestamp, so the design provably predates the data.
MEASURE 1.3Assessors who were not front-line developers, and/or independent assessors, involved in regular assessmentsIndependence is not asserted. It is disclosed, countersigned and contestable.
MEASURE 2.1Test sets, metrics, and details about the tools used during TEVV are documentedMetrics by pre-registration, test sets by custody record, tools by container digest and isolation attestation.
MEASURE 2.3Performance or assurance criteria measured and demonstrated for conditions similar to deploymentThe result carries the configuration, and the replication status states whether that configuration is still reachable.
MEASURE 2.8Risks associated with transparency and accountability examined and documentedThe limits of the claim are published with the claim.
MEASURE 2.13Effectiveness of the employed TEVV metrics and processes evaluated and documentedThis asks whether the measurement process itself works. The method answers with a machine-checked certificate rather than a review.
MEASURE 3.3Feedback processes to report problems and appeal system outcomesThe challenge record: defined grounds, a bounded deadline, a stated outcome, entered in the ledger whichever way it is decided.
GOVERN 6.1Policies addressing risks associated with third-party entitiesApplied to the evaluator, which is the third party nobody else’s policy covers.
ISO/IEC 23894

Guidance on risk management, 2023

The weakest of the four mappings, and we say so. ISO/IEC 23894 is process guidance inherited from ISO 31000, and the method touches it at four points: risk identification (6.4.2) through the threat model, risk analysis (6.4.3) through the claim tiers, monitoring and review (6.6) through deviations and replication status, and recording and reporting (6.7) through the ledger and the evidence package.

Beyond all four

What no framework requires

Every framework assumes test data integrity; none requires it to be shown, and none contemplates that a test set is consumed by being used against a hosted provider. Every framework asks for records of testing; none asks for a machine-checked proof that the published score is the output of the published function on the recorded inputs. Article 31 and ISO/IEC 42001 address the independence of the body; nothing requires the evaluator to disclose its relationship with each subject on each evaluation, have that countersigned, and give standing to contest it. These are the reason to use the method. They are not compliance items, and a mapping that found a clause for everything would be worth nothing.

Verification

How this page was checked

EU AI Act article numbers and application dates are verified against the EUR-Lex consolidated text of 27 July 2026. NIST subcategory identifiers and text are verified against NIST AI 100-1. ISO/IEC 42001 and 23894 clause numbers and titles are verified against the official preview pages published by ISO and its national member bodies, and cross-checked against two independent published listings, with no disagreement found. Body text of the ISO standards was not consulted. If you hold a copy and find a clause cited here that does not say what we say it says, tell us and we will correct it on this page and say what changed.