# VORLUX AI: EU AI Act + GDPR compliance pack

17 templates, built 2026-10-09 from https://vorluxai.com/templates/.
Each template is a working draft to complete with your own facts; it is not legal advice.
Questions, or want a second pair of eyes on yours: https://vorluxai.com/contact/

## Contents

1. Acceptable AI Use Policy for Employees
2. AI Governance Framework
3. AI Incident Response Plan Template
4. AI Literacy Training Plan Template
5. AI Policy Template
6. AI Risk Classification Tool
7. AI Systems Inventory Template
8. AI Transparency Notice Template
9. Conformity Assessment Roadmap (Art. 43)
10. EU Declaration of Conformity (Art. 47, Annex V)
11. Fundamental Rights Impact Assessment (FRIA) Template
12. Data Protection Impact Assessment for AI Systems (GDPR Art. 35 + EU AI Act)
13. Human Oversight Requirements (Art. 14)
14. Prohibited AI Practices Checklist (Art. 5)
15. Shadow AI Detection Checklist
16. Technical Documentation Checklist (Annex IV)
17. AI Vendor Due Diligence Questionnaire

---

# Acceptable AI Use Policy for Employees
_Política de uso aceptable de IA para empleados_

> A comprehensive policy governing employee use of AI tools, covering approved applications, prohibited uses, data handling, content review requirements, and reporting obligations — aligned with EU AI Act requirements.
> Online: https://vorluxai.com/templates/acceptable-use-policy/

> **Disclaimer:** This is guidance only, not legal advice. Consult qualified legal counsel before adopting this policy. | *Este documento es solo orientativo, no constituye asesoramiento jurídico.*

---

## Acceptable AI Use Policy for Employees

**Document Reference:** [ORG-POL-AI-001]
**Version:** 1.0
**Effective Date:** [DATE]
**Review Date:** [DATE + 12 months]
**Owner:** [AI Officer / CISO / Legal — delete as appropriate]
**Approved by:** [Name, Title]
**Classification:** Internal

---

### 1. Purpose and Scope

#### 1.1 Purpose

This Acceptable AI Use Policy ("Policy") establishes the rules and standards governing employee use of artificial intelligence (AI) tools within [ORGANISATION NAME] ("the Organisation"). It is designed to:

- Ensure AI tools are used responsibly, ethically, and in compliance with applicable law
- Protect the Organisation's confidential information and data
- Satisfy obligations under the EU AI Act (Regulation (EU) 2024/1689), GDPR, and applicable Spanish/EU employment law
- Prevent reputational, legal, and operational harm
- Foster a culture of responsible AI use

#### 1.2 Scope

This Policy applies to:

| Category | Covered? |
|----------|----------|
| All permanent employees | Yes |
| Contractors and freelancers with system access | Yes |
| Temporary staff | Yes |
| Board members and executives | Yes |
| Third-party service providers using Org systems | Yes |
| Personal devices used for work (BYOD) | Yes — when accessing work systems or handling work data |

This Policy covers all AI tools, whether accessed via the Organisation's systems, personal devices, or third-party platforms, when used in connection with work activities.

---

### 2. Definitions

| Term | Definition |
|------|-----------|
| **AI Tool** | Any software application using machine learning, large language models, generative AI, or similar technologies, including chatbots, code assistants, image generators, translation tools, and analytics platforms |
| **Approved AI Tool** | An AI tool that has been formally assessed, approved, and listed in Annex A of this Policy |
| **Shadow AI** | Any AI tool used for work purposes without organisational approval |
| **Confidential Information** | Trade secrets, client data, employee data, financial data, strategic plans, and any data classified as Internal, Confidential, or Restricted |
| **Personal Data** | Any information relating to an identified or identifiable natural person, as defined under GDPR Art. 4(1) |
| **AI-Generated Content** | Any text, image, audio, video, code, or other output produced by an AI tool |
| **Human Review** | Review and verification of AI-generated content by a qualified employee before use |

---

### 3. Approved AI Tools

#### 3.1 Current Approved Tool Register

Only tools listed in the Approved AI Tool Register (Annex A) may be used for work purposes. The register is maintained by [AI Officer/IT Department] and reviewed quarterly.

**Current approved tools (as of effective date):**

| Tool | Use Cases | Data Classification Permitted | Conditions |
|------|-----------|-------------------------------|------------|
| [Tool 1 — e.g., Microsoft Copilot (M365)] | Drafting, summarisation, analysis | Internal, Confidential | Must use enterprise tenant; no client PII |
| [Tool 2 — e.g., GitHub Copilot] | Code assistance, code review | Internal | No proprietary algorithms; no credentials in prompts |
| [Tool 3 — e.g., approved image generator] | Marketing visuals, presentations | Public, Internal | Human review required before publication |
| [Tool 4 — e.g., approved translation tool] | Document translation | Internal | Not for legally binding documents without legal review |

*Specific rules for individual tools are set out in Section 4 of this Policy.*

#### 3.2 Requesting Approval for New Tools

Employees wishing to use an AI tool not listed in Annex A must submit an **AI Tool Request Form** (Annex B) to [IT/AI Officer] before use. The approval process takes a maximum of [15] business days. Using a tool prior to approval is a breach of this Policy.

#### 3.3 Approval Criteria

Tools are assessed against:
- Data processing location and GDPR compliance
- Security certifications (ISO 27001, SOC 2 Type II, etc.)
- Terms of service and data retention/training practices
- Risk classification under the EU AI Act
- Business justification and available alternatives

---

### 4. Tool-Specific Rules

#### 4.1 ChatGPT and OpenAI Products

**Approved version(s):** [e.g., ChatGPT Enterprise only / ChatGPT Team / Not approved — delete as applicable]

**Permitted uses:**
- Drafting initial text for internal documents (must be reviewed and edited)
- Brainstorming and idea generation
- Summarising public or internal non-confidential information
- Learning and skills development

**Prohibited uses:**
- Entering client names, contact details, or any client-specific information
- Uploading or pasting contracts, financial statements, or legal documents
- Entering employee personal data (names, salaries, performance data, health information)
- Entering proprietary source code, trade secrets, or competitive intelligence
- Using the free consumer version (ChatGPT.com without an enterprise agreement) for any work purpose

**Data handling rules:**
- If using an enterprise/API version: confirm "Do not train on my data" is enabled in account settings before use
- Never use the consumer (free) version for work-related tasks
- Treat all ChatGPT outputs as drafts requiring verification — do not quote statistics, legal citations, or facts without independent verification

**Content review requirement:**
All ChatGPT-generated content used externally (client-facing, published, or submitted to regulators) must be reviewed and approved by [Department Head / designated reviewer] before use.

---

#### 4.2 GitHub Copilot and AI Code Assistants

**Approved version(s):** [e.g., GitHub Copilot Business (enterprise-configured)]

**Permitted uses:**
- Generating code suggestions and autocomplete
- Code explanation and documentation
- Identifying potential bugs in code under review
- Writing unit tests

**Prohibited uses:**
- Entering authentication credentials, API keys, passwords, or secrets in any prompt or file that will be shared with the AI
- Using Copilot with repositories containing client data or personal data unless the repository is configured to exclude AI training
- Accepting code suggestions without review for security-critical functions
- Using Copilot to generate code that circumvents security controls

**Security requirements:**
- Enable `.gitignore` for all files containing secrets before using Copilot
- Review all AI-generated code for security vulnerabilities before committing
- Do not accept Copilot suggestions in files containing environment variables or configuration secrets
- Run security scanning (e.g., [tool name]) on all code containing significant AI-generated portions

**Content review requirement:**
All AI-generated code included in production systems must be reviewed by a qualified developer and included in the standard code review process. The AI assistance should be noted in the pull request description.

---

#### 4.3 AI Image Generators

**Approved tool(s):** [e.g., Adobe Firefly (enterprise), Canva AI (enterprise)]

**Permitted uses:**
- Creating marketing and presentation visuals
- Generating placeholder content for internal use
- Exploring design concepts

**Prohibited uses:**
- Generating images of real, identifiable individuals without their written consent
- Generating images that could be defamatory, misleading, or in breach of third-party intellectual property rights
- Creating "deepfake" or synthetic media that misrepresents real events or people
- Generating images for any official regulatory submission, legal document, or financial report
- Creating images depicting violence, nudity, or other harmful content

**Intellectual property rules:**
- Images generated using the Organisation's approved enterprise tools are generally permitted for commercial use — check the specific tool's commercial use terms before publication
- Do not use images that closely replicate a specific artist's style if the artist has objected to their work being used for AI training
- Retain records of prompts used for images in official publications

**Content review requirement:**
All AI-generated images used in external communications, marketing materials, or official documents must be reviewed by [Marketing Manager / Brand Owner] and confirmed to meet brand standards and legal requirements.

---

### 5. Prohibited Uses — All AI Tools

The following uses are prohibited regardless of which AI tool is used:

#### 5.1 Absolute Prohibitions

| # | Prohibited Activity | Reason |
|---|---------------------|--------|
| P1 | Processing special category personal data (health, religion, political views, biometrics, sexual orientation) through any AI tool | GDPR Art. 9; high risk of harm |
| P2 | Using AI to make or substantially influence decisions with significant legal or personal effects on individuals (hiring, dismissal, credit, benefits) without human oversight | EU AI Act Art. 14; GDPR Art. 22 |
| P3 | Using AI to generate content that is intentionally deceptive or designed to manipulate individuals against their interests | EU AI Act Art. 5 (prohibited practices) |
| P4 | Using AI for any form of subliminal manipulation, social scoring, or real-time biometric surveillance | EU AI Act Art. 5 (prohibited practices) |
| P5 | Using AI to produce content that infringes copyright, trade marks, or other intellectual property rights | IP law |
| P6 | Using AI to produce content that is defamatory, discriminatory, or harassing | Employment law; civil liability |
| P7 | Misrepresenting AI-generated content as human-created in contexts where this distinction is material | EU AI Act Art. 50; professional standards |
| P8 | Bypassing or attempting to bypass the organisation's AI approval and oversight processes | Policy breach |
| P9 | Using personal AI tool accounts (subscriptions paid by the employee) to process organisational data | Data security |
| P10 | Using AI tools to exfiltrate, leak, or improperly transfer organisational data | Data protection; potential criminal liability |

#### 5.2 Restricted Uses (Require Prior Approval)

| # | Activity | Approval Required From |
|---|----------|------------------------|
| R1 | Using AI in any system that interfaces directly with customers or the public | AI Officer + Legal |
| R2 | Using AI to analyse employee behaviour, performance, or communications | HR Director + DPO + Legal |
| R3 | Using AI for any medical, legal, or financial advice provided to third parties | Relevant professional + Legal |
| R4 | Using AI to process client personal data | DPO + AI Officer |
| R5 | Integrating AI into automated decision-making workflows | AI Officer + Legal + DPO |

---

### 6. Data Handling Requirements

#### 6.1 Data Classification Before Use

Before using any AI tool, employees must classify the data they intend to input:

| Classification | Definition | Examples | Permitted in AI? |
|----------------|------------|----------|-----------------|
| **Public** | Information already in the public domain | Published reports, press releases | Yes — any approved tool |
| **Internal** | Not public but not confidential | Internal memos, meeting notes | Yes — approved tools only |
| **Confidential** | Business-sensitive; restricted circulation | Client contracts, financial forecasts, HR data | Only if tool is specifically approved for this level |
| **Restricted** | Highest sensitivity; strict need-to-know | Personal data, legal privilege, M&A information | Do not enter into any AI tool without explicit approval from DPO/Legal |

#### 6.2 Personal Data Rules

- **Do not enter personal data into any AI tool** unless the tool has been approved for personal data processing and a Data Processing Agreement (DPA) is in place with the tool provider
- This includes: names, email addresses, phone numbers, IP addresses, location data, job titles combined with names, and any information that could identify a specific individual
- Anonymise or pseudonymise data before AI processing wherever possible
- If you are unsure whether data is personal data, treat it as personal data and seek guidance from the DPO

#### 6.3 Minimisation Principle

Only provide AI tools with the minimum information necessary to complete the task. Do not paste entire documents when a summary or excerpt would suffice.

#### 6.4 Output Data

AI-generated outputs that contain or could be derived from personal data must be handled with the same care as the input data. Do not share AI outputs more widely than the input data would have been shared.

---

### 7. Content Review Requirements

#### 7.1 Review Tiers

All AI-generated content must be reviewed before use according to the following tiers:

| Tier | Content Type | Minimum Review Standard |
|------|-------------|------------------------|
| **Tier 1 — Internal Low Risk** | Internal emails, notes, non-binding communications | Employee self-review for accuracy, tone, and appropriateness |
| **Tier 2 — Internal High Risk** | Board reports, HR communications, financial analysis | Line manager or department head review |
| **Tier 3 — External Standard** | Client-facing documents, website content, marketing materials | Department head + Comms/Marketing sign-off |
| **Tier 4 — External High Stakes** | Legal documents, regulatory submissions, press releases, financial reports | Legal / Compliance + relevant C-suite sign-off |

#### 7.2 Factual Verification Obligation

Employees are responsible for verifying the factual accuracy of all AI-generated content before use. AI tools frequently produce:
- Incorrect statistics and figures
- Fabricated citations and references ("hallucinations")
- Outdated information
- Plausible-sounding but incorrect legal or technical assertions

**Verification checklist for AI-generated factual claims:**
- [ ] All statistics traced to an original, verifiable source
- [ ] All legal citations checked against current legislation
- [ ] All named individuals or organisations confirmed to exist and details verified
- [ ] All dates and timelines confirmed as accurate
- [ ] Content checked for internal consistency

#### 7.3 Transparency Obligations

| Situation | Required Disclosure |
|-----------|-------------------|
| Submitting AI-generated content to a regulator or court | Disclose AI assistance to legal counsel for advice on disclosure requirements |
| Publishing AI-generated content on the website | Include AI-assisted disclaimer if the content is substantially AI-generated |
| Providing AI-generated advice to a client | Disclose AI assistance and confirm human professional review |
| Responding to a procurement/tender | Check tender instructions — many public bodies require declaration of AI use |

---

### 8. Reporting Obligations

#### 8.1 What Must Be Reported

Employees must report the following to [AI Officer / IT Security / DPO — as applicable]:

| Event | Report To | Timeframe |
|-------|-----------|-----------|
| Discovery of a colleague using an unapproved AI tool for work | Line Manager or AI Officer | Within 5 business days |
| Accidental input of personal data or confidential information into an AI tool | DPO + Line Manager | Within 24 hours |
| Suspected data breach via an AI tool | DPO + IT Security | Immediately (within 1 hour) |
| AI tool producing discriminatory, harmful, or illegal content | AI Officer + Legal | Within 24 hours |
| Discovering an AI tool has been used to make a significant decision affecting an individual without human review | HR Director + Legal + DPO | Within 24 hours |
| Any incident where AI use has caused or may cause harm to a third party | Legal + AI Officer | Immediately |

#### 8.2 How to Report

Reports should be made via:
- **Primary:** [email address — e.g., ai-incidents@organisation.com]
- **Secondary:** Direct communication to [AI Officer name/role]
- **Urgent incidents:** [Phone number / IT Security hotline]

#### 8.3 Whistleblower Protection

Employees who report AI-related concerns in good faith are protected under the Organisation's whistleblower policy and applicable EU law (Directive (EU) 2019/1937). Retaliation against reporters is a disciplinary offence.

---

### 9. Responsibilities

| Role | Responsibilities |
|------|-----------------|
| **All Employees** | Comply with this Policy; complete mandatory AI literacy training; report incidents |
| **Line Managers** | Ensure team compliance; review Tier 2 content; support reporting culture |
| **AI Officer** | Maintain approved tool register; manage approval requests; oversee incident response; report to board |
| **DPO** | Advise on personal data processing; review DPIA for AI tools; handle data protection incidents |
| **IT/Security** | Implement technical controls; manage tool access; monitor for shadow AI; conduct security assessments |
| **Legal** | Review high-stakes content; advise on compliance; manage external disclosures |
| **HR** | Manage policy communications; handle employee relations aspects; oversee training |

---

### 10. Training Requirements

| Role | Training Required | Frequency |
|------|------------------|-----------|
| All employees | AI Literacy Awareness (minimum 1 hour) | At onboarding + annual refresh |
| Employees regularly using approved AI tools | Role-specific AI tool training | At tool adoption + when tool updates materially |
| Managers | AI governance and oversight responsibilities | Annual |
| AI Officer, DPO, Legal, CISO | Advanced EU AI Act compliance training | Annual + when regulation updates |

Training completion is recorded in [HR System name]. Failure to complete mandatory training within [30 days] of due date is a disciplinary matter.

---

### 11. Consequences of Breach

Breaches of this Policy will be investigated and may result in disciplinary action up to and including dismissal, in accordance with the Organisation's disciplinary procedure. Serious breaches (e.g., data breaches involving personal data, use of prohibited AI practices) may also result in:
- Notification to supervisory authorities (AEPD / EDPS)
- Civil or criminal liability for the individual
- Regulatory fines for the Organisation

---

### 12. Policy Review

This Policy will be reviewed:
- At least annually
- Following any significant change in applicable law or regulation
- Following a material AI-related incident
- When new AI tools are approved that require material policy changes

---

### Annex A — Approved AI Tool Register

*To be maintained by [AI Officer/IT Department] — updated quarterly*

| Tool Name | Provider | Version/Tier | Approved Uses | Data Classes Permitted | Date Approved | Next Review |
|-----------|----------|-------------|---------------|----------------------|---------------|-------------|
| | | | | | | |
| | | | | | | |

---

### Annex B — AI Tool Request Form

**Requestor Name:**
**Department:**
**Date:**
**Tool Name:**
**Provider:**
**URL/Access Method:**
**Proposed Use Case:**
**Data Classification of Data to be Processed:**
**Business Justification:**
**Have you reviewed the tool's privacy policy and terms of service?** Yes / No
**Does the provider offer a Data Processing Agreement?** Yes / No / Unknown
**Urgency:**

*Submit to: [email] | Response within: [15] business days*

---

### Annex C — Politica de Uso Aceptable de IA (Resumen en Español)

#### Versión resumida en español para empleados

**Herramientas aprobadas:** Solo se pueden utilizar las herramientas de IA que figuran en el Registro de Herramientas Aprobadas (Anexo A). Para solicitar la aprobación de una nueva herramienta, completa el Formulario de Solicitud (Anexo B).

**Reglas clave para ChatGPT:**
- No introduzcas datos de clientes, datos personales ni información confidencial
- Usa únicamente la versión empresarial (no la versión gratuita en ChatGPT.com) para trabajo
- Verifica siempre la exactitud del contenido generado antes de usarlo

**Reglas clave para GitHub Copilot:**
- No incluyas credenciales, claves API ni contraseñas en los archivos que usa Copilot
- Revisa todo el código generado por IA antes de incluirlo en producción

**Reglas clave para generadores de imágenes:**
- No generes imágenes de personas reales identificables sin su consentimiento
- No generes contenido engañoso, difamatorio ni que infrinja derechos de propiedad intelectual

**Usos absolutamente prohibidos:**
- Procesar datos de salud, religiosos, políticos, biométricos o de orientación sexual mediante IA
- Usar IA para tomar decisiones que afecten significativamente a personas sin supervisión humana
- Usar IA para manipular o engañar a individuos
- Utilizar herramientas de IA no aprobadas para trabajo

**Cómo notificar un incidente:**
Envía un correo a [ai-incidents@organisation.com] o contacta directamente al Responsable de IA.

*Los empleados que incumplan esta política pueden estar sujetos a medidas disciplinarias.*

---

**Document Footer:**
*Template provided by VORLUX AI | vorluxai.com*
*This is guidance only, not legal advice.*
*Version 1.0 | For EU AI Act compliance use | Last updated: 2026-04-05*

---

### Versión Española

## Politica de Uso Aceptable de IA para Empleados

**Referencia:** [ORG-POL-AI-001]
**Version:** 1.0
**Fecha de vigencia:** [FECHA]
**Fecha de revision:** [FECHA + 12 meses]
**Responsable:** [Responsable de IA / CISO / Juridico]
**Aprobado por:** [Nombre, Cargo]
**Clasificacion:** Interno

---

#### 1. Objeto y Ambito

##### 1.1 Objeto

Esta Politica establece las normas que regulan el uso de herramientas de inteligencia artificial (IA) por parte de los empleados de [NOMBRE DE LA ORGANIZACION]. Su finalidad es:

- Garantizar un uso responsable, etico y conforme a la legislacion vigente
- Proteger la informacion confidencial y los datos de la organizacion
- Cumplir con el EU AI Act (Reglamento (UE) 2024/1689), el GDPR y la legislacion laboral espanola/europea aplicable
- Prevenir danos reputacionales, legales y operativos
- Fomentar una cultura de uso responsable de la IA

##### 1.2 Ambito de aplicacion

| Categoria | Incluido? |
|-----------|-----------|
| Empleados permanentes | Si |
| Contratistas y freelancers con acceso a sistemas | Si |
| Personal temporal | Si |
| Miembros del consejo y directivos | Si |
| Proveedores externos que usen sistemas de la organizacion | Si |
| Dispositivos personales utilizados para el trabajo (BYOD) | Si, al acceder a sistemas o datos corporativos |

Cubre todas las herramientas de IA utilizadas en conexion con actividades laborales, independientemente del dispositivo o plataforma.

---

#### 2. Definiciones

| Termino | Definicion |
|---------|-----------|
| **Herramienta de IA** | Cualquier software que utilice machine learning, LLMs, IA generativa o tecnologias similares (chatbots, asistentes de codigo, generadores de imagenes, traductores, plataformas de analisis) |
| **Herramienta aprobada** | Herramienta evaluada, aprobada y registrada en el Anexo A |
| **Shadow AI** | Cualquier herramienta de IA utilizada sin aprobacion organizativa |
| **Informacion confidencial** | Secretos comerciales, datos de clientes, datos de empleados, datos financieros, planes estrategicos y cualquier dato clasificado como Interno, Confidencial o Restringido |
| **Datos personales** | Toda informacion relativa a una persona fisica identificada o identificable, segun GDPR Art. 4(1) |
| **Contenido generado por IA** | Todo texto, imagen, audio, video, codigo u otro resultado producido por una herramienta de IA |
| **Revision humana** | Verificacion del contenido generado por IA por un empleado cualificado antes de su uso |

---

#### 3. Herramientas de IA Aprobadas

##### 3.1 Registro actual

Solo pueden utilizarse las herramientas del Registro de Herramientas Aprobadas (Anexo A), mantenido por [Responsable de IA/Departamento de TI] y revisado trimestralmente.

| Herramienta | Casos de uso | Clasificacion de datos permitida | Condiciones |
|-------------|-------------|----------------------------------|------------|
| [Herramienta 1 — ej. Microsoft Copilot (M365)] | Redaccion, resumen, analisis | Interno, Confidencial | Usar tenant empresarial; sin PII de clientes |
| [Herramienta 2 — ej. GitHub Copilot] | Asistencia y revision de codigo | Interno | Sin algoritmos propietarios; sin credenciales en prompts |
| [Herramienta 3 — ej. generador de imagenes aprobado] | Visuales de marketing, presentaciones | Publico, Interno | Revision humana antes de publicar |
| [Herramienta 4 — ej. herramienta de traduccion aprobada] | Traduccion de documentos | Interno | No para documentos legalmente vinculantes sin revision juridica |

##### 3.2 Solicitud de nuevas herramientas

Los empleados deben enviar el **Formulario de Solicitud de Herramienta de IA** (Anexo B) a [TI/Responsable de IA] antes de su uso. El proceso de aprobacion tarda un maximo de [15] dias habiles. Utilizar una herramienta sin aprobacion previa constituye un incumplimiento.

##### 3.3 Criterios de aprobacion

- Ubicacion del tratamiento de datos y conformidad con GDPR
- Certificaciones de seguridad (ISO 27001, SOC 2 Type II, etc.)
- Condiciones de servicio y practicas de retencion/entrenamiento de datos
- Clasificacion de riesgo segun el EU AI Act
- Justificacion de negocio y alternativas disponibles

---

#### 4. Reglas por Herramienta

##### 4.1 ChatGPT y productos OpenAI

**Usos permitidos:** redaccion de borradores internos (con revision), brainstorming, resumen de informacion publica o interna no confidencial, aprendizaje.

**Usos prohibidos:** introducir datos de clientes, datos personales de empleados, codigo fuente propietario, contratos o documentos financieros. Prohibido usar la version gratuita para el trabajo.

**Manejo de datos:** confirmar "No entrenar con mis datos" activo; verificar siempre la exactitud del contenido generado.

**Revision:** todo contenido externo debe ser aprobado por [Jefe de Departamento / revisor designado].

##### 4.2 GitHub Copilot y asistentes de codigo

**Usos permitidos:** sugerencias de codigo, documentacion, deteccion de bugs, tests unitarios.

**Usos prohibidos:** credenciales, claves API o secretos en prompts; aceptar sugerencias sin revisar en funciones criticas de seguridad.

**Seguridad:** activar `.gitignore` para secretos; revisar todo codigo generado por IA antes de hacer commit; ejecutar analisis de seguridad.

**Revision:** todo codigo generado por IA para produccion debe pasar por el proceso estandar de code review, indicando la asistencia de IA en el pull request.

##### 4.3 Generadores de imagenes

**Usos permitidos:** visuales de marketing, contenido provisional interno, exploracion de conceptos de diseno.

**Usos prohibidos:** imagenes de personas reales sin consentimiento, contenido enganoso o difamatorio, deepfakes, violencia o desnudos.

**Propiedad intelectual:** verificar terminos comerciales de la herramienta; no replicar estilos de artistas que se hayan opuesto; conservar registro de prompts para publicaciones oficiales.

**Revision:** aprobacion de [Responsable de Marketing / Marca] antes de publicar externamente.

---

#### 5. Usos Prohibidos — Todas las Herramientas

##### 5.1 Prohibiciones absolutas

| N.o | Actividad prohibida | Motivo |
|-----|---------------------|--------|
| P1 | Tratar datos de categorias especiales (salud, religion, opiniones politicas, biometria, orientacion sexual) | GDPR Art. 9 |
| P2 | Usar IA para tomar o influir sustancialmente en decisiones con efectos legales o personales significativos sin supervision humana | EU AI Act Art. 14; GDPR Art. 22 |
| P3 | Generar contenido intencionalmente enganoso o manipulador | EU AI Act Art. 5 |
| P4 | Manipulacion subliminal, social scoring o vigilancia biometrica en tiempo real | EU AI Act Art. 5 |
| P5 | Producir contenido que infrinja derechos de propiedad intelectual | Legislacion de PI |
| P6 | Producir contenido difamatorio, discriminatorio o acosador | Legislacion laboral; responsabilidad civil |
| P7 | Presentar contenido generado por IA como creado por humanos cuando la distincion sea relevante | EU AI Act Art. 50 |
| P8 | Eludir los procesos de aprobacion y supervision de IA de la organizacion | Incumplimiento de politica |
| P9 | Usar cuentas personales de IA para tratar datos de la organizacion | Seguridad de datos |
| P10 | Usar IA para exfiltrar o transferir indebidamente datos organizativos | Proteccion de datos; posible responsabilidad penal |

##### 5.2 Usos restringidos (requieren aprobacion previa)

| N.o | Actividad | Aprobacion requerida de |
|-----|-----------|-------------------------|
| R1 | Usar IA en sistemas que interactuen directamente con clientes o el publico | Responsable de IA + Juridico |
| R2 | Analizar comportamiento, rendimiento o comunicaciones de empleados | Director de RRHH + DPO + Juridico |
| R3 | Usar IA para asesoramiento medico, legal o financiero a terceros | Profesional correspondiente + Juridico |
| R4 | Tratar datos personales de clientes con IA | DPO + Responsable de IA |
| R5 | Integrar IA en flujos de toma de decisiones automatizada | Responsable de IA + Juridico + DPO |

---

#### 6. Requisitos de Manejo de Datos

##### 6.1 Clasificacion antes de su uso

| Clasificacion | Definicion | Ejemplos | Permitido en IA? |
|---------------|-----------|----------|-----------------|
| **Publico** | Informacion ya publica | Informes publicados, notas de prensa | Si, cualquier herramienta aprobada |
| **Interno** | No publico pero no confidencial | Memorandos internos, actas de reuniones | Si, solo herramientas aprobadas |
| **Confidencial** | Sensible para el negocio | Contratos de clientes, previsiones financieras, datos de RRHH | Solo si la herramienta esta aprobada para este nivel |
| **Restringido** | Maxima sensibilidad | Datos personales, privilegio legal, informacion de M&A | No introducir sin aprobacion explicita de DPO/Juridico |

##### 6.2 Reglas sobre datos personales

- No introducir datos personales salvo que la herramienta este aprobada para ello y exista un DPA con el proveedor
- Incluye: nombres, emails, telefonos, IPs, ubicaciones, titulos de puesto combinados con nombres
- Anonimizar o pseudonimizar siempre que sea posible
- En caso de duda, tratar como datos personales y consultar al DPO

##### 6.3 Principio de minimizacion

Proporcionar solo la informacion minima necesaria. No pegar documentos completos cuando baste un resumen o extracto.

##### 6.4 Datos de salida

Los resultados generados por IA que contengan o deriven de datos personales deben manejarse con el mismo cuidado que los datos de entrada.

---

#### 7. Requisitos de Revision de Contenido

##### 7.1 Niveles de revision

| Nivel | Tipo de contenido | Estandar minimo de revision |
|-------|------------------|----------------------------|
| **Nivel 1 — Interno bajo riesgo** | Emails internos, notas, comunicaciones no vinculantes | Auto-revision del empleado |
| **Nivel 2 — Interno alto riesgo** | Informes al consejo, comunicaciones de RRHH, analisis financiero | Revision del responsable directo o jefe de departamento |
| **Nivel 3 — Externo estandar** | Documentos para clientes, contenido web, materiales de marketing | Jefe de departamento + aprobacion de Comunicacion/Marketing |
| **Nivel 4 — Externo alto impacto** | Documentos legales, presentaciones regulatorias, informes financieros | Juridico/Compliance + aprobacion de la direccion |

##### 7.2 Obligacion de verificacion factual

El empleado es responsable de verificar la exactitud de todo contenido generado por IA. Lista de comprobacion:

- [ ] Estadisticas trazadas a una fuente original verificable
- [ ] Citas legales verificadas contra legislacion vigente
- [ ] Personas u organizaciones mencionadas confirmadas
- [ ] Fechas y plazos confirmados
- [ ] Contenido verificado por coherencia interna

##### 7.3 Obligaciones de transparencia

| Situacion | Divulgacion requerida |
|-----------|----------------------|
| Contenido generado por IA enviado a un regulador o tribunal | Informar al asesor juridico para valorar la divulgacion |
| Contenido publicado en la web sustancialmente generado por IA | Incluir aviso de asistencia de IA |
| Asesoramiento generado por IA proporcionado a un cliente | Divulgar asistencia de IA y confirmar revision profesional humana |
| Respuesta a licitacion/concurso publico | Verificar si se exige declaracion de uso de IA |

---

#### 8. Obligaciones de Notificacion

##### 8.1 Que debe notificarse

| Evento | Notificar a | Plazo |
|--------|------------|-------|
| Descubrimiento de uso de herramienta no aprobada | Responsable directo o Responsable de IA | 5 dias habiles |
| Introduccion accidental de datos personales/confidenciales en una herramienta de IA | DPO + Responsable directo | 24 horas |
| Sospecha de violacion de datos via herramienta de IA | DPO + Seguridad TI | Inmediatamente (1 hora) |
| Contenido discriminatorio, danino o ilegal generado por IA | Responsable de IA + Juridico | 24 horas |
| Uso de IA para tomar decisiones significativas sin revision humana | Director de RRHH + Juridico + DPO | 24 horas |
| Cualquier incidente donde el uso de IA haya causado o pueda causar dano a terceros | Juridico + Responsable de IA | Inmediatamente |

##### 8.2 Como notificar

- **Principal:** [email — ej. ai-incidents@organisation.com]
- **Secundario:** Comunicacion directa al [Responsable de IA]
- **Urgente:** [Telefono / linea de Seguridad TI]

##### 8.3 Proteccion del denunciante

Los empleados que notifiquen de buena fe estan protegidos conforme a la politica de denuncias interna y la Directiva (UE) 2019/1937. Las represalias constituyen infraccion disciplinaria.

---

#### 9. Responsabilidades

| Rol | Responsabilidades |
|-----|------------------|
| **Todos los empleados** | Cumplir esta Politica; completar la formacion obligatoria en alfabetizacion de IA; notificar incidentes |
| **Responsables directos** | Asegurar el cumplimiento del equipo; revisar contenido de Nivel 2; fomentar la cultura de notificacion |
| **Responsable de IA** | Mantener el registro de herramientas; gestionar solicitudes; supervisar la respuesta a incidentes; informar al consejo |
| **DPO** | Asesorar sobre tratamiento de datos personales; revisar EIPD para herramientas de IA; gestionar incidentes de proteccion de datos |
| **TI/Seguridad** | Implementar controles tecnicos; gestionar accesos; monitorizar shadow AI; realizar evaluaciones de seguridad |
| **Juridico** | Revisar contenido de alto impacto; asesorar sobre cumplimiento; gestionar divulgaciones externas |
| **RRHH** | Gestionar comunicaciones de la politica; manejar aspectos de relaciones laborales; supervisar la formacion |

---

#### 10. Requisitos de Formacion

| Rol | Formacion requerida | Frecuencia |
|-----|---------------------|-----------|
| Todos los empleados | Concienciacion sobre alfabetizacion en IA (minimo 1 hora) | Al incorporarse + actualizacion anual |
| Empleados que usen herramientas aprobadas regularmente | Formacion especifica de la herramienta por rol | Al adoptarla + cuando se actualice sustancialmente |
| Directivos | Gobernanza de IA y responsabilidades de supervision | Anual |
| Responsable de IA, DPO, Juridico, CISO | Formacion avanzada de conformidad con el EU AI Act | Anual + cuando se actualice la regulacion |

El cumplimiento se registra en [Sistema de RRHH]. No completar la formacion obligatoria en [30 dias] constituye infraccion disciplinaria.

---

#### 11. Consecuencias del Incumplimiento

Los incumplimientos seran investigados y podran resultar en medidas disciplinarias, incluido el despido, conforme al procedimiento disciplinario. Los incumplimientos graves pueden ademas conllevar:

- Notificacion a las autoridades de supervision (AEPD / EDPS)
- Responsabilidad civil o penal para el individuo
- Sanciones regulatorias para la organizacion

---

#### 12. Revision de la Politica

Esta Politica se revisara:

- Al menos anualmente
- Tras cualquier cambio significativo en la legislacion aplicable
- Tras un incidente material relacionado con la IA
- Cuando se aprueben nuevas herramientas que requieran cambios sustanciales en la politica

---

#### Anexo A — Registro de Herramientas de IA Aprobadas

*Mantenido por [Responsable de IA/Departamento de TI] — actualizado trimestralmente*

| Herramienta | Proveedor | Version/Nivel | Usos aprobados | Clases de datos permitidas | Fecha de aprobacion | Proxima revision |
|-------------|----------|---------------|----------------|---------------------------|--------------------|--------------------|
| | | | | | | |

---

#### Anexo B — Formulario de Solicitud de Herramienta de IA

**Nombre del solicitante:**
**Departamento:**
**Fecha:**
**Nombre de la herramienta:**
**Proveedor:**
**URL / Metodo de acceso:**
**Caso de uso propuesto:**
**Clasificacion de los datos a tratar:**
**Justificacion de negocio:**
**Ha revisado la politica de privacidad y condiciones de uso?** Si / No
**El proveedor ofrece un DPA?** Si / No / Desconocido
**Urgencia:**

*Enviar a: [email] | Respuesta en: [15] dias habiles*

---

*Plantilla proporcionada por VORLUX AI | vorluxai.com*
*Este documento es solo orientativo, no constituye asesoramiento juridico.*
*Version 1.0 | Para uso de conformidad con el EU AI Act | Ultima actualizacion: 2026-04-05*

---

# AI Governance Framework
_Marco de gobernanza de IA_

> A comprehensive AI governance framework covering organisational structure, RACI matrix, decision-making processes, risk appetite, monitoring, reporting, and audit schedule — designed for EU AI Act compliance.
> Online: https://vorluxai.com/templates/ai-governance-framework/

> **Disclaimer:** This is guidance only, not legal advice. Consult qualified legal counsel before adopting this framework. | *Este documento es solo orientativo, no constituye asesoramiento jurídico.*

---

## AI Governance Framework

**Document Reference:** [ORG-FRAME-AI-001]
**Version:** 1.0
**Effective Date:** [DATE]
**Review Date:** [DATE + 12 months]
**Framework Owner:** [AI Officer / CTO]
**Approved by:** [CEO / Board]
**Classification:** Internal — Restricted

---

### Executive Summary

[ORGANISATION NAME] ("the Organisation") operates and deploys artificial intelligence systems in the course of its business activities. This AI Governance Framework establishes the structures, processes, accountabilities, and controls that govern how AI is used within the Organisation.

This Framework is designed to:
- Ensure compliance with the EU AI Act (Regulation (EU) 2024/1689) and related legislation
- Protect the Organisation's stakeholders, including employees, customers, and third parties
- Enable the Organisation to realise the benefits of AI while managing risks proportionately
- Demonstrate trustworthy and responsible AI use to regulators, clients, and the public

This Framework applies from [DATE] and must be reviewed at least annually.

---

### 1. Governance Principles

The Organisation's AI governance is founded on the following principles, aligned with the EU AI Act and the EU's Ethics Guidelines for Trustworthy AI:

| # | Principle | Meaning in Practice |
|---|-----------|-------------------|
| 1 | **Human Agency and Oversight** | Meaningful human control is maintained over AI-supported decisions; AI does not replace human judgment on high-stakes matters |
| 2 | **Technical Robustness and Safety** | AI systems are secure, accurate, reliable, and resilient against misuse |
| 3 | **Privacy and Data Governance** | AI use complies with GDPR; personal data is processed lawfully, minimally, and with appropriate safeguards |
| 4 | **Transparency** | Affected individuals are informed when AI is used in decisions affecting them; AI systems are documented and auditable |
| 5 | **Diversity and Fairness** | AI systems are assessed for bias and discriminatory outputs; diverse perspectives inform AI procurement and deployment |
| 6 | **Societal and Environmental Wellbeing** | AI use considers broader impacts, including environmental costs and effects on communities |
| 7 | **Accountability** | Clear ownership of AI risks and decisions; incidents are investigated and corrected |

---

### 2. Organisational Structure for AI Governance

#### 2.1 Governance Architecture

```
┌─────────────────────────────────────────────────────────────────┐
│                        BOARD OF DIRECTORS                        │
│          (Strategic oversight; approve risk appetite;            │
│           receive quarterly AI governance report)                │
└──────────────────────────────┬──────────────────────────────────┘
                               │
┌──────────────────────────────▼──────────────────────────────────┐
│                    AI GOVERNANCE COMMITTEE                        │
│   Chair: CEO | Members: CTO, DPO, CISO, AI Officer, Legal,      │
│   HR, Finance representative                                     │
│   Meets: Quarterly | Reports: Board quarterly                    │
└────────┬──────────────┬───────────────┬────────────┬────────────┘
         │              │               │            │
┌────────▼───┐  ┌───────▼──────┐  ┌────▼──────┐  ┌─▼──────────┐
│  AI OFFICER │  │   DPO        │  │  CISO     │  │  LEGAL     │
│             │  │              │  │           │  │            │
│ Day-to-day  │  │ Data         │  │ Security  │  │ Regulatory │
│ AI ops      │  │ protection   │  │ & cyber   │  │ compliance │
│ & risk mgmt │  │ & GDPR       │  │ risk      │  │ & disputes │
└─────┬───────┘  └──────────────┘  └───────────┘  └────────────┘
      │
┌─────▼─────────────────────────────────────────────────┐
│              AI IMPLEMENTATION TEAMS                   │
│  (Department-level: Business, Technology, Operations)  │
│  AI Champions embedded in each department              │
└───────────────────────────────────────────────────────┘
```

*Adapt the org chart to your actual structure. Add intermediate layers (e.g., Risk Committee) as appropriate.*

#### 2.2 Key Governance Bodies

##### Board of Directors

**Responsibilities:**
- Approve the Organisation's AI risk appetite statement
- Receive and scrutinise the quarterly AI Governance Report
- Hold the CEO accountable for AI governance outcomes
- Consider AI-related risks in strategic decision-making

**Meetings:** AI governance standing agenda item at quarterly board meetings

---

##### AI Governance Committee

**Chair:** CEO (or nominated delegate)
**Membership:**

| Member | Role | Vote |
|--------|------|------|
| CEO (or delegate) | Chair | Yes |
| CTO | Technology strategy | Yes |
| DPO | Data protection | Yes |
| CISO | Information security | Yes |
| AI Officer | AI operations and compliance | Yes |
| General Counsel / Legal | Legal and regulatory | Yes |
| HR Director | People and culture | Advisory |
| Finance representative | Budget and risk | Advisory |

**Responsibilities:**
- Review and approve AI risk assessments for new AI systems
- Set and maintain the AI risk appetite
- Approve AI policies and this Framework
- Review material AI incidents and approve remediation
- Approve the annual AI audit programme
- Monitor regulatory developments and initiate compliance responses

**Meetings:** Quarterly (minimum); extraordinary meetings on 5 business days' notice for material incidents

**Quorum:** Majority of voting members, including AI Officer and at least one of DPO/CISO

---

##### AI Officer

**Reports to:** CTO / CEO (organisation to specify)

**Responsibilities:**
- Day-to-day operational oversight of AI governance
- Maintaining the AI system inventory and risk register
- Managing the AI tool approval process
- Coordinating AI risk assessments
- Monitoring AI system performance and incidents
- Reporting to the AI Governance Committee
- Liaising with the national supervisory authority (Spain: AESIA) where required
- Managing the AI Governance Committee agenda and documentation

**Competencies required:**
- Deep understanding of EU AI Act and applicable regulation
- Technical understanding of AI/ML systems
- Risk management experience
- Strong communication and stakeholder management skills

---

##### Data Protection Officer (DPO)

**Responsibilities:**
- Advising on GDPR compliance for all AI processing activities
- Reviewing and approving DPIAs for AI systems
- Acting as point of contact for the Spanish data protection authority (AEPD)
- Monitoring AI use for compliance with data minimisation and purpose limitation

---

##### CISO

**Responsibilities:**
- Assessing cybersecurity risks of AI systems
- Overseeing AI system security testing and vulnerability management
- Managing AI-related security incidents
- Setting security requirements for AI procurement

---

#### 2.3 AI Champions (Department Level)

Each business department shall designate an AI Champion who:
- Acts as the first point of contact for AI queries in their department
- Participates in the AI Champion Network (quarterly meetings)
- Escalates risks and incidents to the AI Officer
- Supports the rollout of AI training and policy updates

**Current AI Champions:**

| Department | AI Champion Name | Contact | Date Appointed |
|------------|-----------------|---------|---------------|
| [Dept 1] | | | |
| [Dept 2] | | | |
| [Dept 3] | | | |

---

### 3. AI System Inventory

#### 3.1 Inventory Requirements

All AI systems used within the Organisation, whether developed internally, procured from a vendor, or accessed as a service, must be registered in the AI System Inventory (maintained by AI Officer).

