Governance is not a folder. It belongs where it applies.
In most organizations, controls, evidence, and approvals sit beside the process – in matrices, procedures, and document repositories. In the model, they are attached directly to the step they govern – making them auditable instead of merely documented.
The difference
The same control, two very different audit conversations
The audit question is rarely “Do you have a control?” It is usually “Where does it apply, who reviewed it, and how can I verify that?”

The flow
From AI generation to a governed artifact
Seven stages, three of them explicitly human. Something being generated does not mean it has been approved – and that distinction matters.
- AI Generation
- Provenance
- Human Review
- Validation
- Approval
- Versioning
- Governed Artifact
What the tool contributes
The signed provenance seal distinguishes generated from modified content and does not claim provenance for imported third-party files where no such provenance exists.
Details under Provenance and Quality Seal.
What humans contribute
Review, Validation, and Approval. These three steps are not delegated to automation because they carry accountability – not because the technology is missing.
The required level of human involvement depends on the task and its risk, not on a blanket rule.
What gets connected
Obligations belong to objects, not chapters
Processes
Which process is subject to the obligation.
Requirements
What must be fulfilled for compliance to be achieved.
Systems
Where the control is technically implemented.
Decisions
Who made which decision and when.
AI Agents
Which digital role was involved.
Artifacts
Where the evidence is attached.
AI Transparency
AI involvement is disclosed, not hidden
What is recorded on the Artifact
- 01Source and Timestamp
- 02TAOM Version
- 03AI Indicator: generated or modified
- 04Processing History
- 05License Status
Why this is more than a footnote
The EU AI Act introduces transparency and traceability obligations in contexts where AI contributes to decisions and regulated processes. A note in a presentation is not enough – signed provenance attached directly to the Artifact provides a much stronger foundation for traceability.
We do not claim certification where none exists: what is available today and what is still being developed is stated transparently on the Certification.
Typical use cases
Where this is needed
- 01Regulated ManufacturingGxP environments where every approval must be evidenced.
- 02Audit PreparationDemonstrate where a Control applies and who reviewed it.
- 03Enterprise AI AdoptionBefore the first audit asks how AI activity can be traced.
- 04Internal Control SystemControls embedded in the Process instead of maintained in a parallel governance world.
- 05Data Protection & SecurityWhich Process Steps interact with which data.
- 06Approval WorkflowsWho approves, in which sequence, and how that approval can be evidenced.
Getting started
Start with one Control you already need to evidence
Take an obligation from current operations, connect it to the Process Step where it applies, and add the corresponding Evidence and Approval. After that, the question “Where does this apply?” can be answered in seconds.