Risk-tier classification, technical files, transparency obligations and post-market monitoring run inside the same AIMS that drives ISO 42001. One AI portfolio, one set of evidence, two regulators answered.
Unacceptable, high, limited, minimal risk classification
EU AI Act and ISO 42001 mapped to the same AIMS controls
High-risk Annex III obligations enforceable from August
The EU AI Act defines four risk tiers: unacceptable, high, limited, and minimal risk. KaitoSec's classification wizard guides you through the Annex III criteria and prohibited use cases, producing a documented risk classification for every AI system in your portfolio, the first thing any regulator will ask for.
High-risk AI systems require comprehensive technical documentation, conformity assessments, and registration in the EU AI database. KaitoSec provides templates for technical files, risk management records, and data governance documentation aligned with Article 9–17 requirements.
The Act requires organisations to establish human oversight mechanisms, designate responsible roles, and implement quality management for AI. KaitoSec's governance module tracks AI system owners, oversight procedures, incident logs, and post-market monitoring obligations in one place.
Maintain a complete inventory of all AI systems your organisation develops, deploys, or uses. Each system record captures the risk classification, intended purpose, affected user groups, and compliance status, giving you the overview regulators and boards increasingly demand.
High-risk AI systems require extensive technical documentation under Article 11. KaitoSec provides a structured document builder covering system design, training data governance, accuracy metrics, robustness testing, and human oversight mechanisms, exportable in regulator-ready format.
Limited-risk AI systems, such as chatbots and AI-generated content tools, must meet specific transparency obligations including user disclosure. KaitoSec tracks which transparency requirements apply to each system and maintains evidence that disclosure mechanisms are in place.
Built on open catalogs: BSI, MITRE, OWASP, ENISA
Related platform features