**Minimum information per system:**

| Field | Description |
|-------|-------------|
| System ID | Unique identifier (e.g., AI-SYS-001) |
| System Name | Descriptive name |
| Provider | Internal / vendor name |
| EU AI Act Risk Category | Unacceptable / High / Limited / Minimal |
| Primary Business Function | What it does |
| Deployment Scope | Users / departments / geographic reach |
| Data Inputs | Types of data processed |
| Data Outputs | Types of outputs produced |
| Human Oversight Level | None / Partial / Full |
| Risk Assessment Status | Not assessed / In progress / Approved / Conditions |
| DPO Review Status | Not required / In progress / Approved |
| Date Deployed | |
| Last Review Date | |
| Next Review Date | |
| System Owner | Named individual |

#### 3.2 EU AI Act Risk Classification

AI systems must be classified according to the EU AI Act risk hierarchy:

| Category | Definition | Examples | Requirements |
|----------|-----------|---------|-------------|
| **Unacceptable Risk** | Prohibited under Art. 5 | Social scoring by public authorities; real-time biometric surveillance in public spaces; subliminal manipulation | Must not be used |
| **High Risk** | Systems with significant potential harm (Annex III of AI Act) | AI in recruitment, credit decisions, critical infrastructure, education assessment, law enforcement | Full compliance requirements (Art. 9–15) including conformity assessment |
| **Limited Risk** | Specific transparency obligations | Chatbots (must disclose AI nature); deepfakes; emotion recognition | Transparency obligations (Art. 50) |
| **Minimal Risk** | Minimal risk to rights or safety | Spam filters, AI video games, AI productivity tools | No mandatory requirements (voluntary codes encouraged) |

**[ORGANISATION NAME] current high-risk AI systems:**

| System | Risk Basis | Compliance Status |
|--------|-----------|------------------|
| [System name] | [Which Annex III category] | [Compliant / Partial / Non-compliant] |

---

### 4. Risk Management System

#### 4.1 AI Risk Appetite Statement

The Organisation's AI risk appetite is defined as follows:

*[Board to approve this statement — template below]*

> "[ORGANISATION NAME] accepts the use of AI tools and systems that deliver demonstrable business value and can be operated in compliance with applicable law and our ethical principles. We have **low tolerance** for AI-related harms to individuals (including employees, clients, and the public), reputational damage arising from AI misuse, and regulatory non-compliance. We have **moderate tolerance** for AI operational failures that can be detected and remediated without material harm. We have **zero tolerance** for the use of AI systems categorised as posing unacceptable risk under the EU AI Act."

**Risk appetite thresholds:**

| Risk Type | Tolerance Level | Response |
|-----------|----------------|---------|
| Personal data breach via AI | Very low | Immediate suspension; incident response; regulatory notification |
| Discriminatory AI output | Very low | Immediate suspension; investigation; root cause fix |
| AI operational error (low impact) | Moderate | Log; investigate; remediate within SLA |
| Regulatory non-compliance | Very low | Immediate escalation to Legal; remediation plan within 5 days |
| Reputational harm | Low | Immediate escalation to CEO; comms plan |
| AI cost overrun | Moderate | CFO notification; budget review |

#### 4.2 Risk Assessment Process

All AI systems must undergo a risk assessment before deployment and periodically thereafter. The process:

```
Step 1: IDENTIFY
  ↓ Complete AI System Registration Form (Annex A)
  ↓ AI Officer conducts initial risk screening (3–5 business days)

Step 2: ASSESS
  ↓ Full risk assessment if screening indicates Medium risk or above
  ↓ DPO conducts DPIA if personal data involved
  ↓ CISO conducts security assessment
  ↓ Legal reviews regulatory classification

Step 3: DECIDE
  ↓ AI Governance Committee review for High/Unacceptable risk systems
  ↓ AI Officer approval for Low/Minimal risk systems
  ↓ Decision documented with conditions (if any)

Step 4: IMPLEMENT
  ↓ Technical and organisational measures implemented
  ↓ User training completed
  ↓ Monitoring plan established
  ↓ System added to inventory

Step 5: MONITOR
  ↓ Ongoing performance monitoring
  ↓ Incident logging
  ↓ Periodic review (annually minimum; 6-monthly for High risk)
```

#### 4.3 AI Risk Register

The AI Risk Register is maintained by the AI Officer and reviewed quarterly by the AI Governance Committee.

**Risk Register Template:**

| Risk ID | AI System | Risk Description | Likelihood (1–5) | Impact (1–5) | Risk Score | Controls | Residual Risk | Owner | Review Date |
|---------|-----------|-----------------|------------------|--------------|------------|---------|---------------|-------|------------|
| AIR-001 | | | | | | | | | |

**Likelihood Scale:** 1 = Rare, 2 = Unlikely, 3 = Possible, 4 = Likely, 5 = Almost certain
**Impact Scale:** 1 = Negligible, 2 = Minor, 3 = Moderate, 4 = Major, 5 = Catastrophic
**Risk Score = Likelihood × Impact**
**Risk Appetite Threshold:** Scores ≥12 require immediate escalation to AI Governance Committee

---

### 5. Decision-Making Processes

#### 5.1 New AI System Adoption

```
Business Unit identifies need for AI system
          ↓
AI Champion submits AI System Request to AI Officer
          ↓
AI Officer conducts risk screening (5 business days)
          ↓
         /  \
    Low risk  High/Unknown risk
        ↓            ↓
  AI Officer    Full assessment
  approves       package:
  (with           - Risk assessment
  conditions)     - DPIA (if PD)
                  - Security review
                  - Legal review
                         ↓
                 AI Governance Committee
                 reviews and decides
                         ↓
                    Approve / Reject /
                    Approve with conditions
```

**Decision timeline targets:**
- Initial screening: 5 business days
- Low risk approval: 10 business days
- High risk Committee review: 20 business days

#### 5.2 AI Incident Response

| Severity | Definition | Initial Response | Escalation |
|----------|-----------|-----------------|------------|
| **P1 — Critical** | Personal data breach; prohibited use; imminent harm to individual | Immediate system suspension; notify AI Officer within 1 hour | CEO + DPO + Legal within 2 hours |
| **P2 — High** | Significant discriminatory output; near-miss on personal data; customer-facing failure | System review within 4 hours; AI Officer notified | AI Governance Committee within 24 hours |
| **P3 — Medium** | Repeated incorrect outputs; user policy breach; vendor issue | Investigate within 24 hours; AI Officer notified | AI Champion + Line Manager |
| **P4 — Low** | Isolated error; no data or harm involved | Log and investigate within 5 business days | AI Champion monitors |

#### 5.3 Escalation Matrix

| Situation | Escalate To | By | Timeframe |
|-----------|------------|-----|----------|
| Personal data breach via AI | DPO → CISO → CEO | AI Champion / User | Immediately |
| Suspected prohibited AI use | AI Officer → Legal → CEO | Any employee | Within 1 hour |
| High-risk system performing outside parameters | AI Officer → CTO | System Owner | Within 4 hours |
| Regulatory inquiry about AI | Legal → CEO | Compliance / Any recipient | Immediately |
| Vendor security incident | CISO → AI Officer | IT / System Owner | Within 2 hours |
| Employee AI policy breach | HR → Line Manager → AI Officer | Line Manager / Peer | Within 24 hours |

---

### 6. Monitoring and Performance

#### 6.1 Ongoing Monitoring Requirements

| System Category | Monitoring Frequency | Metrics | Responsible |
|----------------|---------------------|---------|------------|
| High-risk AI systems | Continuous automated + weekly human review | Accuracy, false positive/negative rate, bias indicators, uptime | System Owner + AI Officer |
| Customer-facing AI | Daily | Error rate, escalation rate, sentiment, complaints | System Owner + Customer Service |
| Internal AI tools | Monthly | Usage statistics, incident count, user feedback | AI Officer |
| All AI systems | Quarterly | Risk register review, performance vs. baseline | AI Officer |

#### 6.2 Key Performance Indicators

| KPI | Target | Measurement Method | Reporting Frequency |
|-----|--------|-------------------|-------------------|
| % AI systems with current risk assessments | 100% | AI inventory review | Quarterly |
| AI incident response time (P1) | <2 hours from detection | Incident log | Monthly |
| Mandatory AI training completion rate | >95% | HR system | Quarterly |
| AI-related GDPR breaches reported to AEPD | 0 | AEPD/DPO records | Annually |
| % employees aware of AI policy | >90% (surveyed) | Annual survey | Annually |
| Shadow AI instances detected | Target: trending to 0 | IT monitoring + audits | Quarterly |
| AI Governance Committee quorum achieved | 100% of meetings | Committee minutes | Quarterly |

#### 6.3 Reporting Structure

| Report | Content | Prepared by | For | Frequency |
|--------|---------|-------------|-----|-----------|
| **AI Operational Dashboard** | System status, incidents, usage | AI Officer | AI Officer | Weekly |
| **AI Governance Committee Report** | Risk register, incidents, KPIs, policy updates, regulatory developments | AI Officer | AI Governance Committee | Quarterly |
| **Board AI Governance Report** | Executive summary: risk posture, material incidents, regulatory status, strategic AI initiatives | AI Officer (approved by CEO) | Board of Directors | Quarterly |
| **AI Audit Report** | Annual independent audit findings and recommendations | Internal/External Auditor | AI Governance Committee + Board | Annually |
| **Regulatory Notifications** | AEPD, AESIA notifications as required | DPO / Legal | Regulatory authorities | As required |

---

### 7. Audit Schedule

#### 7.1 Internal AI Audit Programme

The annual internal AI audit programme covers:

| Quarter | Audit Focus | Auditor | Deliverable |
|---------|------------|---------|------------|
| Q1 | AI System Inventory accuracy and completeness; risk assessment quality | Internal Audit | Findings report + management response |
| Q2 | Data protection compliance for AI systems (GDPR/DPIA quality) | Internal Audit + DPO | Compliance gap report |
| Q3 | Technical controls and security for AI systems | CISO / IT Audit | Security findings + remediation plan |
| Q4 | Policy compliance (user behaviour, training completion, shadow AI) | HR + AI Officer + Internal Audit | Compliance report + annual programme review |

#### 7.2 External AI Audit

An independent external AI audit shall be conducted:
- Annually (for organisations using High-risk AI systems under EU AI Act)
- When required by regulators
- Following a material AI incident

**Scope of external audit:**
- EU AI Act compliance (applicable requirements for deployers and/or providers)
- GDPR compliance for AI data processing
- AI governance framework effectiveness
- Technical robustness of high-risk AI systems

#### 7.3 Audit Findings Management

| Finding Severity | Response Timeline | Escalation |
|-----------------|------------------|------------|
| Critical | Immediate suspension of system / practice; remediation plan within 5 days | CEO + Board |
| High | Remediation plan within 15 business days | AI Governance Committee |
| Medium | Remediation plan within 30 business days | AI Officer |
| Low | Remediation in next planning cycle | System Owner |

All audit findings are tracked in the Audit Findings Register maintained by Internal Audit. Progress is reported to the AI Governance Committee quarterly.

---

### 8. Regulatory Compliance Management

#### 8.1 Applicable Regulations

| Regulation | Scope | Primary Owner | Review Frequency |
|-----------|-------|--------------|-----------------|
| EU AI Act (Regulation (EU) 2024/1689) | All AI systems | AI Officer + Legal | Ongoing — Act fully applies from August 2026 |
| GDPR (Regulation (EU) 2016/679) | All AI processing personal data | DPO | Ongoing |
| Spanish LOPDGDD (Ley Orgánica 3/2018) | Spanish operations | DPO | Annual |
| EU AI Liability Directive (proposed) | Liability for AI-caused harm | Legal | When adopted |
| Sector-specific regulation | [Insert applicable sector rules] | Legal + Compliance | Annual |

#### 8.2 Regulatory Watch Process

The Legal department, supported by the AI Officer, monitors:
- EU Official Journal for new AI-related legislation
- AESIA (Spanish AI supervisory authority) guidance and decisions
- AEPD guidance on AI and data protection
- EDPB opinions on AI matters
- European Commission AI guidance and standards

Significant regulatory developments are escalated to the AI Governance Committee within 10 business days of publication.

#### 8.3 Supervisory Authority Contacts

| Authority | Jurisdiction | Contact | Purpose |
|-----------|-------------|---------|---------|
| AESIA (Agencia Española de Supervisión de Inteligencia Artificial) | Spain — AI Act enforcement | [www.aesia.es] | AI Act notifications, incidents |
| AEPD (Agencia Española de Protección de Datos) | Spain — GDPR enforcement | [www.aepd.es] | Data breaches, DPIA consultations |
| EDPB (European Data Protection Board) | EU-wide GDPR | [www.edpb.europa.eu] | Cross-border matters |

---

### 9. Documentation and Records

#### 9.1 Document Retention

| Document | Retention Period | Storage Location | Owner |
|----------|-----------------|-----------------|-------|
| AI System Inventory | Indefinitely (current version) + 5 years historic | [System] | AI Officer |
| Risk Assessments | 10 years from system decommission | [System] | AI Officer |
| DPIAs | 3 years from last review (minimum) | [System] | DPO |
| Incident Reports | 5 years | [System] | AI Officer + DPO |
| Training Records | Duration of employment + 5 years | HR System | HR |
| Audit Reports | 7 years | [System] | Internal Audit |
| Committee Minutes | 7 years | Board/Committee Secretary | AI Officer |

#### 9.2 Document Control

This Framework and all associated policy documents are:
- Version controlled
- Stored in [Document Management System]
- Accessible to all employees via [Intranet link]
- Subject to formal change management procedures

---

### 10. Framework Review and Updates

This Framework will be reviewed:
- Annually (by [MONTH] each year)
- Following any significant change in applicable law
- Following a material AI incident or near-miss
- When the Organisation's AI footprint changes materially

Review is led by the AI Officer with input from DPO, CISO, and Legal. Revised versions require approval from the AI Governance Committee.

---

### Annex A — AI System Registration Form

**System Name:**
**Business Unit:**
**System Owner:**
**Date of Registration:**
**Brief Description:**
**Vendor/Provider:**
**Intended Users:**
**Data Inputs:**
**Data Outputs:**
**Does it process personal data?** Yes / No
**Estimated EU AI Act Risk Category (initial assessment):** Unacceptable / High / Limited / Minimal / Unknown
**Proposed Go-Live Date:**
**Business Justification:**

---

### Annex B — Framework Change Log

| Version | Date | Changed By | Summary of Changes | Approved By |
|---------|------|-----------|-------------------|------------|
| 1.0 | [DATE] | [Name] | Initial version | [Name, Title] |

---

**Document Footer:**
*Template provided by VORLUX AI | vorluxai.com*
*This is guidance only, not legal advice.*
*Version 1.0 | For EU AI Act compliance use | Last updated: 2026-04-05*

---

### Versión Española

> **Aviso legal:** Este documento es solo orientativo, no constituye asesoramiento jurídico. Consulte con un abogado cualificado antes de adoptar este marco.

---

## Marco de Gobernanza de IA

**Referencia:** [ORG-FRAME-AI-001]
**Versión:** 1.0
**Fecha de vigencia:** [FECHA]
**Fecha de revisión:** [FECHA + 12 meses]
**Responsable del marco:** [AI Officer / CTO]
**Aprobado por:** [CEO / Consejo]
**Clasificación:** Interna — Restringida

---

### Resumen Ejecutivo

[NOMBRE DE LA ORGANIZACIÓN] opera y despliega sistemas de inteligencia artificial en el curso de sus actividades. Este Marco establece las estructuras, procesos, responsabilidades y controles que rigen el uso de la IA.

Objetivos del Marco:
- Garantizar el cumplimiento del EU AI Act (Reglamento (UE) 2024/1689) y legislación conexa
- Proteger a las partes interesadas: empleados, clientes y terceros
- Aprovechar los beneficios de la IA gestionando riesgos de forma proporcionada
- Demostrar un uso fiable y responsable de la IA ante reguladores, clientes y público

Vigente desde [FECHA]; revisión mínima anual.

---

### 1. Principios de Gobernanza

Principios alineados con el EU AI Act y las Directrices de la UE para una IA Fiable:

| # | Principio | Significado Práctico |
|---|-----------|---------------------|
| 1 | **Agencia Humana y Supervisión** | Control humano efectivo sobre decisiones asistidas por IA; la IA no sustituye el juicio humano en asuntos de alto impacto |
| 2 | **Robustez Técnica y Seguridad** | Sistemas seguros, precisos, fiables y resilientes frente al mal uso |
| 3 | **Privacidad y Gobernanza de Datos** | Cumplimiento del GDPR; tratamiento de datos personales lícito, mínimo y con salvaguardas adecuadas |
| 4 | **Transparencia** | Las personas afectadas son informadas del uso de IA en decisiones que les conciernen; sistemas documentados y auditables |
| 5 | **Diversidad y Equidad** | Evaluación de sesgo y discriminación; perspectivas diversas en la adquisición y despliegue de IA |
| 6 | **Bienestar Social y Medioambiental** | Consideración de impactos amplios, incluyendo costes ambientales y efectos en comunidades |
| 7 | **Rendición de Cuentas** | Titularidad clara de riesgos y decisiones de IA; los incidentes se investigan y corrigen |

---

### 2. Estructura Organizativa para la Gobernanza de IA

#### 2.1 Arquitectura de Gobernanza

```
┌─────────────────────────────────────────────────────────────────┐
│                     CONSEJO DE ADMINISTRACIÓN                     │
│        (Supervisión estratégica; aprobación del apetito de       │
│         riesgo; informe trimestral de gobernanza de IA)          │
└──────────────────────────────┬──────────────────────────────────┘
                               │
┌──────────────────────────────▼──────────────────────────────────┐
│                  COMITÉ DE GOBERNANZA DE IA                       │
│   Preside: CEO | Miembros: CTO, DPO, CISO, AI Officer, Legal,  │
│   RR.HH., representante de Finanzas                              │
│   Reuniones: Trimestrales | Reporta: Consejo trimestralmente    │
└────────┬──────────────┬───────────────┬────────────┬────────────┘
         │              │               │            │
┌────────▼───┐  ┌───────▼──────┐  ┌────▼──────┐  ┌─▼──────────┐
│ AI OFFICER  │  │   DPO        │  │  CISO     │  │  LEGAL     │
│             │  │              │  │           │  │            │
│ Operaciones │  │ Protección   │  │ Seguridad │  │ Cumplim.   │
│ diarias IA  │  │ de datos     │  │ y ciber   │  │ regulat.   │
│ y gestión   │  │ y GDPR       │  │           │  │ y disputas │
│ de riesgos  │  │              │  │           │  │            │
└─────┬───────┘  └──────────────┘  └───────────┘  └────────────┘
      │
┌─────▼─────────────────────────────────────────────────┐
│            EQUIPOS DE IMPLEMENTACIÓN DE IA             │
│  (Nivel departamental: Negocio, Tecnología, Operac.)  │
│  AI Champions integrados en cada departamento         │
└───────────────────────────────────────────────────────┘
```

#### 2.2 Órganos de Gobernanza Clave

##### Consejo de Administración

**Responsabilidades:**
- Aprobar la declaración de apetito de riesgo de IA
- Recibir y examinar el Informe Trimestral de Gobernanza de IA
- Exigir al CEO resultados en gobernanza de IA
- Considerar riesgos de IA en decisiones estratégicas

**Reuniones:** Gobernanza de IA como punto fijo en el orden del día trimestral

##### Comité de Gobernanza de IA

**Preside:** CEO (o delegado)

| Miembro | Rol | Voto |
|---------|-----|------|
| CEO (o delegado) | Presidente | Sí |
| CTO | Estrategia tecnológica | Sí |
| DPO | Protección de datos | Sí |
| CISO | Seguridad de la información | Sí |
| AI Officer | Operaciones y cumplimiento IA | Sí |
| Asesor Jurídico | Legal y regulatorio | Sí |
| Director/a de RR.HH. | Personas y cultura | Consultivo |
| Representante de Finanzas | Presupuesto y riesgo | Consultivo |

**Responsabilidades:**
- Revisar y aprobar evaluaciones de riesgo de nuevos sistemas de IA
- Establecer y mantener el apetito de riesgo de IA
- Aprobar políticas de IA y este Marco
- Revisar incidentes materiales de IA y aprobar remediación
- Aprobar el programa anual de auditoría de IA
- Supervisar desarrollos regulatorios e iniciar respuestas de cumplimiento

**Reuniones:** Trimestrales (mínimo); extraordinarias con 5 días hábiles de aviso para incidentes materiales

**Quórum:** Mayoría de miembros con voto, incluido AI Officer y al menos uno entre DPO/CISO

##### AI Officer

**Reporta a:** CTO / CEO

**Responsabilidades:**
- Supervisión operativa diaria de la gobernanza de IA
- Mantenimiento del inventario de sistemas de IA y del registro de riesgos
- Gestión del proceso de aprobación de herramientas de IA
- Coordinación de evaluaciones de riesgo
- Monitorización del rendimiento e incidentes de sistemas de IA
- Reporte al Comité de Gobernanza de IA
- Enlace con la autoridad supervisora nacional (España: AESIA) cuando sea necesario

**Competencias requeridas:** Conocimiento profundo del EU AI Act, comprensión técnica de sistemas IA/ML, experiencia en gestión de riesgos, habilidades de comunicación y gestión de partes interesadas.

##### DPO

- Asesoramiento sobre cumplimiento GDPR para todas las actividades de tratamiento con IA
- Revisión y aprobación de DPIA para sistemas de IA
- Punto de contacto con la AEPD
- Supervisión del cumplimiento de minimización de datos y limitación de finalidad

##### CISO

- Evaluación de riesgos de ciberseguridad de sistemas de IA
- Supervisión de pruebas de seguridad y gestión de vulnerabilidades
- Gestión de incidentes de seguridad relacionados con IA
- Definición de requisitos de seguridad para adquisición de IA

#### 2.3 AI Champions (Nivel Departamental)

Cada departamento designará un AI Champion que:
- Actúa como primer punto de contacto para consultas de IA
- Participa en la Red de AI Champions (reuniones trimestrales)
- Escala riesgos e incidentes al AI Officer
- Apoya el despliegue de formación y actualizaciones de políticas

| Departamento | Nombre del AI Champion | Contacto | Fecha de Nombramiento |
|--------------|----------------------|----------|----------------------|
| [Dept 1] | | | |
| [Dept 2] | | | |
| [Dept 3] | | | |

---

### 3. Inventario de Sistemas de IA

#### 3.1 Requisitos del Inventario

Todos los sistemas de IA (desarrollados internamente, adquiridos o usados como servicio) deben registrarse en el Inventario de Sistemas de IA (mantenido por el AI Officer).

**Información mínima por sistema:**

| Campo | Descripción |
|-------|-------------|
| ID del Sistema | Identificador único (ej. AI-SYS-001) |
| Nombre del Sistema | Nombre descriptivo |
| Proveedor | Interno / nombre del proveedor |
| Categoría de Riesgo EU AI Act | Inaceptable / Alto / Limitado / Mínimo |
| Función Empresarial Principal | Qué hace |
| Alcance del Despliegue | Usuarios / departamentos / cobertura geográfica |
| Datos de Entrada | Tipos de datos tratados |
| Datos de Salida | Tipos de resultados producidos |
| Nivel de Supervisión Humana | Ninguno / Parcial / Completo |
| Estado de Evaluación de Riesgo | No evaluado / En curso / Aprobado / Con condiciones |
| Estado de Revisión DPO | No requerida / En curso / Aprobada |
| Fecha de Despliegue | |
| Última Fecha de Revisión | |
| Próxima Fecha de Revisión | |
| Responsable del Sistema | Persona designada |

#### 3.2 Clasificación de Riesgo según EU AI Act

| Categoría | Definición | Ejemplos | Requisitos |
|-----------|-----------|----------|-----------|
| **Riesgo Inaceptable** | Prohibido (Art. 5) | Puntuación social por autoridades públicas; vigilancia biométrica en tiempo real en espacios públicos; manipulación subliminal | No debe usarse |
| **Riesgo Alto** | Potencial de daño significativo (Anexo III) | IA en selección de personal, decisiones crediticias, infraestructuras críticas, evaluación educativa, aplicación de la ley | Cumplimiento completo (Art. 9-15) incluida evaluación de conformidad |
| **Riesgo Limitado** | Obligaciones específicas de transparencia | Chatbots (deben revelar naturaleza IA); deepfakes; reconocimiento de emociones | Obligaciones de transparencia (Art. 50) |
| **Riesgo Mínimo** | Riesgo mínimo para derechos o seguridad | Filtros de spam, videojuegos con IA, herramientas de productividad | Sin requisitos obligatorios (códigos voluntarios recomendados) |

---

### 4. Sistema de Gestión de Riesgos

#### 4.1 Declaración de Apetito de Riesgo de IA

> "[NOMBRE DE LA ORGANIZACIÓN] acepta el uso de herramientas y sistemas de IA que aporten valor empresarial demostrable y puedan operarse cumpliendo la legislación aplicable y nuestros principios éticos. Tenemos **baja tolerancia** a daños a individuos, daño reputacional por mal uso de IA e incumplimiento regulatorio. Tenemos **tolerancia moderada** a fallos operativos de IA detectables y remediables sin daño material. Tenemos **tolerancia cero** al uso de sistemas de IA categorizados como riesgo inaceptable bajo el EU AI Act."

**Umbrales de apetito de riesgo:**

| Tipo de Riesgo | Nivel de Tolerancia | Respuesta |
|----------------|--------------------|-----------| 
| Brecha de datos personales vía IA | Muy baja | Suspensión inmediata; respuesta a incidentes; notificación regulatoria |
| Resultado discriminatorio de IA | Muy baja | Suspensión inmediata; investigación; corrección de causa raíz |
| Error operativo de IA (bajo impacto) | Moderada | Registrar; investigar; remediar dentro de SLA |
| Incumplimiento regulatorio | Muy baja | Escalado inmediato a Legal; plan de remediación en 5 días |
| Daño reputacional | Baja | Escalado inmediato a CEO; plan de comunicación |
| Sobrecoste de IA | Moderada | Notificación a CFO; revisión presupuestaria |

#### 4.2 Proceso de Evaluación de Riesgos

```
Paso 1: IDENTIFICAR
  ↓ Completar Formulario de Registro de Sistema de IA (Anexo A)
  ↓ AI Officer realiza cribado inicial de riesgo (3-5 días hábiles)

Paso 2: EVALUAR
  ↓ Evaluación completa si el cribado indica riesgo Medio o superior
  ↓ DPO realiza DPIA si hay datos personales
  ↓ CISO realiza evaluación de seguridad
  ↓ Legal revisa la clasificación regulatoria

Paso 3: DECIDIR
  ↓ Revisión del Comité para sistemas de riesgo Alto/Inaceptable
  ↓ Aprobación del AI Officer para riesgo Bajo/Mínimo
  ↓ Decisión documentada con condiciones (si las hay)

Paso 4: IMPLEMENTAR
  ↓ Medidas técnicas y organizativas implementadas
  ↓ Formación de usuarios completada
  ↓ Plan de monitorización establecido
  ↓ Sistema añadido al inventario

Paso 5: MONITORIZAR
  ↓ Monitorización continua del rendimiento
  ↓ Registro de incidentes
  ↓ Revisión periódica (anual mínimo; semestral para riesgo Alto)
```

#### 4.3 Registro de Riesgos de IA

| ID Riesgo | Sistema IA | Descripción del Riesgo | Probabilidad (1-5) | Impacto (1-5) | Puntuación | Controles | Riesgo Residual | Responsable | Fecha Revisión |
|-----------|-----------|----------------------|--------------------|--------------|-----------|-----------|-----------------|-----------|----|
| AIR-001 | | | | | | | | | |

**Escala de Probabilidad:** 1 = Rara, 2 = Improbable, 3 = Posible, 4 = Probable, 5 = Casi segura
**Escala de Impacto:** 1 = Insignificante, 2 = Menor, 3 = Moderado, 4 = Mayor, 5 = Catastrófico
**Puntuación = Probabilidad x Impacto**
**Umbral de apetito de riesgo:** Puntuaciones >= 12 requieren escalado inmediato al Comité

---

### 5. Procesos de Toma de Decisiones

#### 5.1 Adopción de Nuevos Sistemas de IA

```
Unidad de Negocio identifica necesidad de sistema de IA
          ↓
AI Champion envía Solicitud al AI Officer
          ↓
AI Officer realiza cribado de riesgo (5 días hábiles)
          ↓
         /  \
  Riesgo bajo  Riesgo alto/desconocido
        ↓            ↓
  AI Officer    Paquete de evaluación
  aprueba       completa:
  (con            - Evaluación de riesgo
  condiciones)    - DPIA (si hay DP)
                  - Revisión de seguridad
                  - Revisión legal
                         ↓
                 Comité de Gobernanza de IA
                 revisa y decide
                         ↓
                    Aprobar / Rechazar /
                    Aprobar con condiciones
```

**Plazos objetivo:**
- Cribado inicial: 5 días hábiles
- Aprobación riesgo bajo: 10 días hábiles
- Revisión del Comité para riesgo alto: 20 días hábiles

#### 5.2 Respuesta a Incidentes de IA

| Severidad | Definición | Respuesta Inicial | Escalado |
|-----------|-----------|-------------------|----------|
| **P1 — Crítico** | Brecha de datos personales; uso prohibido; daño inminente | Suspensión inmediata del sistema; notificar al AI Officer en 1 hora | CEO + DPO + Legal en 2 horas |
| **P2 — Alto** | Resultado discriminatorio significativo; casi-brecha de datos; fallo orientado al cliente | Revisión del sistema en 4 horas; AI Officer notificado | Comité en 24 horas |
| **P3 — Medio** | Resultados incorrectos repetidos; incumplimiento de política por usuario; problema de proveedor | Investigar en 24 horas; AI Officer notificado | AI Champion + Responsable directo |
| **P4 — Bajo** | Error aislado; sin datos ni daño involucrado | Registrar e investigar en 5 días hábiles | AI Champion supervisa |

#### 5.3 Matriz de Escalado

| Situación | Escalar A | Por | Plazo |
|-----------|----------|-----|-------|
| Brecha de datos personales vía IA | DPO → CISO → CEO | AI Champion / Usuario | Inmediatamente |
| Sospecha de uso prohibido de IA | AI Officer → Legal → CEO | Cualquier empleado | En 1 hora |
| Sistema de alto riesgo fuera de parámetros | AI Officer → CTO | Responsable del sistema | En 4 horas |
| Consulta regulatoria sobre IA | Legal → CEO | Cumplimiento / Destinatario | Inmediatamente |
| Incidente de seguridad del proveedor | CISO → AI Officer | TI / Responsable del sistema | En 2 horas |
| Incumplimiento de política de IA por empleado | RR.HH. → Responsable directo → AI Officer | Responsable directo | En 24 horas |

---

### 6. Monitorización y Rendimiento

#### 6.1 Requisitos de Monitorización Continua

| Categoría del Sistema | Frecuencia | Métricas | Responsable |
|----------------------|-----------|---------|------------|
| Sistemas de IA de alto riesgo | Continua automatizada + revisión humana semanal | Precisión, tasas de falsos positivos/negativos, indicadores de sesgo, disponibilidad | Responsable del sistema + AI Officer |
| IA orientada al cliente | Diaria | Tasa de error, tasa de escalado, sentimiento, quejas | Responsable + Atención al Cliente |
| Herramientas internas de IA | Mensual | Estadísticas de uso, recuento de incidentes, retroalimentación de usuarios | AI Officer |
| Todos los sistemas de IA | Trimestral | Revisión del registro de riesgos, rendimiento vs. línea base | AI Officer |

#### 6.2 Indicadores Clave de Rendimiento

| KPI | Objetivo | Método de Medición | Frecuencia |
|-----|---------|-------------------|-----------|
| % sistemas de IA con evaluaciones de riesgo vigentes | 100% | Revisión del inventario | Trimestral |
| Tiempo de respuesta a incidentes (P1) | <2 horas desde detección | Registro de incidentes | Mensual |
| Tasa de finalización de formación obligatoria en IA | >95% | Sistema de RR.HH. | Trimestral |
| Brechas GDPR relacionadas con IA notificadas a AEPD | 0 | Registros AEPD/DPO | Anual |
| % empleados conocedores de la política de IA | >90% (encuestados) | Encuesta anual | Anual |
| Instancias de Shadow AI detectadas | Objetivo: tendencia a 0 | Monitorización TI + auditorías | Trimestral |
| Quórum alcanzado en el Comité | 100% de reuniones | Actas del Comité | Trimestral |

#### 6.3 Estructura de Informes

| Informe | Contenido | Elaborado por | Destinatario | Frecuencia |
|---------|----------|--------------|-------------|-----------|
| **Dashboard Operativo de IA** | Estado de sistemas, incidentes, uso | AI Officer | AI Officer | Semanal |
| **Informe del Comité** | Registro de riesgos, incidentes, KPIs, actualizaciones de políticas, novedades regulatorias | AI Officer | Comité | Trimestral |
| **Informe de IA para el Consejo** | Resumen ejecutivo: postura de riesgo, incidentes materiales, estado regulatorio, iniciativas estratégicas | AI Officer (aprobado por CEO) | Consejo | Trimestral |
| **Informe de Auditoría de IA** | Hallazgos y recomendaciones de auditoría independiente anual | Auditor Interno/Externo | Comité + Consejo | Anual |
| **Notificaciones Regulatorias** | Notificaciones a AEPD, AESIA según proceda | DPO / Legal | Autoridades regulatorias | Según proceda |

---

### 7. Calendario de Auditorías

#### 7.1 Programa Interno de Auditoría de IA

| Trimestre | Foco de Auditoría | Auditor | Entregable |
|-----------|-------------------|---------|-----------|
| T1 | Precisión y completitud del inventario; calidad de evaluaciones de riesgo | Auditoría Interna | Informe de hallazgos + respuesta de la dirección |
| T2 | Cumplimiento de protección de datos para sistemas de IA (calidad GDPR/DPIA) | Auditoría Interna + DPO | Informe de brechas de cumplimiento |
| T3 | Controles técnicos y seguridad para sistemas de IA | CISO / Auditoría TI | Hallazgos de seguridad + plan de remediación |
| T4 | Cumplimiento de políticas (comportamiento de usuarios, formación, Shadow AI) | RR.HH. + AI Officer + Auditoría Interna | Informe de cumplimiento + revisión del programa anual |

#### 7.2 Auditoría Externa de IA

Se realizará una auditoría externa independiente:
- Anualmente (para organizaciones con sistemas de IA de alto riesgo bajo el EU AI Act)
- Cuando lo requieran los reguladores
- Tras un incidente material de IA

**Alcance:** Cumplimiento EU AI Act, cumplimiento GDPR, eficacia del marco de gobernanza, robustez técnica de sistemas de alto riesgo.

#### 7.3 Gestión de Hallazgos de Auditoría

| Severidad del Hallazgo | Plazo de Respuesta | Escalado |
|------------------------|-------------------|----------|
| Crítico | Suspensión inmediata; plan de remediación en 5 días | CEO + Consejo |
| Alto | Plan de remediación en 15 días hábiles | Comité |
| Medio | Plan de remediación en 30 días hábiles | AI Officer |
| Bajo | Remediación en el próximo ciclo de planificación | Responsable del sistema |

Todos los hallazgos se registran en el Registro de Hallazgos de Auditoría (Auditoría Interna). El progreso se reporta al Comité trimestralmente.

---

### 8. Gestión del Cumplimiento Regulatorio

#### 8.1 Normativa Aplicable

| Regulación | Alcance | Responsable Principal | Frecuencia de Revisión |
|-----------|--------|----------------------|----------------------|
| EU AI Act (Reglamento (UE) 2024/1689) | Todos los sistemas de IA | AI Officer + Legal | Continua — plenamente aplicable desde agosto 2026 |
| GDPR (Reglamento (UE) 2016/679) | Todo tratamiento de IA con datos personales | DPO | Continua |
| LOPDGDD (Ley Orgánica 3/2018) | Operaciones en España | DPO | Anual |
| Directiva de Responsabilidad por IA de la UE (propuesta) | Responsabilidad por daños causados por IA | Legal | Al adoptarse |
| Regulación sectorial | [Insertar normas sectoriales aplicables] | Legal + Cumplimiento | Anual |

#### 8.2 Proceso de Vigilancia Regulatoria

Legal, con el apoyo del AI Officer, supervisa:
- Diario Oficial de la UE para nueva legislación sobre IA
- Orientaciones y decisiones de AESIA
- Orientaciones de AEPD sobre IA y protección de datos
- Dictámenes del EDPB sobre IA
- Directrices y normas de la Comisión Europea sobre IA

Los desarrollos regulatorios significativos se escalan al Comité en 10 días hábiles desde su publicación.

#### 8.3 Contactos de Autoridades Supervisoras

| Autoridad | Jurisdicción | Contacto | Propósito |
|-----------|-------------|----------|----------|
| AESIA | España — aplicación EU AI Act | [www.aesia.es] | Notificaciones e incidentes EU AI Act |
| AEPD | España — aplicación GDPR | [www.aepd.es] | Brechas de datos, consultas DPIA |
| EDPB | UE — GDPR transfronterizo | [www.edpb.europa.eu] | Asuntos transfronterizos |

---

### 9. Documentación y Registros

#### 9.1 Retención de Documentos

| Documento | Período de Retención | Ubicación | Responsable |
|-----------|---------------------|-----------|------------|
| Inventario de Sistemas de IA | Indefinidamente (versión actual) + 5 años histórico | [Sistema] | AI Officer |
| Evaluaciones de Riesgo | 10 años desde desmantelamiento del sistema | [Sistema] | AI Officer |
| DPIAs | 3 años desde última revisión (mínimo) | [Sistema] | DPO |
| Informes de Incidentes | 5 años | [Sistema] | AI Officer + DPO |
| Registros de Formación | Duración del empleo + 5 años | Sistema RR.HH. | RR.HH. |
| Informes de Auditoría | 7 años | [Sistema] | Auditoría Interna |
| Actas de Comités | 7 años | Secretaría del Consejo/Comité | AI Officer |

#### 9.2 Control de Documentos

Este Marco y todos los documentos de política asociados están:
- Controlados por versiones
- Almacenados en [Sistema de Gestión Documental]
- Accesibles para todos los empleados vía [enlace intranet]
- Sujetos a procedimientos formales de gestión de cambios

---

### 10. Revisión y Actualización del Marco

Este Marco se revisará:
- Anualmente (en [MES] de cada año)
- Tras cualquier cambio significativo en la legislación aplicable
- Tras un incidente material o cuasi-incidente de IA
- Cuando la huella de IA de la Organización cambie materialmente

La revisión es liderada por el AI Officer con aportaciones del DPO, CISO y Legal. Las versiones revisadas requieren aprobación del Comité de Gobernanza de IA.

---

### Anexo A — Formulario de Registro de Sistema de IA

**Nombre del Sistema:**
**Unidad de Negocio:**
**Responsable del Sistema:**
**Fecha de Registro:**
**Descripción Breve:**
**Proveedor:**
**Usuarios Previstos:**
**Datos de Entrada:**
**Datos de Salida:**
**¿Trata datos personales?** Sí / No
**Categoría de Riesgo EU AI Act Estimada (evaluación inicial):** Inaceptable / Alto / Limitado / Mínimo / Desconocido
**Fecha Prevista de Puesta en Marcha:**
**Justificación Empresarial:**

---

### Anexo B — Registro de Cambios del Marco

| Versión | Fecha | Modificado Por | Resumen de Cambios | Aprobado Por |
|---------|-------|---------------|--------------------|----|
| 1.0 | [FECHA] | [Nombre] | Versión inicial | [Nombre, Cargo] |

---

**Pie de documento:**
*Plantilla proporcionada por VORLUX AI | vorluxai.com*
*Este documento es solo orientativo, no constituye asesoramiento jurídico.*
*Versión 1.0 | Para cumplimiento del EU AI Act | Última actualización: 2026-04-05*

---

# AI Incident Response Plan Template
_Plantilla de plan de respuesta a incidentes de IA_

> Comprehensive AI incident response plan covering incident categories, severity levels, response procedures, reporting obligations under EU AI Act Article 73, and post-incident review processes.
> Online: https://vorluxai.com/templates/ai-incident-response/

> **Disclaimer:** This template is provided for guidance purposes only. It does not constitute legal advice. Organisations should consult qualified legal counsel to ensure compliance with applicable laws and regulations.
>
> *Template provided by VORLUX AI — vorluxai.com*

---

## AI Incident Response Plan
### EU AI Act — Article 73 Compliance Template

**Organisation:** _______________
**Document Reference:** AIRP-[YYYY]-[NNN]
**Version:** _______________
**Prepared by:** _______________
**Approved by:** _______________
**Effective Date:** _______________
**Review Date:** _______________

---

### Section 1: Purpose and Scope

#### 1.1 Purpose

This plan defines how **[Organisation Name]** identifies, classifies, responds to, reports, and learns from incidents involving AI systems. It ensures compliance with Article 73 of the EU AI Act (serious incident reporting) and supports the organisation's broader risk management obligations.

