Opencomplai Compliance Report

System: golden-sys · Commit: HEAD · Generated:

Heuristic aid only — not legal certification. The signed CI gate is compliance-artifact.json from opencomplai check, not this HTML file.

Manifest summary

FieldValue
system_idgolden-sys
intended_purposecredit scoring for loan applications
compliance_targetEU_AI_ACT
high_risk_presumptionFalse

Rule / control results

RuleStatusReferenceRationale
Prohibited AI Practice Detection (Article 5)PASSEU AI Act, Article 5No prohibited practice signals detected in 'credit scoring for loan applications'.
High-Risk System Classification (Article 6 / Annex III)FAILEU AI Act, Article 6, Annex IIIUse case 'credit scoring for loan applications' matches Annex III categories: essential_services.
Profiling Detection — Force High-Risk (Article 6(3))FAILEU AI Act, Article 6(3), Recital 34Profiling signals detected in use case: credit, credit scoring, scoring. System is classified as high-risk per Article 6(3).
Substantial Modification Trap (Article 25 / Article 3(23))PASSEU AI Act, Article 25, Article 3(23), Recital 66No substantial modification declared in assessment answers.

Gap report

ArticleStatusSourceEvidenceRationale
Art. 4UNVERIFIEDobligationai_literacyObligation 'AI literacy' applies; no automated verification run.
Art. 5UNVERIFIEDobligationprohibitedObligation 'Prohibited AI practices' applies; no automated verification run.
Art. 6MISSINGruleEU_AIA_ART6_HIGH_RISKUse case 'credit scoring for loan applications' matches Annex III categories: essential_services.
Art. 9PARTIALartifactdocs/risk_register.mdFound candidate artifact/signal for 'risk_register' (2 path(s), 0 code hint(s)) with content markers found (risk identification + mitigation). Heuristic only — not a full obligation assessment.
Art. 10UNVERIFIEDevaluatornoneNo source data supplied for this article in this run.
Art. 11UNVERIFIEDrulenoneNo source data supplied for this article in this run.
Art. 12UNVERIFIEDrulenoneNo source data supplied for this article in this run.
Art. 13PARTIALartifactINSTRUCTIONS.mdFound candidate artifact/signal for 'deployer_instructions' (1 path(s), 0 code hint(s)). Heuristic only — not a full obligation assessment.
Art. 14MISSINGartifacthuman_oversight_constructNo conventional documentation/code probe matched for 'human_oversight_construct'. Add the expected file or construct, then re-run gaps.
Art. 15UNVERIFIEDevaluatornoneNo source data supplied for this article in this run.
Art. 16MISSINGartifactprovider_qms_bundleNo conventional documentation/code probe matched for 'provider_qms_bundle'. Add the expected file or construct, then re-run gaps.
Art. 17PARTIALartifactdocs/qms.mdFound candidate artifact/signal for 'provider_qms' (1 path(s), 0 code hint(s)). Heuristic only — not a full obligation assessment.
Art. 24MISSINGartifactdistributor_conformityNo conventional documentation/code probe matched for 'distributor_conformity'. Add the expected file or construct, then re-run gaps.
Art. 25METruleEU_AIA_ART25_MODIFICATION_TRAPNo substantial modification declared in assessment answers.
Art. 27MISSINGartifactprovider_friaNo conventional documentation/code probe matched for 'provider_fria'. Add the expected file or construct, then re-run gaps.
Art. 43MISSINGartifactconformity_assessment_docsNo conventional documentation/code probe matched for 'conformity_assessment_docs'. Add the expected file or construct, then re-run gaps.
Art. 50UNVERIFIEDobligationtransparencyObligation 'Transparency obligations' applies; no automated verification run.
Art. 53UNVERIFIEDobligationgpai_providerObligation 'General-purpose AI model provider obligations' applies; no automated verification run.
Art. 55UNVERIFIEDobligationgpai_systemic_riskObligation 'GPAI model with systemic risk obligations' applies; no automated verification run.

Eval summary

No eval summary supplied — run with --sample-set.

Scan corroboration summary

No scan summary supplied — run with --scan.

Generated by opencomplai report. Informational only — the canonical CI gate is compliance-artifact.json produced by opencomplai check. This report does not replace the Annex IV dossier (opencomplai docs generate). Embedded JSON is a CLI envelope, not a signed ScanStatusArtifact.