| Field | Value |
|---|---|
| system_id | golden-sys |
| intended_purpose | credit scoring for loan applications |
| compliance_target | EU_AI_ACT |
| high_risk_presumption | False |
| Rule | Status | Reference | Rationale |
|---|---|---|---|
| Prohibited AI Practice Detection (Article 5) | PASS | EU AI Act, Article 5 | No prohibited practice signals detected in 'credit scoring for loan applications'. |
| High-Risk System Classification (Article 6 / Annex III) | FAIL | EU AI Act, Article 6, Annex III | Use case 'credit scoring for loan applications' matches Annex III categories: essential_services. |
| Profiling Detection — Force High-Risk (Article 6(3)) | FAIL | EU AI Act, Article 6(3), Recital 34 | Profiling signals detected in use case: credit, credit scoring, scoring. System is classified as high-risk per Article 6(3). |
| Substantial Modification Trap (Article 25 / Article 3(23)) | PASS | EU AI Act, Article 25, Article 3(23), Recital 66 | No substantial modification declared in assessment answers. |
| Article | Status | Source | Evidence | Rationale |
|---|---|---|---|---|
| Art. 4 | UNVERIFIED | obligation | ai_literacy | Obligation 'AI literacy' applies; no automated verification run. |
| Art. 5 | UNVERIFIED | obligation | prohibited | Obligation 'Prohibited AI practices' applies; no automated verification run. |
| Art. 6 | MISSING | rule | EU_AIA_ART6_HIGH_RISK | Use case 'credit scoring for loan applications' matches Annex III categories: essential_services. |
| Art. 9 | PARTIAL | artifact | docs/risk_register.md | Found candidate artifact/signal for 'risk_register' (2 path(s), 0 code hint(s)) with content markers found (risk identification + mitigation). Heuristic only — not a full obligation assessment. |
| Art. 10 | UNVERIFIED | evaluator | none | No source data supplied for this article in this run. |
| Art. 11 | UNVERIFIED | rule | none | No source data supplied for this article in this run. |
| Art. 12 | UNVERIFIED | rule | none | No source data supplied for this article in this run. |
| Art. 13 | PARTIAL | artifact | INSTRUCTIONS.md | Found candidate artifact/signal for 'deployer_instructions' (1 path(s), 0 code hint(s)). Heuristic only — not a full obligation assessment. |
| Art. 14 | MISSING | artifact | human_oversight_construct | No conventional documentation/code probe matched for 'human_oversight_construct'. Add the expected file or construct, then re-run gaps. |
| Art. 15 | UNVERIFIED | evaluator | none | No source data supplied for this article in this run. |
| Art. 16 | MISSING | artifact | provider_qms_bundle | No conventional documentation/code probe matched for 'provider_qms_bundle'. Add the expected file or construct, then re-run gaps. |
| Art. 17 | PARTIAL | artifact | docs/qms.md | Found candidate artifact/signal for 'provider_qms' (1 path(s), 0 code hint(s)). Heuristic only — not a full obligation assessment. |
| Art. 24 | MISSING | artifact | distributor_conformity | No conventional documentation/code probe matched for 'distributor_conformity'. Add the expected file or construct, then re-run gaps. |
| Art. 25 | MET | rule | EU_AIA_ART25_MODIFICATION_TRAP | No substantial modification declared in assessment answers. |
| Art. 27 | MISSING | artifact | provider_fria | No conventional documentation/code probe matched for 'provider_fria'. Add the expected file or construct, then re-run gaps. |
| Art. 43 | MISSING | artifact | conformity_assessment_docs | No conventional documentation/code probe matched for 'conformity_assessment_docs'. Add the expected file or construct, then re-run gaps. |
| Art. 50 | UNVERIFIED | obligation | transparency | Obligation 'Transparency obligations' applies; no automated verification run. |
| Art. 53 | UNVERIFIED | obligation | gpai_provider | Obligation 'General-purpose AI model provider obligations' applies; no automated verification run. |
| Art. 55 | UNVERIFIED | obligation | gpai_systemic_risk | Obligation 'GPAI model with systemic risk obligations' applies; no automated verification run. |
No eval summary supplied — run with --sample-set.
No scan summary supplied — run with --scan.
Generated by opencomplai report. Informational only — the canonical CI gate
is compliance-artifact.json produced by opencomplai check. This
report does not replace the Annex IV dossier (opencomplai docs generate).
Embedded JSON is a CLI envelope, not a signed ScanStatusArtifact.