#### 1.2 Scope

This plan applies to:
- All AI systems operated by the organisation in a deployer capacity
- All AI systems developed or provided by the organisation
- All staff, contractors, and third parties involved in operating or monitoring AI systems

**AI Systems Covered:**

| System Name | Risk Classification | System Owner | Version |
|-------------|-------------------|--------------|---------|
| | ☐ High-risk ☐ Limited ☐ Minimal | | |
| | ☐ High-risk ☐ Limited ☐ Minimal | | |
| | ☐ High-risk ☐ Limited ☐ Minimal | | |

#### 1.3 Regulatory Context

Under Article 73, providers of high-risk AI systems must report serious incidents to the relevant national market surveillance authority. A **serious incident** is defined as an incident or malfunctioning of an AI system that, directly or indirectly, leads to:

- The death of a person or serious damage to a person's health
- A serious and irreversible disruption of critical infrastructure
- An infringement of fundamental rights
- Serious damage to property or the environment

**Competent Authority for [Country]:** _______________
**Reporting Portal / Contact:** _______________
**Initial Report Deadline:** 15 working days (life-threatening: 2 working days) after becoming aware

---

### Section 2: Incident Categories

#### 2.1 Category Framework

| Category | Code | Description | Examples |
|----------|------|-------------|---------|
| Safety Incident | CAT-S | AI output causes or risks physical harm | Medical AI misdiagnosis; autonomous system collision |
| Rights Violation | CAT-R | AI output infringes fundamental rights | Discriminatory hiring decision; unlawful profiling |
| Data Incident | CAT-D | AI system involved in data breach, leak, or misuse | Training data exfiltrated; personal data exposed in output |
| System Failure | CAT-F | AI system unavailable, degraded, or behaving unexpectedly | Model crashes; severe accuracy degradation |
| Manipulation / Misuse | CAT-M | AI system used or manipulated for harmful purposes | Adversarial attacks; prompt injection leading to policy violation |
| Compliance Incident | CAT-C | AI system found to be non-compliant with regulation | Missing conformity assessment; prohibited use discovered |
| Transparency Breach | CAT-T | Failure to disclose AI involvement as required | Chatbot not labelled; automated decision not notified |
| Reputational Incident | CAT-P | AI system causes significant public trust harm | Media coverage of biased AI output; customer complaints |

---

### Section 3: Severity Levels

#### 3.1 Severity Classification

| Level | Name | Definition | Response Timeframe |
|-------|------|------------|-------------------|
| **SEV-1** | Critical | Active harm occurring or imminent; fundamental rights severely violated; life at risk | Immediate (< 1 hour) |
| **SEV-2** | High | Serious harm occurred or likely; significant regulatory obligation triggered | < 4 hours |
| **SEV-3** | Medium | Harmful output detected; no immediate harm but risk of escalation | < 24 hours |
| **SEV-4** | Low | Near-miss; policy violation without harm; isolated anomaly | < 5 business days |
| **SEV-5** | Informational | Performance degradation below threshold; curiosity for monitoring | Next review cycle |

#### 3.2 Severity Decision Matrix

Use the following questions to classify severity:

**Step 1 — Has harm already occurred?**
- Death or serious physical injury → **SEV-1**
- Significant financial or psychological harm → **SEV-2**
- Minor harm or harm risk only → **SEV-3 or lower**

**Step 2 — Is a fundamental right involved?**
- Irreversible rights violation → **SEV-1**
- Reversible rights violation → **SEV-2**
- Possible / minor rights impact → **SEV-3**

**Step 3 — Is regulatory reporting triggered?**
- Article 73 reporting threshold met → escalate to **minimum SEV-2**

**Step 4 — Is the system still running and causing harm?**
- Yes → **escalate by one level**; consider immediate shutdown

---

### Section 4: Incident Response Procedures

#### 4.1 Response Team

| Role | Responsibilities | Primary Contact | Backup Contact |
|------|-----------------|----------------|----------------|
| Incident Commander (IC) | Overall incident ownership; decisions on containment and reporting | | |
| AI System Owner | Technical knowledge; system access | | |
| Legal / Compliance | Regulatory reporting; legal exposure assessment | | |
| DPO | Data protection assessment; GDPR obligations | | |
| Communications Lead | Internal and external communications | | |
| IT / Security | System access; logging; technical containment | | |
| Executive Sponsor | Authorises major decisions (shutdown, public disclosure) | | |

**Escalation Hotline (internal):** _______________
**24/7 On-call rotation:** _______________

---

#### 4.2 Phase 1: Detection and Intake (All Severities)

**Detection Sources:**
- [ ] Internal monitoring / alerting system
- [ ] User complaint or report
- [ ] Employee observation
- [ ] Third-party notification (vendor, partner, regulator)
- [ ] Media / social media monitoring
- [ ] Post-incident audit discovery

**Immediate Actions (within first 60 minutes for SEV-1/2):**

1. **Log the incident** in the Incident Register (see Section 7)
2. **Assign an Incident ID:** INC-[YYYY]-[NNN]
3. **Assign an Incident Commander**
4. **Classify severity** using the matrix in Section 3.2
5. **Notify the response team** using communication templates in Section 6
6. **Preserve evidence:** logs, screenshots, model versions, input/output data
7. **Assess whether the AI system must be suspended** (see Section 4.3)

---

#### 4.3 Phase 2: Containment

**Containment Decision Checklist:**

| Question | Yes → Action |
|----------|-------------|
| Is the AI system currently producing harmful outputs? | Suspend or throttle the system immediately |
| Can the root cause be isolated to a specific feature or input type? | Restrict that input type; keep other functions running |
| Is the incident limited to one user/case? | Quarantine that case; continue with enhanced monitoring |
| Is the issue in the underlying model (not just an edge case)? | Full system suspension; notify vendor |
| Has a data breach occurred? | Invoke GDPR breach procedures; notify DPO |

**System Suspension Protocol:**

| Action | Authorised by | Documentation Required |
|--------|--------------|----------------------|
| Suspend AI system for < 4 hours | AI System Owner | Incident log entry |
| Suspend AI system for 4–24 hours | AI System Owner + IC | Incident log + executive notification |
| Suspend AI system for > 24 hours | Executive Sponsor + Legal | Board notification; customer communication |

**Temporary workaround:** _______________

---

#### 4.4 Phase 3: Investigation

**Investigation Checklist:**

- [ ] Identify the precise AI system and version involved
- [ ] Retrieve and preserve input/output logs for the affected period
- [ ] Determine whether the incident is isolated or systemic
- [ ] Identify root cause (data quality, model error, configuration, misuse, infrastructure)
- [ ] Assess scope: how many individuals are affected?
- [ ] Assess duration: when did the incident begin?
- [ ] Review whether safeguards (monitoring, human oversight) failed and why
- [ ] Interview relevant staff
- [ ] Engage vendor if third-party model is involved (see communication template in Section 6)
- [ ] Document all investigation steps with timestamps

**Root Cause Categories:**

| Code | Root Cause | Investigation Focus |
|------|-----------|-------------------|
| RC-01 | Training data issue | Data quality, bias, outdated data |
| RC-02 | Model architecture flaw | Model evaluation reports |
| RC-03 | Prompt / input manipulation | Input validation, security |
| RC-04 | Infrastructure / integration failure | System logs, API calls |
| RC-05 | Human oversight failure | Process review, training records |
| RC-06 | Scope creep / misuse | Usage logs, authorisation records |
| RC-07 | Vendor / third-party failure | SLA review, vendor communication |
| RC-08 | Regulatory gap | Policy and compliance review |

---

#### 4.5 Phase 4: Remediation

**Remediation Plan Template:**

| Issue Identified | Remediation Action | Owner | Deadline | Status |
|------------------|-------------------|-------|----------|--------|
| | | | | ☐ Planned ☐ In progress ☐ Complete |
| | | | | ☐ Planned ☐ In progress ☐ Complete |
| | | | | ☐ Planned ☐ In progress ☐ Complete |

**Before resuming system operation, confirm:**

- [ ] Root cause identified and resolved
- [ ] Affected individuals notified (if required)
- [ ] Regulatory reports submitted (if required)
- [ ] Enhanced monitoring in place
- [ ] Sign-off from Incident Commander, Legal, and AI System Owner

---

#### 4.6 Phase 5: Recovery and Monitoring

**Recovery Checklist:**

- [ ] System reinstated at [date/time]: _______________
- [ ] Enhanced monitoring period defined: _______________ days
- [ ] KPIs and anomaly thresholds reviewed and updated
- [ ] Staff briefed on post-incident monitoring responsibilities
- [ ] Post-incident review scheduled for: _______________

---

### Section 5: Reporting Obligations

#### 5.1 Internal Reporting

| Report Type | Audience | Timing | Template |
|-------------|----------|--------|----------|
| Incident Alert | Response Team | Immediately on detection | Section 6.1 |
| Status Update | Executive Sponsor | Every 4 hours for SEV-1/2 | Section 6.2 |
| Board Notification | Board / Governance | For SEV-1 or regulatory report triggered | Section 6.3 |
| Incident Summary | All stakeholders | Within 5 days of closure | Section 6.4 |

#### 5.2 External Reporting

**Regulatory Reporting (Article 73 — Serious Incidents):**

| Trigger | Timeline | Authority | Method |
|---------|----------|-----------|--------|
| Life-threatening incident | 2 working days | National market surveillance authority | [Portal/contact] |
| Other serious incident | 15 working days | National market surveillance authority | [Portal/contact] |
| Root cause update | As available | Same authority | Follow-up notification |
| Final report | Within 3 months | Same authority | Written report |

**GDPR Reporting (if personal data involved):**

| Trigger | Timeline | Authority | Method |
|---------|----------|-----------|--------|
| Personal data breach | 72 hours | Supervisory Authority (e.g., AEPD for Spain) | [Portal/contact] |
| High risk to individuals | Without undue delay | Affected individuals | Direct notification |

**Affected Individual Notification:**
Required when: ☐ High-risk AI system ☐ Rights violated ☐ Personal data breached ☐ Decision affected them
Notification method: ☐ Email ☐ Letter ☐ In-app ☐ Phone

---

### Section 6: Communication Templates

#### 6.1 Internal Incident Alert

**Subject:** [URGENT] AI Incident Alert — INC-[YYYY]-[NNN] — [System Name] — SEV-[X]

> **AI INCIDENT ALERT**
>
> **Incident ID:** INC-[YYYY]-[NNN]
> **Date/Time:** [DD/MM/YYYY HH:MM]
> **AI System:** [System Name and Version]
> **Severity:** SEV-[1/2/3/4]
> **Category:** [Category Code and Name]
> **Incident Commander:** [Name]
>
> **Summary:** [2–3 sentence description of what has happened]
>
> **Current Status:** [Ongoing / Contained / Resolved]
>
> **Immediate actions taken:**
> - [Action 1]
> - [Action 2]
>
> **Next update by:** [HH:MM]
>
> **Incident bridge/channel:** [Link or number]

---

#### 6.2 Executive Status Update

**Subject:** AI Incident Status Update — INC-[YYYY]-[NNN] — [Time]

> **STATUS UPDATE — [Time]**
>
> **Incident:** INC-[YYYY]-[NNN] | [System Name] | SEV-[X]
> **Update #:** [N]
>
> **Current situation:** [Brief description]
> **Individuals affected:** [Number / Unknown]
> **System status:** ☐ Running normally ☐ Suspended ☐ Partially suspended
> **Regulatory obligation triggered?** ☐ Yes — report due by [date] ☐ No ☐ Under assessment
>
> **Actions completed since last update:**
> - [Action]
>
> **Actions in progress:**
> - [Action]
>
> **Decisions needed from executive sponsor:**
> - [Decision point, if any]
>
> **Next update by:** [Time]

---

#### 6.3 Regulatory Notification Letter (Article 73)

**[Organisation letterhead]**

Date: _______________
To: [National Market Surveillance Authority Name and Address]

**Re: Serious Incident Notification — EU AI Act Article 73**
**Incident Reference:** INC-[YYYY]-[NNN]

Dear [Authority Name / Sir or Madam],

In accordance with Article 73 of Regulation (EU) 2024/1689 (the EU AI Act), we are notifying you of a serious incident involving an AI system for which **[Organisation Name]** is the [provider / deployer].

**1. AI System Details**
- System name and version: _______________
- Risk classification: High-risk (Annex III, category: _______________)
- EU declaration of conformity reference: _______________

**2. Incident Summary**
- Date/time of occurrence: _______________
- Date/time we became aware: _______________
- Nature of incident: _______________
- Categories of persons affected: _______________
- Estimated number of affected individuals: _______________
- Geographical scope: _______________

**3. Immediate Actions Taken**
[Describe containment and mitigation actions]

**4. Ongoing Actions**
[Describe current and planned remediation]

**5. Further Information**
A follow-up report with root cause analysis and final remediation measures will be provided by [date].

We are available for any further questions or information requests. Please contact [Name, Role] at [email / phone].

Yours sincerely,

_______________
[Name]
[Title / AI Officer / DPO]
[Organisation]

---

#### 6.4 Affected Individual Notification

**Subject:** Important notice regarding an AI system that affected you

> Dear [Name / Customer],
>
> We are writing to let you know that an incident occurred involving an artificial intelligence system used by **[Organisation Name]** that may have affected [you / a decision made about you / your data].
>
> **What happened:**
> [Plain language description of the incident]
>
> **How it affected you:**
> [Explain the specific impact on this individual]
>
> **What we have done:**
> [List actions taken to contain and remediate]
>
> **What you can do:**
> - If a decision was made about you using AI, you have the right to request a human review of that decision.
> - You may request further information about how AI was used.
> - You may contact our AI Officer at **[contact details]** with any questions.
>
> We sincerely apologise for any inconvenience or harm caused.
>
> [Name, Role]
> [Organisation]
> [Date]

---

#### 6.5 Vendor Notification

**Subject:** AI Incident Notification — [System Name] — INC-[YYYY]-[NNN]

> Dear [Vendor Contact],
>
> We are writing to notify you of an incident involving **[System Name / API / Model]** provided by your organisation and deployed by us in [context].
>
> **Incident reference:** INC-[YYYY]-[NNN]
> **Date/time of incident:** _______________
> **Nature of incident:** [Brief description]
>
> We require the following from you as a matter of urgency:
> 1. Confirmation of whether this issue is known or has affected other customers
> 2. Relevant system logs for the period [start time] to [end time]
> 3. Preliminary root cause assessment by [deadline]
> 4. Your incident response contact and escalation path
>
> Please treat this as priority. Respond to [name] at [email] within [timeframe].
>
> [Name, Role]
> [Organisation]

---

### Section 7: Incident Register

Use the table below (or integrate with your GRC/ITSM platform) to maintain a log of all AI incidents.

| Incident ID | Date | System | Category | Severity | Status | Regulatory Report? | IC | Date Closed |
|------------|------|--------|----------|----------|--------|-------------------|-----|-------------|
| INC-[YYYY]-001 | | | | | ☐ Open ☐ Closed | ☐ Yes ☐ No | | |
| INC-[YYYY]-002 | | | | | ☐ Open ☐ Closed | ☐ Yes ☐ No | | |

**Retention:** Incident records must be retained for a minimum of 5 years.

---

### Section 8: Post-Incident Review

#### 8.1 Review Process

A post-incident review (PIR) must be conducted for all SEV-1 to SEV-3 incidents within 10 business days of incident closure.

**PIR Meeting Agenda:**

1. Incident timeline (15 min)
2. Root cause walkthrough (20 min)
3. What went well (10 min)
4. What could have been better (15 min)
5. Action items and owners (15 min)
6. Policy / process updates required (10 min)
7. Training updates required (5 min)

#### 8.2 Post-Incident Review Report

**Incident ID:** _______________
**PIR Date:** _______________
**Facilitator:** _______________
**Attendees:** _______________

| Section | Summary |
|---------|---------|
| Root Cause (confirmed) | |
| Contributing factors | |
| Detection time | |
| Response time | |
| Containment time | |
| Total impact (individuals, duration) | |
| Regulatory notifications made | |
| What worked well | |
| What needs improvement | |

**Action Items from PIR:**

| Action | Owner | Deadline | Status |
|--------|-------|----------|--------|
| | | | |
| | | | |
| | | | |

**Policy or process updates triggered:** ☐ Yes (specify): _______________ ☐ No
**Training updates triggered:** ☐ Yes (specify): _______________ ☐ No
**FRIA update triggered:** ☐ Yes ☐ No

---

### Section 9: Plan Review and Maintenance

| Review Trigger | Action |
|----------------|--------|
| Annually | Full plan review |
| After any SEV-1 or SEV-2 incident | Review and update affected sections |
| New AI system deployed | Verify coverage; update system registry |
| Regulatory update | Review reporting obligations |
| Change in team structure | Update contact details |

**Last reviewed:** _______________
**Approved by:** _______________

---

*Template provided by VORLUX AI | vorluxai.com*
*Version 1.0 — April 2026 | EU AI Act Article 73 compliant template*
*This is guidance only, not legal advice. Consult qualified legal counsel for your specific situation.*

---

### Versión Española

**Aviso:** Este plantilla se proporciona solo con fines de orientación. No constituye asesoramiento legal. Las organizaciones deben consultar a abogados calificados para asegurarse de que cumplan con las leyes y regulaciones aplicables.

---

## Plan de respuesta a incidentes de IA
### Cumplimiento del artículo 73 del Reglamento de IA de la UE — Plantilla de cumplimiento

**Organización:** _______________
**Referencia del documento:** AIRP-[YYYY]-[NNN]
**Versión:** _______________
**Preparado por:** _______________
**Aprobado por:** _______________
**Fecha de entrada en vigor:** _______________
**Fecha de revisión:** _______________

---

### Sección 1: Propósito y alcance

#### 1.1 Propósito

Este plan define cómo **[Nombre de la organización]** identifica, clasifica, responde a, reporta y aprende de los incidentes que involucran sistemas de IA. Garantiza el cumplimiento del artículo 73 del Reglamento de IA de la UE (informe sobre incidentes graves) y apoya las obligaciones de gestión de riesgos más amplias de la organización.

#### 1.2 Alcance

Este plan se aplica a:
- Todos los sistemas de IA operados por la organización en una capacidad de proveedor
- Todos los sistemas de IA desarrollados o proporcionados por la organización
- Todo el personal, contratistas y terceros involucrados en la operación o monitoreo de sistemas de IA

**Sistemas de IA cubiertos:**

| Nombre del sistema | Clasificación de riesgo | Propietario del sistema | Versión |
|-------------------|----------------------|------------------------|---------|
|                    | ☐ Alto riesgo ☐ Limitado ☐ Mínimo |                        |         |
|                    | ☐ Alto riesgo ☐ Limitado ☐ Mínimo |                        |         |
|                    | ☐ Alto riesgo ☐ Limitado ☐ Mínimo |                        |         |

#### 1.3 Contexto regulatorio

Según el artículo 73, los proveedores de sistemas de IA de alto riesgo deben informar sobre incidentes graves a la autoridad competente nacional correspondiente. Un **incidente grave** se define como un incidente o falla en un sistema de IA que, directa o indirectamente, lleva a:

- La muerte de una persona o daño grave a la salud de una persona
- Una interrupción grave e irreversible de infraestructura crítica
- Infracción de derechos fundamentales
- Daños graves a la propiedad o al medio ambiente

**Autoridad competente para [País]:** _______________
**Portal de informes / Contacto:** _______________
**Plazo límite para el informe inicial:** 15 días hábiles (vida en peligro: 2 días hábiles) después de que se tenga conocimiento

---

### Sección 2: Categorías de incidentes

#### 2.1 Marco de categorías

| Categoría | Código | Descripción | Ejemplos |
|-----------|--------|-------------|---------|
| Incidente de seguridad | CAT-S | Salida de IA que causa o pone en riesgo daño físico | Diagnóstico médico incorrecto; colisión del sistema autónomo |
| Violación de derechos | CAT-R | Salida de IA que infringe derechos fundamentales | Decisión de contratación discriminatoria; perfilaje ilegal |
| Incidente de datos | CAT-D | Sistema de IA involucrado en robo, filtración o uso inadecuado de datos | Exfiltración de datos de entrenamiento; exposición de datos personales en la salida |
| Falla del sistema | CAT-F | Sistema de IA no disponible, degradado o comportándose de manera inesperada | Colapso del modelo; degradación severa de precisión |
| Manipulación / Uso inadecuado | CAT-M | Sistema de IA utilizado o manipulado con fines perjudiciales | Ataque adversarial; inyección de promt que lleva a violación de política |
| Incidente de cumplimiento | CAT-C | Sistema de IA no cumple con la regulación | Faltan evaluaciones de conformidad; uso prohibido descubierto |
| Incumplimiento de transparencia | CAT-T | Falta de divulgación de la participación de IA como se requiere | Chatbot sin etiquetado; decisión automática no notificada |
| Incidente reputacional | CAT-P | Sistema de IA causa daño significativo a la confianza pública | Cobertura mediática de salida sesgada de IA; quejas del cliente |

---

### Sección 3: Niveles de gravedad

#### 3.1 Clasificación de severidad

| Nivel | Nombre | Definición | Plazo de respuesta |
|-------|--------|-------------|-------------------|
| **SEV-1** | Crítico | Daño activo o inminente; derechos fundamentales gravemente violados; vida en peligro | Inmediato (< 1 hora) |
| **SEV-2** | Alto | Daño grave ocurrido o probable; obligación regulatoria significativa desencadenada | < 4 horas |
| **SEV-3** | Medio | Salida dañina detectada; no hay daño inmediato pero existe riesgo de escalada | < 24 horas |
| **SEV-4** | Bajo | Cuasi incidente; incumplimiento de política sin daño; anomalía aislada | < 5 días hábiles |
| **SEV-5** | Informativo | Degradación del rendimiento por debajo del umbral; hallazgo a vigilar | Siguiente ciclo de revisión |

> **Nota sobre esta versión.** La traducción al español cubre hasta la clasificación de severidad.
> El procedimiento completo — matriz de decisión (3.2), flujo de respuesta, plantillas de informe
> al artículo 73 y registro posterior al incidente — está en la versión inglesa de esta misma
> página. Estamos completando la traducción; si la necesita antes,
> [escríbanos](../../contact/) y se la enviamos.

---

*Plantilla de VORLUX AI | vorluxai.com | Basada en el artículo 73 del Reglamento (UE) 2024/1689 de IA*
*Esta plantilla tiene carácter orientativo y no constituye asesoramiento jurídico.*

---

# AI Literacy Training Plan Template
_Plantilla de plan de formación en alfabetización en IA_

> Structured AI literacy training plan for organisations deploying AI systems under EU AI Act Article 4, covering role-based objectives, module descriptions, and competency levels.
> Online: https://vorluxai.com/templates/ai-literacy-training/

> **Disclaimer:** This template is provided for guidance purposes only. It does not constitute legal advice. Organisations should consult qualified legal counsel to ensure compliance with applicable laws and regulations.
>
> *Template provided by VORLUX AI — vorluxai.com*

---

## AI Literacy Training Plan
### EU AI Act — Article 4 Compliance Template

**Organisation:** _______________
**Document Reference:** AITP-[YYYY]-[NNN]
**Version:** _______________
**Prepared by:** _______________
**Approved by:** _______________
**Effective Date:** _______________
**Review Date:** _______________

---

### Section 1: Purpose and Legal Basis

Article 4 of the EU AI Act (Regulation 2024/1689), as replaced by Regulation (EU) 2026/1744 from 27 July 2026, requires providers and deployers of AI systems to take measures to support AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf — contractors, service providers, even clients — taking into account their technical knowledge, experience, education and training and the context the systems are used in. No specific or "sufficient" level is mandated, and no certificate is needed: the European Commission states that an internal record of trainings and other initiatives is enough ([AI Literacy Q&A](https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers)). The duty has applied since 2 February 2025, and national authorities supervise it from 2 August 2026. This plan is that record.

This training plan documents how **[Organisation Name]** meets this obligation.

**AI Systems in Scope:**

| System Name | Risk Classification | Primary Users | Go-Live Date |
|-------------|-------------------|---------------|--------------|
| | ☐ High-risk ☐ Limited ☐ Minimal | | |
| | ☐ High-risk ☐ Limited ☐ Minimal | | |
| | ☐ High-risk ☐ Limited ☐ Minimal | | |

---

### Section 2: Competency Framework

#### 2.1 Competency Levels

This organisation defines three AI literacy competency levels:

---

**Level 1 — Basic (Foundation)**

> *Target audience: All employees who may encounter AI-generated outputs or work in environments where AI systems operate.*

Core competencies at this level:
- Understands what AI is and what it is not (limitations, errors, hallucinations)
- Can identify when AI is being used in a process or tool
- Knows their right to request human review of AI decisions
- Understands basic data privacy considerations when using AI tools
- Knows how to report AI-related concerns internally

**Assessment threshold:** 70% on foundation assessment

---

**Level 2 — Intermediate (Practitioner)**

> *Target audience: Employees who regularly use AI systems as part of their role, including HR practitioners, customer service agents, analysts, and operations staff.*

Core competencies at this level:
- All Level 1 competencies, plus:
- Understands AI risk categories under the EU AI Act (prohibited practices, high-risk, transparency obligations, minimal risk)
- Can identify potential bias in AI outputs and apply critical evaluation
- Knows the organisation's AI governance policies and escalation procedures
- Understands data quality requirements for AI systems
- Can apply the organisation's human oversight protocols
- Understands transparency obligations to affected individuals

**Assessment threshold:** 75% on practitioner assessment

---

**Level 3 — Expert (Governance & Technical)**

> *Target audience: AI system developers, data scientists, compliance officers, legal counsel, senior managers, and AI governance board members.*

Core competencies at this level:
- All Level 1 and Level 2 competencies, plus:
- Deep knowledge of the EU AI Act obligations by actor type (provider, deployer, importer)
- Ability to conduct or review Fundamental Rights Impact Assessments
- Technical understanding of model evaluation, bias testing, and performance metrics
- Knows conformity assessment procedures and CE marking requirements
- Understands post-market monitoring obligations
- Can interpret AI audit logs and incident reports
- Understands international AI regulatory landscape (UK, USA, China, etc.)

**Assessment threshold:** 80% on expert assessment + practical case study

---

#### 2.2 Competency Mapping by Role

| Role | Required Level | Training Track |
|------|---------------|----------------|
| All employees (general) | Level 1 | Foundation Track |
| Executive / Senior Management | Level 2 | Leadership Track |
| HR / People Teams | Level 2 | Practitioner Track |
| Customer Service / Operations | Level 2 | Practitioner Track |
| Marketing / Communications | Level 1–2 | Practitioner Track |
| Finance / Procurement | Level 2 | Practitioner Track |
| Legal / Compliance | Level 3 | Expert Track |
| IT / Data Engineering | Level 3 | Expert Track |
| Data Scientists / ML Engineers | Level 3 | Expert Track |
| Product Managers (AI products) | Level 3 | Expert Track |
| AI Governance Board | Level 3 | Expert Track |
| DPO / AI Officer | Level 3 | Expert Track |

---

### Section 3: Learning Objectives by Role

#### 3.1 All Staff — Foundation Objectives

By the end of the Foundation Track, participants will be able to:

- [ ] Define artificial intelligence and distinguish it from traditional software
- [ ] Explain in plain terms what machine learning and generative AI mean
- [ ] Recognise signs that an AI system may be producing inaccurate or biased outputs
- [ ] State their rights as an individual subject to AI-assisted decisions
- [ ] Identify the organisation's AI usage policies
- [ ] Know who to contact with AI-related questions or concerns
- [ ] Describe the basic concept of data privacy and why it matters in AI contexts

---

#### 3.2 Practitioners — Additional Objectives

By the end of the Practitioner Track, participants will also be able to:

- [ ] Identify the EU AI Act risk tier of each AI system they use
- [ ] Apply structured critical thinking when reviewing AI outputs (SCAT framework: Source, Confidence, Alternatives, Traceability)
- [ ] Execute the human oversight protocol for their specific AI system(s)
- [ ] Document and escalate AI incidents using the organisation's procedure
- [ ] Explain transparency requirements to customers or clients
- [ ] Recognise discriminatory or unfair patterns in AI recommendations
- [ ] Complete a post-decision review when overriding an AI recommendation

---

#### 3.3 Experts — Additional Objectives

By the end of the Expert Track, participants will also be able to:

- [ ] Interpret the EU AI Act Articles 9–17 (technical documentation, data governance, accuracy requirements)
- [ ] Design and interpret a bias/fairness audit report
- [ ] Conduct a FRIA or a Data Protection Impact Assessment (DPIA) for an AI system
- [ ] Evaluate vendor AI claims against regulatory standards
- [ ] Write AI governance policy and internal standards
- [ ] Brief executives, regulators, or auditors on AI compliance posture
- [ ] Manage an AI incident response from detection to post-incident review

---

### Section 4: Training Modules

#### Module 1: What is AI? (Foundation — All Staff)

| Parameter | Detail |
|-----------|--------|
| Duration | 45 minutes |
| Format | ☐ E-learning ☐ Live workshop ☐ Blended |
| Delivery | Self-paced |
| Frequency | Once on onboarding; annually refreshed |
| Prerequisites | None |

**Topics covered:**
1. History and current state of AI
2. How machine learning models are trained
3. What AI can and cannot do (limitations and risks)
4. Generative AI: capabilities, risks, hallucination
5. AI in everyday tools (email, search, HR systems)
6. Real-world AI mistakes and their consequences

**Knowledge check questions (sample):**
- What is the key difference between a rule-based system and a machine learning model?
- Give two examples of tasks where AI tends to make errors.
- What should you do if you suspect an AI recommendation is incorrect?

---

#### Module 2: AI at Our Organisation (Foundation — All Staff)

| Parameter | Detail |
|-----------|--------|
| Duration | 30 minutes |
| Format | ☐ E-learning ☐ Live workshop ☐ Blended |
| Delivery | Self-paced |
| Frequency | Once on onboarding; updated when new systems are deployed |
| Prerequisites | Module 1 |

**Topics covered:**
1. Which AI systems our organisation uses and why
2. How AI outputs influence our work processes
3. Our AI usage policy and code of conduct
4. Data privacy basics when using AI tools
5. How to report a concern or raise a question

---

#### Module 3: EU AI Act — What It Means for You (Foundation + Practitioner)

| Parameter | Detail |
|-----------|--------|
| Duration | 60 minutes |
| Format | ☐ E-learning ☐ Live workshop ☐ Blended |
| Delivery | Recommended: live with Q&A |
| Frequency | Annually or when regulation updates |
| Prerequisites | Module 1 |

**Topics covered:**
1. What is the EU AI Act and when does it apply?
2. Risk tiers: prohibited practices, high-risk, transparency obligations, minimal risk
3. Rights of individuals affected by AI (transparency, human review, redress)
4. Our obligations as a deployer
5. Prohibited AI practices: social scoring, manipulation, real-time biometric surveillance
6. Penalties for non-compliance

---

#### Module 4: Human Oversight and Critical Evaluation (Practitioner)

| Parameter | Detail |
|-----------|--------|
| Duration | 90 minutes |
| Format | ☐ E-learning ☐ Live workshop ☐ Blended |
| Delivery | Live workshop recommended |
| Frequency | Annually |
| Prerequisites | Modules 1–3 |

**Topics covered:**
1. The SCAT framework for evaluating AI outputs
2. When and how to override an AI recommendation
3. Documenting overrides and reasoning
4. Recognising algorithmic bias in practice
5. Human-in-the-loop vs. human-on-the-loop roles
6. Case studies: AI failures and how human oversight would have caught them

**Practical exercise:** Participants review three AI recommendations in their domain and document their assessment using the SCAT framework.

---

#### Module 5: AI Governance and Compliance Deep-Dive (Expert)

| Parameter | Detail |
|-----------|--------|
| Duration | Half-day (4 hours) |
| Format | ☐ E-learning ☐ Live workshop ☐ Blended |
| Delivery | Instructor-led with case studies |
| Frequency | Annually |
| Prerequisites | Modules 1–4 |

**Topics covered:**
1. EU AI Act Articles 9–17: obligations for high-risk AI providers
2. Technical documentation requirements
3. Conformity assessment and CE marking
4. Bias and fairness testing methodologies
5. Post-market monitoring and incident reporting
6. FRIA walkthrough
7. Vendor due diligence for AI systems
8. Regulatory horizon: international AI law

**Assessment:** Written case study (60 minutes) evaluated by AI governance lead.

---

#### Module 6: Annual Refresher (All Levels)

| Parameter | Detail |
|-----------|--------|
| Duration | 20–30 minutes |
| Format | ☐ E-learning ☐ Live workshop ☐ Blended |
| Delivery | Self-paced |
| Frequency | Annually |
| Prerequisites | Prior year completion |

**Topics covered:**
1. Regulatory updates from the past year
2. Lessons learned from internal AI incidents
3. Updates to AI systems or governance policies
4. Refreshed scenarios and quiz

---

### Section 5: Assessment Criteria

#### 5.1 Assessment Methods

| Level | Assessment Type | Pass Threshold | Retake Policy |
|-------|----------------|----------------|---------------|
| Level 1 (Foundation) | 20-question multiple choice quiz | 70% (14/20) | Up to 2 retakes; re-training required after 2nd fail |
| Level 2 (Practitioner) | 30-question quiz + 1 practical scenario | 75% quiz + satisfactory scenario | Up to 2 retakes |
| Level 3 (Expert) | 40-question quiz + written case study | 80% quiz + case study pass | Re-training required; case study reviewed by governance lead |

#### 5.2 Sample Assessment Questions

**Foundation Level:**
1. An AI system tells you a job applicant has a low suitability score. What should you do first?
   - a) Reject the applicant immediately
   - b) Critically review the AI's reasoning and consider other factors ✓
   - c) Ask a colleague what they think without telling them it's AI-generated
   - d) Accept the AI's judgment as it is objective

2. Under the EU AI Act, AI systems used for scoring individuals' social behaviour are:
   - a) Permitted with user consent
   - b) Permitted for public bodies only
   - c) Prohibited ✓
   - d) Classified as limited-risk

**Practitioner Level:**
3. You notice that an AI hiring tool recommends far fewer women than men for technical roles. What is the most appropriate first step?
   - a) Assume the data reflects real-world patterns
   - b) Flag it as a potential bias issue to your AI Officer and suspend use pending investigation ✓
   - c) Manually adjust all female candidates' scores upward
   - d) Report it externally to a regulator immediately

**Expert Level:**
4. Outline the key obligations of a deployer (not provider) of a high-risk AI system under Articles 26 and 29 of the EU AI Act.

*(Open-ended — assessed against model answer)*

---

### Section 6: Training Schedule

#### 6.1 Rollout Timeline

| Phase | Activity | Target Group | Deadline | Owner |
|-------|----------|-------------|----------|-------|
| Phase 1 | Foundation track launch | All existing staff | [Date] | HR |
| Phase 1 | Foundation track for new joiners (integrated into onboarding) | New hires | [Date] | HR |
| Phase 2 | Practitioner track | Identified practitioner roles | [Date] | AI Officer |
| Phase 3 | Expert track | Governance / tech / legal | [Date] | AI Officer |
| Phase 4 | Annual refresher cycle | All staff | [Annually] | HR + AI Officer |

#### 6.2 Completion Tracking

| Metric | Target | Measurement Method |
|--------|--------|-------------------|
| Foundation track completion rate | 100% of all staff | LMS report |
| Practitioner track completion rate | 100% of identified practitioners | LMS report |
| Expert track completion rate | 100% of identified experts | LMS report + assessment record |
| Pass rate (first attempt) | >85% | LMS report |
| Annual refresher completion | 100% by [date each year] | LMS report |

**Learning Management System (LMS) used:** _______________
**Training records retention period:** Minimum 5 years (aligned with AI Act documentation obligations)

---

### Section 7: Governance and Review

#### 7.1 Roles and Responsibilities

| Role | Responsibility |
|------|---------------|
| AI Officer / DPO | Overall ownership of AI literacy programme |
| HR Manager | Coordination with LMS, onboarding integration |
| Department Managers | Ensuring team completion; flagging gaps |
| Legal / Compliance | Regulatory update monitoring |
| IT / Security | LMS infrastructure and access management |

#### 7.2 Programme Review Cycle

This training plan will be reviewed:
- Annually (minimum)
- When a new high-risk AI system is deployed
- When the EU AI Act or related guidance is updated
- After a significant AI incident

**Last reviewed:** _______________
**Next scheduled review:** _______________
**Reviewed by:** _______________

---

*Template provided by VORLUX AI | vorluxai.com*
*Version 1.1 — September 2026 | Template to evidence EU AI Act Article 4 (as amended by Regulation 2026/1744)*
*This is guidance only, not legal advice. Consult qualified legal counsel for your specific situation.*

---

### Versión Española

**Aviso:** Este modelo se proporciona solo a título de orientación. No constituye asesoramiento legal. Las organizaciones deben consultar a abogados calificados para asegurarse de que cumplan con las leyes y regulaciones aplicables.

---

## Plan de capacitación en inteligencia artificial (IA)

### Ley de IA de la UE — Artículo 4

**Organización:** _______________
**Referencia del documento:** AITP-[YYYY]-[NNN]
**Versión:** _______________
**Preparado por:** _______________
**Aprobado por:** _______________
**Fecha de entrada en vigor:** _______________
**Fecha de revisión:** _______________

---

### Sección 1: Propósito y base legal

El artículo 4 de la Ley de IA de la UE (Reglamento 2024/1689), en la redacción que le dio el Reglamento (UE) 2026/1744 desde el 27 de julio de 2026, exige a proveedores y responsables del despliegue adoptar medidas para apoyar la alfabetización en IA de su personal y de las demás personas que manejan o usan sistemas de IA en su nombre —contratistas, proveedores de servicios, incluso clientes—, teniendo en cuenta sus conocimientos técnicos, experiencia, educación y formación y el contexto de uso. No se exige un nivel concreto ni «suficiente», ni un certificado: según la Comisión Europea basta un registro interno de formaciones y demás iniciativas ([preguntas y respuestas de la Comisión](https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers)). La obligación se aplica desde el 2 de febrero de 2025 y las autoridades nacionales la supervisan desde el 2 de agosto de 2026. Este plan es ese registro.

Este plan de capacitación documenta cómo **[Nombre de la Organización]** cumple con esta obligación.

**Sistemas de IA en ámbito:**

| Nombre del sistema | Clasificación de riesgo | Usuarios principales | Fecha de puesta en marcha |
|-------------------|----------------------|--------------------|-------------------------|
| | ☐ Alto riesgo ☐ Limitado ☐ Mínimo | | |
| | ☐ Alto riesgo ☐ Limitado ☐ Mínimo | | |
| | ☐ Alto riesgo ☐ Limitado ☐ Mínimo | | |

---

### Sección 2: Marco de competencias

#### 2.1 Niveles de competencia

Esta organización define tres niveles de competencia en alfabetización en IA:

---

**Nivel 1 — Básico (Fundamental)**

> *Público objetivo: Todos los empleados que pueden encontrar salidas generadas por la IA o trabajar en entornos donde operan sistemas de IA.*

Competencias básicas a este nivel:
- Entiende qué es la IA y lo que no es (limitaciones, errores, alucinaciones)
- Puede identificar cuando se utiliza la IA en un proceso o herramienta
- Conoce su derecho a solicitar una revisión humana de las decisiones de la IA
- Entiende consideraciones básicas sobre privacidad de datos al usar herramientas de IA
- Conoce cómo reportar preocupaciones relacionadas con la IA internamente

**Umbral de evaluación:** 70% en la evaluación de fundamentos

---

**Nivel 2 — Intermedio (Practitioner)**

> *Público objetivo: Empleados que utilizan regularmente sistemas de IA como parte de su función, incluidos profesionales de RRHH, agentes de atención al cliente, analistas y personal de operaciones.*

Competencias básicas a este nivel:
- Todas las competencias del Nivel 1, más:
- Entiende categorías de riesgo de la IA bajo la Ley de IA de la UE (prácticas prohibidas, alto riesgo, obligaciones de transparencia, riesgo mínimo)
- Puede identificar potenciales sesgos en salidas de la IA y aplicar una evaluación crítica
- Conoce las políticas de gobernanza de la IA de la organización y los procedimientos de escalada
- Entiende los requisitos de calidad de datos para sistemas de IA
- Puede aplicar los protocolos de supervisión humana de la organización
- Entiende obligaciones de transparencia con respecto a las personas afectadas

**Umbral de evaluación:** 75% en la evaluación del practicante

---

**Nivel 3 — Experto (Gobernanza y técnico)**

> *Público objetivo: Desarrolladores de sistemas de IA, científicos de datos, oficiales de cumplimiento, consejeros legales, gerentes senior y miembros del comité de gobernanza de la IA.*

Competencias básicas a este nivel:
- Todas las competencias del Nivel 1 y del Nivel 2, más:
- Conocimientos profundos sobre las obligaciones de la Ley de IA de la UE por tipo de actor (proveedor, usuario, importador)
- Capacidad para conducir o revisar evaluaciones de impacto en derechos fundamentales
- Comprensión técnica de la evaluación de modelos, pruebas de sesgo y métricas de rendimiento
- Conoce procedimientos de conformidad con las normas y requisitos de marcado CE
- Entiende obligaciones de monitoreo post-comercialización
- Puede interpretar registros de auditoría de IA e informes de incidentes
- Entiende el paisaje regulatorio internacional de la IA (Reino Unido, EE. UU., China, etc.)

