A procured agentic underwriting system
The proof page. A deployer runs a bought-in agentic system that makes creditworthiness decisions about natural persons — an Annex III high-risk category — and the question is not are they compliant but what can actually be established, and what cannot. Taken end to end: 8 facts, 7 evidence items, 5 provisions, 3 findings, 5 risks, 4 stakeholder views, 2 projects, and 9 questions of which 5 are unanswered.
The five unanswered questions are the actual output of the exercise.
Why this example
Three properties make it the right one to publish. It is procured rather than built, which is the common case and the hard one — the deployer does not hold most of the evidence. It is agentic, so the human-oversight provisions bite in a way they do not for a scoring model. And it lands in a named Annex III category, so the high-risk classification is a citation rather than an argument.
The chain
fact -> evidence -> provision -> finding -> risk -> stakeholder view -> project
Each arrow is an edge that either exists or does not. Where one does not, the chain stops and the stop is recorded — which is the grounding ladder applied rather than described.
The three findings
| # | Finding | Points at | Kind |
|---|---|---|---|
| V1 | Log retention is below the required minimum. The deployment record says thirty days; the provision requires at least six months | Art. 26(6) | Arithmetic. No interpretation required |
| V2 | The suspension-and-notification path has never been exercised. It is described in the vendor's documentation and has no operational record behind it | Art. 26(5), Art. 14 | Capability, untested. A design document is not a capability |
| V3 | Residual risk has not been judged against any stated standard. There is an acceptance; there is no record of what it was judged against | Art. 9(5) | Judgement, ungrounded. Accepted is not acceptable |
V1 in detail — and its caveat
Thirty days against six months. There is no reading of that comparison under which it comes out differently, which is why it is the most defensible finding in the graph — and why it is over-represented in every demonstration of this method, including this one.
A system that leads with its arithmetic findings quietly teaches its reader that compliance is arithmetic. Two of the three findings here are not, and they are the ones that matter more.
The nine questions, five unanswered
| # | Question | State |
|---|---|---|
| Q1 | Is the system within a named Annex III category? | Yes — creditworthiness of natural persons, Annex III point 5(b) |
| Q2 | Are inference logs automatically generated and retained? | Yes — 30 days, from the deployment record |
| Q3 | Is there a documented human-oversight path? | Yes — in the vendor's documentation |
| Q4 | Was a fundamental rights impact assessment performed? | Yes — dated, and predating the current model version |
| Q5 | Has the oversight path ever been exercised? | Unanswered |
| Q6 | Who is the responsible natural person, by name? | Unanswered |
| Q7 | Against what standard was residual risk judged acceptable? | Unanswered |
| Q8 | Does the FRIA cover the model version currently in production? | Unanswered |
| Q9 | What did the provider actually supply under its Article 13 obligations? | Unanswered |
Five ghosted rows, rendered rather than dropped. Four of the five are questions the deployer cannot answer alone because the evidence sits with the provider — which is itself the finding: a procurement relationship that does not transfer evidence leaves the deployer holding obligations it cannot discharge.
And the one that surprises people
None of the deliverables currently grants presumption of conformity, because none has been cited in the Official Journal. Both conditions are required and neither is met.
Conformity with a harmonised standard grants a presumption of conformity with the Regulation — once the standard exists and has been cited in the Official Journal. For the AI Act, that has not happened. An organisation planning to discharge its obligations by conforming to a standard that has not been published, and would not yet grant the presumption if it had, is planning against a mechanism that is not yet available. Status →
What this example does not do
Deconfliction: the acceptance decision — whether V3's residual risk should have been accepted, by whom, against what appetite — belongs to risks.sgit.ai. This page owns the provision and the arithmetic. Q1 →