**Umbral de evaluación:** 80% en la evaluación del experto + caso práctico

---

#### 2.2 Mapeo de competencias por función

| Función | Nivel requerido | Carrera de capacitación |
|---------|-----------------|------------------------|
| Todos los empleados (general) | Nivel 1 | Carrera de fundamentos |
| Ejecutivo / Gerente senior | Nivel 2 | Carrera de líderes |
| RRHH / Equipo de personas | Nivel 2 | Carrera del practicante |
| Atención al cliente / Operaciones | Nivel 2 | Carrera del practicante |
| Marketing / Comunicación | Nivel 1-2 | Carrera del practicante |
| Finanzas /

---

# AI Policy Template
_Plantilla de política corporativa de IA_

> 16-page governance framework covering organizational AI policy, roles, procedures, and compliance requirements under the EU AI Act.
> Online: https://vorluxai.com/templates/ai-policy-template/

## AI Policy Template — Corporate Governance Framework

> EU AI Act Compliance | VORLUX AI | Based on Regulation 2024/1689

### 1. Purpose and Scope

#### 1.1 Purpose
This policy establishes the governance framework for the development, deployment, and use of Artificial Intelligence (AI) systems within [COMPANY NAME]. It ensures compliance with the EU AI Act (Regulation 2024/1689) and alignment with organizational values.

#### 1.2 Scope
This policy applies to:
- All AI systems developed, deployed, or used by [COMPANY NAME]
- All employees, contractors, and third parties interacting with AI systems
- All departments and business units
- Both internal and client-facing AI applications

#### 1.3 Definitions

| Term | Definition |
|------|-----------|
| AI System | A machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness and that infers, from input it receives, how to generate outputs such as predictions, content, recommendations, or decisions (Art. 3(1)) |
| Provider | Natural or legal person that develops or has an AI system developed and places it on the market or puts it into service under its own name or trademark (Art. 3(3)) |
| Deployer | Natural or legal person using an AI system under its authority (Art. 3(4)) |
| High-Risk AI | AI systems listed in Annex I or Annex III of the EU AI Act |
| GPAI | General-Purpose AI model trained with large amounts of data using self-supervision at scale |

### 2. Governance Structure

#### 2.1 AI Governance Board

| Role | Responsibility | Person |
|------|---------------|--------|
| AI Compliance Officer | Overall compliance with EU AI Act | _____________ |
| Data Protection Officer | GDPR alignment for AI systems | _____________ |
| Technical Lead | AI system architecture and security | _____________ |
| Legal Counsel | Regulatory interpretation and contracts | _____________ |
| Department Heads | Use case identification and risk assessment | _____________ |

#### 2.2 Decision-Making Authority

| Decision Type | Authority Level | Approval Required |
|--------------|----------------|-------------------|
| New AI system procurement | Department Head + AI Compliance Officer | Yes |
| High-risk AI deployment | AI Governance Board | Unanimous |
| AI system modification | Technical Lead + AI Compliance Officer | Yes |
| Incident escalation | AI Compliance Officer | Immediate |
| Policy exceptions | AI Governance Board | Majority |

### 3. AI System Classification

#### 3.1 Risk Assessment Process

For every AI system, complete the following:

1. **Identify**: Document the AI system in the inventory (Art. 49)
2. **Classify**: Determine risk level (prohibited/high/limited/minimal)
3. **Assess**: Complete risk assessment and FRIA if high-risk (Art. 27)
4. **Document**: Create technical documentation (Annex IV) if high-risk
5. **Monitor**: Establish ongoing monitoring and review schedule

#### 3.2 Classification Decision Tree

```
Is the AI system performing a prohibited practice (Art. 5)?
├── YES → PROHIBITED — Discontinue immediately
└── NO → Is it listed in Annex I or III?
    ├── YES → Does Art. 6(3) exception apply?
    │   ├── YES → LIMITED RISK
    │   └── NO → HIGH RISK — Full compliance required
    └── NO → Does it interact with humans or generate content?
        ├── YES → LIMITED RISK — Transparency obligations
        └── NO → MINIMAL RISK — No specific obligations
```

### 4. Acceptable Use

#### 4.1 Permitted Uses
- Document processing and classification
- Customer service chatbots (with transparency disclosure)
- Internal knowledge search and retrieval
- Content generation (with human review)
- Data analysis and reporting
- Process automation

#### 4.2 Prohibited Uses
- Social scoring of employees or customers
- Subliminal manipulation techniques
- Real-time biometric identification without authorization
- Emotion recognition in workplace (except safety-critical roles with consent)
- Automated decision-making without human oversight for high-impact decisions

#### 4.3 Employee Responsibilities

All employees using AI systems must:
- [ ] Complete AI literacy training (Art. 4)
- [ ] Use only approved AI systems
- [ ] Report any AI-related incidents
- [ ] Not input sensitive/personal data into unapproved AI tools
- [ ] Review AI outputs before sharing externally
- [ ] Follow department-specific AI usage guidelines

### 5. Transparency Requirements (Art. 50)

#### 5.1 User Notification
When an AI system interacts with a person, they must be informed that they are interacting with AI. This includes:
- Chatbots and virtual assistants
- AI-generated email responses
- Automated customer service
- AI-powered recommendation systems

#### 5.2 Content Marking
AI-generated content must be:
- Identifiable as AI-generated when published externally
- Reviewed by a human before external distribution
- Stored with metadata indicating AI involvement

#### 5.3 Template Notice

```
[TRANSPARENCY NOTICE]
This [content/interaction/response] was [generated/assisted] by an
artificial intelligence system. A human has reviewed this output.
For questions, contact: [contact details]
```

### 6. Data Governance

#### 6.1 Data Quality Requirements (Art. 10)
AI training and operational data must:
- Be relevant and representative
- Be free from errors to the extent possible
- Consider potential biases
- Be appropriate for the intended purpose
- Comply with GDPR data minimization principles

#### 6.2 Data Processing Records
Maintain records of:
- Data sources used for AI training
- Data preprocessing and cleaning procedures
- Bias testing and mitigation results
- Data retention and deletion schedules

### 7. Human Oversight (Art. 14)

#### 7.1 Oversight Mechanisms
For high-risk AI systems:
- Designated human overseer for each system
- Clear escalation procedures
- Ability to override or stop AI decisions
- Regular review of AI outputs and decisions
- Documentation of override decisions

#### 7.2 Override Authority

| AI System | Overseer | Override Threshold |
|-----------|----------|-------------------|
| [System 1] | [Name] | [When to override] |
| [System 2] | [Name] | [When to override] |

### 8. Incident Management

#### 8.1 Incident Categories

| Category | Description | Response Time | Reporting |
|----------|-------------|--------------|-----------|
| Critical | Safety/rights impact, prohibited practice detected | Immediate | Board + authority |
| High | Significant malfunction, bias detected | 4 hours | AI Compliance Officer |
| Medium | Performance degradation, minor errors | 24 hours | Technical Lead |
| Low | User complaints, feature requests | 72 hours | Department Head |

#### 8.2 Incident Response Steps

1. **Detect**: Identify the incident through monitoring or reports
2. **Contain**: Isolate affected systems if necessary
3. **Assess**: Determine severity and impact
4. **Report**: Notify appropriate stakeholders per table above
5. **Remediate**: Fix the issue and verify resolution
6. **Document**: Record all actions taken
7. **Review**: Post-incident analysis and policy updates

### 9. Vendor Management

#### 9.1 AI Vendor Assessment Checklist

Before procuring any AI system, verify:
- [ ] Vendor's EU AI Act compliance status
- [ ] Data processing location (EU vs non-EU)
- [ ] Technical documentation availability
- [ ] Transparency measures implemented
- [ ] Incident response capabilities
- [ ] Training and support offered
- [ ] Contract terms include compliance obligations
- [ ] Exit strategy and data portability

### 10. Training and Awareness (Art. 4)

#### 10.1 Training Requirements

| Audience | Content | Frequency |
|----------|---------|-----------|
| All employees | AI basics, acceptable use, risks | Annual |
| AI users | System-specific training, oversight | Before use + annual refresh |
| Technical staff | Technical documentation, monitoring | Quarterly |
| Management | Governance, risk assessment, compliance | Semi-annual |
| AI Compliance Officer | Full EU AI Act, updates, case law | Continuous |

### 11. Review and Updates

#### 11.1 Review Schedule

| Review Type | Frequency | Owner |
|-------------|-----------|-------|
| Policy review | Annual | AI Governance Board |
| System inventory update | Quarterly | AI Compliance Officer |
| Risk assessment refresh | Semi-annual | Technical Lead |
| Training effectiveness | Annual | HR + AI Compliance Officer |
| Vendor compliance check | Annual | Procurement + Legal |

#### 11.2 Change Management
All policy changes must be:
- Approved by the AI Governance Board
- Communicated to all affected employees
- Reflected in training materials
- Documented with version history

---

### Document Control

| Field | Value |
|-------|-------|
| Version | 1.0 |
| Effective Date | _____________ |
| Next Review | _____________ |
| Approved By | _____________ |
| Classification | Internal |

---

*Template provided by VORLUX AI | vorluxai.com*
*Based on EU AI Act (Regulation 2024/1689). This template is for guidance only and does not constitute legal advice. Consult qualified legal counsel for your specific situation.*

---

### Versión Española

## Plantilla de Política de Inteligencia Artificial — Marco de Gobernanza Corporativa

> Cumplimiento con el Reglamento de IA de la UE | VORLUX AI | Basado en Reglamento 2024/1689

### 1. Propósito y Ámbito

#### 1.1 Propósito
Esta política establece el marco de gobernanza para el desarrollo, implementación y uso de sistemas de Inteligencia Artificial (IA) dentro de [NOMBRE DE LA COMPANÍA]. Garantiza la conformidad con el Reglamento de IA de la UE (Reglamento (UE) 2024/1689) y alinea con los valores organizacionales.

#### 1.2 Ámbito
Esta política se aplica a:
- Todos los sistemas de IA desarrollados, implementados o utilizados por [NOMBRE DE LA COMPANÍA]
- Todos los empleados, contratistas y terceros que interactúan con sistemas de IA
- Todas las departamentos y unidades comerciales
- Ambas aplicaciones internas y client-facing de IA

#### 1.3 Definiciones

| Término | Definición |
|------|-----------|
| Sistema de IA | Un sistema basado en máquinas diseñado para operar con niveles variables de autonomía, que puede exhibir adaptabilidad y que infiere, a partir de la entrada que recibe, cómo generar salidas como predicciones, contenido, recomendaciones o decisiones (Art. 3(1)) |
| Proveedor | Persona natural o jurídica que desarrolla o tiene un sistema de IA desarrollado y lo coloca en el mercado o lo pone en servicio bajo su propio nombre o marca (Art. 3(3)) |
| Desplegador | Persona natural o jurídica que utiliza un sistema de IA bajo su autoridad (Art. 3(4)) |
| IA con alto riesgo | Sistemas de IA enumerados en el Anexo I o III de el Reglamento de IA de la UE |
| GPAI | Modelo de IA generalizado entrenado con grandes cantidades de datos utilizando auto-supervisión a escala |

### 2. Estructura de Gobernanza

#### 2.1 Junta de Gobernanza de IA

| Rol | Responsabilidad | Persona |
|------|---------------|--------|
| Oficial de Cumplimiento de IA | Cumplimiento general con el Reglamento de IA de la UE | _____________ |
| Delegado de Protección de Datos | Alineación con el RGPD para sistemas de IA | _____________ |
| Líder Técnico | Arquitectura y seguridad del sistema de IA | _____________ |
| Asesor Jurídico | Interpretación regulatoria y contratos | _____________ |
| Jefes de Departamento | Identificación de casos de uso y evaluación de riesgos | _____________ |

#### 2.2 Autoridad para la Tomada de Decisiones

| Tipo de decisión | Nivel de autoridad | Aprobación requerida |
|--------------|----------------|-------------------|
| Adquisición de nuevo sistema de IA | Jefe de Departamento + Oficial de Cumplimiento de IA | Sí |
| Implementación de IA con alto riesgo | Junta de Gobernanza de IA | Unánime |
| Modificación del sistema de IA | Líder Técnico + Oficial de Cumplimiento de IA | Sí |
| Escalada de incidentes | Oficial de Cumplimiento de IA | Inmediato |
| Excepciones a la política | Junta de Gobernanza de IA | Mayoritaria |

### 3. Clasificación del Sistema de IA

#### 3.1 Proceso de Evaluación de Riesgos

Para cada sistema de IA, complete lo siguiente:

1. **Identificar**: Documentar el sistema de IA en la inventario (Art. 49)
2. **Clasificar**: Determinar nivel de riesgo (prohibido/alto/limitado/minimo)
3. **Evaluar**: Realizar evaluación de riesgos y FRIA si es alto-riesgo (Art. 27)
4. **Documentar**: Crear documentación técnica (Anexo IV) si es alto-riesgo
5. **Monitorear**: Establecer horario para monitoreo y revisión continuos

#### 3.2 Árbol de Decisiones de Clasificación

```
¿El sistema de IA realiza una práctica prohibida (Art. 5)?
├── SÍ → PROHIBIDO — Interrumpir inmediatamente
└── NO → ¿Está listado en el Anexo I o III?
    ├── SÍ → ¿Aplica la excepción del Art. 6(3)?
    │   ├── SÍ → RIESGO LIMITADO
    │   └── NO → RIESGO ALTO — Cumplimiento completo requerido
    └── NO → ¿Interactúa con humanos o genera contenido?
        ├── SÍ → RIESGO LIMITADO — Obligaciones de transparencia
        └── NO → RIESGO MINIMO — Ninguna obligación específica
```

### 4. Uso Aceptable

#### 4.1 Usos Permisibles
- Procesamiento y clasificación de documentos
- Chatbots de servicio al cliente (con declaración de transparencia)
- Búsqueda y recuperación de conocimiento interno
- Generación de contenido (con revisión humana)
- Análisis de datos y informes
- Automatización de procesos

#### 4.2 Usos Prohibidos
- Puntuación social de empleados o clientes
- Técnicas de manipulación subliminal
- Identificación biométrica en tiempo real sin autorización
- Reconocimiento emocional en el lugar de trabajo (excepto para roles críticos con seguridad y consentimiento)
- Tomada de decisiones automatizada sin supervisión humana para alto-impact

---

# AI Risk Classification Tool
_Herramienta de clasificación de riesgo de IA_

> Determine the risk level of your AI systems per EU AI Act. 5-step assessment covering Articles 5, 6, and Annexes I-III.
> Online: https://vorluxai.com/templates/ai-risk-classification/

## AI Risk Classification Tool

> Based on EU AI Act — Regulation 2024/1689 | VORLUX AI

### Purpose

This tool helps organizations determine the risk classification of their AI systems under the EU AI Act. Classifications determine your compliance obligations.

### Step 1: Check for Prohibited Practices (Article 5)

Does your AI system perform any of the following? If YES to any → **PROHIBITED (must discontinue)**

- [ ] Social scoring by public authorities
- [ ] Real-time remote biometric identification in public spaces (with exceptions)
- [ ] Subliminal manipulation that causes harm
- [ ] Exploitation of vulnerabilities (age, disability, social situation)
- [ ] Predictive policing based solely on profiling
- [ ] Untargeted scraping for facial recognition databases
- [ ] Emotion recognition in workplace or education (with exceptions)
- [ ] Biometric categorization inferring sensitive attributes

**Result:** If any checked → System is PROHIBITED. Stop here.

### Step 2: Check Annex I — High-Risk Product Safety

Is your AI system a safety component of, or itself constitutes, a product covered by:

- [ ] Machinery (Regulation 2023/1230)
- [ ] Toys (Directive 2009/48/EC)
- [ ] Lifts (Directive 2014/33/EU)
- [ ] Medical devices (Regulations 2017/745, 2017/746)
- [ ] Motor vehicles (Regulation 2019/2144)
- [ ] Aviation (Regulation 2018/1139)
- [ ] Rail (Directive 2016/797)
- [ ] Marine equipment (Directive 2014/90/EU)

**Result:** If any checked → **HIGH RISK**. Full compliance required (Articles 8-15).

### Step 3: Check Annex III — High-Risk Use Cases

Does your AI system fall into any of these categories?

#### Biometrics (3a, 3b)
- [ ] Remote biometric identification (not real-time in public)
- [ ] Biometric categorization
- [ ] Emotion recognition

#### Critical Infrastructure (4)
- [ ] Safety component of critical infrastructure (water, gas, heating, electricity, transport)

#### Education (5)
- [ ] Determining access to education
- [ ] Evaluating learning outcomes
- [ ] Monitoring prohibited behavior during tests

#### Employment (6)
- [ ] Recruitment and selection (CV screening, interview analysis)
- [ ] Promotion, termination, task allocation decisions
- [ ] Monitoring and evaluating work performance

#### Essential Services (7)
- [ ] Creditworthiness assessment
- [ ] Risk assessment for life/health insurance
- [ ] Evaluation of emergency calls (dispatching)

#### Law Enforcement (8)
- [ ] Individual risk assessment (recidivism prediction)
- [ ] Polygraphs and similar tools
- [ ] Evidence analysis
- [ ] Crime prediction (geographic or individual)

#### Migration (9)
- [ ] Risk assessment for irregular migration
- [ ] Examination of asylum applications
- [ ] Identification of persons (border control)

#### Justice & Democracy (10)
- [ ] Assistance to judicial authorities (legal research, case analysis)
- [ ] Influencing election outcomes

**Result:** If any checked → Likely **HIGH RISK** (subject to Article 6(3) exception).

### Step 4: Article 6(3) Exception Check

Even if listed in Annex III, your system is NOT high-risk if ALL of these apply:

- [ ] The AI system performs a narrow procedural task
- [ ] It improves the result of a previously completed human activity
- [ ] It detects decision patterns without replacing human assessment
- [ ] It performs a preparatory task relevant to Annex III use cases

AND the AI output does not create a significant risk of harm to health, safety, or fundamental rights.

**Result:** If all checked → **LIMITED RISK** (transparency obligations only).

### Step 5: Determine Your Classification

| Classification | Your Obligations |
|---------------|-----------------|
| **Prohibited** | Must discontinue immediately |
| **High Risk** | Full compliance: risk management, data governance, technical documentation, transparency, human oversight, accuracy/robustness |
| **Limited Risk** | Transparency: inform users they interact with AI, mark AI-generated content |
| **Minimal Risk** | No specific obligations (voluntary codes of conduct) |

### Your Assessment

| Field | Your Input |
|-------|-----------|
| **System name** | _________________ |
| **Description** | _________________ |
| **Risk classification** | ☐ Prohibited ☐ High ☐ Limited ☐ Minimal |
| **Key articles** | _________________ |
| **Assessment date** | _________________ |
| **Assessed by** | _________________ |
| **Next review** | _________________ |

---

### Next Steps

Based on your classification:

- **High Risk**: You need technical documentation (Annex IV), conformity assessment (Art. 43), and registration (Art. 49). [Contact us for a compliance audit →](../../contact/)
- **Limited Risk**: Implement transparency measures. We can help. [Request assessment →](../../contact/)
- **Minimal Risk**: No mandatory obligations, but we recommend documenting your AI inventory.

---

*Template provided by VORLUX AI | vorluxai.com | Based on EU AI Act Regulation 2024/1689*
*This template is for guidance only and does not constitute legal advice.*

---

### Versión Española

## Herramienta de Clasificación de Riesgos para Inteligencia Artificial

> Basado en el Reglamento de IA de la UE — Reglamento 2024/1689 | VORLUX AI

### Propósito

Esta herramienta ayuda a las organizaciones a determinar la clasificación del riesgo de sus sistemas de inteligencia artificial bajo el Reglamento de IA de la UE. Las clasificaciones determinan sus obligaciones de cumplimiento.

### Paso 1: Verificar Prácticas Prohibidas (Artículo 5)

¿Su sistema de inteligencia artificial realiza alguna de las siguientes actividades? Si SÍ a cualquier una → **PROHIBIDO (debe cesar)**

- [ ] Puntuación social por parte de autoridades públicas
- [ ] Identificación biométrica en tiempo real en espacios públicos (con excepciones)
- [ ] Manipulación subliminal que causa daño
- [ ] Explotación de vulnerabilidades (edad, discapacidad, situación social)
- [ ] Policía predictiva basada únicamente en perfiles
- [ ] Scraping no dirigido para bases de datos de reconocimiento facial
- [ ] Reconocimiento emocional en el lugar de trabajo o la educación (con excepciones)
- [ ] Categorización biométrica que infiere atributos sensibles

**Resultado:** Si alguna marcada → El sistema es PROHIBIDO. Detener aquí.

### Paso 2: Verificar Anexo I — Seguridad de Productos con Alto Riesgo

¿Su sistema de inteligencia artificial es un componente de seguridad o constituye en sí mismo un producto cubierto por:

- [ ] Máquinas (Reglamento 2023/1230)
- [ ] Juguetes (Directiva 2009/48/CE)
- [ ] Ascensores (Directiva 2014/33/UE)
- [ ] Dispositivos médicos (Regulaciones 2017/745, 2017/746)
- [ ] Vehículos motorizados (Reglamento 2019/2144)
- [ ] Aviación (Reglamento 2018/1139)
- [ ] Ferrocarril (Directiva 2016/797)
- [ ] Equipo marítimo (Directiva 2014/90/UE)

**Resultado:** Si alguna marcada → **ALTO RIESGO**. Cumplimiento completo requerido (Artículos 8-15).

### Paso 3: Verificar Anexo III — Uso de Alto Riesgo

¿Su sistema de inteligencia artificial cae en alguna de estas categorías?

#### Biometría (3a, 3b)
- [ ] Identificación biométrica remota (no en tiempo real en espacios públicos)
- [ ] Categorización biométrica
- [ ] Reconocimiento emocional

#### Infraestructura Crítica (4)
- [ ] Componente de seguridad de infraestructuras críticas (agua, gas, calefacción, electricidad, transporte)

#### Educación (5)
- [ ] Determinar acceso a la educación
- [ ] Evaluación de resultados de aprendizaje
- [ ] Monitoreo de comportamiento prohibido durante exámenes

#### Empleo (6)
- [ ] Selección y contratación (análisis de currículum, análisis de entrevistas)
- [ ] Decisión de promoción, despido o asignación de tareas
- [ ] Monitoreo y evaluación del desempeño laboral

#### Servicios Esenciales (7)
- [ ] Evaluación de la capacidad crediticia
- [ ] Evaluación de riesgo para seguros de vida/seguros de salud
- [ ] Análisis de llamadas de emergencia (despacho)

#### Vigilancia (8)
- [ ] Evaluación individual de riesgos (predicción de reincidencia)
- [ ] Polígrafos y herramientas similares
- [ ] Análisis de pruebas
- [ ] Predicción de delitos (geográfica o individual)

#### Migración (9)
- [ ] Evaluación de riesgo para migrantes irregulares
- [ ] Examen de solicitudes de asilo
- [ ] Identificación de personas (control fronterizo)

#### Justicia y Democracia (10)
- [ ] Asistencia a autoridades judiciales (investigación legal, análisis de casos)
- [ ] Influencia en resultados electorales

**Resultado:** Si alguna marcada → Probablemente **ALTO RIESGO** (excepción del artículo 6(3)).

### Paso 4: Verificar Excepción del Artículo 6(3)

A pesar de estar incluido en el Anexo III, su sistema no es alto riesgo si se cumplen todas las siguientes condiciones:

- [ ] El sistema de inteligencia artificial realiza una tarea procedimental estrecha
- [ ] Mejora el resultado de una actividad humana previamente completada
- [ ] Detecta patrones de decisión sin reemplazar la evaluación humana
- [ ] Realiza una tarea preparatoria relevante para los casos de uso del Anexo III

Y el output del sistema no crea un riesgo significativo de daño a la salud, seguridad o derechos fundamentales.

**Resultado:** Si todas las condiciones se cumplen → **RIESGO LIMITADO** (obligaciones de transparencia solo).

### Paso 5: Determinar Su Clasificación

| Clasificación | Sus Obligaciones |
|---------------|-----------------|
| **Prohibido** | Debe cesar inmediatamente |
| **Alto Riesgo** | Cumplimiento completo: gestión de riesgos, gobernanza de datos, documentación técnica, transparencia, supervisión humana, precisión/robustez |
| **Riesgo Limitado** | Transparencia: informar a los usuarios que interactúan con IA, marcar contenido generado por IA |
| **Riesgo Mínimo** | Sin obligaciones específicas (códigos de conducta voluntarios) |

### Su Evaluación

| Campo | Su Respuesta |
|-------|--------------|
| **Nombre del sistema** | _________________ |
| **Descripción** | _________________ |
| **Clasificación de riesgo** | ☐ Prohibido ☐ Alto ☐ Limitado ☐ Mínimo |
| **Artículos clave** | _________________ |
| **Fecha de evaluación** | _________________ |
| **Evaluado por** | _________________ |
| **Próxima revisión** | _________________ |

---

### Siguientes Pasos

Según su clasificación:

- **Alto riesgo**: necesita documentación técnica (Anexo IV), evaluación de conformidad (art. 43) y registro (art. 49). [Escríbanos para una auditoría de cumplimiento →](../../contact/)
- **Riesgo limitado**: implante las medidas de transparencia. Podemos ayudarle. [Solicitar evaluación →](../../contact/)
- **Riesgo mínimo**: no hay obligaciones obligatorias, pero recomendamos documentar su inventario de IA.

---

*Plantilla de VORLUX AI | vorluxai.com | Basada en el Reglamento (UE) 2024/1689 de IA*
*Esta plantilla tiene carácter orientativo y no constituye asesoramiento jurídico.*

---

# AI Systems Inventory Template
_Plantilla de inventario de sistemas de IA_

> Catalogue all AI systems in your organization with risk classification, responsible parties, and compliance status.
> Online: https://vorluxai.com/templates/ai-systems-inventory/

## AI Systems Inventory — Article 49

> EU AI Act Compliance | VORLUX AI

### Instructions

Complete one row per AI system used in your organization. Include all systems — commercial (SaaS), open-source, custom-built, and employee-used tools (ChatGPT, Copilot, etc.).

### Inventory Register

For each AI system, document:

#### System Identification

| Field | Description | Example |
|-------|-------------|---------|
| System ID | Unique identifier | AI-2026-001 |
| System Name | Commercial or internal name | ChatGPT Enterprise |
| Provider | Company providing the AI | OpenAI |
| Version | Current version deployed | GPT-4o, May 2026 |
| Deployment Date | When first deployed | 2025-09-15 |
| Department | Primary department using it | Customer Service |
| Responsible Person | Internal owner | Maria Lopez, CS Manager |

#### Classification

| Field | Options |
|-------|---------|
| Risk Level | ☐ Prohibited ☐ High ☐ Limited ☐ Minimal |
| Provider/Deployer Role | ☐ Provider ☐ Deployer ☐ Both |
| Processing Location | ☐ Local (on-premise) ☐ Cloud (EU) ☐ Cloud (non-EU) |
| Personal Data | ☐ None ☐ Non-sensitive ☐ Sensitive (Art. 9 GDPR) |

#### Compliance Status

| Requirement | Status | Notes |
|-------------|--------|-------|
| Transparency (Art. 50) | ☐ Done ☐ In progress ☐ Not started | |
| DPIA completed | ☐ Done ☐ Not needed ☐ Pending | |
| Vendor due diligence | ☐ Done ☐ In progress ☐ Not started | |
| AI literacy training | ☐ Done ☐ Scheduled ☐ Not started | |
| Human oversight defined | ☐ Done ☐ In progress ☐ Not started | |
| Incident response plan | ☐ Done ☐ In progress ☐ Not started | |

#### Usage Details

| Field | Your Input |
|-------|-----------|
| Purpose | (describe what the AI does) |
| Users | (who uses it, how many) |
| Input data types | (text, images, personal data, etc.) |
| Output | (recommendations, decisions, content, etc.) |
| Human review | (how are outputs reviewed before action) |
| Alternatives | (what would you use without this AI) |

---

### Common Systems to Include

Don't forget these — they're often overlooked:

- [ ] ChatGPT / Copilot subscriptions (individual or team)
- [ ] Email AI features (smart compose, spam filters)
- [ ] CRM AI predictions (lead scoring, churn prediction)
- [ ] HR screening tools (CV parsers, interview analysis)
- [ ] Translation tools (DeepL, Google Translate in workflows)
- [ ] Content generators (image, text, code)
- [ ] Analytics AI (predictive dashboards, anomaly detection)
- [ ] Security AI (threat detection, fraud prevention)
- [ ] Customer chatbots (support, sales)
- [ ] Search and recommendation engines

---

### Shadow AI Detection

Ask each department:

1. Do any team members use AI tools not provided by IT?
2. Have any browser extensions with AI features been installed?
3. Are any AI APIs being called from custom scripts or spreadsheets?
4. Are employees uploading company data to free AI tools?

Document any discovered shadow AI systems in this inventory.

---

*Template provided by VORLUX AI | vorluxai.com*
*This template is for guidance only and does not constitute legal advice.*

---

### Versión Española

## Inventario de Sistemas de Inteligencia Artificial — Artículo 49

> Cumplimiento con el Reglamento de IA de la UE | VORLUX AI

### Instrucciones

Complete una fila por cada sistema de inteligencia artificial utilizado en su organización. Incluya todos los sistemas — comerciales (SaaS), de código abierto, personalizados y herramientas utilizadas por empleados (ChatGPT, Copilot, etc.).

### Registro del Inventario

Para cada sistema de inteligencia artificial, documente:

#### Identificación del Sistema

| Campo | Descripción | Ejemplo |
|-------|-------------|---------|
| ID del Sistema | Identificador único | AI-2026-001 |
| Nombre del Sistema | Nombre comercial o interno | ChatGPT Enterprise |
| Proveedor | Compañía que proporciona la IA | OpenAI |
| Versión | Versión actualmente desplegada | GPT-4o, mayo 2026 |
| Fecha de Despliegue | Cuando se desplegó por primera vez | 2025-09-15 |
| Departamento | Departamento principal que lo utiliza | Servicio al Cliente |
| Persona Responsable | Propietario interno | María López, Gerente del CS |

#### Clasificación

| Campo | Opciones |
|-------|---------|
| Nivel de Riesgo | ☐ Prohibido ☐ Alto ☐ Limitado ☐ Mínimo |
| Rol del Proveedor/Desplegador | ☐ Proveedor ☐ Desplegador ☐ Ambos |
| Ubicación del Procesamiento | ☐ Local (en sitio) ☐ Nube (UE) ☐ Nube (no UE) |
| Datos Personales | ☐ Ninguno ☐ No sensibles ☐ Sensibles (Art. 9 RGPD) |

#### Estado de Cumplimiento

| Requisito | Estado | Notas |
|-------------|--------|-------|
| Transparencia (Art. 50) | ☐ Hecho ☐ En progreso ☐ No iniciado | |
| DPIA completada | ☐ Hecho ☐ No necesario ☐ Pendiente | |
| Diligencia del proveedor | ☐ Hecho ☐ En progreso ☐ No iniciado | |
| Capacitación en IA | ☐ Hecho ☐ Programada ☐ No iniciado | |
| Definición de revisión humana | ☐ Hecho ☐ En progreso ☐ No iniciado | |
| Plan de respuesta a incidentes | ☐ Hecho ☐ En progreso ☐ No iniciado | |

#### Detalles del Uso

| Campo | Su Input |
|-------|-----------|
| Propósito | (describe qué hace la IA) |
| Usuarios | (quién lo utiliza, cuántos) |
| Tipos de datos de entrada | (texto, imágenes, datos personales, etc.) |
| Salida | (recomendaciones, decisiones, contenido, etc.) |
| Revisión humana | (cómo se revisan las salidas antes de la acción) |
| Alternativas | (qué utilizaría sin esta IA) |

---

### Sistemas Comunes a Incluir

No olvide estos — a menudo se pasan por alto:

- [ ] Suscripciones a ChatGPT / Copilot (individual o equipo)
- [ ] Características de AI en el correo electrónico (composición inteligente, filtros de spam)
- [ ] Predicciones de CRM (puntuación de leads, predicción de abandono)
- [ ] Herramientas de selección de personal (analizadores de CV, análisis de entrevistas)
- [ ] Herramientas de traducción (DeepL, Google Translate en flujos de trabajo)
- [ ] Generadores de contenido (imágenes, texto, código)
- [ ] Análitica AI (tableros predictivos, detección de anomalías)
- [ ] Seguridad AI (detección de amenazas, prevención de fraude)
- [ ] Chatbots de clientes (soporte, ventas)
- [ ] Motores de búsqueda y recomendación

---

### Deteción de IA en la Sombra

Pregunte a cada departamento:

1. ¿Algunos miembros del equipo utilizan herramientas de AI no proporcionadas por IT?
2. ¿Se han instalado extensiones de navegador con características de AI?
3. ¿Se están llamando APIs de AI desde scripts o hojas de cálculo personalizados?
4. ¿Los empleados están subiendo datos de la empresa a herramientas de AI gratuitas?

Documente cualquier sistema de IA en la sombra descubierto en este inventario.

---

*Plantilla proporcionada por VORLUX AI | vorluxai.com*
*Esta plantilla es para orientación solo y no constituye asesoramiento legal.*

---

# AI Transparency Notice Template
_Plantilla de aviso de transparencia de IA_

> Ready-to-use transparency notices for chatbots and AI-generated content under EU AI Act Article 50, plus automated-decision notices under GDPR Article 22. Copy-paste notices in English and Spanish.
> Online: https://vorluxai.com/templates/ai-transparency-notice/

> **Disclaimer:** This template is provided for guidance purposes only. It does not constitute legal advice. Organisations should consult qualified legal counsel to ensure compliance with applicable laws and regulations.
>
> *Template provided by VORLUX AI — vorluxai.com*

---

## AI Transparency Notice Template
### EU AI Act Article 50 and GDPR Article 22 notices

**Organisation:** _______________
**Document Reference:** AITN-[YYYY]-[NNN]
**Version:** _______________
**Prepared by:** _______________
**Approved by:** _______________
**Effective Date:** _______________

---

### Introduction: Article 50 Obligations

Article 50 of the EU AI Act (Regulation 2024/1689) sets transparency duties that apply from 2 August 2026:

1. **Chatbots and conversational AI — Art. 50(1), a provider duty:** people must be told they are interacting with an AI system, unless this is obvious from the context. If you put an assistant into service under your own name, the provider may be you (Art. 3(3)).
2. **AI-generated content:** providers of generative systems must mark outputs in a machine-readable way (Art. 50(2)). As a deployer you must disclose deep fakes, and AI-generated or manipulated text published to inform the public on matters of public interest unless it has undergone human review or editorial control and someone holds editorial responsibility (Art. 50(4)).
3. **Emotion recognition and biometric categorisation — Art. 50(3):** deployers must inform the people exposed to them.

Notices must be clear and distinguishable, at the latest at the first interaction or exposure (Art. 50(5)).

**Automated decisions are not Article 50.** They fall under GDPR Article 22 and its information duties (Articles 13(2)(f) and 14(2)(g)) and, for Annex III high-risk AI systems (from 2 December 2027), AI Act Articles 26(11) and 86. Part 3 covers them.

This document provides copy-paste ready notices for each scenario, in both English and Spanish.

---

### Part 1: Chatbot and Conversational AI Notices

#### 1.1 When to Display

The notice must appear **before or at the very start** of the interaction. It should not be buried in terms and conditions.

**Trigger events requiring notice:**
- [ ] First message in a new chat session
- [ ] When a user is transferred from human to AI agent
- [ ] When a user explicitly asks "Am I talking to a person?"
- [ ] At session start on any web chat widget
- [ ] Before voice interactions begin (IVR / voice bots)

---

#### 1.2 Standard Chatbot Notice — ENGLISH

**Short form (for chat widget header/banner):**

> **You are interacting with an AI assistant.**
> This service is powered by artificial intelligence. Responses are generated automatically and may not always be accurate. For important matters, please contact a human advisor.

---

**Long form (for first-message or modal):**

> **Automated AI Interaction Notice**
>
> You are about to interact with an AI-powered assistant provided by **[Organisation Name]**. This means:
>
> - Your conversation is handled by an artificial intelligence system, not a human.
> - The AI may make mistakes or provide incomplete information.
> - Your conversation may be logged and used to improve the service, in accordance with our Privacy Policy.
> - You have the right to request to speak with a human representative at any time by typing **"HUMAN"** or clicking the button below.
>
> By continuing, you acknowledge that you are interacting with an AI system.
>
> [Continue with AI] [Speak with a human]

---

**Response to "Are you human?" or "Am I talking to a real person?" — ENGLISH:**

> I am an AI assistant, not a human. I'm here to help you with [describe purpose, e.g., "questions about your account"], but I have limitations and may make mistakes. If you'd prefer to speak with a human agent, I can connect you now. Just say **"transfer to human"** or click [here].

---

#### 1.3 Standard Chatbot Notice — SPANISH / ESPAÑOL

**Forma corta (para encabezado/banner del chat):**

> **Estás interactuando con un asistente de IA.**
> Este servicio está impulsado por inteligencia artificial. Las respuestas se generan automáticamente y pueden no ser siempre precisas. Para asuntos importantes, contacta con un asesor humano.

---

**Forma larga (para primer mensaje o modal):**

> **Aviso de Interacción Automatizada con IA**
>
> Estás a punto de interactuar con un asistente impulsado por inteligencia artificial proporcionado por **[Nombre de la Organización]**. Esto significa:
>
> - Tu conversación es gestionada por un sistema de inteligencia artificial, no por una persona.
> - La IA puede cometer errores o proporcionar información incompleta.
> - Tu conversación puede ser registrada y usada para mejorar el servicio, de acuerdo con nuestra Política de Privacidad.
> - Tienes derecho a solicitar hablar con un representante humano en cualquier momento escribiendo **"HUMANO"** o haciendo clic en el botón de abajo.
>
> Al continuar, reconoces que estás interactuando con un sistema de inteligencia artificial.
>
> [Continuar con IA] [Hablar con una persona]

---

**Respuesta a "¿Eres humano?" o "¿Estoy hablando con una persona real?" — ESPAÑOL:**

> Soy un asistente de IA, no un ser humano. Estoy aquí para ayudarte con [describir propósito, p.ej. "preguntas sobre tu cuenta"], pero tengo limitaciones y puedo cometer errores. Si prefieres hablar con un agente humano, puedo conectarte ahora. Solo di **"transferir a humano"** o haz clic [aquí].

---

#### 1.4 Voice / IVR Systems

**English — Before voice AI interaction:**

> "Hello. Before we begin, please be aware that you are interacting with an automated AI voice assistant, not a human agent. This assistant can help you with [describe purpose]. If you'd prefer to speak with a human at any time, say 'agent' or press zero."

**Español — Antes de interacción por voz con IA:**

> "Hola. Antes de comenzar, le informamos que está interactuando con un asistente de voz automatizado por inteligencia artificial, no con un agente humano. Este asistente puede ayudarle con [describir el propósito]. Si en algún momento prefiere hablar con una persona, diga 'agente' o pulse cero."

---

### Part 2: AI-Generated Content Notices

#### 2.1 When Required

As a deployer, Article 50(4) requires disclosure in two cases:
- **Deep fakes:** image, audio or video content that resembles existing persons, objects, places or events and would falsely appear authentic (for evidently artistic, satirical or fictional work, a disclosure that does not hamper the work is enough).
- **Text published to inform the public on matters of public interest** that was generated or manipulated by AI, unless it has undergone human review or editorial control and someone holds editorial responsibility.

Providers of generative AI must also mark outputs in a machine-readable format (Art. 50(2)); for systems placed on the market before 2 August 2026, Regulation (EU) 2026/1744 gives until 2 December 2026.

Labelling other AI-assisted material (marketing copy, internal reports) is good practice and builds trust, but is not in itself a legal duty.

---

#### 2.2 Text / Written Content Labels — ENGLISH

**Inline label (short):**
> *This content was generated with the assistance of artificial intelligence.*

**Disclosure block (full — for reports or formal documents):**

> **AI Content Disclosure**
>
> This document [or: portions of this document] was generated or significantly assisted by an artificial intelligence system. The content has been reviewed by [a human editor / [Name, Role]] and [approved as accurate / may contain errors that have not been fully verified]. For decisions of consequence, please verify information independently.
>
> AI system used: [Name/version, or "Proprietary system"]
> Date generated: _______________
> Human reviewer: _______________

---

#### 2.3 Text / Written Content Labels — SPANISH / ESPAÑOL

**Etiqueta en línea (corta):**
> *Este contenido fue generado con la asistencia de inteligencia artificial.*

**Bloque de divulgación (completo — para informes o documentos formales):**

> **Declaración de Contenido Generado por IA**
>
> Este documento [o: partes de este documento] fue generado o significativamente asistido por un sistema de inteligencia artificial. El contenido ha sido revisado por [un editor humano / [Nombre, Cargo]] y [aprobado como exacto / puede contener errores que no han sido verificados completamente]. Para decisiones de importancia, verifique la información de forma independiente.
>
> Sistema de IA utilizado: [Nombre/versión, o "Sistema propietario"]
> Fecha de generación: _______________
> Revisor humano: _______________

---

#### 2.4 Image and Video Watermark / Caption Labels

**For social media / web images — ENGLISH:**
> [Image/Video generated by AI] | [AI-assisted image]

**For social media / web images — ESPAÑOL:**
> [Imagen/vídeo generado por IA] | [Imagen asistida por IA]

**For formal publications or advertising — ENGLISH:**
> *Important: This image/video was created using artificial intelligence tools. It does not depict real people, events, or locations unless stated otherwise.*

**For formal publications or advertising — ESPAÑOL:**
> *Importante: Esta imagen/vídeo fue creada utilizando herramientas de inteligencia artificial. No representa personas, eventos o lugares reales a menos que se indique lo contrario.*

---

#### 2.5 Email / Newsletter Disclosure

**Footer addition — ENGLISH:**
> Parts of this email may have been drafted using AI writing tools and reviewed by our team before sending.

**Footer addition — ESPAÑOL:**
> Partes de este correo pueden haber sido redactadas con herramientas de escritura de IA y revisadas por nuestro equipo antes de enviarse.

---

### Part 3: Automated Decision Notices

#### 3.1 When Required

This part is not Article 50. Under GDPR Article 22, people have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on them (with exceptions and safeguards), and Articles 13(2)(f) and 14(2)(g) require telling them about it, with meaningful information about the logic involved. For Annex III high-risk AI systems (from 2 December 2027), AI Act Article 26(11) requires deployers to inform the people concerned, and Article 86 gives them a right to an explanation. Typical cases:

- Recruitment or promotion decisions
- Credit or insurance decisions
- Benefits or social service eligibility
- Access to services or products
- Medical or health recommendations
- Educational assessment or grading

---

#### 3.2 Pre-Decision Notice — ENGLISH

*(Displayed before or at the start of a process involving automated decisions)*

> **Automated Decision-Making Notice**
>
> **[Organisation Name]** uses automated systems, including artificial intelligence, to support decisions in this process. This means that some or all of the assessment may be carried out or influenced by an algorithm, not solely by a human.
>
> **Your rights:**
> - You have the right to request a human review of any automated decision that significantly affects you.
> - You have the right to ask for an explanation of how the decision was reached.
> - You have the right to contest a decision you believe is incorrect or unfair.
>
> To exercise any of these rights, contact us at: **[email/phone/link]**
>
> For more information, see our [AI Transparency Policy] and [Privacy Policy].

---

#### 3.3 Post-Decision Notice — ENGLISH

*(Sent or displayed after an automated decision is made)*

> **Automated Decision Notification**
>
> We are writing to inform you that the decision regarding **[describe the decision, e.g., "your application for [role/product/service]"]** was made using an automated assessment system supported by artificial intelligence.
>
> **Outcome:** [State the decision clearly]
>
> **Key factors considered:** [List the main factors the AI assessed, e.g., credit history, qualifications, usage data]
>
> **Your rights:**
> You have 30 days from this notice to:
> - Request a full explanation of the factors and logic used
> - Request that a human member of our team review the decision
> - Challenge the decision if you believe it is incorrect or unjust
>
> To exercise these rights, please contact: **[Name/Team]** at **[contact details]**
>
> Reference number for your request: _______________

---

#### 3.4 Pre-Decision Notice — SPANISH / ESPAÑOL

*(Para mostrar antes o al inicio de un proceso con decisiones automatizadas)*

> **Aviso de Toma de Decisiones Automatizada**
>
> **[Nombre de la Organización]** utiliza sistemas automatizados, incluida la inteligencia artificial, para apoyar las decisiones en este proceso. Esto significa que parte o la totalidad de la evaluación puede ser realizada o influenciada por un algoritmo, no únicamente por una persona.
>
> **Sus derechos:**
> - Tiene derecho a solicitar una revisión humana de cualquier decisión automatizada que le afecte significativamente.
> - Tiene derecho a solicitar una explicación sobre cómo se tomó la decisión.
> - Tiene derecho a impugnar una decisión que considere incorrecta o injusta.
>
> Para ejercer cualquiera de estos derechos, contáctenos en: **[correo/teléfono/enlace]**
>
> Para más información, consulte nuestra [Política de Transparencia de IA] y [Política de Privacidad].

---

#### 3.5 Post-Decision Notice — SPANISH / ESPAÑOL

*(Enviado o mostrado tras una decisión automatizada)*

> **Notificación de Decisión Automatizada**
>
> Le informamos que la decisión sobre **[describir la decisión, p.ej. "su solicitud de [puesto/producto/servicio]"]** fue tomada utilizando un sistema de evaluación automatizado apoyado por inteligencia artificial.
>
> **Resultado:** [Indique la decisión claramente]
>
> **Factores clave considerados:** [Liste los principales factores que evaluó la IA, p.ej. historial crediticio, cualificaciones, datos de uso]
>
> **Sus derechos:**
> Dispone de 30 días desde este aviso para:
> - Solicitar una explicación completa de los factores y la lógica utilizada
> - Solicitar que un miembro humano de nuestro equipo revise la decisión
> - Impugnar la decisión si considera que es incorrecta o injusta
>
> Para ejercer estos derechos, contacte con: **[Nombre/Equipo]** en **[datos de contacto]**
>
> Número de referencia para su solicitud: _______________

---

### Part 4: Implementation Checklist

| Requirement | Status | Owner | Date Completed |
|-------------|--------|-------|----------------|
| Chatbot notice displayed at session start | ☐ Done ☐ Pending ☐ N/A | | |
| "Are you human?" response configured | ☐ Done ☐ Pending ☐ N/A | | |
| Voice AI disclosure recorded and activated | ☐ Done ☐ Pending ☐ N/A | | |
| AI content label on all AI-generated text | ☐ Done ☐ Pending ☐ N/A | | |
| AI label on all AI-generated images/video | ☐ Done ☐ Pending ☐ N/A | | |
| Pre-decision notice in relevant processes | ☐ Done ☐ Pending ☐ N/A | | |
| Post-decision notice template integrated | ☐ Done ☐ Pending ☐ N/A | | |
| Human review mechanism functional | ☐ Done ☐ Pending ☐ N/A | | |
| Contact details for rights exercise up to date | ☐ Done ☐ Pending ☐ N/A | | |
| Notices reviewed by legal counsel | ☐ Done ☐ Pending ☐ N/A | | |
| Staff trained on when to use each notice | ☐ Done ☐ Pending ☐ N/A | | |
| Spanish versions deployed where required | ☐ Done ☐ Pending ☐ N/A | | |

---

### Part 5: Customisation Log

Track changes made to these notices from the base template:

| Section Modified | Change Description | Modified by | Date | Approved by |
|------------------|--------------------|-------------|------|-------------|
| | | | | |
| | | | | |

---

*Template provided by VORLUX AI | vorluxai.com*
*Version 1.1 — September 2026 | Template to help meet EU AI Act Article 50 and GDPR Article 22*
*This is guidance only, not legal advice. Consult qualified legal counsel for your specific situation.*

---

### Versión Española

> **Aviso legal:** Esta plantilla se proporciona únicamente con fines orientativos. No constituye asesoramiento jurídico. Las organizaciones deben consultar con un abogado cualificado para garantizar el cumplimiento de la legislación y normativa aplicable.
>
> *Plantilla proporcionada por VORLUX AI — vorluxai.com*

---

## Plantilla de Aviso de Transparencia de IA
### Avisos del artículo 50 de la Ley de IA y del artículo 22 del RGPD

**Organización:** _______________
**Referencia del documento:** AITN-[AAAA]-[NNN]
**Versión:** _______________
**Preparado por:** _______________
**Aprobado por:** _______________
**Fecha de entrada en vigor:** _______________

---

### Introducción: Obligaciones del Artículo 50

El artículo 50 de la Ley de IA de la UE (Reglamento 2024/1689) fija deberes de transparencia que se aplican desde el 2 de agosto de 2026:

1. **Chatbots e IA conversacional — art. 50.1, deber del proveedor:** la persona debe saber que interactúa con un sistema de IA, salvo que resulte evidente por el contexto. Si pones en servicio un asistente con tu nombre, el proveedor puedes ser tú (art. 3.3).
2. **Contenido generado por IA:** los proveedores de sistemas generativos deben marcar sus resultados de forma legible por máquina (art. 50.2). Como responsable del despliegue debes revelar las ultrasuplantaciones y el texto generado o manipulado por IA que publiques para informar al público sobre asuntos de interés público, salvo que haya pasado revisión humana o control editorial y alguien asuma la responsabilidad editorial (art. 50.4).
3. **Reconocimiento de emociones y categorización biométrica — art. 50.3:** el responsable del despliegue debe informar a las personas expuestas.

El aviso debe ser claro y distinguible, a más tardar en la primera interacción o exposición (art. 50.5).

**Las decisiones automatizadas no son artículo 50.** Se rigen por el artículo 22 del RGPD y sus deberes de información (artículos 13.2.f y 14.2.g) y, en sistemas de alto riesgo del anexo III (desde el 2 de diciembre de 2027), por los artículos 26.11 y 86 de la Ley de IA. La parte 3 los cubre.

Este documento proporciona avisos listos para copiar y pegar para cada escenario, en inglés y español.

---

### Parte 1: Avisos para Chatbots e IA Conversacional

#### 1.1 Cuándo mostrar el aviso

El aviso debe aparecer **antes o al inicio** de la interacción. No debe quedar oculto en los términos y condiciones.

**Eventos que requieren aviso:**
- [ ] Primer mensaje en una nueva sesión de chat
- [ ] Cuando un usuario es transferido de un agente humano a uno de IA
- [ ] Cuando un usuario pregunta explícitamente "¿Estoy hablando con una persona?"
- [ ] Al inicio de sesión en cualquier widget de chat web
- [ ] Antes de que comiencen las interacciones de voz (IVR / bots de voz)

---

#### 1.2 Aviso estándar para chatbot

**Forma corta (para encabezado/banner del chat):**

> **Está interactuando con un asistente de IA.**
> Este servicio funciona con inteligencia artificial. Las respuestas se generan automáticamente y pueden no ser siempre precisas. Para asuntos importantes, contacte con un asesor humano.

---

**Forma larga (para primer mensaje o modal):**

> **Aviso de Interacción Automatizada con IA**
>
> Está a punto de interactuar con un asistente impulsado por inteligencia artificial proporcionado por **[Nombre de la Organización]**. Esto significa:
>
> - Su conversación es gestionada por un sistema de inteligencia artificial, no por una persona.
> - La IA puede cometer errores o proporcionar información incompleta.
> - Su conversación puede ser registrada y utilizada para mejorar el servicio, de acuerdo con nuestra Política de Privacidad.
> - Tiene derecho a solicitar hablar con un representante humano en cualquier momento escribiendo **"HUMANO"** o haciendo clic en el botón de abajo.
>
> Al continuar, reconoce que está interactuando con un sistema de inteligencia artificial.
>
> [Continuar con IA] [Hablar con una persona]

---

**Respuesta a "¿Es usted humano?" o "¿Estoy hablando con una persona real?":**

> Soy un asistente de IA, no un ser humano. Estoy aquí para ayudarle con [describir el propósito, p.ej. "preguntas sobre su cuenta"], pero tengo limitaciones y puedo cometer errores. Si prefiere hablar con un agente humano, puedo conectarle ahora. Solo diga **"transferir a humano"** o haga clic [aquí].

---

#### 1.3 Sistemas de voz / IVR

**Antes de la interacción por voz con IA:**

> "Hola. Antes de comenzar, le informamos de que está interactuando con un asistente de voz automatizado por inteligencia artificial, no con un agente humano. Este asistente puede ayudarle con [describir el propósito]. Si en algún momento prefiere hablar con una persona, diga 'agente' o pulse cero."

---

### Parte 2: Avisos de Contenido Generado por IA

#### 2.1 Cuándo es obligatorio

Como responsable del despliegue, el artículo 50.4 te obliga a revelarlo en dos casos:
- **Ultrasuplantaciones:** imagen, audio o vídeo que se parece a personas, objetos, lugares o hechos reales y puede parecer auténtico sin serlo (en obras claramente artísticas, satíricas o de ficción basta un aviso que no estorbe la obra).
- **Texto publicado para informar al público sobre asuntos de interés público** generado o manipulado por IA, salvo que haya pasado revisión humana o control editorial y alguien asuma la responsabilidad editorial.

Los proveedores de IA generativa deben además marcar sus resultados en un formato legible por máquina (art. 50.2); para sistemas introducidos en el mercado antes del 2 de agosto de 2026, el Reglamento (UE) 2026/1744 da plazo hasta el 2 de diciembre de 2026.

Etiquetar otro material hecho con ayuda de IA (textos de marketing, informes internos) es una buena práctica que genera confianza, pero no es por sí mismo una obligación legal.

---

#### 2.2 Etiquetas de contenido escrito / textual

**Etiqueta en línea (corta):**
> *Este contenido fue generado con la asistencia de inteligencia artificial.*

**Bloque de divulgación (completo — para informes o documentos formales):**

> **Declaración de Contenido Generado por IA**
>
> Este documento [o: partes de este documento] fue generado o significativamente asistido por un sistema de inteligencia artificial. El contenido ha sido revisado por [un editor humano / [Nombre, Cargo]] y [aprobado como exacto / puede contener errores que no han sido verificados completamente]. Para decisiones de importancia, verifique la información de forma independiente.
>
> Sistema de IA utilizado: [Nombre/versión, o "Sistema propietario"]
> Fecha de generación: _______________
> Revisor humano: _______________

---

#### 2.3 Etiquetas para imágenes y vídeos

**Para redes sociales / imágenes web:**
> [Imagen/vídeo generado por IA] | [Imagen asistida por IA]

**Para publicaciones formales o publicidad:**
> *Importante: Esta imagen/vídeo fue creada utilizando herramientas de inteligencia artificial. No representa personas, eventos o lugares reales a menos que se indique lo contrario.*

---

#### 2.4 Divulgación en correo electrónico / newsletter

**Pie de página:**
> Partes de este correo pueden haber sido redactadas con herramientas de escritura de IA y revisadas por nuestro equipo antes de enviarse.

---

### Parte 3: Avisos de Decisiones Automatizadas

#### 3.1 Cuándo es obligatorio

Esta parte no es artículo 50. Según el artículo 22 del RGPD, las personas tienen derecho a no ser objeto de una decisión basada únicamente en un tratamiento automatizado que produzca efectos jurídicos o les afecte significativamente de modo similar (con excepciones y garantías), y los artículos 13.2.f y 14.2.g exigen informarles, con información significativa sobre la lógica aplicada. En sistemas de alto riesgo del anexo III (desde el 2 de diciembre de 2027), el artículo 26.11 de la Ley de IA obliga al responsable del despliegue a informar a las personas afectadas, y el artículo 86 les da derecho a una explicación. Casos típicos:

- Decisiones de contratación o promoción
- Decisiones de crédito o seguros
- Elegibilidad para prestaciones o servicios sociales
- Acceso a servicios o productos
- Recomendaciones médicas o de salud
- Evaluación educativa o calificación

---

#### 3.2 Aviso previo a la decisión

*(Para mostrar antes o al inicio de un proceso con decisiones automatizadas)*

> **Aviso de Toma de Decisiones Automatizada**
>
> **[Nombre de la Organización]** utiliza sistemas automatizados, incluida la inteligencia artificial, para apoyar las decisiones en este proceso. Esto significa que parte o la totalidad de la evaluación puede ser realizada o influenciada por un algoritmo, no únicamente por una persona.
>
> **Sus derechos:**
> - Tiene derecho a solicitar una revisión humana de cualquier decisión automatizada que le afecte significativamente.
> - Tiene derecho a solicitar una explicación sobre cómo se tomó la decisión.
> - Tiene derecho a impugnar una decisión que considere incorrecta o injusta.
>
> Para ejercer cualquiera de estos derechos, contáctenos en: **[correo/teléfono/enlace]**
>
> Para más información, consulte nuestra [Política de Transparencia de IA] y [Política de Privacidad].

---

#### 3.3 Aviso posterior a la decisión

*(Enviado o mostrado tras una decisión automatizada)*

> **Notificación de Decisión Automatizada**
>
> Le informamos de que la decisión sobre **[describir la decisión, p.ej. "su solicitud de [puesto/producto/servicio]"]** fue tomada utilizando un sistema de evaluación automatizado apoyado por inteligencia artificial.
>
> **Resultado:** [Indique la decisión claramente]
>
> **Factores clave considerados:** [Liste los principales factores que evaluó la IA, p.ej. historial crediticio, cualificaciones, datos de uso]
>
> **Sus derechos:**
> Dispone de 30 días desde este aviso para:
> - Solicitar una explicación completa de los factores y la lógica utilizada
> - Solicitar que un miembro humano de nuestro equipo revise la decisión
> - Impugnar la decisión si considera que es incorrecta o injusta
>
> Para ejercer estos derechos, contacte con: **[Nombre/Equipo]** en **[datos de contacto]**
>
> Número de referencia para su solicitud: _______________

---

### Parte 4: Lista de verificación de implementación

| Requisito | Estado | Responsable | Fecha de finalización |
|-----------|--------|-------------|----------------------|
| Aviso de chatbot mostrado al inicio de sesión | ☐ Hecho ☐ Pendiente ☐ N/A | | |
| Respuesta a "¿Es usted humano?" configurada | ☐ Hecho ☐ Pendiente ☐ N/A | | |
| Divulgación de IA por voz grabada y activada | ☐ Hecho ☐ Pendiente ☐ N/A | | |
| Etiqueta de IA en todo el texto generado por IA | ☐ Hecho ☐ Pendiente ☐ N/A | | |
| Etiqueta de IA en todas las imágenes/vídeos generados por IA | ☐ Hecho ☐ Pendiente ☐ N/A | | |
| Aviso previo a la decisión en procesos relevantes | ☐ Hecho ☐ Pendiente ☐ N/A | | |
| Plantilla de aviso posterior a la decisión integrada | ☐ Hecho ☐ Pendiente ☐ N/A | | |
| Mecanismo de revisión humana funcional | ☐ Hecho ☐ Pendiente ☐ N/A | | |
| Datos de contacto para ejercicio de derechos actualizados | ☐ Hecho ☐ Pendiente ☐ N/A | | |
| Avisos revisados por asesoría jurídica | ☐ Hecho ☐ Pendiente ☐ N/A | | |
| Personal formado sobre cuándo usar cada aviso | ☐ Hecho ☐ Pendiente ☐ N/A | | |
| Versiones en español desplegadas donde sea necesario | ☐ Hecho ☐ Pendiente ☐ N/A | | |

---

### Parte 5: Registro de personalización

Registre los cambios realizados a estos avisos desde la plantilla base:

| Sección modificada | Descripción del cambio | Modificado por | Fecha | Aprobado por |
|--------------------|------------------------|----------------|-------|--------------|
| | | | | |
| | | | | |

---

*Plantilla proporcionada por VORLUX AI | vorluxai.com*
*Versión 1.1 — Septiembre 2026 | Plantilla para ayudar a cumplir el artículo 50 de la Ley de IA y el artículo 22 del RGPD*
*Esto es solo orientación, no asesoramiento jurídico. Consulte con un abogado cualificado para su situación específica.*

---

# Conformity Assessment Roadmap (Art. 43)
_Hoja de ruta para la evaluación de conformidad (art. 43)_

> Step-by-step conformity assessment roadmap for high-risk AI systems under EU AI Act Article 43, covering internal control (Annex VI) and notified body procedures (Annex VII).
> Online: https://vorluxai.com/templates/conformity-assessment/

## Conformity Assessment Roadmap — EU AI Act Article 43

> **Disclaimer:** This is guidance only, not legal advice. Consult qualified legal counsel for your specific compliance obligations.

**Template provided by VORLUX AI** | [vorluxai.com](https://vorluxai.com)

---

### Overview

Article 43 of the EU AI Act establishes the conformity assessment procedures that providers of high-risk AI systems must follow before CE marking and placing the system on the market. The route you take depends on your system category.

#### Quick Decision: Which Route Applies?

```
Is your system a high-risk AI system under Annex III?
        │
        ├── YES
        │       │
        │       ├── Is it listed in Annex III, item 1 (biometric identification)?
        │       │       │
        │       │       ├── YES → ROUTE B: Notified Body Assessment (Annex VII)
        │       │       │
        │       │       └── NO → Is it covered by pre-existing EU harmonised legislation
        │       │               that already requires notified body involvement?
        │       │                       │
        │       │                       ├── YES → Follow that sectoral procedure
        │       │                       │
        │       │                       └── NO → ROUTE A: Internal Control (Annex VI)
        │       │
        │       └── Has the provider chosen voluntary notified body involvement?
        │               │
        │               └── YES → ROUTE B (voluntary)
        │
        └── NO → EU AI Act high-risk conformity assessment does not apply
```

---

### Route A: Internal Control (Annex VI)

*Applicable to most Annex III, items 2–8 AI systems*

#### Phase 1 — Preparation (Weeks 1–4)

##### 1.1 Scope Definition

- [ ] Confirm the AI system is correctly classified as high-risk under Annex III
- [ ] Identify the specific Annex III category and item number
- [ ] Confirm no mandatory notified body route applies to this category
- [ ] Assign a Conformity Assessment Project Owner

| Field | Value |
|-------|-------|
| System Name | `___________________________` |
| Annex III Item | `___________________________` |
| Assessment Route | ☐ Route A (Annex VI) ☐ Route B (Annex VII) |
| Project Owner | `___________________________` |
| Start Date | `____-__-__` |
| Target Completion | `____-__-__` |

##### 1.2 Gap Analysis

- [ ] Review existing technical documentation against Annex IV requirements
- [ ] Review quality management system against Article 17 requirements
- [ ] Identify compliance gaps with a prioritised remediation plan
- [ ] Estimate effort and resource requirements to close all gaps

**Gap Analysis Summary:**

| Requirement Area | Gap Identified | Priority (H/M/L) | Remediation Owner | Due Date |
|-----------------|----------------|------------------|-------------------|----------|
| Technical Documentation (Annex IV) | `___________` | `___` | `___` | `____-__-__` |
| Quality Management (Art. 17) | `___________` | `___` | `___` | `____-__-__` |
| Risk Management (Art. 9) | `___________` | `___` | `___` | `____-__-__` |
| Data Governance (Art. 10) | `___________` | `___` | `___` | `____-__-__` |
| Human Oversight (Art. 14) | `___________` | `___` | `___` | `____-__-__` |
| Transparency (Art. 13) | `___________` | `___` | `___` | `____-__-__` |
| Accuracy & Robustness (Art. 15) | `___________` | `___` | `___` | `____-__-__` |
| Post-Market Monitoring (Art. 72) | `___________` | `___` | `___` | `____-__-__` |

---

#### Phase 2 — Evidence Collection and Documentation (Weeks 4–12)

##### 2.1 Technical Documentation (Article 11 + Annex IV)

- [ ] Complete all 15 sections of Annex IV technical documentation
- [ ] Technical documentation reviewed by subject matter experts
- [ ] Technical documentation reviewed by legal/compliance team
- [ ] Version controlled and stored in compliance document management system

**Reference:** See `technical-documentation-annex-iv.md` template

##### 2.2 Quality Management System (Article 17)

The QMS must address all of the following elements:

- [ ] **Strategy** — Regulatory compliance strategy documented and approved
- [ ] **Roles** — Roles, responsibilities, and authorities for quality clearly defined
- [ ] **Design** — Systematic approach to design and development including design review
- [ ] **Control** — Techniques for monitoring, measuring, and continual improvement
- [ ] **Data Governance** — Examination and validation of data management systems
- [ ] **Risk** — Risk management system in place and operational
- [ ] **Post-Market** — Post-market monitoring plan established
- [ ] **Incidents** — Serious incident reporting procedures established
- [ ] **Records** — Record management procedures ensuring traceability
- [ ] **Resources** — Resource allocation process for AI Act obligations
- [ ] **Accountability** — Management review and sign-off procedures

**QMS Document Reference:** `[File: ___________]`
**QMS Version:** `___`
**QMS Approval Date:** `____-__-__`

##### 2.3 Data Governance Evidence (Article 10)

- [ ] Training data documentation completed
- [ ] Validation and test data documentation completed
- [ ] Bias analysis results documented
- [ ] Data quality management procedures documented
- [ ] Personal data processing lawful basis confirmed

##### 2.4 Human Oversight Evidence (Article 14)

- [ ] Human oversight mechanisms described and implemented
- [ ] Operator competency requirements defined
- [ ] Override and intervention procedures documented and tested
- [ ] Monitoring dashboard requirements specified

**Reference:** See `human-oversight-guide.md` template

##### 2.5 Transparency and Instructions (Article 13)

- [ ] Instructions for use drafted and reviewed
- [ ] Capability and limitation disclosures included
- [ ] User-facing transparency notices prepared
- [ ] Multi-language versions for target markets prepared

---

#### Phase 3 — Internal Assessment (Weeks 12–16)

##### 3.1 Self-Assessment Criteria

Use the following table to assess compliance against each Article 43 requirement.

**Rating Scale:** 1 = Non-compliant | 2 = Partially compliant | 3 = Largely compliant | 4 = Fully compliant

| Requirement | Article | Evidence Reference | Rating (1–4) | Gaps / Actions |
|-------------|---------|-------------------|--------------|----------------|
| Risk Management System | Art. 9 | `___________` | `___` | `___________` |
| Data Governance | Art. 10 | `___________` | `___` | `___________` |
| Technical Documentation | Art. 11 | `___________` | `___` | `___________` |
| Transparency & Information | Art. 13 | `___________` | `___` | `___________` |
| Human Oversight | Art. 14 | `___________` | `___` | `___________` |
| Accuracy, Robustness, Cybersecurity | Art. 15 | `___________` | `___` | `___________` |
| Quality Management System | Art. 17 | `___________` | `___` | `___________` |
| Registration (EUAIS DB) | Art. 49 | `___________` | `___` | `___________` |

**Overall Compliance Rating:** `_____ / 32`

**Pass Threshold:** All items rated 4 (or documented exception agreed with legal counsel)

##### 3.2 Internal Review Panel

- [ ] Technical review completed by: `___________________________` on `____-__-__`
- [ ] Legal/compliance review completed by: `___________________________` on `____-__-__`
- [ ] Data protection review completed by DPO: `___________________________` on `____-__-__`
- [ ] Senior management sign-off: `___________________________` on `____-__-__`

##### 3.3 Remediation of Outstanding Gaps

- [ ] All critical (High priority) gaps closed
- [ ] Medium priority gaps closed or risk-accepted with documented rationale
- [ ] Evidence of gap closure collected and filed
- [ ] Updated technical documentation version issued

---

#### Phase 4 — Declaration and Registration (Weeks 16–18)

##### 4.1 EU Declaration of Conformity

- [ ] EU Declaration of Conformity drafted (see `declaration-of-conformity.md`)
- [ ] Declaration reviewed by legal counsel
- [ ] Declaration signed by authorised person
- [ ] Declaration dated and version-controlled
- [ ] Declaration stored for minimum 10 years after last placement on market

**Declaration Reference:** `DOC-____-____`
**Declaration Date:** `____-__-__`
**Authorised Signatory:** `___________________________`

##### 4.2 CE Marking

- [ ] CE marking affixed to the system (or accompanying documentation where marking on system not possible)
- [ ] CE marking meets format requirements (minimum height 5mm where size allows)
- [ ] CE marking accompanied by identification number of notified body (Route B only)

##### 4.3 EU AI System Database Registration

- [ ] High-risk AI system registered in EU AI systems database before placing on market
- [ ] Registration number obtained: `___________________________`
- [ ] Registration kept up to date with each significant change

---

### Route B: Conformity Assessment Involving Notified Body (Annex VII)

*Required for: Annex III item 1 (biometric ID systems); Optional for others*

#### When Must You Use a Notified Body?

| Trigger | Mandatory? | Notes |
|---------|------------|-------|
| Biometric identification/categorisation systems (Annex III, item 1) | YES | All systems in this category |
| Remote biometric identification in public spaces | YES | Even when prohibited categories are excluded |
| Provider voluntary choice | No — optional | Provider may choose for added assurance |
| Significant change to a system previously assessed by NB | Conditional | Check with your NB |

#### Selecting a Notified Body

- [ ] Confirm the notified body is accredited for the relevant AI Act scope
- [ ] Verify notified body is listed in NANDO (New Approach Notified and Designated Organisations) database
- [ ] Check notified body has relevant sector expertise
- [ ] Obtain quotes from at least 2 notified bodies
- [ ] Select notified body and formalise engagement

**Selected Notified Body:** `___________________________`
**NB Reference Number:** `___________________________`
**NB Contact:** `___________________________`
**Engagement Agreement Date:** `____-__-__`

#### Notified Body Assessment Phases

##### NB Phase 1 — Application and Scoping

- [ ] Formal application submitted to notified body
- [ ] Scope of assessment agreed in writing
- [ ] Technical documentation package submitted (Annex IV)
- [ ] QMS documentation submitted (Art. 17)
- [ ] Pre-assessment meeting held

**Application Date:** `____-__-__`
**Agreed Scope Reference:** `___________________________`

##### NB Phase 2 — Document Review

- [ ] Notified body reviews technical documentation
- [ ] Notified body reviews QMS
- [ ] NB queries/requests for information responded to
- [ ] Document review outcome received: ☐ Satisfactory ☐ Conditional ☐ Unsatisfactory

**Document Review Completion Date:** `____-__-__`
**Outcome Summary:** `___________________________`

##### NB Phase 3 — On-Site Assessment (where applicable)

- [ ] On-site assessment dates agreed: `____-__-__` to `____-__-__`
- [ ] Team briefed on assessment process
- [ ] Systems and environments prepared for demonstration
- [ ] Test cases and evidence packages ready for review
- [ ] Non-conformities identified and tracked

**On-Site Assessment Outcome:** ☐ Pass ☐ Pass with conditions ☐ Fail (major non-conformities)

##### NB Phase 4 — Certificate Issuance

- [ ] All major non-conformities closed
- [ ] Notified body issues EU type-examination certificate (Annex VII, module B) or
- [ ] Quality management system approval issued (Annex VII, module D)
- [ ] Certificate reference number recorded: `___________________________`
- [ ] Certificate validity period noted: `____-__-__` to `____-__-__`
- [ ] Annual surveillance schedule agreed with NB

---

### Third-Party Assessment Triggers

Even under Route A (internal control), the following events should prompt consideration of voluntary third-party review or mandatory re-assessment:

| Trigger | Action Required |
|---------|----------------|
| Substantial modification to the AI system | Repeat conformity assessment for modified aspects |
| Change of intended purpose | Full reassessment required |
| New deployment in a new Annex III category | New conformity assessment required |
| Material change to training data | Re-run data governance section; consider partial reassessment |
| Serious incident involving the AI system | Incident investigation; assess whether reassessment needed |
| Significant performance degradation | Technical documentation update; risk management review |
| New harmonised standards published | Gap analysis against new standards; update as needed |
| Regulatory guidance update from national authority | Review compliance and update documentation |
| Acquisition / change of legal entity | Confirm obligations transfer; update declarations |

---

### Conformity Assessment Timeline Tracker

| Phase | Planned Start | Planned End | Actual End | Status |
|-------|---------------|-------------|------------|--------|
| 1. Preparation & Gap Analysis | `____-__-__` | `____-__-__` | `____-__-__` | ☐ Not started ☐ In progress ☐ Complete |
| 2. Evidence Collection | `____-__-__` | `____-__-__` | `____-__-__` | ☐ Not started ☐ In progress ☐ Complete |
| 3. Internal Assessment | `____-__-__` | `____-__-__` | `____-__-__` | ☐ Not started ☐ In progress ☐ Complete |
| 4. Declaration & Registration | `____-__-__` | `____-__-__` | `____-__-__` | ☐ Not started ☐ In progress ☐ Complete |
| 5. NB Assessment (Route B only) | `____-__-__` | `____-__-__` | `____-__-__` | ☐ N/A ☐ In progress ☐ Complete |

---

### Related Templates

| Template | Purpose |
|----------|---------|
| `technical-documentation-annex-iv.md` | Complete Annex IV technical documentation |
| `declaration-of-conformity.md` | EU Declaration of Conformity (Art. 47) |
| `prohibited-practices-checklist.md` | Confirm no prohibited AI practices (Art. 5) |
| `human-oversight-guide.md` | Human oversight implementation (Art. 14) |

---

*Template provided by VORLUX AI | vorluxai.com | This is guidance only, not legal advice.*

---

### Versión Española

## Mapa de Evaluación de Conformidad — Artículo 43 del Acto UE sobre Inteligencia Artificial > **Advertencia:** Esta es orientación solo, no asesoramiento legal. Consulte a un abogado calificado para sus obligaciones específicas de cumplimiento. **Plantilla proporcionada por VORLUX AI** | [vorluxai.com](https://vorluxai.com) --- ## Visión general El artículo 43 del Acto UE sobre Inteligencia Artificial establece los procedimientos de evaluación de conformidad que deben seguirse por parte de los proveedores de sistemas de inteligencia artificial de alto riesgo antes de marcar con CE y poner el sistema en el mercado. La ruta que debes tomar depende de la categoría de tu sistema.

#### Decisión rápida: ¿Cuál es la Ruta que Aplica?

``` 
¿Es su sistema un sistema de inteligencia artificial de alto riesgo según el Anexo III?
│ ├── SÍ
│ │ │ ├── ¿Está incluido en el Anexo III, item 1 (identificación biométrica)?
│ │ │ │ │ ├── SÍ → RUTA B: Evaluación por parte de un Organismo Notificado (Anexo VII)
│ │ │ │ │ └── NO → ¿Se cubre con legislación UE armonizada preexistente que ya requiere la participación de un organismo notificado?
│ │ │ │ │ │ ├── SÍ → Sigue el procedimiento sectorial
│ │ │ │ │ │ └── NO → RUTA A: Control Interno (Anexo VI)
│ │ │ └── ¿El proveedor ha elegido la participación voluntaria de un organismo notificado?
│ │ │ └── SÍ → RUTA B (voluntario)
└── NO → La evaluación de conformidad del Acto UE sobre Inteligencia Artificial no se aplica a sistemas de alto riesgo
```

--- ## Ruta A: Control Interno (Anexo VI) *Aplicable a la mayoría de los sistemas de inteligencia artificial de alto riesgo según el Anexo III, items 2–8*

#### Fase 1 — Preparación (Semanas 1-4)

##### 1.1 Definición del alcance - [ ] Confirme que el sistema de inteligencia artificial se ha clasificado correctamente como de alto riesgo según el Anexo III - [ ] Identifique la categoría específica y número del item del Anexo III - [ ] Confirme que no hay una ruta obligatoria de organismo notificado aplicable a esta categoría - [ ] Asigne un Propietario de Proyecto de Evaluación de Conformidad | Campo | Valor | |-------|-------| | Nombre del sistema | `___________________________` | | Item del Anexo III | `___________________________` | | Ruta de evaluación | ☐ RUTA A (Anexo VI) ☐ RUTA B (Anexo VII) | | Propietario del Proyecto | `___________________________` | | Fecha de inicio | `____-__-__` | | Fecha objetivo de finalización | `____-__-__` |

##### 1.2 Análisis de brechas - [ ] Revisa la documentación técnica existente frente a los requisitos del Anexo IV - [ ] Revisa el sistema de gestión de calidad frente a los requisitos del artículo 17 - [ ] Identifica las brechas de cumplimiento con un plan de priorización para su remediaciónde - [ ] Estima el esfuerzo y recursos necesarios para cerrar todas las brechas **Resumen del Análisis de Brechas:** | Área de Requisito | Brecha identificada | Prioridad (A/M/B) | Propietario de la Remediaciónde | Fecha límite | |-----------------|----------------|------------------|-------------------|----------| | Documentación técnica (Anexo IV) | `___________` | `___` | `___` | `____

y control de versiones - [ ] Declaración almacenada durante un mínimo de 10 años después de la última colocación en el mercado **Referencia a la declaración:** `DOC-____-____` **Fecha de la declaración:** `____-__-__` **Firma autorizada:** `___________________________`

##### 4.2 Marcado CE - [ ] Marcado CE aplicado al sistema (o documentación acompañante donde no sea posible el marcado en el sistema) - [ ] El marcado CE cumple con los requisitos de formato (mínimo altura de 5mm donde sea posible) - [ ] El marcado CE está acompañado del número de identificación de la entidad notificada (Ruta B solo)

##### 4.3 Registro de bases de datos de sistemas AI de la UE - [ ] Sistema AI de alto riesgo registrado en la base de datos de sistemas AI de la UE antes de colocarlo en el mercado - [ ] Número de registro obtenido: `___________________________` - [ ] El registro se mantiene actualizado con cada cambio significativo

--- 

### Ruta B: Evaluación de conformidad que implica una entidad notificada (Anexo VII)

*Requerido para: Anexo III, item 1 (sistemas de identificación biométrica); Opcional para otros*

#### ¿Cuándo debe utilizar una entidad notificada?

| Desencadenante | Obligatorio? | Notas |
|---------|------------|-------|
| Sistemas de identificación/categorización biométricos (Anexo III, item 1) | SÍ | Todos los sistemas en esta categoría |
| Identificación biométrica remota en espacios públicos | SÍ | Incluso cuando se excluyen las categorías prohibidas |
| Elección voluntaria del proveedor | No — opcional | El proveedor puede elegir para obtener una mayor garantía |
| Cambio significativo a un sistema previamente evaluado por la entidad notificada | Condicionado | Verifique con su entidad notificada |

#### Seleccione una entidad notificada

- [ ] Confirme que la entidad notificada está acreditada para el alcance relevante del Reglamento AI
- [ ] Verifique si la entidad notificada está incluida en la base de datos NANDO (Nuevas Enfoques Notificadas y Organizaciones Designadas)
- [ ] Verifique que la entidad notificada tenga experiencia en el sector relevante
- [ ] Obtenga cotizaciones de al menos 2 entidades notificadas
- [ ] Seleccione la entidad notificada y formalice su compromiso

**Entidad Notificada Seleccionada:** `___________________________`
**Número de referencia de la entidad notificada:** `___________________________`
**Contacto de la entidad notificada:** `___________________________`
**Fecha del acuerdo de compromiso:** `____-__-__`

#### Fases de evaluación de la entidad notificada

##### Fase 1 de la entidad notificada — Solicitud y alcance

- [ ] Solicitud formal presentada a la entidad notificada
- [ ] Alcance del análisis acordado por escrito
- [ ] Paquete de documentación técnica presentado (Anexo IV)
- [ ] Documentación de QMS presentada (Art. 17)
- [ ] Reunión previa al análisis realizada

**Fecha de la solicitud:** `____-__-__`
**Referencia del alcance acordado:** `___________________________`

##### Fase 2 de la entidad notificada — Revisión documental

- [ ] La entidad notificada revisa la documentación técnica

---

# EU Declaration of Conformity (Art. 47, Annex V)
_Declaración UE de conformidad (art. 47, anexo V)_

> Official EU Declaration of Conformity template for high-risk AI systems as required by EU AI Act Article 47 and Annex V, including all mandatory fields and reference standards.
> Online: https://vorluxai.com/templates/declaration-of-conformity/

## EU Declaration of Conformity
### Article 47 & Annex V — EU AI Act (Regulation (EU) 2024/1689)

> **Disclaimer:** This is guidance only, not legal advice. Consult qualified legal counsel before signing and issuing this declaration. An incorrectly issued Declaration of Conformity may expose the provider to liability under the EU AI Act.

**Template provided by VORLUX AI** | [vorluxai.com](https://vorluxai.com)

---

### Instructions for Completing This Declaration

Annex V of the EU AI Act mandates specific content for the Declaration of Conformity. This document must:

1. Be drawn up for **each high-risk AI system** separately
2. Contain **all the information** listed in Annex V
3. Be **kept for 10 years** after the AI system has been placed on the market or put into service
4. Be **made available to national competent authorities** on request
5. Be **updated** when a substantial modification is made to the AI system
6. Be **translated** into the official language(s) of Member States where the system is deployed, if required by national authority

---

### ═══════════════════════════════════════════════
### EU DECLARATION OF CONFORMITY
### ═══════════════════════════════════════════════

**Declaration No.:** `DOC-____-____-____`
**Issue Date:** `____-__-__`
**Version:** `___`

---

#### 1. Provider Identification

*[Annex V §1 — Full name and address of provider]*

| Field | Details |
|-------|---------|
| Legal Entity Name | `___________________________` |
| Trading Name (if different) | `___________________________` |
| Legal Form | `___________________________` |
| Registered Address (Line 1) | `___________________________` |
| Registered Address (Line 2) | `___________________________` |
| City | `___________________________` |
| Postcode | `___________________________` |
| Country (EU Member State) | `___________________________` |
| VAT / Company Registration No. | `___________________________` |
| Contact Email | `___________________________` |
| Contact Telephone | `___________________________` |
| Website | `___________________________` |

**Where the provider is not established in the EU:**

| Field | Details |
|-------|---------|
| EU Authorised Representative Name | `___________________________` |
| EU Authorised Representative Address | `___________________________` |
| EU Authorised Representative Contact | `___________________________` |
| Mandate Reference | `___________________________` |

---

#### 2. AI System Identification

*[Annex V §2 — Name and type of the AI system, version information]*

| Field | Details |
|-------|---------|
| AI System Name | `___________________________` |
| Product / Model Reference | `___________________________` |
| Version Number | `___________________________` |
| Software Version / Build ID | `___________________________` |
| Serial Number (if applicable) | `___________________________` |
| Batch / Lot Number (if applicable) | `___________________________` |
| Unique Identifier (UUID/SKU) | `___________________________` |
| Date of Manufacture / Release | `____-__-__` |

**Brief System Description:**

```
[Provide a concise description of what the AI system does, sufficient to identify it
clearly. Example: "An AI-based recruitment screening tool that analyses CVs and
ranks candidates for shortlisting, intended for use by HR professionals in
medium-to-large enterprises."]
```

**High-Risk Classification:**
- Annex III Item: `_____`
- Category: `___________________________`
- Deployment Context: `___________________________`

---

#### 3. Statement of Conformity

*[Annex V §3 — Statement that the AI system is in conformity with this Regulation]*

This EU Declaration of Conformity is issued under the sole responsibility of the provider identified in Section 1 above.

The AI system identified in Section 2:

> **is in conformity with Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) and amending certain Union legislative acts.**

Specifically, the AI system complies with the following provisions of Regulation (EU) 2024/1689:

| Provision | Subject Matter | Compliant |
|-----------|---------------|-----------|
| Article 9 | Risk management system | ☐ Yes ☐ N/A |
| Article 10 | Data and data governance | ☐ Yes ☐ N/A |
| Article 11 | Technical documentation | ☐ Yes ☐ N/A |
| Article 12 | Record-keeping | ☐ Yes ☐ N/A |
| Article 13 | Transparency and provision of information | ☐ Yes ☐ N/A |
| Article 14 | Human oversight | ☐ Yes ☐ N/A |
| Article 15 | Accuracy, robustness and cybersecurity | ☐ Yes ☐ N/A |
| Article 17 | Quality management system | ☐ Yes ☐ N/A |
| Article 49 | Registration in EU database | ☐ Yes ☐ N/A |

---

#### 4. Reference to Applicable Harmonised Standards

*[Annex V §4 — Where relevant, reference to harmonised standards applied]*

Harmonised standards applied (tick all that apply and fill in details):

| Standard | Title | Version | Applied |
|----------|-------|---------|---------|
| EN ISO/IEC 42001 | Information technology — Artificial intelligence — Management system | `____` | ☐ Full ☐ Partial ☐ No |
| ISO/IEC 27001 | Information security management systems | `____` | ☐ Full ☐ Partial ☐ No |
| ISO/IEC 27701 | Privacy information management | `____` | ☐ Full ☐ Partial ☐ No |
| ISO/IEC 23894 | AI — Guidance on risk management | `____` | ☐ Full ☐ Partial ☐ No |
| ISO/IEC 38507 | Governance of IT — Governance implications of the use of AI | `____` | ☐ Full ☐ Partial ☐ No |
| CEN/CENELEC TR 17279 | AI — Overview of trustworthiness | `____` | ☐ Full ☐ Partial ☐ No |
| ETSI EN 303 645 | Cyber security for consumer IoT (if applicable) | `____` | ☐ Full ☐ Partial ☐ No |
| Other: `___________` | `___________` | `____` | ☐ Full ☐ Partial ☐ No |

**Note on partial application:** Where a standard has been applied only partially, specify which clauses or elements were applied and which were not, with justification:

```
[List clauses applied, clauses not applied, and reason for non-application]
```

---

#### 5. Reference to Other EU Legislation

*[Annex V §5 — Reference to any other relevant Union harmonisation legislation applied]*

Where the AI system also falls within the scope of other EU harmonisation legislation, declare conformity with that legislation here:

| Regulation / Directive | Reference | Conformity Status |
|------------------------|-----------|-------------------|
| GDPR (Regulation (EU) 2016/679) | ☐ Applies | `___________` |
| Medical Device Regulation (EU) 2017/745 | ☐ Applies | `___________` |
| Machinery Regulation (EU) 2023/1230 | ☐ Applies | `___________` |
| Radio Equipment Directive 2014/53/EU | ☐ Applies | `___________` |
| General Product Safety Regulation | ☐ Applies | `___________` |
| NIS2 Directive (EU) 2022/2555 | ☐ Applies | `___________` |
| Other: `___________` | ☐ Applies | `___________` |

---

#### 6. Notified Body Information

*[Annex V §6 — Where applicable, notified body name and number]*

☐ **Route A (Annex VI) — Internal Control:** No notified body involvement. Declaration is based on provider's internal conformity assessment.

☐ **Route B (Annex VII) — Notified Body Assessment:** The following notified body was involved:

| Field | Details |
|-------|---------|
| Notified Body Name | `___________________________` |
| Notified Body EU Reference Number | `___________________________` |
| Notified Body Address | `___________________________` |
| Type of Assessment Performed | ☐ Annex VII Module B (type-examination) ☐ Annex VII Module D (QMS) ☐ Other |
| Certificate / Report Reference | `___________________________` |
| Certificate Issue Date | `____-__-__` |
| Certificate Validity Date | `____-__-__` |

---

#### 7. Technical Documentation Reference

*[Supporting evidence — not an Annex V requirement but strongly recommended]*

| Document | Reference | Version | Location |
|----------|-----------|---------|----------|
| Annex IV Technical Documentation | `TDD-____-____` | `___` | `[Secure document store]` |
| Risk Management Report | `RMR-____-____` | `___` | `[Secure document store]` |
| Data Governance Report | `DGR-____-____` | `___` | `[Secure document store]` |
| QMS Documentation | `QMS-____-____` | `___` | `[Secure document store]` |
| Conformity Assessment Report | `CAR-____-____` | `___` | `[Secure document store]` |

---

#### 8. Signature and Authorisation

*[Annex V §7 — Place and date of issue; name, function and signature of person authorised to sign]*

This declaration is signed on behalf of the provider by:

**Place of Issue:** `___________________________`

**Date of Issue:** `____-__-__`

---

| Field | Details |
|-------|---------|
| Full Name | `___________________________` |
| Function / Title | `___________________________` |
| Department | `___________________________` |
| Email | `___________________________` |

**Signature:**

```
___________________________
[Wet signature or qualified electronic signature (QES) required for official use]
```

**Company Stamp / Seal:** *(where required by national law)*

```
[STAMP / SEAL]
```

---

### Declaration Version Control

| Version | Date | Author | Changes |
|---------|------|--------|---------|
| 1.0 | `____-__-__` | `___________` | Initial issue |
| `___` | `____-__-__` | `___________` | `___________` |

---

### Post-Issuance Obligations

After signing this declaration, the provider must:

| Obligation | Deadline | Status |
|------------|----------|--------|
| Retain declaration for 10 years after last placement on market | Ongoing | ☐ Confirmed |
| Provide to national competent authority on request | Within period specified by authority | ☐ Procedure in place |
| Update declaration if substantial modification made to system | Before modified system is placed on market | ☐ Process defined |
| Update declaration if new EU harmonised standards become applicable | Upon publication and after transition period | ☐ Monitoring in place |
| Ensure EU authorised representative holds copy (if non-EU provider) | At time of issue | ☐ Confirmed |
| Include reference/link to declaration in instructions for use | At time of issue | ☐ Confirmed |
| Register or update entry in EU AI systems database (Art. 49) | Before placement on market | ☐ Completed — Reg. No.: `___` |

---

### Substantial Modification Checklist

A new or updated declaration is required whenever the AI system undergoes a **substantial modification**. Review the following after any system change:

| Change Type | Substantial Modification? | New Declaration Required? |
|-------------|--------------------------|--------------------------|
| Change to intended purpose | Almost always YES | YES |
| Change to Annex III category | YES | YES |
| Significant change to model architecture | Assess case-by-case | Likely YES |
| Retraining on materially different data | Assess case-by-case | May be required |
| Security patch only | Usually NO | NO |
| UI/interface change only | Usually NO | NO |
| Performance improvement without architectural change | Assess case-by-case | May be required |
| Deployment to new Member State | NO (update instructions only) | NO (update registration) |

**Decision Rule:** When in doubt, consult legal counsel and document the decision rationale.

---

*Template provided by VORLUX AI | vorluxai.com | This is guidance only, not legal advice.*

---

### Versión Española

## Declaración de Conformidad de la UE
### Artículo 47 & Anexo V — EU AI Act (Regulación (UE) 2024/1689)

> **Aviso:** Este es solo una guía, no asesoramiento legal. Consulte a un abogado calificado antes de firmar e emitir esta declaración. Una Declaración de Conformidad emitida incorrectamente puede exponer al proveedor a responsabilidad bajo la EU AI Act.

**Plantilla proporcionada por VORLUX AI** | [vorluxai.com](https://vorluxai.com)

---

### Instrucciones para completar esta declaración

El Anexo V de la EU AI Act establece contenido específico para la Declaración de Conformidad. Este documento debe:

1. Ser elaborado **para cada sistema de inteligencia artificial de alto riesgo** por separado
2. Contener **toda la información** enumerada en el Anexo V
3. Ser **mantenida durante 10 años** después de que el sistema de inteligencia artificial haya sido puesto en el mercado o puesta en servicio
4. Ser **facilitada a las autoridades competentes nacionales** a petición
5. Ser **actualizada** cuando se realice una modificación sustancial al sistema de inteligencia artificial
6. Ser **traducida** a los idiomas oficiales de los Estados miembros donde el sistema está desplegado, si lo requiere la autoridad nacional

---

### ═══════════════════════════════════════════════
### DECLARACIÓN DE CONFORMIDAD DE LA UE
### ═══════════════════════════════════════════════

**Número de Declaración:** `DOC-____-____-____`
**Fecha de emisión:** `____-__-__`
**Versión:** `___`

---

#### 1. Identificación del proveedor

*[Anexo V §1 — Nombre y dirección completa del proveedor]*

| Campo | Detalles |
|-------|---------|
| Nombre Legal de la Entidad | `___________________________` |
| Razón Social (si es diferente) | `___________________________` |
| Forma Jurídica | `___________________________` |
| Dirección Registrada (Línea 1) | `___________________________` |
| Dirección Registrada (Línea 2) | `___________________________` |
| Ciudad | `___________________________` |
| Código Postal | `___________________________` |
| País (Estado miembro de la UE) | `___________________________` |
| Número de Identificación Fiscal / Registro Comercial | `___________________________` |
| Correo Electrónico de Contacto | `___________________________` |
| Teléfono de Contacto | `___________________________` |
| Sitio Web | `___________________________` |

**Si el proveedor no está establecido en la UE:**

| Campo | Detalles |
|-------|---------|
| Nombre del Representante Autorizado por la UE | `___________________________` |
| Dirección del Representante Autorizado por la UE | `___________________________` |
| Contacto del Representante Autorizado por la UE | `___________________________` |
| Referencia de Mandato | `___________________________` |

---

#### 2. Identificación del Sistema de Inteligencia Artificial

*[Anexo V §2 — Nombre y tipo del sistema de inteligencia artificial, información de versión]*

| Campo | Detalles |
|-------|---------|
| Nombre del Sistema de Inteligencia Artificial | `___________________________` |
| Referencia del Producto / Modelo | `___________________________` |
| Número de Versión | `___________________________` |
| Versión del Software / ID de Compilación | `___________________________` |
| Número de Serie (si corresponde) | `___________________________` |
| Número de Lote / Lot (si corresponde) | `___________________________` |
| Identificador Único (UUID/SKU) | `___________________________` |
| Fecha de Fabricación / Lanzamiento | `____-__-__` |

**Descripción del Sistema Breve:**

```
[Proporcione una descripción concisa de qué hace el sistema de inteligencia artificial, suficiente para identificarlo claramente. Ejemplo: "Una herramienta de screening de inteligencia artificial basada en CV que analiza y clasifica a los candidatos para su selección, destinada al uso por profesionales de RRHH en empresas medianas y grandes."]
```

**Clasificación de Alto Riesgo:**
- Anexo III Item: `_____`
- Categoría: `___________________________`
- Contexto de Despliegue: `___________________________`

---

#### 3. Declaración de Conformidad

*[Anexo V §3 — Declaración de que el sistema de inteligencia artificial es conforme con esta regulación]*

Esta Declaración de Conformidad de la UE se emite bajo la responsabilidad exclusiva del proveedor identificado en la Sección 1 anterior.

El sistema de inteligencia artificial identificado en la Sección 2:

> **es conforme con la Regulación (UE) 2024/1689 del Parlamento Europeo y del Consejo de 13 de junio de 2024 que establece normas armonizadas sobre la inteligencia artificial (Artificial Intelligence).**

---

# Fundamental Rights Impact Assessment (FRIA) Template
_Plantilla de evaluación de impacto sobre los derechos fundamentales (FRIA)_

> Structured template for conducting a Fundamental Rights Impact Assessment for high-risk AI systems under EU AI Act Article 27.
> Online: https://vorluxai.com/templates/fria-template/

> **Disclaimer:** This template is provided for guidance purposes only. It does not constitute legal advice. Organisations should consult qualified legal counsel to ensure compliance with applicable laws and regulations.
>
> *Template provided by VORLUX AI — vorluxai.com*

---

## Fundamental Rights Impact Assessment (FRIA)
### EU AI Act — Article 27 Compliance Template

**Document Reference:** FRIA-[YYYY]-[NNN]
**Version:** _______________
**Date Initiated:** _______________
**Date Completed:** _______________
**Next Review Date:** _______________
**Classification:** ☐ Public  ☐ Internal  ☐ Confidential

---

### Part A: Organisation & System Details

| Field | Entry |
|-------|-------|
| Organisation Name | |
| Organisation Type | ☐ Public body  ☐ Private company  ☐ Non-profit |
| Contact Person (DPO/AI Officer) | |
| Email | |
| AI System Name | |
| AI System Version | |
| Deployment Region(s) | |
| Intended Go-Live Date | |
| High-Risk Category (Annex III) | |

---

### Part B: System Description

#### B.1 Purpose and Functionality

**What does the AI system do? (Describe in plain language)**

> *[Provide a clear, jargon-free description of what the system does, its inputs, processing logic, and outputs.]*

_______________________________________________________________________________
_______________________________________________________________________________
_______________________________________________________________________________

**What specific decision(s) does the system make or support?**

- Decision 1: _______________
- Decision 2: _______________
- Decision 3: _______________

**Is the AI system the sole decision-maker, or does a human review outputs?**

☐ Fully automated (no human review)
☐ Human-in-the-loop (human can override)
☐ Human-on-the-loop (human monitors, intervenes if needed)
☐ Human-in-command (AI is advisory only)

**Describe the human oversight mechanism:**

_______________________________________________________________________________

---

#### B.2 Affected Populations

**Who are the individuals or groups directly affected by this system?**

| Population Group | Estimated Number | Vulnerability Level |
|-----------------|-----------------|-------------------|
| | | ☐ Low ☐ Medium ☐ High |
| | | ☐ Low ☐ Medium ☐ High |
| | | ☐ Low ☐ Medium ☐ High |
| | | ☐ Low ☐ Medium ☐ High |

**Do affected groups include vulnerable persons?** ☐ Yes  ☐ No  ☐ Possibly

If yes, specify:
☐ Minors (under 18)
☐ Elderly persons
☐ Persons with disabilities
☐ Persons with mental health conditions
☐ Persons in economically precarious situations
☐ Asylum seekers / migrants
☐ Other: _______________

---

#### B.3 Technical Specification Summary

| Parameter | Detail |
|-----------|--------|
| AI/ML Model Type | |
| Training Data Sources | |
| Data Freshness | |
| Known Accuracy / Error Rate | |
| External APIs or Third-party Models Used | |
| Data Processed (categories) | |
| Special Category Data Involved? | ☐ Yes  ☐ No |

---

### Part C: Rights Affected — Screening

**Instructions:** For each fundamental right, indicate whether the AI system *affects* it (even indirectly). Mark all that apply and proceed to the risk scoring in Part D for each marked right.

| # | Fundamental Right | Affected? | Potential Impact |
|---|-------------------|-----------|-----------------|
| 1 | Human dignity (Art. 1 EUCFR) | ☐ Yes ☐ No ☐ Unclear | |
| 2 | Right to life (Art. 2) | ☐ Yes ☐ No ☐ Unclear | |
| 3 | Prohibition of torture / inhuman treatment (Art. 4) | ☐ Yes ☐ No ☐ Unclear | |
| 4 | Prohibition of slavery (Art. 5) | ☐ Yes ☐ No ☐ Unclear | |
| 5 | Right to liberty and security (Art. 6) | ☐ Yes ☐ No ☐ Unclear | |
| 6 | Respect for private and family life (Art. 7) | ☐ Yes ☐ No ☐ Unclear | |
| 7 | Protection of personal data (Art. 8) | ☐ Yes ☐ No ☐ Unclear | |
| 8 | Right to marry and found a family (Art. 9) | ☐ Yes ☐ No ☐ Unclear | |
| 9 | Freedom of thought, conscience, religion (Art. 10) | ☐ Yes ☐ No ☐ Unclear | |
| 10 | Freedom of expression and information (Art. 11) | ☐ Yes ☐ No ☐ Unclear | |
| 11 | Freedom of assembly and association (Art. 12) | ☐ Yes ☐ No ☐ Unclear | |
| 12 | Freedom of the arts and sciences (Art. 13) | ☐ Yes ☐ No ☐ Unclear | |
| 13 | Right to education (Art. 14) | ☐ Yes ☐ No ☐ Unclear | |
| 14 | Freedom to choose an occupation (Art. 15) | ☐ Yes ☐ No ☐ Unclear | |
| 15 | Freedom to conduct a business (Art. 16) | ☐ Yes ☐ No ☐ Unclear | |
| 16 | Right to property (Art. 17) | ☐ Yes ☐ No ☐ Unclear | |
| 17 | Right to asylum (Art. 18) | ☐ Yes ☐ No ☐ Unclear | |
| 18 | Equality before the law (Art. 20) | ☐ Yes ☐ No ☐ Unclear | |
| 19 | Non-discrimination (Art. 21) | ☐ Yes ☐ No ☐ Unclear | |
| 20 | Cultural, religious, linguistic diversity (Art. 22) | ☐ Yes ☐ No ☐ Unclear | |
| 21 | Equality between men and women (Art. 23) | ☐ Yes ☐ No ☐ Unclear | |
| 22 | Rights of the child (Art. 24) | ☐ Yes ☐ No ☐ Unclear | |
| 23 | Rights of the elderly (Art. 25) | ☐ Yes ☐ No ☐ Unclear | |
| 24 | Integration of persons with disabilities (Art. 26) | ☐ Yes ☐ No ☐ Unclear | |
| 25 | Right to an effective remedy / fair trial (Art. 47) | ☐ Yes ☐ No ☐ Unclear | |
| 26 | Presumption of innocence (Art. 48) | ☐ Yes ☐ No ☐ Unclear | |
| 27 | Legality / proportionality of criminal offences (Art. 49) | ☐ Yes ☐ No ☐ Unclear | |
| 28 | Right not to be tried twice (Art. 50) | ☐ Yes ☐ No ☐ Unclear | |

---

### Part D: Risk Analysis

#### D.1 Scoring Methodology

For each right flagged **Yes** or **Unclear** in Part C, complete the scoring table below.

**Likelihood Score (L):**
| Score | Meaning |
|-------|---------|
| 1 | Remote — impact unlikely under normal operation |
| 2 | Possible — impact could occur in some circumstances |
| 3 | Likely — impact expected under certain conditions |
| 4 | Certain — impact will occur in normal operation |

**Severity Score (S):**
| Score | Meaning |
|-------|---------|
| 1 | Negligible — minimal effect, easily reversible |
| 2 | Moderate — noticeable harm, reversible with effort |
| 3 | Significant — serious harm, difficult to reverse |
| 4 | Severe — irreversible or catastrophic harm |

**Risk Score = L × S**
| Score Range | Risk Level |
|-------------|------------|
| 1–3 | Low |
| 4–8 | Medium |
| 9–12 | High |
| 13–16 | Critical |

---

#### D.2 Risk Scoring Table

| Right | Likelihood (1–4) | Severity (1–4) | Risk Score | Risk Level | Notes |
|-------|-----------------|----------------|------------|------------|-------|
| [e.g., Non-discrimination] | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |
| | | | | | |

---

#### D.3 Detailed Risk Narratives

For each **Medium**, **High**, or **Critical** risk, complete the following:

---

**Right affected:** _______________
**Risk Score:** _______________  **Risk Level:** _______________

*How does the AI system create or exacerbate this risk?*

_______________________________________________________________________________

*Which affected groups are most exposed to this risk?*

_______________________________________________________________________________

*What is the worst-case scenario?*

_______________________________________________________________________________

*Is there historical precedent or research evidence for this risk?*

_______________________________________________________________________________

*(Copy this block for each risk identified)*

---

### Part E: Mitigation Measures

#### E.1 Mitigation Catalogue

For each identified risk, document mitigation measures:

| Risk ID | Risk Description | Mitigation Measure | Type | Owner | Deadline | Status |
|---------|-----------------|-------------------|------|-------|----------|--------|
| R-01 | | | ☐ Technical ☐ Organisational ☐ Legal | | | ☐ Planned ☐ In progress ☐ Done |
| R-02 | | | ☐ Technical ☐ Organisational ☐ Legal | | | ☐ Planned ☐ In progress ☐ Done |
| R-03 | | | ☐ Technical ☐ Organisational ☐ Legal | | | ☐ Planned ☐ In progress ☐ Done |
| R-04 | | | ☐ Technical ☐ Organisational ☐ Legal | | | ☐ Planned ☐ In progress ☐ Done |
| R-05 | | | ☐ Technical ☐ Organisational ☐ Legal | | | ☐ Planned ☐ In progress ☐ Done |

#### E.2 Residual Risk Assessment

After mitigations, reassess each risk:

| Risk ID | Original Score | Residual Score | Residual Level | Accepted? |
|---------|---------------|----------------|----------------|-----------|
| R-01 | | | | ☐ Yes  ☐ Escalate |
| R-02 | | | | ☐ Yes  ☐ Escalate |
| R-03 | | | | ☐ Yes  ☐ Escalate |

**Overall residual risk level for deployment:** ☐ Acceptable  ☐ Conditional  ☐ Unacceptable

If conditional, list conditions for deployment:

_______________________________________________________________________________

---

### Part F: Monitoring Plan

#### F.1 Ongoing Monitoring Activities

| Monitoring Activity | Frequency | Responsible Person | KPI / Threshold | Escalation Trigger |
|--------------------|-----------|-------------------|----------------|-------------------|
| Model performance review | | | | |
| Bias / fairness audit | | | | |
| User complaint review | | | | |
| Data drift check | | | | |
| Incident log review | | | | |
| Regulatory update review | | | | |

#### F.2 Re-assessment Triggers

This FRIA must be reviewed and updated if any of the following occur:

☐ Significant change to the AI system's purpose or functionality
☐ Significant change to the data used for training or inference
☐ Material change in the regulatory or legal environment
☐ Incident causing or nearly causing fundamental rights harm
☐ Entry into a new deployment territory or context
☐ Annual review (minimum)
☐ Other: _______________

#### F.3 Incident Reporting

**Internal escalation contact:** _______________
**DPO / AI Officer contact:** _______________
**Regulatory reporting obligation?** ☐ Yes (specify authority): _______________ ☐ No

---

### Part G: Consultation Record

| Stakeholder / Group Consulted | Date | Method | Key Findings / Concerns |
|-------------------------------|------|--------|------------------------|
| Internal legal team | | | |
| DPO | | | |
| Affected community representative | | | |
| Technical team | | | |
| External expert | | | |

---

### Part H: Sign-off

| Role | Name | Signature | Date |
|------|------|-----------|------|
| AI System Owner | | | |
| Data Protection Officer | | | |
| Legal Counsel | | | |
| Executive Sponsor | | | |

**Final Assessment Decision:**

☐ **Approved** — System may proceed to deployment as described.
☐ **Approved with conditions** — System may proceed subject to the conditions listed in Part E.
☐ **Rejected** — Residual risks are unacceptable. System must not deploy until risks are reduced.

**Rationale for decision:**

_______________________________________________________________________________
_______________________________________________________________________________

---

*Template provided by VORLUX AI | vorluxai.com*
*Version 1.0 — April 2026 | EU AI Act Article 27 compliant template*
*This is guidance only, not legal advice. Consult qualified legal counsel for your specific situation.*

---

### Versión Española

> **Aviso:** Este modelo se proporciona solo con fines de orientación. No constituye asesoramiento legal. Las organizaciones deben consultar a abogados calificados para asegurarse de que cumplan con las leyes y regulaciones aplicables.

---

## Evaluación del Impacto en los Derechos Fundamentales (FRIA)

### Reglamento UE sobre Inteligencia Artificial — Cumplimiento del artículo 27

**Referencia del documento:** FRIA-[YYYY]-[NNN]

**Versión:** _______________

**Fecha de inicio:** _______________

**Fecha de finalización:** _______________

**Fecha de revisión siguiente:** _______________

**Clasificación:** ☐ Público ☐ Interno ☐ Confidencial

---

### Parte A: Detalles de la organización y el sistema

| Campo | Entrada |
|-------|--------|
| Nombre de la organización |  |
| Tipo de organización | ☐ Entidad pública ☐ Empresa privada ☐ Sin fines de lucro |
| Persona de contacto (DPO/Oficial de Inteligencia Artificial) |  |
| Correo electrónico |  |
| Nombre del sistema de inteligencia artificial |  |
| Versión del sistema de inteligencia artificial |  |
| Regiones de despliegue |  |
| Fecha prevista para el lanzamiento |  |
| Categoría de alto riesgo (Anexo III) |  |

---

### Parte B: Descripción del sistema

#### B.1 Propósito y funcionalidad

**¿Qué hace el sistema de inteligencia artificial? (Describe en lenguaje llano)**

> *[Proporciona una descripción clara y sin jerga de lo que hace el sistema, sus entradas, lógica de procesamiento y salidas.]* _______________________________________________________________________________ _______________________________________________________________________________ _______________________________________________________________________________

**¿Qué decisión(es) específica(s) toma o respalda el sistema?**

- Decisión 1: _______________
- Decisión 2: _______________
- Decisión 3: _______________

**¿Es el sistema de inteligencia artificial el único tomador de decisiones, o un humano revisa las salidas?**

☐ Automatizado por completo (sin revisión humana) ☐ Con la participación del ser humano (el ser humano puede superar) ☐ Con la supervisión del ser humano (el ser humano monitorea e interviene si es necesario) ☐ A cargo de un ser humano (la inteligencia artificial es solo consultiva)

**Describe el mecanismo de revisión humana:**

_____________________________________________________________________________

---

#### B.2 Poblaciones afectadas

**¿Quiénes son los individuos o grupos directamente afectados por este sistema?**

| Grupo poblacional | Número estimado | Nivel de vulnerabilidad |
|-----------------|-----------------|-----------------------|
|  |  | ☐ Bajo ☐ Medio ☐ Alto |
|  |  | ☐ Bajo ☐ Medio ☐ Alto |
|  |  | ☐ Bajo ☐ Medio ☐ Alto |
|  |  | ☐ Bajo ☐ Medio ☐ Alto |

**¿Las poblaciones afectadas incluyen personas vulnerables?**

☐ Sí ☐ No ☐ Posiblemente

Si es así, especificar:

☐ Menores de edad (menos de 18 años) ☐ Personas mayores ☐ Personas con discapacidad ☐ Otras

#### D.3 Narrativas de riesgo detalladas Para cada **Medio**, **Alto** o **Crítico** riesgo, complete lo siguiente: --- **Derecho afectado:** _______________ **Puntuación de Riesgo:** _______________ **Nivel de Riesgo:** _______________ *¿Cómo crea o agudiza el sistema AI este riesgo?* _______________________________________________________________________________ *¿Qué grupos afectados están más expuestos a este riesgo?* _______________________________________________________________________________ *¿Cuál es la peor escena posible?* _______________________________________________________________________________ *¿Hay precedentes históricos o evidencia de investigación para este riesgo?* _______________________________________________________________________________ *(Copie esta bloque para cada riesgo identificado)* --- ## Parte E: Medidas de mitigación ### E.1 Catálogo de medidas de mitigación Para cada riesgo identificado, documente las medidas de mitigación: | ID del Riesgo | Descripción del Riesgo | Medida de Mitigación | Tipo | Propietario | Plazo | Estado | |---------|-----------------|-------------------|------|-------|----------|--------| | R-01 | | | ☐ Técnico ☐ Organisacional ☐ Legal | | | ☐ Planificado ☐ En progreso ☐ Hecho | | R-02 | | | ☐ Técnico ☐ Organisacional ☐ Legal | | | ☐ Planificado ☐ En progreso ☐ Hecho | | R-03 | | | ☐ Técnico ☐ Organisacional ☐ Legal | | | ☐ Planificado ☐ En progreso ☐ Hecho | | R-04 | | | ☐ Técnico ☐ Organisacional ☐ Legal | | | ☐ Planificado ☐ En progreso ☐ Hecho | | R-05 | | | ☐ Técnico ☐ Organisacional ☐ Legal | | | ☐ Planificado ☐ En progreso ☐ Hecho | ### E.2 Evaluación de riesgo residual Después de las mitigaciones, reavalúe cada riesgo: | ID del Riesgo | Puntuación Original | Puntuación Residual | Nivel Residual | Aceptado? | |---------|---------------|----------------|----------------|-----------| | R-01 | | | | ☐ Sí ☐ Escalada | | R-02 | | | | ☐ Sí ☐ Escalada | | R-03 | | | | ☐ Sí ☐ Escalada | **Nivel residual de riesgo general para la implementación:** ☐ Aceptable ☐ Condicional ☐ Inaceptable Si condicional, liste las condiciones para la implementación: _______________________________________________________________________________ --- ## Parte F: Plan de monitoreo ### F.1 Actividades de monitoreo continuo | Actividad de Monitoreo | Frecuencia | Persona Responsable | KPI / Umbral | Desencadenante de Escalada | |--------------------|-----------|-------------------|----------------|-------------------| | Revisión del rendimiento del modelo | | | | | | Auditoría de sesgo/fairness | | | | | | Revisión de quejas de usuarios | | | | | |

---

# Data Protection Impact Assessment for AI Systems (GDPR Art. 35 + EU AI Act)
_Evaluación de impacto en la protección de datos para sistemas de IA (RGPD art. 35 + Reglamento de IA de la UE)_

> A complete DPIA template for AI systems combining GDPR Article 35 requirements with EU AI Act risk management obligations — covering processing description, necessity assessment, risk identification, mitigation, and supervisory authority consultation triggers.
> Online: https://vorluxai.com/templates/gdpr-dpia-ai/

> **Disclaimer:** This is guidance only, not legal advice. Consult qualified legal counsel and your DPO before adopting or submitting this DPIA. | *Este documento es solo orientativo, no constituye asesoramiento jurídico.*

---

## Data Protection Impact Assessment (DPIA) for AI Systems

**Document Reference:** [ORG-DPIA-AI-___]
**DPIA Version:** [1.0]
**Status:** [ ] Draft | [ ] DPO Review | [ ] Approved | [ ] Approved with Conditions | [ ] Rejected
**System / Processing Activity Name:**
**Prepared by:**
**Department / Business Owner:**
**DPO Reviewer:**
**Date Initiated:**
**Date DPO Review Completed:**
**Date Approved:**
**Next Scheduled Review:** [Date or event trigger]

---

### DPIA At a Glance — Executive Summary

*Complete this section after all other sections are finished. Maximum 1 page.*

| Item | Details |
|------|---------|
| **AI System Name** | |
| **Purpose of AI Processing** | |
| **Categories of Personal Data Processed** | |
| **Number / Volume of Data Subjects** | |
| **EU AI Act Risk Classification** | Unacceptable / High / Limited / Minimal |
| **GDPR High-Risk Indicators Present** | Yes / No (list below) |
| **Overall DPIA Risk Level** | Low / Medium / High / Very High |
| **DPO Recommendation** | Proceed / Proceed with conditions / Do not proceed |
| **Supervisory Authority Consultation Required** | Yes / No |
| **Approval Decision** | |
| **Conditions / Required Actions** | |

---

### Part 1: Description of the Processing

#### 1.1 AI System Overview

**System name:**

**Vendor / Provider (if external):**

**System type:** (select all that apply)
- [ ] Generative AI (text, image, audio, video, code)
- [ ] Predictive AI (scoring, forecasting, classification)
- [ ] Automated decision-making system
- [ ] AI-assisted decision support tool
- [ ] Natural language processing / chatbot
- [ ] Computer vision / image recognition
- [ ] Voice / audio processing
- [ ] Recommendation system
- [ ] Behavioural analysis / profiling
- [ ] Other: ___________

**EU AI Act Risk Category:**
- [ ] Unacceptable Risk (prohibited — must not be deployed)
- [ ] High Risk (Annex III — full compliance required)
  - [ ] Biometric identification and categorisation
  - [ ] Critical infrastructure management
  - [ ] Education and vocational training
  - [ ] Employment, workers management, and access to self-employment
  - [ ] Access to essential private and public services and benefits
  - [ ] Law enforcement
  - [ ] Migration, asylum, and border control management
  - [ ] Administration of justice and democratic processes
- [ ] Limited Risk (transparency obligations apply)
- [ ] Minimal Risk

**System description:** *(Describe the AI system, how it works, what it does, and how outputs are used. Include information about the underlying model/algorithm if known.)*

_______________________________________________

**What problem does this AI system solve, and what is the expected business benefit?**

_______________________________________________

#### 1.2 Purposes of Processing

List all purposes for which personal data is processed by or through this AI system:

| Purpose ID | Purpose Description | Legal Basis (GDPR Art. 6/9) | Applicable to Special Category Data? |
|------------|--------------------|-----------------------------|--------------------------------------|
| P1 | | | |
| P2 | | | |
| P3 | | | |

**Legal bases used (tick all that apply):**
- [ ] Art. 6(1)(a) — Consent
- [ ] Art. 6(1)(b) — Contract performance
- [ ] Art. 6(1)(c) — Legal obligation
- [ ] Art. 6(1)(d) — Vital interests
- [ ] Art. 6(1)(e) — Public task
- [ ] Art. 6(1)(f) — Legitimate interests (LIA required — attach)
- [ ] Art. 9(2)(a) — Explicit consent (special categories)
- [ ] Art. 9(2)(b) — Employment / social security obligations
- [ ] Art. 9(2)(h) — Health / medical purposes
- [ ] Other: ___________

#### 1.3 Data Flows

**Data sources (where does personal data originate from?):**

| Source | Data Type | Volume/Frequency | Direct/Indirect |
|--------|-----------|-----------------|----------------|
| | | | |
| | | | |

**Data flows diagram:**
*(Attach a data flow diagram showing: data source → collection method → AI system inputs → AI processing → outputs → downstream use → storage → deletion. See Annex A for template.)*

[ ] Data flow diagram attached

**International transfers:**
- Does personal data flow outside the EU/EEA? [ ] Yes [ ] No [ ] Unknown
- If yes, destination country(ies): ___________
- Transfer mechanism: [ ] Adequacy decision [ ] Standard Contractual Clauses [ ] BCRs [ ] Other: ___________
- Transfer Impact Assessment conducted: [ ] Yes [ ] No [ ] In progress

#### 1.4 Categories of Personal Data

| Data Category | Specific Data Types | Special Category (Art. 9)? | Volume / Number of Data Subjects |
|--------------|--------------------|-----------------------------|----------------------------------|
| Identity data | Names, employee IDs, usernames | No | |
| Contact data | Email, phone, address | No | |
| Behavioural data | Usage patterns, interaction data | No | |
| Location data | IP addresses, geographic location | No | |
| Financial data | Salary, payment data, credit data | No | |
| Health data | Medical records, sick leave | YES | |
| Biometric data | Fingerprints, facial data, voice | YES | |
| Genetic data | | YES | |
| Racial/ethnic origin | | YES | |
| Political opinions | | YES | |
| Religious beliefs | | YES | |
| Sexual orientation | | YES | |
| Criminal convictions | | YES | |
| Other: | | | |

**Total estimated number of data subjects:**

**Are any data subjects in vulnerable groups?** *(children, elderly, employees, patients, etc.)*
- [ ] Yes — specify: ___________
- [ ] No

#### 1.5 Processing Operations

Describe the specific processing operations performed by the AI system:

| Operation | Description | Automated / Human-in-loop |
|-----------|-------------|--------------------------|
| Data collection / ingestion | | |
| Data pre-processing / cleaning | | |
| Model training (if applicable) | | |
| Inference / prediction generation | | |
| Output delivery to users | | |
| Output storage and logging | | |
| Data deletion / anonymisation | | |

**Retention periods:**

| Data Type | Retention Period | Basis | Deletion Method |
|-----------|-----------------|-------|----------------|
| Training data | | | |
| AI-generated outputs | | | |
| System logs | | | |
| Model parameters | | | |

---

### Part 2: Necessity and Proportionality Assessment

#### 2.1 Necessity Assessment

For each purpose identified in Section 1.2, assess whether the AI processing is necessary:

| Purpose | Could the purpose be achieved without AI or with less privacy-intrusive means? | Is AI use proportionate to the benefit? | Assessment |
|---------|--------------------------------------------------------------------------------|----------------------------------------|------------|
| P1 | | | [ ] Necessary [ ] Not necessary [ ] Uncertain |
| P2 | | | [ ] Necessary [ ] Not necessary [ ] Uncertain |
| P3 | | | [ ] Necessary [ ] Not necessary [ ] Uncertain |

#### 2.2 Data Minimisation

| Question | Response |
|----------|---------|
| Is only the minimum necessary personal data collected? | [ ] Yes [ ] No [ ] Partially |
| Can any data fields be removed without materially affecting system performance? | [ ] Yes — list fields: ___ [ ] No |
| Is there a pseudonymisation or anonymisation option that has been evaluated? | [ ] Yes (implemented/rejected — explain) [ ] No |
| Are test/development environments using anonymised data? | [ ] Yes [ ] No [ ] N/A |

**Data minimisation issues identified:**

_______________________________________________

#### 2.3 Accuracy and Data Quality

| Question | Response | Action Required |
|----------|---------|----------------|
| Are mechanisms in place to ensure input data accuracy? | [ ] Yes [ ] No | |
| Can data subjects access and correct their data? | [ ] Yes [ ] No | |
| Is the training data representative and free from known biases? | [ ] Yes [ ] No [ ] Assessed below | |
| Are there quality controls on AI outputs? | [ ] Yes [ ] No | |

**Bias and fairness assessment:**
*(Describe any bias assessment conducted on training data and AI outputs. Reference any bias testing methodology used.)*

_______________________________________________

**Bias risk level:** [ ] Low [ ] Medium [ ] High

#### 2.4 Transparency and Right to Explanation

| Question | Response |
|----------|---------|
| Are data subjects informed about the AI processing in the privacy notice? | [ ] Yes [ ] No — action required |
| Do data subjects know when AI is being used to make or support decisions affecting them? | [ ] Yes [ ] No — action required |
| Where automated decision-making (Art. 22 GDPR) applies, can a human review be requested? | [ ] Yes [ ] No [ ] N/A — Art. 22 not applicable |
| Can the AI system provide an explanation of its outputs (explainability)? | [ ] Yes [ ] Partially [ ] No |
| Is the AI system able to demonstrate compliance with Art. 22 safeguards? | [ ] Yes [ ] No [ ] N/A |

#### 2.5 Compliance with Data Subject Rights

Assess how the AI system accommodates each right:

| Right | How accommodated | Gap / Issue |
|-------|-----------------|------------|
| Right of access (Art. 15) | | |
| Right to rectification (Art. 16) | | |
| Right to erasure (Art. 17) | | |
| Right to restriction (Art. 18) | | |
| Right to data portability (Art. 20) | | |
| Right to object (Art. 21) | | |
| Rights re: automated decision-making (Art. 22) | | |

**Rights compliance gap summary:**

_______________________________________________

---

### Part 3: Risk Identification

#### 3.1 GDPR High-Risk Indicator Screening

A DPIA is **mandatory** where processing is likely to result in high risk. Check all applicable indicators (AEPD guidance and EDPB WP248):

| # | High-Risk Indicator | Applies? | Notes |
|---|--------------------|---------|----|
| 1 | Automated decision-making with significant legal or similarly significant effects (Art. 22) | [ ] Yes [ ] No | |
| 2 | Large-scale processing of special category data (Art. 9) or criminal conviction data (Art. 10) | [ ] Yes [ ] No | |
| 3 | Systematic monitoring of publicly accessible areas | [ ] Yes [ ] No | |
| 4 | Processing of data of vulnerable data subjects (children, employees, patients) | [ ] Yes [ ] No | |
| 5 | Innovative use of technology (new AI application, novel use of existing AI) | [ ] Yes [ ] No | |
| 6 | Use of data in a way data subjects would not reasonably expect (purpose creep) | [ ] Yes [ ] No | |
| 7 | Denial of service, contract, or benefit based on AI scoring | [ ] Yes [ ] No | |
| 8 | Large-scale profiling | [ ] Yes [ ] No | |
| 9 | Combination / matching of datasets that data subjects would not expect | [ ] Yes [ ] No | |

**Number of high-risk indicators present:** ___
*(EDPB guidance: DPIA generally required where 2 or more criteria apply)*

**Is this DPIA mandatory?** [ ] Yes [ ] No [ ] Precautionary (not legally required but conducted as good practice)

#### 3.2 EU AI Act Risk Indicators

In addition to GDPR risks, assess risks under the EU AI Act:

| AI Act Risk Area | Applicable? | Risk Level | Notes |
|-----------------|------------|-----------|-------|
| Fundamental rights impact | [ ] Yes [ ] No | L / M / H | |
| Safety risks to individuals | [ ] Yes [ ] No | L / M / H | |
| Discrimination or unfair treatment risk | [ ] Yes [ ] No | L / M / H | |
| Lack of human oversight on consequential decisions | [ ] Yes [ ] No | L / M / H | |
| Opacity / lack of explainability | [ ] Yes [ ] No | L / M / H | |
| Data quality and representativeness issues | [ ] Yes [ ] No | L / M / H | |
| Robustness and accuracy risks | [ ] Yes [ ] No | L / M / H | |
| Cybersecurity vulnerabilities | [ ] Yes [ ] No | L / M / H | |

#### 3.3 Risk Register

Identify specific risks to data subjects arising from this AI processing activity. Use the risk register below:

| Risk ID | Risk Description | Source (GDPR/AI Act/Both) | Likelihood (1–5) | Impact (1–5) | Inherent Risk Score | Controls Identified | Residual Risk |
|---------|-----------------|--------------------------|-----------------|--------------|---------------------|-------------------|---------------|
| R1 | Unauthorised access to personal data processed by AI system | GDPR | | | | | |
| R2 | AI system produces discriminatory outputs based on protected characteristics | Both | | | | | |
| R3 | Personal data used to train AI model beyond original purpose | GDPR | | | | | |
| R4 | Automated decision causes adverse effect on data subject without human review | Both | | | | | |
| R5 | Data subject unable to exercise their rights (access, erasure, explanation) | GDPR | | | | | |
| R6 | Inaccurate AI output used in decision affecting data subject's interests | Both | | | | | |
| R7 | International transfer of personal data without adequate safeguards | GDPR | | | | | |
| R8 | Data retention longer than necessary; deletion failure | GDPR | | | | | |
| R9 | AI system produces false or misleading outputs (hallucinations) affecting data subjects | AI Act | | | | | |
| R10 | Third-party vendor security incident exposing processed personal data | GDPR | | | | | |
| [Add further risks specific to this system] | | | | | | | |

**Risk Score Scale:**
- Likelihood: 1 = Rare, 2 = Unlikely, 3 = Possible, 4 = Likely, 5 = Almost Certain
- Impact: 1 = Negligible, 2 = Minor, 3 = Moderate, 4 = Significant, 5 = Severe
- Inherent Risk Score = Likelihood × Impact
- High risk threshold: ≥12 | Medium: 6–11 | Low: ≤5

---

### Part 4: Risk Mitigation

#### 4.1 Technical Measures

| Measure | Description | Status | Owner | Target Date |
|---------|-------------|--------|-------|------------|
| Encryption at rest | Personal data encrypted at rest using [standard] | [ ] Implemented [ ] Planned [ ] N/A | | |
| Encryption in transit | TLS 1.2+ for all data in transit | [ ] Implemented [ ] Planned [ ] N/A | | |
| Access controls | Role-based access control; minimum necessary access | [ ] Implemented [ ] Planned [ ] N/A | | |
| Pseudonymisation | Training and/or inference data pseudonymised where possible | [ ] Implemented [ ] Planned [ ] N/A | | |
| Anonymisation | AI outputs anonymised before non-essential storage | [ ] Implemented [ ] Planned [ ] N/A | | |
| Audit logging | Full audit trail of AI system access and outputs | [ ] Implemented [ ] Planned [ ] N/A | | |
| Data minimisation (technical) | Technical controls prevent over-collection | [ ] Implemented [ ] Planned [ ] N/A | | |
| Automated deletion | Automated deletion schedule configured per retention policy | [ ] Implemented [ ] Planned [ ] N/A | | |
| Human override / override mechanism | Data subjects can trigger human review of AI decisions | [ ] Implemented [ ] Planned [ ] N/A | | |
| Output monitoring | AI outputs monitored for accuracy, bias, anomalies | [ ] Implemented [ ] Planned [ ] N/A | | |
| Penetration testing | AI system and API security tested | [ ] Implemented [ ] Planned [ ] N/A | | |
| Bias testing | Systematic bias/fairness testing conducted pre-deployment and periodically | [ ] Implemented [ ] Planned [ ] N/A | | |

#### 4.2 Organisational Measures

| Measure | Description | Status | Owner | Target Date |
|---------|-------------|--------|-------|------------|
| Data Processing Agreement | DPA signed with AI vendor | [ ] Signed [ ] In negotiation [ ] N/A | | |
| Training for system operators | Relevant staff trained on data protection requirements | [ ] Complete [ ] Planned | | |
| Privacy notice update | Privacy notice updated to describe AI processing | [ ] Complete [ ] Planned | | |
| Data subject rights procedure | Process for handling DSARs related to AI system | [ ] Documented [ ] Planned | | |
| Incident response procedure | Specific procedure for AI-related data breaches | [ ] Documented [ ] Planned | | |
| Vendor due diligence | Third-party AI vendor assessed for data protection compliance | [ ] Complete [ ] Planned | | |
| AI system logging and audit | System activity logged and reviewed regularly | [ ] Implemented [ ] Planned | | |
| Human oversight procedure | Defined procedure for human review of AI decisions | [ ] Documented [ ] Planned | | |
| Bias and fairness review schedule | Periodic review of AI outputs for discriminatory patterns | [ ] Scheduled [ ] Not yet | | |
| Data retention policy | Documented retention schedule enforced | [ ] In place [ ] Needed | | |

#### 4.3 Risk Mitigation Summary

| Risk ID | Original Risk Score | Mitigation Measures Applied | Residual Risk Score | Residual Risk Level | Accepted by DPO? |
|---------|--------------------|-----------------------------|--------------------|--------------------|-----------------|
| R1 | | | | L / M / H | [ ] Yes [ ] No |
| R2 | | | | L / M / H | [ ] Yes [ ] No |
| R3 | | | | L / M / H | [ ] Yes [ ] No |
| R4 | | | | L / M / H | [ ] Yes [ ] No |
| R5 | | | | L / M / H | [ ] Yes [ ] No |
| R6 | | | | L / M / H | [ ] Yes [ ] No |
| R7 | | | | L / M / H | [ ] Yes [ ] No |
| R8 | | | | L / M / H | [ ] Yes [ ] No |
| R9 | | | | L / M / H | [ ] Yes [ ] No |
| R10 | | | | L / M / H | [ ] Yes [ ] No |

**Residual risks that cannot be mitigated to acceptable level:**

*(If any residual risks remain at High, describe here and determine whether supervisory authority consultation is required — see Part 6.)*

_______________________________________________

---

### Part 5: DPO Consultation

#### 5.1 DPO Review Checklist

The DPO must review and sign off on this DPIA before the AI system is deployed. The DPO should assess:

| DPO Review Item | DPO Finding | Action Required |
|----------------|------------|----------------|
| Is the DPIA complete and of sufficient quality? | | |
| Are all relevant processing activities described? | | |
| Is the legal basis appropriate and well-documented? | | |
| Are all categories of personal data correctly identified? | | |
| Has data minimisation been adequately considered? | | |
| Are data subject rights adequately accommodated? | | |
| Are identified risks plausible and comprehensive? | | |
| Are proposed mitigations sufficient to reduce risks to acceptable level? | | |
| Has international transfer risk been adequately assessed? | | |
| Is supervisory authority consultation required (see Part 6)? | | |
| Does the AI system comply with Art. 22 where applicable? | | |
| Have any gaps in vendor DPAs been identified? | | |

#### 5.2 DPO Opinion

**DPO Recommendation:** *(Select one)*
- [ ] **Proceed** — The DPIA identifies no residual high risks; the processing can proceed as described.
- [ ] **Proceed with conditions** — The DPIA identifies residual risks that are acceptable subject to the conditions listed below.
- [ ] **Do not proceed pending prior consultation** — Residual risks remain high; prior consultation with AEPD is required before processing begins.
- [ ] **Do not proceed** — The processing is disproportionate, unlawful, or poses unacceptable risks to data subjects.

**Conditions / Required actions (if applicable):**

_______________________________________________

**DPO name:**
**DPO signature/approval date:**
**Next DPIA review date (as recommended by DPO):**

#### 5.3 Business Owner Response to DPO Opinion

*(Complete if DPO recommended conditions or do not proceed)*

**Do you accept the DPO's conditions?** [ ] Yes — with implementation plan below [ ] No — requesting escalation to [CEO/Board]

**Implementation plan for DPO conditions:**

| Condition | Action | Owner | Due Date | Completed |
|-----------|--------|-------|----------|----------|
| | | | | |
| | | | | |

**Escalation (if DPO recommendation not followed):**

If the controller (organisation) decides to proceed against the DPO's advice, record the decision and the reasons. GDPR Art. 35(2) requires the controller to seek the DPO's advice when carrying out a DPIA, and the accountability principle (Art. 5(2)) means the controller must be able to demonstrate compliance, so keep the DPO's written opinion with the DPIA.

*Documented decision to proceed against DPO advice (if applicable):*

_______________________________________________

*Authorised by:* [Name, Title, Date]

---

### Part 6: Supervisory Authority Consultation Triggers

#### 6.1 When is Prior Consultation Required?

Under **GDPR Art. 36**, the controller **must** consult the supervisory authority (in Spain: AEPD) before processing **where a DPIA indicates that processing would result in high residual risk** and the controller cannot mitigate that risk with reasonable measures.

Note: the lists the AEPD has published under GDPR Art. 35(4) and 35(5) say when a DPIA is or is not required; they are not prior-consultation lists. Separately, Art. 36(5) allows Member State law to require prior consultation and authorisation for processing carried out in the performance of a task in the public interest.

#### 6.2 Prior Consultation Trigger Assessment

| Trigger | Applies? | Evidence / Notes |
|---------|---------|-----------------|
| DPIA indicates the processing would result in a high risk in the absence of mitigating measures, and the measures identified do not bring it down (Art. 36(1)) | [ ] Yes [ ] No | |
| Member State law requires prior consultation for this public-interest processing (Art. 36(5)) | [ ] Yes [ ] No | |

Only the two rows above trigger prior consultation. The factors below do not trigger it by themselves; weigh them when judging whether the residual risk is still high:

| Factor to weigh | Present? | Evidence / Notes |
|---------|---------|-----------------|
| AI system is high-risk under the EU AI Act (Annex III, from 2 December 2027) | [ ] Yes [ ] No | |
| Large-scale profiling or automated decision-making with legal or similarly significant effects (GDPR Art. 22) | [ ] Yes [ ] No | |
| Special category data (Art. 9) processed at scale | [ ] Yes [ ] No | |
| New technology where uncertainty about the risks remains after the DPIA | [ ] Yes [ ] No | |

**Is prior consultation with AEPD required?** [ ] YES — see Section 6.3 [ ] NO — document rationale below

**Rationale for not consulting (if applicable):**

_______________________________________________

#### 6.3 Prior Consultation Process (if required)

If prior consultation is triggered, the following steps apply:

| Step | Action | Responsible | Timeline |
|------|--------|------------|---------|
| 1 | Compile consultation package (DPIA + processing description + contact details of DPO) | DPO | Before processing begins |
| 2 | Submit to AEPD via formal consultation channel | DPO + Legal | Before processing begins |
| 3 | Wait for AEPD response | DPO | AEPD has 8 weeks to respond (extendable by 6 weeks for complex cases) |
| 4 | Implement any AEPD recommendations | System Owner + AI Officer | Per AEPD guidance |
| 5 | Document outcome and update DPIA | DPO | After AEPD response |
| **Do not begin processing until AEPD consultation period has elapsed or AEPD has responded** | | | |

**AEPD contact for prior consultation:** [https://www.aepd.es/] — Consulta Previa / Prior Consultation

#### 6.4 EU AI Act Notification Obligations

For **high-risk AI systems** under the EU AI Act (Annex III obligations apply from 2 December 2027 under Regulation 2026/1744), additional registration and notification obligations may apply to providers and deployers. Check with Legal and the AI Officer whether:

| Obligation | Applies? | Status |
|-----------|---------|--------|
| Registration in the EU database — providers of Annex III high-risk systems (AI Act Art. 49(1)); deployers that are public authorities or act on their behalf register their use (Art. 49(3)) | [ ] Yes [ ] No | |
| Deployer duty to inform the provider and the market surveillance authority (AESIA in Spain) of risks and serious incidents, and to suspend use where needed (AI Act Art. 26(5)) | [ ] Yes [ ] No | |
| Notified body conformity assessment (for specific high-risk categories) | [ ] Yes [ ] No | |
| EU AI Act post-market monitoring plan | [ ] Yes [ ] No | |

---

### Part 7: Ongoing Review and Monitoring

#### 7.1 DPIA Review Triggers

This DPIA must be reviewed:

| Trigger | Review Required? | Responsible |
|---------|-----------------|------------|
| Annual scheduled review | Yes | DPO + System Owner |
| Material change to AI system functionality | Yes | DPO + System Owner |
| Change in categories of personal data processed | Yes | DPO |
| Change in purpose of processing | Yes | DPO |
| Change in AI vendor or sub-processor | Yes | DPO |
| Significant AI-related incident or near-miss | Yes | DPO + AI Officer |
| Material change in applicable law or regulatory guidance | Yes | DPO + Legal |
| Evidence of bias or discriminatory outcomes | Yes | DPO + AI Officer |
| Change in scale (significant increase in data subjects) | Yes | DPO |

#### 7.2 Post-Deployment Monitoring Plan

| Monitoring Activity | Frequency | Responsible | KPIs / Thresholds |
|--------------------|-----------|------------|------------------|
| AI output accuracy review | Monthly | System Owner | Target: [X]% accuracy; alert if <[Y]% |
| Bias and fairness check | Quarterly | AI Officer + System Owner | Zero material bias findings |
| Data subject rights request handling | Per request + monthly aggregate | DPO | 100% answered within one month (GDPR Art. 12(3); extendable by two months for complex requests) |
| Security and access log review | Monthly | CISO | Zero unauthorised access events |
| Data retention compliance check | Quarterly | System Owner | 100% data deleted per schedule |
| Vendor compliance check | Annually | DPO + Legal | Valid DPA; valid certifications |

---

### Annex A — Data Flow Diagram Template

*Use this template or attach a completed diagram.*

```
[Data Source] ──→ [Collection Method] ──→ [AI System Input]
                                               │
                                         [AI Processing]
                                               │
                                          [AI Output]
                                           /        \
                              [Downstream Use]    [Storage]
                                                      │
                                               [Deletion / Anonymisation]
```

*Label each arrow with: data type, transfer mechanism, encryption status, and legal basis.*

---

### Annex B — Version Control

| Version | Date | Author | Change Description | Approved By |
|---------|------|--------|-------------------|------------|
| 1.0 | | | Initial DPIA | |
| | | | | |

---

### Annex C — Supporting Documents

| Document | Version | Location | Attached? |
|----------|---------|---------|----------|
| Legitimate Interests Assessment (if Art. 6(1)(f) used) | | | [ ] Yes [ ] N/A |
| Transfer Impact Assessment (if international transfer) | | | [ ] Yes [ ] N/A |
| Data Processing Agreement with vendor | | | [ ] Yes [ ] N/A |
| Vendor security assessment | | | [ ] Yes [ ] N/A |
| Bias testing report | | | [ ] Yes [ ] N/A |
| EU AI Act technical documentation (if high-risk) | | | [ ] Yes [ ] N/A |
| Privacy notice (showing AI disclosure) | | | [ ] Yes [ ] N/A |

---

*Template provided by VORLUX AI | vorluxai.com*
*This is guidance only, not legal advice.*
*Version 1.0 | For GDPR Art. 35 + EU AI Act compliance use | Last updated: 2026-04-05*

---

### Versión Española

> **Aviso legal:** Este documento es solo orientativo, no constituye asesoramiento jurídico. Consulte a un abogado cualificado y a su DPO antes de adoptar o presentar esta EIPD.

---

## Evaluación de Impacto en la Protección de Datos (EIPD) para Sistemas de IA

**Referencia del documento:** [ORG-DPIA-AI-___]
**Versión de la EIPD:** [1.0]
**Estado:** [ ] Borrador | [ ] Revisión DPO | [ ] Aprobada | [ ] Aprobada con condiciones | [ ] Rechazada
**Nombre del sistema / actividad de tratamiento:**
**Elaborado por:**
**Departamento / Responsable:**
**DPO revisor:**
**Fecha de inicio:**
**Fecha de revisión DPO:**
**Fecha de aprobación:**
**Próxima revisión programada:** [Fecha o evento desencadenante]

---

#### Resumen Ejecutivo de la EIPD

*Complete esta sección tras finalizar todas las demás. Máximo 1 página.*

| Elemento | Detalles |
|----------|----------|
| **Nombre del sistema de IA** | |
| **Finalidad del tratamiento con IA** | |
| **Categorías de datos personales tratados** | |
| **Número / volumen de interesados** | |
| **Clasificación de riesgo (EU AI Act)** | Inaceptable / Alto / Limitado / Mínimo |
| **Indicadores de alto riesgo GDPR presentes** | Sí / No (detallar) |
| **Nivel de riesgo global de la EIPD** | Bajo / Medio / Alto / Muy alto |
| **Recomendación del DPO** | Proceder / Proceder con condiciones / No proceder |
| **Consulta previa a la autoridad de control requerida** | Sí / No |
| **Decisión de aprobación** | |
| **Condiciones / acciones requeridas** | |

---

#### Parte 1: Descripción del Tratamiento

##### 1.1 Visión general del sistema de IA

**Nombre del sistema:**

**Proveedor (si es externo):**

**Tipo de sistema:** (seleccione todos los aplicables)
- [ ] IA generativa (texto, imagen, audio, vídeo, código)
- [ ] IA predictiva (puntuación, previsión, clasificación)
- [ ] Sistema de toma de decisiones automatizada
- [ ] Herramienta de apoyo a la decisión asistida por IA
- [ ] Procesamiento de lenguaje natural / chatbot
- [ ] Visión artificial / reconocimiento de imágenes
- [ ] Procesamiento de voz / audio
- [ ] Sistema de recomendación
- [ ] Análisis de comportamiento / perfilado
- [ ] Otro: ___________

**Categoría de riesgo (EU AI Act):**
- [ ] Riesgo inaceptable (prohibido — no debe desplegarse)
- [ ] Riesgo alto (Anexo III — cumplimiento completo obligatorio)
  - [ ] Identificación y categorización biométrica
  - [ ] Gestión de infraestructuras críticas
  - [ ] Educación y formación profesional
  - [ ] Empleo, gestión de trabajadores y acceso al autoempleo
  - [ ] Acceso a servicios esenciales públicos y privados y prestaciones
  - [ ] Aplicación de la ley
  - [ ] Migración, asilo y gestión de fronteras
  - [ ] Administración de justicia y procesos democráticos
- [ ] Riesgo limitado (aplican obligaciones de transparencia)
- [ ] Riesgo mínimo

**Descripción del sistema:** *(Describa el sistema de IA, cómo funciona, qué hace y cómo se utilizan los resultados. Incluya información sobre el modelo/algoritmo subyacente si se conoce.)*

_______________________________________________

**¿Qué problema resuelve este sistema de IA y cuál es el beneficio empresarial esperado?**

_______________________________________________

##### 1.2 Finalidades del tratamiento

| ID | Descripción de la finalidad | Base jurídica (GDPR Art. 6/9) | ¿Datos de categoría especial? |
|----|----------------------------|-------------------------------|-------------------------------|
| P1 | | | |
| P2 | | | |
| P3 | | | |

**Bases jurídicas utilizadas:**
- [ ] Art. 6(1)(a) — Consentimiento
- [ ] Art. 6(1)(b) — Ejecución de contrato
- [ ] Art. 6(1)(c) — Obligación legal
- [ ] Art. 6(1)(d) — Intereses vitales
- [ ] Art. 6(1)(e) — Misión de interés público
- [ ] Art. 6(1)(f) — Intereses legítimos (requiere LIA — adjuntar)
- [ ] Art. 9(2)(a) — Consentimiento explícito (categorías especiales)
- [ ] Art. 9(2)(b) — Obligaciones de empleo / seguridad social
- [ ] Art. 9(2)(h) — Fines sanitarios / médicos
- [ ] Otro: ___________

##### 1.3 Flujos de datos

**Orígenes de los datos:**

| Origen | Tipo de datos | Volumen / frecuencia | Directo / Indirecto |
|--------|--------------|---------------------|---------------------|
| | | | |

**Diagrama de flujo de datos:**
*(Adjunte un diagrama: origen → método de recogida → entrada al sistema IA → procesamiento → resultados → uso posterior → almacenamiento → eliminación. Ver Anexo A.)*

[ ] Diagrama de flujo adjunto

**Transferencias internacionales:**
- ¿Salen datos personales fuera del EEE? [ ] Sí [ ] No [ ] Desconocido
- Si sí, país(es) de destino: ___________
- Mecanismo de transferencia: [ ] Decisión de adecuación [ ] Cláusulas Contractuales Tipo [ ] BCRs [ ] Otro: ___________
- Evaluación de impacto de transferencia realizada: [ ] Sí [ ] No [ ] En curso

##### 1.4 Categorías de datos personales

| Categoría | Tipos de datos específicos | ¿Categoría especial (Art. 9)? | Volumen / N.º de interesados |
|-----------|---------------------------|-------------------------------|------------------------------|
| Datos de identidad | Nombres, IDs de empleado, nombres de usuario | No | |
| Datos de contacto | Correo electrónico, teléfono, dirección | No | |
| Datos de comportamiento | Patrones de uso, datos de interacción | No | |
| Datos de localización | Direcciones IP, ubicación geográfica | No | |
| Datos financieros | Salario, datos de pago, datos crediticios | No | |
| Datos de salud | Historiales médicos, bajas médicas | SÍ | |
| Datos biométricos | Huellas dactilares, datos faciales, voz | SÍ | |
| Datos genéticos | | SÍ | |
| Origen racial/étnico | | SÍ | |
| Opiniones políticas | | SÍ | |
| Creencias religiosas | | SÍ | |
| Orientación sexual | | SÍ | |
| Condenas penales | | SÍ | |
| Otro: | | | |

**Número total estimado de interesados:**

**¿Hay interesados en grupos vulnerables?** *(menores, personas mayores, empleados, pacientes, etc.)*
- [ ] Sí — especificar: ___________
- [ ] No

##### 1.5 Operaciones de tratamiento

| Operación | Descripción | Automatizado / Intervención humana |
|-----------|-------------|-----------------------------------|
| Recogida / ingesta de datos | | |
| Preprocesamiento / limpieza de datos | | |
| Entrenamiento del modelo (si aplica) | | |
| Inferencia / generación de predicciones | | |
| Entrega de resultados a usuarios | | |
| Almacenamiento y registro de resultados | | |
| Eliminación / anonimización de datos | | |

**Plazos de conservación:**

| Tipo de dato | Plazo de conservación | Fundamento | Método de eliminación |
|-------------|----------------------|------------|----------------------|
| Datos de entrenamiento | | | |
| Resultados generados por IA | | | |
| Registros del sistema | | | |
| Parámetros del modelo | | | |

---

#### Parte 2: Evaluación de Necesidad y Proporcionalidad

##### 2.1 Evaluación de necesidad

| Finalidad | ¿Podría lograrse sin IA o con medios menos intrusivos? | ¿El uso de IA es proporcionado al beneficio? | Evaluación |
|-----------|--------------------------------------------------------|---------------------------------------------|------------|
| P1 | | | [ ] Necesario [ ] No necesario [ ] Incierto |
| P2 | | | [ ] Necesario [ ] No necesario [ ] Incierto |
| P3 | | | [ ] Necesario [ ] No necesario [ ] Incierto |

##### 2.2 Minimización de datos

| Pregunta | Respuesta |
|----------|-----------|
| ¿Se recogen solo los datos mínimos necesarios? | [ ] Sí [ ] No [ ] Parcialmente |
| ¿Podrían eliminarse campos sin afectar materialmente al rendimiento? | [ ] Sí — indicar campos: ___ [ ] No |
| ¿Se ha evaluado la seudonimización o anonimización? | [ ] Sí (implementada/descartada — explicar) [ ] No |
| ¿Los entornos de prueba usan datos anonimizados? | [ ] Sí [ ] No [ ] N/A |

**Problemas de minimización identificados:**

_______________________________________________

##### 2.3 Exactitud y calidad de los datos

| Pregunta | Respuesta | Acción requerida |
|----------|-----------|-----------------|
| ¿Existen mecanismos para asegurar la exactitud de los datos de entrada? | [ ] Sí [ ] No | |
| ¿Pueden los interesados acceder y corregir sus datos? | [ ] Sí [ ] No | |
| ¿Son los datos de entrenamiento representativos y libres de sesgos conocidos? | [ ] Sí [ ] No [ ] Evaluado abajo | |
| ¿Existen controles de calidad sobre los resultados de IA? | [ ] Sí [ ] No | |

**Evaluación de sesgo y equidad:**
*(Describa las evaluaciones de sesgo realizadas sobre datos de entrenamiento y resultados de IA.)*

_______________________________________________

**Nivel de riesgo de sesgo:** [ ] Bajo [ ] Medio [ ] Alto

##### 2.4 Transparencia y derecho a la explicación

| Pregunta | Respuesta |
|----------|-----------|
| ¿Se informa a los interesados sobre el tratamiento con IA en el aviso de privacidad? | [ ] Sí [ ] No — acción requerida |
| ¿Saben los interesados cuándo se usa IA para tomar o apoyar decisiones que les afectan? | [ ] Sí [ ] No — acción requerida |
| Cuando aplica la toma de decisiones automatizada (Art. 22 GDPR), ¿puede solicitarse revisión humana? | [ ] Sí [ ] No [ ] N/A — Art. 22 no aplicable |
| ¿Puede el sistema de IA proporcionar una explicación de sus resultados (explicabilidad)? | [ ] Sí [ ] Parcialmente [ ] No |
| ¿Puede el sistema demostrar cumplimiento con las garantías del Art. 22? | [ ] Sí [ ] No [ ] N/A |

##### 2.5 Cumplimiento de los derechos de los interesados

| Derecho | Cómo se garantiza | Deficiencia / problema |
|---------|-------------------|----------------------|
| Derecho de acceso (Art. 15) | | |
| Derecho de rectificación (Art. 16) | | |
| Derecho de supresión (Art. 17) | | |
| Derecho a la limitación del tratamiento (Art. 18) | | |
| Derecho a la portabilidad (Art. 20) | | |
| Derecho de oposición (Art. 21) | | |
| Derechos relativos a decisiones automatizadas (Art. 22) | | |

**Resumen de deficiencias en el cumplimiento de derechos:**

_______________________________________________

---

#### Parte 3: Identificación de Riesgos

##### 3.1 Cribado de indicadores de alto riesgo GDPR

La EIPD es **obligatoria** cuando el tratamiento pueda entrañar un alto riesgo. Marque los indicadores aplicables (guía AEPD y EDPB WP248):

| # | Indicador de alto riesgo | ¿Aplica? | Notas |
|---|--------------------------|----------|-------|
| 1 | Toma de decisiones automatizada con efectos jurídicos significativos o similares (Art. 22) | [ ] Sí [ ] No | |
| 2 | Tratamiento a gran escala de datos de categoría especial (Art. 9) o de condenas penales (Art. 10) | [ ] Sí [ ] No | |
| 3 | Vigilancia sistemática de zonas de acceso público | [ ] Sí [ ] No | |
| 4 | Tratamiento de datos de interesados vulnerables (menores, empleados, pacientes) | [ ] Sí [ ] No | |
| 5 | Uso innovador de tecnología (nueva aplicación de IA, uso novedoso de IA existente) | [ ] Sí [ ] No | |
| 6 | Uso de datos de forma inesperada para los interesados (desviación de finalidad) | [ ] Sí [ ] No | |
| 7 | Denegación de servicio, contrato o prestación basada en puntuación de IA | [ ] Sí [ ] No | |
| 8 | Perfilado a gran escala | [ ] Sí [ ] No | |
| 9 | Combinación / cruce de conjuntos de datos no esperado por los interesados | [ ] Sí [ ] No | |

**Número de indicadores de alto riesgo presentes:** ___
*(Guía EDPB: la EIPD es generalmente obligatoria cuando aplican 2 o más criterios)*

**¿Es esta EIPD obligatoria?** [ ] Sí [ ] No [ ] Precautoria (no legalmente requerida pero realizada como buena práctica)

##### 3.2 Indicadores de riesgo del EU AI Act

| Área de riesgo (AI Act) | ¿Aplica? | Nivel de riesgo | Notas |
|--------------------------|----------|----------------|-------|
| Impacto en derechos fundamentales | [ ] Sí [ ] No | B / M / A | |
| Riesgos de seguridad para las personas | [ ] Sí [ ] No | B / M / A | |
| Riesgo de discriminación o trato injusto | [ ] Sí [ ] No | B / M / A | |
| Falta de supervisión humana en decisiones de consecuencia | [ ] Sí [ ] No | B / M / A | |
| Opacidad / falta de explicabilidad | [ ] Sí [ ] No | B / M / A | |
| Problemas de calidad y representatividad de datos | [ ] Sí [ ] No | B / M / A | |
| Riesgos de robustez y exactitud | [ ] Sí [ ] No | B / M / A | |
| Vulnerabilidades de ciberseguridad | [ ] Sí [ ] No | B / M / A | |

##### 3.3 Registro de riesgos

| ID | Descripción del riesgo | Origen (GDPR/AI Act/Ambos) | Probabilidad (1–5) | Impacto (1–5) | Riesgo inherente | Controles identificados | Riesgo residual |
|----|----------------------|---------------------------|-------------------|--------------|-----------------|------------------------|----------------|
| R1 | Acceso no autorizado a datos personales tratados por el sistema de IA | GDPR | | | | | |
| R2 | El sistema de IA produce resultados discriminatorios basados en características protegidas | Ambos | | | | | |
| R3 | Datos personales utilizados para entrenar el modelo más allá de la finalidad original | GDPR | | | | | |
| R4 | Decisión automatizada causa efecto adverso al interesado sin revisión humana | Ambos | | | | | |
| R5 | El interesado no puede ejercer sus derechos (acceso, supresión, explicación) | GDPR | | | | | |
| R6 | Resultado inexacto de IA utilizado en decisión que afecta intereses del interesado | Ambos | | | | | |
| R7 | Transferencia internacional de datos personales sin garantías adecuadas | GDPR | | | | | |
| R8 | Conservación de datos más allá de lo necesario; fallo en la eliminación | GDPR | | | | | |
| R9 | El sistema de IA produce resultados falsos o engañosos (alucinaciones) que afectan a interesados | AI Act | | | | | |
| R10 | Incidente de seguridad del proveedor que expone datos personales tratados | GDPR | | | | | |
| [Añada riesgos adicionales específicos de este sistema] | | | | | | | |

**Escala de puntuación de riesgos:**
- Probabilidad: 1 = Rara, 2 = Improbable, 3 = Posible, 4 = Probable, 5 = Casi segura
- Impacto: 1 = Insignificante, 2 = Menor, 3 = Moderado, 4 = Significativo, 5 = Grave
- Riesgo inherente = Probabilidad x Impacto
- Umbral de alto riesgo: ≥12 | Medio: 6–11 | Bajo: ≤5

---

#### Parte 4: Mitigación de Riesgos

##### 4.1 Medidas técnicas

| Medida | Descripción | Estado | Responsable | Fecha objetivo |
|--------|-------------|--------|-------------|---------------|
| Cifrado en reposo | Datos personales cifrados en reposo con [estándar] | [ ] Implementado [ ] Planificado [ ] N/A | | |
| Cifrado en tránsito | TLS 1.2+ para todos los datos en tránsito | [ ] Implementado [ ] Planificado [ ] N/A | | |
| Controles de acceso | Control de acceso basado en roles; acceso mínimo necesario | [ ] Implementado [ ] Planificado [ ] N/A | | |
| Seudonimización | Datos de entrenamiento/inferencia seudonimizados donde sea posible | [ ] Implementado [ ] Planificado [ ] N/A | | |
| Anonimización | Resultados de IA anonimizados antes de almacenamiento no esencial | [ ] Implementado [ ] Planificado [ ] N/A | | |
| Registro de auditoría | Trazabilidad completa de accesos y resultados del sistema de IA | [ ] Implementado [ ] Planificado [ ] N/A | | |
| Minimización de datos (técnica) | Controles técnicos que impiden la recogida excesiva | [ ] Implementado [ ] Planificado [ ] N/A | | |
| Eliminación automatizada | Programación de eliminación automatizada según política de conservación | [ ] Implementado [ ] Planificado [ ] N/A | | |
| Mecanismo de anulación humana | Los interesados pueden solicitar revisión humana de decisiones de IA | [ ] Implementado [ ] Planificado [ ] N/A | | |
| Monitorización de resultados | Resultados de IA monitorizados en cuanto a exactitud, sesgo y anomalías | [ ] Implementado [ ] Planificado [ ] N/A | | |
| Pruebas de penetración | Sistema de IA y seguridad de API probados | [ ] Implementado [ ] Planificado [ ] N/A | | |
| Pruebas de sesgo | Pruebas sistemáticas de sesgo/equidad previas al despliegue y periódicas | [ ] Implementado [ ] Planificado [ ] N/A | | |

##### 4.2 Medidas organizativas

| Medida | Descripción | Estado | Responsable | Fecha objetivo |
|--------|-------------|--------|-------------|---------------|
| Acuerdo de tratamiento de datos | DPA firmado con proveedor de IA | [ ] Firmado [ ] En negociación [ ] N/A | | |
| Formación para operadores del sistema | Personal relevante formado en requisitos de protección de datos | [ ] Completada [ ] Planificada | | |
| Actualización del aviso de privacidad | Aviso de privacidad actualizado para describir tratamiento con IA | [ ] Completada [ ] Planificada | | |
| Procedimiento de derechos de interesados | Proceso para gestionar solicitudes de derechos relacionadas con el sistema de IA | [ ] Documentado [ ] Planificado | | |
| Procedimiento de respuesta a incidentes | Procedimiento específico para brechas de datos relacionadas con IA | [ ] Documentado [ ] Planificado | | |
| Diligencia debida del proveedor | Evaluación del proveedor de IA en materia de protección de datos | [ ] Completada [ ] Planificada | | |
| Registro y auditoría del sistema de IA | Actividad del sistema registrada y revisada periódicamente | [ ] Implementado [ ] Planificado | | |
| Procedimiento de supervisión humana | Procedimiento definido para revisión humana de decisiones de IA | [ ] Documentado [ ] Planificado | | |
| Calendario de revisión de sesgo y equidad | Revisión periódica de resultados de IA buscando patrones discriminatorios | [ ] Programado [ ] Pendiente | | |
| Política de conservación de datos | Calendario de conservación documentado y aplicado | [ ] Vigente [ ] Necesario | | |

##### 4.3 Resumen de mitigación de riesgos

| ID | Puntuación original | Medidas de mitigación aplicadas | Puntuación residual | Nivel residual | ¿Aceptado por DPO? |
|----|---------------------|---------------------------------|--------------------|--------------|--------------------|
| R1 | | | | B / M / A | [ ] Sí [ ] No |
| R2 | | | | B / M / A | [ ] Sí [ ] No |
| R3 | | | | B / M / A | [ ] Sí [ ] No |
| R4 | | | | B / M / A | [ ] Sí [ ] No |
| R5 | | | | B / M / A | [ ] Sí [ ] No |
| R6 | | | | B / M / A | [ ] Sí [ ] No |
| R7 | | | | B / M / A | [ ] Sí [ ] No |
| R8 | | | | B / M / A | [ ] Sí [ ] No |
| R9 | | | | B / M / A | [ ] Sí [ ] No |
| R10 | | | | B / M / A | [ ] Sí [ ] No |

**Riesgos residuales que no pueden mitigarse a un nivel aceptable:**

*(Si algún riesgo residual permanece en nivel Alto, descríbalo aquí y determine si es necesaria la consulta previa a la autoridad de control — véase Parte 6.)*

_______________________________________________

---

#### Parte 5: Consulta al DPO

##### 5.1 Lista de verificación de revisión del DPO

El DPO debe revisar y aprobar esta EIPD antes del despliegue del sistema de IA:

| Elemento de revisión del DPO | Resultado del DPO | Acción requerida |
|------------------------------|-------------------|-----------------|
| ¿La EIPD está completa y tiene calidad suficiente? | | |
| ¿Se describen todas las actividades de tratamiento relevantes? | | |
| ¿La base jurídica es apropiada y está bien documentada? | | |
| ¿Se identifican correctamente todas las categorías de datos personales? | | |
| ¿Se ha considerado adecuadamente la minimización de datos? | | |
| ¿Se garantizan adecuadamente los derechos de los interesados? | | |
| ¿Son los riesgos identificados plausibles y exhaustivos? | | |
| ¿Son las mitigaciones propuestas suficientes para reducir riesgos a un nivel aceptable? | | |
| ¿Se ha evaluado adecuadamente el riesgo de transferencia internacional? | | |
| ¿Es necesaria la consulta previa a la autoridad de control (véase Parte 6)? | | |
| ¿Cumple el sistema de IA con el Art. 22 cuando sea aplicable? | | |
| ¿Se han identificado deficiencias en DPAs con proveedores? | | |

##### 5.2 Dictamen del DPO

**Recomendación del DPO:** *(Seleccione una)*
- [ ] **Proceder** — La EIPD no identifica riesgos residuales altos; el tratamiento puede proceder tal como se describe.
- [ ] **Proceder con condiciones** — La EIPD identifica riesgos residuales aceptables sujetos a las condiciones indicadas.
- [ ] **No proceder sin consulta previa** — Los riesgos residuales permanecen altos; se requiere consulta previa a la AEPD antes de iniciar el tratamiento.
- [ ] **No proceder** — El tratamiento es desproporcionado, ilícito o supone riesgos inaceptables para los interesados.

**Condiciones / acciones requeridas (si aplica):**

_______________________________________________

**Nombre del DPO:**
**Firma/fecha de aprobación del DPO:**
**Próxima fecha de revisión de la EIPD (recomendada por el DPO):**

##### 5.3 Respuesta del responsable del negocio al dictamen del DPO

*(Completar si el DPO recomendó condiciones o no proceder)*

**¿Acepta las condiciones del DPO?** [ ] Sí — con plan de implementación abajo [ ] No — solicita escalado a [CEO/Consejo]

**Plan de implementación de las condiciones del DPO:**

| Condición | Acción | Responsable | Fecha límite | Completado |
|-----------|--------|-------------|-------------|------------|
| | | | | |

**Escalado (si no se sigue la recomendación del DPO):**

Si el responsable del tratamiento decide proceder en contra del consejo del DPO, documente la decisión y sus motivos. El art. 35.2 del RGPD obliga a recabar el asesoramiento del DPO al realizar la EIPD, y el principio de responsabilidad proactiva (art. 5.2) exige poder demostrar el cumplimiento, así que conserve el dictamen escrito del DPO junto a la EIPD.

*Decisión documentada de proceder en contra del consejo del DPO (si aplica):*

_______________________________________________

*Autorizado por:* [Nombre, Cargo, Fecha]

---

#### Parte 6: Umbrales de Consulta a la Autoridad de Control

##### 6.1 ¿Cuándo es obligatoria la consulta previa?

Conforme al **GDPR Art. 36**, el responsable **debe** consultar a la autoridad de control (en España: AEPD) antes del tratamiento **cuando una EIPD indique que el tratamiento entrañaría un riesgo residual alto** y el responsable no pueda mitigar ese riesgo con medidas razonables.

Nota: las listas que la AEPD ha publicado conforme a los arts. 35.4 y 35.5 del RGPD indican cuándo se requiere o no una EIPD; no son listas de consulta previa. Aparte, el art. 36.5 permite que el Derecho de un Estado miembro exija consulta y autorización previas para tratamientos realizados en cumplimiento de una misión de interés público.

##### 6.2 Evaluación de los desencadenantes de consulta previa

| Desencadenante | ¿Aplica? | Evidencia / Notas |
|----------------|----------|-------------------|
| La EIPD muestra que el tratamiento entrañaría un alto riesgo si no se toman medidas, y las medidas identificadas no lo reducen (art. 36.1) | [ ] Sí [ ] No | |
| El Derecho nacional exige consulta previa para este tratamiento de interés público (art. 36.5) | [ ] Sí [ ] No | |

Sólo las dos filas anteriores activan la consulta previa. Los factores siguientes no la activan por sí solos; pondéralos al valorar si el riesgo residual sigue siendo alto:

| Factor a ponderar | ¿Presente? | Evidencia / Notas |
|----------------|----------|-------------------|
| El sistema de IA es de alto riesgo según la Ley de IA (anexo III, desde el 2 de diciembre de 2027) | [ ] Sí [ ] No | |
| Perfilado a gran escala o decisiones automatizadas con efectos jurídicos o similares (art. 22 RGPD) | [ ] Sí [ ] No | |
| Categorías especiales de datos (art. 9) a gran escala | [ ] Sí [ ] No | |
| Nueva tecnología con incertidumbre sobre los riesgos tras la EIPD | [ ] Sí [ ] No | |

**¿Es necesaria la consulta previa a la AEPD?** [ ] SÍ — véase Sección 6.3 [ ] NO — documentar justificación

**Justificación para no consultar (si aplica):**

_______________________________________________

##### 6.3 Proceso de consulta previa (si es necesario)

| Paso | Acción | Responsable | Plazo |
|------|--------|-------------|-------|
| 1 | Compilar paquete de consulta (EIPD + descripción del tratamiento + datos de contacto del DPO) | DPO | Antes de iniciar el tratamiento |
| 2 | Presentar a la AEPD por el canal formal de consulta | DPO + Legal | Antes de iniciar el tratamiento |
| 3 | Esperar respuesta de la AEPD | DPO | La AEPD tiene 8 semanas para responder (ampliable 6 semanas en casos complejos) |
| 4 | Implementar las recomendaciones de la AEPD | Responsable del sistema + Responsable de IA | Según indicaciones de la AEPD |
| 5 | Documentar resultado y actualizar la EIPD | DPO | Tras respuesta de la AEPD |
| **No iniciar el tratamiento hasta que el plazo de consulta haya transcurrido o la AEPD haya respondido** | | | |

**Contacto de la AEPD para consulta previa:** [https://www.aepd.es/] — Consulta Previa

##### 6.4 Obligaciones de notificación del EU AI Act

Para **sistemas de IA de alto riesgo** según la Ley de IA (las obligaciones del anexo III se aplican desde el 2 de diciembre de 2027 por el Reglamento 2026/1744), pueden aplicar obligaciones adicionales de registro y notificación a proveedores y responsables del despliegue. Comprueba con Legal y el Responsable de IA si aplican:

| Obligación | ¿Aplica? | Estado |
|-----------|----------|--------|
| Registro en la base de datos de la UE: proveedores de sistemas de alto riesgo del anexo III (art. 49.1 Ley de IA); los responsables del despliegue que son autoridades públicas, o actúan en su nombre, registran su uso (art. 49.3) | [ ] Sí [ ] No | |
| Deber del responsable del despliegue de informar al proveedor y a la autoridad de vigilancia del mercado (AESIA en España) de riesgos e incidentes graves, y de suspender el uso si es necesario (art. 26.5 Ley de IA) | [ ] Sí [ ] No | |
| Evaluación de conformidad por organismo notificado (para categorías de alto riesgo específicas) | [ ] Sí [ ] No | |
| Plan de vigilancia post-comercialización del EU AI Act | [ ] Sí [ ] No | |

---

#### Parte 7: Revisión y Monitorización Continua

##### 7.1 Desencadenantes de revisión de la EIPD

| Desencadenante | ¿Revisión necesaria? | Responsable |
|----------------|---------------------|-------------|
| Revisión anual programada | Sí | DPO + Responsable del sistema |
| Cambio material en la funcionalidad del sistema de IA | Sí | DPO + Responsable del sistema |
| Cambio en las categorías de datos personales tratados | Sí | DPO |
| Cambio en la finalidad del tratamiento | Sí | DPO |
| Cambio de proveedor de IA o subencargado | Sí | DPO |
| Incidente significativo relacionado con IA o cuasi-incidente | Sí | DPO + Responsable de IA |
| Cambio material en la legislación aplicable u orientaciones regulatorias | Sí | DPO + Legal |
| Evidencia de sesgo o resultados discriminatorios | Sí | DPO + Responsable de IA |
| Cambio de escala (aumento significativo de interesados) | Sí | DPO |

##### 7.2 Plan de monitorización post-despliegue

| Actividad de monitorización | Frecuencia | Responsable | KPIs / Umbrales |
|-----------------------------|-----------|-------------|----------------|
| Revisión de exactitud de resultados de IA | Mensual | Responsable del sistema | Objetivo: [X]% exactitud; alerta si <[Y]% |
| Verificación de sesgo y equidad | Trimestral | Responsable de IA + Responsable del sistema | Cero hallazgos materiales de sesgo |
| Gestión de solicitudes de derechos de interesados | Por solicitud + agregado mensual | DPO | 100% respondidas en un mes (art. 12.3 RGPD; ampliable dos meses si la solicitud es compleja) |
| Revisión de registros de seguridad y acceso | Mensual | CISO | Cero eventos de acceso no autorizado |
| Verificación de cumplimiento de conservación de datos | Trimestral | Responsable del sistema | 100% datos eliminados según calendario |
| Verificación de cumplimiento del proveedor | Anual | DPO + Legal | DPA vigente; certificaciones válidas |

---

#### Anexo A — Plantilla de diagrama de flujo de datos

*Utilice esta plantilla o adjunte un diagrama completo.*

```
[Origen de datos] ──→ [Método de recogida] ──→ [Entrada al sistema IA]
                                                       │
                                                 [Tratamiento IA]
                                                       │
                                                  [Resultado IA]
                                                   /          \
                                    [Uso posterior]        [Almacenamiento]
                                                                │
                                                   [Eliminación / Anonimización]
```

*Etiquete cada flecha con: tipo de dato, mecanismo de transferencia, estado de cifrado y base jurídica.*

---

#### Anexo B — Control de versiones

| Versión | Fecha | Autor | Descripción del cambio | Aprobado por |
|---------|-------|-------|------------------------|-------------|
| 1.0 | | | EIPD inicial | |
| | | | | |

---

#### Anexo C — Documentos de apoyo

| Documento | Versión | Ubicación | ¿Adjunto? |
|-----------|---------|-----------|-----------|
| Evaluación de intereses legítimos (si Art. 6(1)(f) utilizado) | | | [ ] Sí [ ] N/A |
| Evaluación de impacto de transferencia (si transferencia internacional) | | | [ ] Sí [ ] N/A |
| Acuerdo de tratamiento de datos con proveedor | | | [ ] Sí [ ] N/A |
| Evaluación de seguridad del proveedor | | | [ ] Sí [ ] N/A |
| Informe de pruebas de sesgo | | | [ ] Sí [ ] N/A |
| Documentación técnica del EU AI Act (si alto riesgo) | | | [ ] Sí [ ] N/A |
| Aviso de privacidad (con mención de IA) | | | [ ] Sí [ ] N/A |

---

*Plantilla proporcionada por VORLUX AI | vorluxai.com*
*Este documento es solo orientativo, no constituye asesoramiento jurídico.*
*Versión 1.0 | Para cumplimiento de GDPR Art. 35 + EU AI Act | Última actualización: 2026-04-05*

---

# Human Oversight Requirements (Art. 14)
_Requisitos de supervisión humana (art. 14)_

> Comprehensive implementation guide for Article 14 human oversight requirements, covering oversight mechanisms, competency standards, override procedures, documentation, and monitoring dashboards for high-risk AI systems.
> Online: https://vorluxai.com/templates/human-oversight-guide/

## Human Oversight Requirements Implementation Guide — EU AI Act Article 14

> **Disclaimer:** This is guidance only, not legal advice. Consult qualified legal counsel for your specific compliance obligations.

**Template provided by VORLUX AI** | [vorluxai.com](https://vorluxai.com)

---

### What Article 14 Requires

Article 14 of the EU AI Act mandates that high-risk AI systems be **designed and developed** in such a way that they can be effectively overseen by natural persons during the period of use. This is not merely a policy requirement — it must be **built into the system architecture and operational procedures**.

#### The Four Core Article 14 Obligations

| Obligation | Article Ref | What It Means |
|------------|------------|---------------|
| Meaningful oversight by design | 14(1) | System must be technically capable of being overridden, stopped, or corrected |
| Appropriate interface for oversight | 14(2) | Tools and information must enable the human overseer to actually understand and control the system |
| Overseer competency | 14(3) | Persons assigned to oversee the system must have the knowledge and authority to do so effectively |
| Override and stop capability | 14(4) | Overseer must be able to intervene in real time and override or interrupt system operation |

---

### Part 1 — Oversight Mechanism Design

#### 1.1 System-Level Requirements

Before deployment, confirm the following are implemented in the AI system:

**Interpretability and Transparency**
- [ ] System outputs include confidence scores or uncertainty estimates where technically feasible
- [ ] System provides human-interpretable explanations for outputs (appropriate to the risk level and use case)
- [ ] System flags cases where it is operating near or outside its design envelope
- [ ] System surfaces the most relevant input features or factors contributing to each decision

**Oversight Interface**
- [ ] A dedicated oversight interface exists (dashboard, API, or operator console)
- [ ] The interface shows current system status (running, paused, degraded, error)
- [ ] The interface displays input data, model output, confidence, and key decision factors
- [ ] The interface provides access to audit logs
- [ ] The interface is accessible to oversight personnel without specialist technical knowledge

**Override and Control Capabilities**
- [ ] Manual override of individual AI decisions is possible in real time
- [ ] System-wide pause / stop function is available and accessible within `____` seconds
- [ ] Outputs can be flagged for human review before taking effect (if pre-decision mode is appropriate)
- [ ] Revocation / reversal of AI decisions is possible for a defined window after output: `____` hours/days
- [ ] Fallback to manual process is documented and tested

**Technical Architecture Controls**

| Control | Implementation | Test Date | Test Result |
|---------|---------------|-----------|-------------|
| Emergency stop button / API endpoint | `___________` | `____-__-__` | ☐ Pass ☐ Fail |
| Decision audit trail (tamper-evident) | `___________` | `____-__-__` | ☐ Pass ☐ Fail |
| Real-time output monitoring | `___________` | `____-__-__` | ☐ Pass ☐ Fail |
| Human override logging | `___________` | `____-__-__` | ☐ Pass ☐ Fail |
| Rollback capability | `___________` | `____-__-__` | ☐ Pass ☐ Fail |

#### 1.2 Oversight Mode Matrix

Define when human oversight is active and what level is required:

| Operational Mode | Description | Oversight Level Required | Trigger |
|-----------------|-------------|-------------------------|---------|
| **Human-in-the-Loop** | Every decision reviewed before effect | Full review of each output | High-stakes decisions; low-volume contexts |
| **Human-on-the-Loop** | AI acts; human monitors and can override | Sampling + anomaly alerts | Medium-volume; reversible decisions |
| **Human-over-the-Loop** | AI operates autonomously; periodic human audit | Audit of sample + KPI dashboard | High-volume; lower-stakes; reversible |
| **Emergency Override** | Human takes full manual control | Complete manual operation | Incident; system anomaly; legal requirement |

**Current Operational Mode for this system:** `___________________________`

**Rationale for selected mode (must be proportionate to risk):**
```
[Explain why this oversight mode is appropriate given the system's risk profile,
decision reversibility, volume, and stakes involved]
```

---

### Part 2 — Competency Requirements for Oversight Personnel

#### 2.1 Roles and Responsibilities

Define oversight roles appropriate to your system:

| Role | Responsibility | Authority Level | Minimum Staffing |
|------|---------------|-----------------|-----------------|
| **AI System Operator** | Day-to-day use; first-line monitoring | Can flag for review; cannot override model | `___` FTE |
| **Human Overseer** | Monitors outputs; can override individual decisions | Full override of individual outputs | `___` FTE |
| **Responsible AI Officer** | System-level accountability; escalation authority | Can pause or stop system; escalates incidents | `___` FTE |
| **System Administrator** | Technical monitoring; infrastructure controls | Can stop system; restart; rollback | `___` FTE |

#### 2.2 Competency Framework

Article 14(3) requires oversight persons to have the **necessary competence, training, and authority** and be given **appropriate access to information**.

##### Minimum Competency Requirements

| Competency Area | Human Overseer | Responsible AI Officer |
|----------------|---------------|----------------------|
| Understanding of AI system purpose and limitations | Required | Required |
| Ability to interpret system outputs and confidence scores | Required | Required |
| Domain knowledge relevant to system's decisions | Required | Desirable |
| Understanding of when to escalate vs. intervene | Required | Required |
| Knowledge of override procedures | Required | Required |
| Understanding of prohibited AI practices (Art. 5) | Required | Required |
| Knowledge of reporting obligations | Desirable | Required |
| Basic AI/ML literacy | Desirable | Required |

##### Competency Assessment Checklist

For each person assigned to human oversight, confirm:

- [ ] Role-specific job description updated to include AI oversight responsibilities
- [ ] Competency baseline assessment completed
- [ ] Required training completed (see Section 2.3)
- [ ] Competency confirmed via assessment or sign-off
- [ ] Access to relevant information and systems granted
- [ ] Oversight authority formally delegated in writing
- [ ] Emergency contact details and escalation path provided

**Oversight Personnel Register:**

| Name | Role | Competency Confirmed | Training Date | Authority Granted | Review Date |
|------|------|---------------------|---------------|-------------------|-------------|
| `___________` | `___________` | ☐ Yes ☐ No | `____-__-__` | ☐ Yes ☐ No | `____-__-__` |
| `___________` | `___________` | ☐ Yes ☐ No | `____-__-__` | ☐ Yes ☐ No | `____-__-__` |
| `___________` | `___________` | ☐ Yes ☐ No | `____-__-__` | ☐ Yes ☐ No | `____-__-__` |

#### 2.3 Training Programme

Design a training programme appropriate to the system and the oversight role:

**Core Training Modules (all oversight personnel)**

| Module | Content | Duration | Delivery | Assessment |
|--------|---------|----------|----------|------------|
| AI System Overview | Purpose, capabilities, limitations, design envelope | `___ hrs` | ☐ Classroom ☐ E-learning ☐ Practical | ☐ Test ☐ Sign-off |
| Output Interpretation | How to read outputs, confidence scores, flags, explanations | `___ hrs` | ☐ Classroom ☐ E-learning ☐ Practical | ☐ Test ☐ Sign-off |
| Oversight Procedures | When and how to intervene, override, escalate | `___ hrs` | ☐ Classroom ☐ E-learning ☐ Practical | ☐ Test ☐ Sign-off |
| Override Operations | Practical use of override controls; system stop | `___ hrs` | ☐ Classroom ☐ E-learning ☐ Practical | ☐ Test ☐ Sign-off |
| Incident Reporting | What to report, to whom, within what timeframe | `___ hrs` | ☐ Classroom ☐ E-learning ☐ Practical | ☐ Test ☐ Sign-off |
| Legal and Ethical Obligations | EU AI Act basics; prohibited practices; rights of affected persons | `___ hrs` | ☐ Classroom ☐ E-learning ☐ Practical | ☐ Test ☐ Sign-off |

**Training Refresher Frequency:** ☐ Quarterly ☐ Biannually ☐ Annually ☐ Trigger-based

**Trigger Events for Ad-Hoc Training:**
- Significant model update or version change
- Incident or near-miss involving the AI system
- Change in the oversight role or operating environment
- New regulatory guidance published
- Results of audit identify competency gap

---

### Part 3 — Override Procedures

#### 3.1 Override Decision Framework

Human overseers must know when to intervene. Provide clear guidance:

**Mandatory Override Scenarios (overseer MUST intervene):**

| Scenario | Detection Method | Override Action | Documentation Required |
|----------|-----------------|-----------------|----------------------|
| System confidence score below threshold (`< ____`) | Dashboard alert | Refer to manual review | Yes — log reason and outcome |
| Output affects a protected characteristic (Art. 10) | Flag in output | Pause and escalate | Yes — immediate log + senior sign-off |
| System operating outside design envelope | Out-of-distribution alert | Stop and notify admin | Yes — incident report |
| User / affected person objects or appeals | User request | Pause and human review | Yes — record objection and decision |
| Regulatory or legal query about a decision | External request | Pause outputs; flag for legal | Yes — log all communications |
| Serious incident triggered | Alert / report | Emergency stop | Yes — full incident report |

**Discretionary Override Scenarios (overseer MAY intervene):**

| Scenario | Guidance |
|----------|---------|
| Output "feels wrong" to the overseer based on domain knowledge | Investigate; compare with recent outputs; escalate if concern persists |
| Unusual pattern of outputs across a session | Review session logs; compare with baseline; consider temporary pause |
| Contextual information not available to the AI suggests different outcome | Document; override if justified; submit feedback to system owners |
| Affected person provides additional information | Consider new information; override if it would materially change the output |

#### 3.2 Step-by-Step Override Procedure

```
HUMAN OVERRIDE STANDARD PROCEDURE
==================================

Step 1: IDENTIFY
  - Note the system output and the reason for concern
  - Record the decision ID, timestamp, and affected person/case reference

Step 2: ASSESS
  - Review available evidence (inputs, confidence score, explanation)
  - Apply domain knowledge and context
  - Consult with a colleague if unsure (do not delay if harm is imminent)

Step 3: DECIDE
  - If overriding: determine the correct outcome
  - If pausing: decide whether to refer to another overseer or escalate
  - If accepting output: document your agreement and rationale

Step 4: ACT
  - Use the override interface to record your decision
  - Apply the overridden outcome in the relevant system/process
  - Note any system feedback or acknowledgement

Step 5: DOCUMENT
  - Complete the override log (Section 3.3 below)
  - Submit feedback to the AI system team if the override suggests a systematic issue
  - Report to supervisor if the override indicates a material system problem

Step 6: FOLLOW UP
  - Check that overridden outcome was applied correctly
  - If escalation was required, confirm escalation was received and is being addressed
  - Contribute to periodic override pattern review (see Section 4.3)
```

#### 3.3 Override Log Template

Maintain a log of all overrides. This log forms part of the audit trail required under Art. 12.

| Field | Value |
|-------|-------|
| Override ID | `OVR-____-____-____` |
| Date and Time | `____-__-__` `__:__:__` |
| AI System Version | `___` |
| Decision / Output ID | `___________________________` |
| Overseer Name | `___________________________` |
| Original AI Output | `___________________________` |
| AI Confidence Score | `____%` |
| Reason for Override | `___________________________` |
| Human Decision | `___________________________` |
| Evidence Considered | `___________________________` |
| Outcome Applied | ☐ Yes ☐ No — Reason: `___` |
| Escalated? | ☐ Yes → Escalation ID: `___` ☐ No |
| Supervisor Notified? | ☐ Yes ☐ No |
| Feedback Submitted to AI Team? | ☐ Yes ☐ No |
| Follow-Up Required? | ☐ Yes — Action: `___` ☐ No |

#### 3.4 Emergency Stop Procedure

```
EMERGENCY STOP PROCEDURE
=========================

USE WHEN: AI system is producing harmful outputs, behaving unexpectedly, or
involved in a serious incident requiring immediate cessation of operation.

STEP 1: ACCESS EMERGENCY STOP
  Option A: Dashboard → [EMERGENCY STOP] button (red)
  Option B: API call: POST /api/v1/system/emergency-stop (requires admin token)
  Option C: Contact system administrator at: ___________________________
            Phone: ___________________________  (24/7)

STEP 2: CONFIRM STOP
  - Verify system status shows "HALTED" in dashboard
  - Confirm no new outputs are being generated
  - Alert team members that system is stopped

STEP 3: NOTIFY IMMEDIATELY
  - Responsible AI Officer: ___________________________
  - System Administrator: ___________________________
  - Department Head: ___________________________

STEP 4: PRESERVE EVIDENCE
  - Do not restart the system without authorisation
  - Export and preserve logs from the period of concern
  - Document what you observed and when

STEP 5: INCIDENT REPORT
  - Complete full incident report within ___ hours
  - Reference: Incident Reporting Procedure [Doc: ___________]

RESTART AUTHORISATION:
  - System may only be restarted with sign-off from: ___________________________
  - Restart requires: root cause identified + mitigation implemented + sign-off obtained
```

---

### Part 4 — Documentation Requirements

#### 4.1 Oversight Documentation Matrix

| Document | Purpose | Owner | Frequency | Retention |
|----------|---------|-------|-----------|-----------|
| Oversight Procedure Manual | Instructions for oversight personnel | Responsible AI Officer | Review annually | 10 years |
| Override Log | Record of all human overrides | Human Overseer | Per override | 10 years |
| Incident Reports | Record of serious incidents | Responsible AI Officer | Per incident | 10 years |
| Training Records | Proof of oversight personnel competency | HR / Responsible AI Officer | Per training | Duration of role + 5 years |
| Competency Assessments | Baseline and periodic competency checks | Manager | Per person, annually | Duration of role + 5 years |
| Oversight Audit Reports | Periodic review of oversight effectiveness | Internal Audit | Quarterly/Annually | 10 years |
| System Status Logs | Technical logs of system operation | System Administrator | Continuous | Defined in data retention policy |
| Post-Market Monitoring Reports | Aggregate performance and oversight findings | Responsible AI Officer | Quarterly/Annually | 10 years |

#### 4.2 Minimum Logging Requirements

The following must be captured and stored for the required retention period:

**For every AI system decision/output:**
- [ ] Unique decision identifier
- [ ] Timestamp (UTC)
- [ ] Input data reference (or hash)
- [ ] Model version
- [ ] Output value(s) and confidence score
- [ ] Any flags or alerts triggered
- [ ] Whether output was reviewed, overridden, or accepted by a human
- [ ] Identity of human overseer who reviewed (where applicable)

**For every override:**
- [ ] Override ID linked to original decision ID
- [ ] Overseer identity
- [ ] Reason for override (structured categories + free text)
- [ ] Override decision
- [ ] Timestamp

**For every incident:**
- [ ] Incident ID
- [ ] Discovery timestamp
- [ ] Nature of incident
- [ ] Decisions/outputs involved
- [ ] Persons affected (pseudonymised where required)
- [ ] Immediate actions taken
- [ ] Root cause analysis reference
- [ ] Resolution and preventive actions

---

### Part 5 — Monitoring Dashboards

#### 5.1 Real-Time Oversight Dashboard Specification

The oversight dashboard must enable the human overseer to monitor the AI system effectively without requiring deep technical expertise. Use this specification to brief your development team:

**Dashboard Panel 1: System Status**

| Widget | Data Source | Update Frequency | Alert Threshold |
|--------|------------|------------------|-----------------|
| System health (Green/Amber/Red) | Health check API | Every 30 seconds | Any non-green |
| Output volume (last 1hr / 24hr / 7d) | Decision log | Every 1 minute | Volume spike > `___`% above baseline |
| Error rate (%) | Error log | Every 1 minute | Error rate > `___`% |
| Average confidence score | Decision log | Every 5 minutes | Average confidence < `____%` |
| Override rate (%) | Override log | Every 5 minutes | Override rate > `___`% |

**Dashboard Panel 2: Decision Stream (Human-on-the-Loop)**

| Widget | Data Source | Update Frequency |
|--------|------------|------------------|
| Live feed of most recent outputs | Decision log | Real-time |
| Flagged decisions awaiting review | Review queue | Real-time |
| Low-confidence decisions (< threshold) | Decision log | Real-time |
| Decisions affecting sensitive categories | Decision log | Real-time |

**Dashboard Panel 3: Performance Trends**

| Widget | Data Source | Time Window |
|--------|------------|-------------|
| Accuracy trend (rolling average) | Ground truth comparison | Rolling 30 days |
| Confidence score distribution | Decision log | Rolling 7 days |
| Prediction distribution (output categories) | Decision log | Rolling 7 days |
| Data drift indicator | Drift monitor | Rolling 7 days |

**Dashboard Panel 4: Override and Incident History**

| Widget | Data Source | Display |
|--------|------------|---------|
| Override count and rate | Override log | Last 30 days |
| Top override reasons | Override log | Last 30 days |
| Open incidents | Incident tracker | Current |
| Incident trend | Incident tracker | Last 90 days |

#### 5.2 Alert Configuration

Configure alerts to notify oversight personnel of events requiring attention:

| Alert Type | Trigger Condition | Notification Method | Recipients |
|------------|------------------|---------------------|------------|
| Critical — System Down | System health = Red | SMS + Email | All oversight personnel |
| High — Confidence Threshold Breached | Avg. confidence < `____%` for > `___` min | Email + Dashboard | Human Overseer, Responsible AI Officer |
| High — Unusual Override Rate | Override rate > `___`% in `___` min | Email + Dashboard | Responsible AI Officer |
| Medium — Error Rate Spike | Error rate > `___`% | Email | System Admin, Human Overseer |
| Medium — Data Drift Detected | Drift index > `___` | Email | Responsible AI Officer, Technical Lead |
| Low — Performance Degradation | Accuracy < `___`% (rolling 7d) | Dashboard | Responsible AI Officer |
| Informational — Daily Summary | Every day at `__:__` | Email | All oversight personnel |

---

### Part 6 — Periodic Oversight Review

#### 6.1 Weekly Oversight Review Checklist

To be completed by the Human Overseer or Responsible AI Officer each week:

- [ ] Review override log — note patterns and trends
- [ ] Review flagged decisions and their outcomes
- [ ] Check performance KPIs against thresholds
- [ ] Review any open incidents and their status
- [ ] Confirm all oversight personnel completed required monitoring sessions
- [ ] Note any anomalies or concerns for escalation

**Weekly Review Record:**

| Week Ending | Reviewer | Override Count | Incidents | Performance Status | Action Items |
|-------------|----------|----------------|-----------|-------------------|--------------|
| `____-__-__` | `___________` | `___` | `___` | ☐ Normal ☐ Concern | `___________` |

#### 6.2 Quarterly Oversight Effectiveness Review

- [ ] Analyse override patterns — are overrides concentrated in specific scenario types?
- [ ] Assess whether oversight procedures are being followed correctly (audit sample of override logs)
- [ ] Review training records — are all oversight personnel current?
- [ ] Review incident history — identify systemic issues
- [ ] Test emergency stop procedure (planned drill): Date: `____-__-__`
- [ ] Assess whether oversight mode remains appropriate (human-in-the-loop vs. on-the-loop)
- [ ] Review dashboard adequacy — are all required alerts and panels functioning?
- [ ] Update oversight procedures if gaps identified
- [ ] Report to senior management / Responsible AI Officer

#### 6.3 Annual Oversight Governance Review

- [ ] Full review of Article 14 compliance against latest regulatory guidance
- [ ] Independent internal audit of oversight procedures and logs
- [ ] Reassessment of overseer competencies
- [ ] Review and update Oversight Procedure Manual
- [ ] Update training materials
- [ ] Benchmark against sector best practices
- [ ] Update technical documentation (Annex IV Section 3)
- [ ] Report to board / senior leadership with recommendations

---

### Oversight Requirements by AI System Risk Profile

Use this table to calibrate the intensity of oversight to the risk profile of your system:

| Risk Factor | Low-End Profile | High-End Profile | Oversight Intensity |
|-------------|----------------|-----------------|---------------------|
| Decision reversibility | Easily reversible (e.g., content recommendation) | Irreversible (e.g., loan denial, employment rejection) | Higher risk → Human-in-the-Loop |
| Affected population size | Small, defined group | Large, general population | Higher risk → More frequent oversight |
| Severity of potential harm | Minor inconvenience | Physical, financial, fundamental rights harm | Higher risk → Mandatory override capability |
| Speed of decision | Hours or days (time to intervene) | Real-time (seconds) | Faster → More robust auto-alert systems |
| Operator expertise | High domain expertise | Low AI/technical expertise | Lower expertise → Simpler interface + more training |
| System maturity | Proven, stable system | New or recently changed system | Less mature → More intensive oversight |

---

### Related Templates

| Template | Purpose |
|----------|---------|
| `technical-documentation-annex-iv.md` | Annex IV Section 3 (Monitoring) and Section 14 (Instructions for Use) |
| `conformity-assessment.md` | Human oversight evidence for conformity assessment |
| `declaration-of-conformity.md` | Article 14 referenced in the declaration |
| `prohibited-practices-checklist.md` | Confirm oversight personnel awareness of prohibited practices |

---

*Template provided by VORLUX AI | vorluxai.com | This is guidance only, not legal advice.*

---

### Versión Española

## Requisitos de supervisión humana para la implementación — Guía del artículo 14 de la Directiva UE sobre Inteligencia Artificial

> **Aviso:** Esta es una guía solo, no asesoramiento legal. Consulte a un abogado calificado para sus obligaciones de cumplimiento específicas.

**Plantilla proporcionada por VORLUX AI** | [vorluxai.com](https://vorluxai.com)

---

### Lo que exige el artículo 14

El artículo 14 de la Directiva UE sobre Inteligencia Artificial exige que los sistemas de IA de alto riesgo sean **diseñados y desarrollados** de tal manera que puedan ser efectivamente supervisados por personas naturales durante el período de uso. Esto no es solo una política requerida — debe estar **integrado en la arquitectura del sistema y las proceduras operativas**.

#### Las cuatro obligaciones centrales del artículo 14

| Obligación | Artículo Ref | Qué significa |
|------------|------------|---------------|
| Supervisión significativa por diseño | 14(1) | El sistema debe ser técnicamente capaz de ser sobrescrito, detenido o corregido |
| Interfaz adecuada para la supervisión | 14(2) | Las herramientas y la información deben permitir al supervisor humano comprender y controlar realmente el sistema |
| Competencia del supervisor | 14(3) | Las personas asignadas a supervisar el sistema deben tener el conocimiento y la autoridad necesarios para hacerlo de manera efectiva |
| Capacidad de sobrescritura y parada | 14(4) | El supervisor debe poder intervenir en tiempo real y sobrescribir o interrumpir la operación del sistema |

---

### Parte 1 — Diseño de la mecanismo de supervisión

#### 1.1 Requisitos a nivel de sistema

Antes de la implementación, confirme que se han implementado los siguientes en el sistema de IA:

**Interpretabilidad y transparencia**
- [ ] Los resultados del sistema incluyen puntuaciones de confianza o estimaciones de incertidumbre donde sea técnicamente posible
- [ ] El sistema proporciona explicaciones humanas interpretables para los resultados (apropiadas al nivel de riesgo y uso)
- [ ] El sistema marca los casos en que está operando cerca o fuera de su límite de diseño
- [ ] El sistema muestra las características de entrada más relevantes o factores contribuyentes a cada decisión

**Interfaz de supervisión**
- [ ] Existe una interfaz de supervisión dedicada (panel, API o consola de operador)
- [ ] La interfaz muestra el estado actual del sistema (en ejecución, pausado, degradado, error)
- [ ] La interfaz muestra los datos de entrada, salida del modelo, confianza y factores clave de decisión
- [ ] La interfaz proporciona acceso a registros de auditoría
- [ ] La interfaz es accesible para el personal de supervisión sin conocimientos técnicos especializados

**Capacidades de sobrescritura y control**
- [ ] Es posible la sobrescritura manual de decisiones individuales en tiempo real
- [ ] La función de pausa / parada del sistema está disponible y accesible dentro de `____` segundos
- [ ] Los resultados pueden marcarse para revisión humana antes de tener efecto (si el modo pre-decision es apropiado)
- [ ] La revocación / reversión de decisiones de IA es posible durante un plazo definido después del resultado: `____` horas/días
- [ ] El fallback a un proceso manual está documentado y probado

**Controles de arquitectura técnica**

| Control | Implementación | Fecha de prueba | Resultado de la prueba |
|---------|---------------|-----------------|----------------------|
| Botón de emergencia / punto final API | `___________` | `____-__-__` | ☐ Aprobado ☐ Rechazado |
| Rastro de auditoría de decisiones (tamper-evident) | `___________` | `____-__-__` | ☐ Aprobado ☐ Rechazado |
| Monitoreo en tiempo real de resultados | `___________` | `____-__-__` | ☐ Aprobado ☐ Rechazado |
| Registro de supervisión humana | `___________` | `____-__-__` | ☐ Aprobado ☐ Rechazado |
| Capacidad de retroceso | `___________` | `____-__-__` | ☐ Aprobado ☐ Rechazado |

#### 1.2 Matriz de nivel de supervisión

Defina cuando la supervisión humana es activa y qué nivel se requiere:

| Modo operativo | Descripción | Nivel de supervisión requerido | Disparador |
|-----------------|-------------|-------------------------|-----------|
| **Human-in-the-Loop** | Cada decisión revisada antes de tener efecto | Revisión completa de cada resultado | Decisiones de alto riesgo; contextos de baja volumetría |
| **Human-on-the-Loop** | La IA actúa; el humano monitorea y puede sobrescribir | Muestreo + alertas de anomalías | Volumen medio; decisiones reversibles |
| **Human-over-the-Loop** | La IA opera de manera autónoma; auditoría humana periódica | Auditoría de muestra + panel de indicadores clave (KPI) | Volumen alto; decisiones de menor riesgo; reversibles |

---

### Parte 2 — Formación y competencia del supervisor

#### 2.1 Requisitos de competencia (Art. 14(3))

Cada persona asignada como supervisor de un sistema de IA debe cumplir:

| Competencia | Evidencia requerida | Verificación |
|------------|---------------------|-------------|
| Comprensión del propósito y limitaciones del sistema | Certificado de formación | ☐ Completado |
| Capacidad para interpretar resultados y puntuaciones de confianza | Evaluación práctica | ☐ Aprobado |
| Conocimiento del dominio relevante al uso del sistema | Cualificación profesional o experiencia documentada | ☐ Verificado |
| Conocimiento de sesgos potenciales y modos de fallo | Módulo de formación específico | ☐ Completado |
| Capacidad para usar la interfaz de sobrescritura | Ejercicio práctico supervisado | ☐ Demostrado |
| Autoridad para detener el sistema si es necesario | Autorización formal por escrito | ☐ Firmado |

#### 2.2 Plan de formación

- [ ] Formación inicial antes de la primera supervisión (mínimo `___` horas)
- [ ] Formación de actualización cada `___` meses
- [ ] Simulacro de intervención/sobrescritura cada `___` meses
- [ ] Registro de formación archivado como evidencia de cumplimiento

---

### Parte 3 — Protocolo de intervención y sobrescritura

#### 3.1 Procedimiento de sobrescritura en 6 pasos

```
Paso 1: IDENTIFICAR — Anotar el resultado del sistema y la razón de preocupación
Paso 2: EVALUAR — Revisar evidencia (entradas, confianza, explicación)
Paso 3: DECIDIR — Sobrescribir, pausar, escalar o aceptar
Paso 4: ACTUAR — Usar interfaz de sobrescritura, registrar decisión
Paso 5: DOCUMENTAR — Completar el registro de sobrescritura
Paso 6: SEGUIMIENTO — Verificar que el resultado fue aplicado correctamente
```

#### 3.2 Registro de sobrescritura

| Campo | Valor |
|-------|-------|
| ID de sobrescritura | `OVR-____-____-____` |
| Fecha y hora | `____-__-__` `__:__:__` |
| Resultado original del sistema | `___________________________` |
| Confianza del sistema | `____%` |
| Razón de la sobrescritura | `___________________________` |
| Decisión humana | `___________________________` |
| ¿Escalado? | ☐ Sí → ID: `___` ☐ No |
| ¿Supervisor notificado? | ☐ Sí ☐ No |

---

### Parte 4 — Mejora continua y auditoría

#### 4.1 Revisión periódica

- [ ] Revisión mensual de métricas de supervisión
- [ ] Análisis trimestral de patrones de sobrescritura
- [ ] Informe anual de cumplimiento para dirección
- [ ] Actualización de umbrales basada en rendimiento real

#### 4.2 Métricas de supervisión

| Métrica | Objetivo | Frecuencia |
|---------|----------|-----------|
| Tasa de sobrescritura | < `__`% de decisiones | Mensual |
| Tiempo medio de intervención | < `__` minutos | Mensual |
| Cobertura de formación | 100% supervisores activos | Trimestral |
| Simulacros completados | ≥ 1 por trimestre | Trimestral |
| Incidentes escalados | Seguimiento 100% | Continuo |

---

*¿Necesita ayuda implementando supervisión humana para sus sistemas de IA? [Contacte con VORLUX AI](https://vorluxai.com/contact?ref=template-human-oversight) para una evaluación personalizada.*

---

# Prohibited AI Practices Checklist (Art. 5)
_Lista de verificación de prácticas de IA prohibidas (art. 5)_

> Complete self-assessment checklist for all 8 prohibited AI practices under EU AI Act Article 5, with examples, edge cases, self-assessment questions, and incident response procedures.
> Online: https://vorluxai.com/templates/prohibited-practices-checklist/

## Prohibited AI Practices Checklist — EU AI Act Article 5

> **Disclaimer:** This is guidance only, not legal advice. Consult qualified legal counsel for your specific compliance obligations. Operating a prohibited AI system carries significant penalties under the EU AI Act, including fines of up to EUR 35,000,000 or 7% of total worldwide annual turnover.

**Template provided by VORLUX AI** | [vorluxai.com](https://vorluxai.com)

---

### Purpose and Scope

Article 5 of the EU AI Act bans certain AI practices outright — they cannot be authorised, exempted, or justified by proportionality. No conformity assessment procedure can make them lawful. This checklist must be completed:

- **Before developing or deploying any AI system**
- **When the intended purpose or capabilities of an existing system change**
- **When a new use case is identified for an existing AI system**
- **Annually as part of ongoing compliance review**

| Field | Value |
|-------|-------|
| AI System / Use Case Name | `___________________________` |
| Assessment Date | `____-__-__` |
| Assessor Name | `___________________________` |
| Assessor Role | `___________________________` |
| Reviewed by (Legal) | `___________________________` |
| Review Date | `____-__-__` |

---

### How to Complete This Checklist

For each of the 8 prohibited practices:

1. **Read the prohibition description** carefully
2. **Answer all self-assessment questions** honestly
3. **Review the edge cases** — if any apply to your system, seek legal advice before proceeding
4. **Record your determination:** ☐ Practice does NOT apply | ☐ UNCERTAIN — escalate | ☐ Practice MAY apply — STOP

**Any "UNCERTAIN" or "MAY apply" determination must be escalated to legal counsel before the system is developed, deployed, or continued in operation.**

---

### Prohibited Practice 1 — Subliminal or Manipulative Techniques

*Article 5(1)(a)*

#### The Prohibition

AI systems that deploy subliminal techniques beyond a person's consciousness, or deliberately exploit psychological weaknesses or vulnerabilities of individuals or specific groups, in a way that is **likely to cause harm** to those persons by distorting their behaviour.

#### Self-Assessment Questions

| # | Question | Yes | No | Unsure |
|---|----------|-----|----|--------|
| 1.1 | Does the system present information or stimuli designed to operate below the level of conscious awareness? | ☐ | ☐ | ☐ |
| 1.2 | Does the system use psychological profiling to identify and exploit individual weaknesses? | ☐ | ☐ | ☐ |
| 1.3 | Is the system designed to produce behavioural changes in users without their awareness? | ☐ | ☐ | ☐ |
| 1.4 | Does the system use techniques specifically designed to bypass rational decision-making? | ☐ | ☐ | ☐ |
| 1.5 | Could the system cause persons to make choices that harm their interests without being aware they are being influenced? | ☐ | ☐ | ☐ |

#### Examples of Prohibited Conduct

- Images flashed faster than the human eye can consciously perceive, designed to influence purchasing behaviour
- AI that detects emotional vulnerability (e.g., grief, anxiety) from voice patterns and serves manipulative content at those moments
- Personalised dark patterns that exploit cognitive biases identified from user data
- Subliminal audio embedded in content to promote specific products or views

#### Edge Cases — Seek Legal Advice If

- Your system uses persuasion or recommendation engines — the line between lawful persuasion and manipulation depends on **intent to harm** and **bypassing consciousness**
- Your system targets advertising at users based on psychological profiles
- Your system adjusts its approach based on detected emotional states

#### Determination

☐ Practice does NOT apply to this system
☐ UNCERTAIN — escalating to legal counsel on `____-__-__`
☐ Practice MAY apply — STOP — do not proceed without legal clearance

**Evidence / Rationale:**
```
[Document your reasoning and supporting evidence]
```

---

### Prohibited Practice 2 — Exploitation of Vulnerable Groups

*Article 5(1)(b)*

#### The Prohibition

AI systems that exploit any of the vulnerabilities of a specific group of persons due to their **age, disability, or specific social or economic situation**, in a way that is likely to cause those persons or third parties harm by distorting their behaviour.

#### Self-Assessment Questions

| # | Question | Yes | No | Unsure |
|---|----------|-----|----|--------|
| 2.1 | Does the system target or disproportionately reach children, elderly persons, or persons with cognitive disabilities? | ☐ | ☐ | ☐ |
| 2.2 | Does the system use age-specific or disability-specific psychological techniques to influence behaviour? | ☐ | ☐ | ☐ |
| 2.3 | Does the system target persons in economic difficulty with offers or recommendations that could cause harm? | ☐ | ☐ | ☐ |
| 2.4 | Has the system been tested for differential impact on vulnerable groups? | ☐ | ☐ | ☐ |
| 2.5 | Could a vulnerable person be harmed by acting on the system's outputs or recommendations? | ☐ | ☐ | ☐ |

#### Examples of Prohibited Conduct

- AI promoting high-interest loans to persons identified as financially distressed
- Chatbots targeting minors using age-specific engagement techniques to drive purchases
- Gaming AI exploiting addiction patterns identified in behavioural data
- AI targeting persons with gambling addiction with personalised gambling content

#### Edge Cases — Seek Legal Advice If

- Your system serves or will foreseeably be used by minors or elderly persons
- Your system makes financial product recommendations without assessing user vulnerability
- Your system operates in social care, mental health support, or financial advice contexts

#### Determination

☐ Practice does NOT apply to this system
☐ UNCERTAIN — escalating to legal counsel on `____-__-__`
☐ Practice MAY apply — STOP — do not proceed without legal clearance

**Evidence / Rationale:**
```
[Document your reasoning and supporting evidence]
```

---

### Prohibited Practice 3 — Social Scoring by Public Authorities

*Article 5(1)(c)*

#### The Prohibition

AI systems used by **public authorities** (or on their behalf) for the evaluation or classification of natural persons or groups over a certain period of time based on their **social behaviour or known or predicted personal or personality characteristics**, leading to detrimental or unfavourable treatment that is either:
- unrelated to the social context in which the data was generated, **or**
- unjustified or disproportionate relative to the social behaviour.

#### Self-Assessment Questions

| # | Question | Yes | No | Unsure |
|---|----------|-----|----|--------|
| 3.1 | Is this system used by or on behalf of a public authority? | ☐ | ☐ | ☐ |
| 3.2 | Does the system aggregate individual behaviour data over time to create a score or classification of persons? | ☐ | ☐ | ☐ |
| 3.3 | Are decisions or differential treatments made based on that score/classification? | ☐ | ☐ | ☐ |
| 3.4 | Could the treatment resulting from the score affect persons in a different social context from where data was collected? | ☐ | ☐ | ☐ |
| 3.5 | Is the potential harm disproportionate to the social behaviour it purports to reflect? | ☐ | ☐ | ☐ |

#### Examples of Prohibited Conduct

- A national government deploying a "citizen score" that affects access to public services based on social media activity
- Tax authority systems that use predicted lifestyle scores to determine audit likelihood and deny benefits
- Immigration services using algorithmic social scores generated from third-country behaviour data

#### Edge Cases — Seek Legal Advice If

- Your client is a public authority and your system produces any kind of person-level scoring or ranking
- Your system is used in public service eligibility decisions
- Your system produces outputs that could feed into governmental decision-making about individuals

#### Determination

☐ Practice does NOT apply to this system (not a public authority context)
☐ UNCERTAIN — escalating to legal counsel on `____-__-__`
☐ Practice MAY apply — STOP — do not proceed without legal clearance

**Evidence / Rationale:**
```
[Document your reasoning and supporting evidence]
```

---

### Prohibited Practice 4 — Real-Time Remote Biometric Identification in Public Spaces

*Article 5(1)(d)*

#### The Prohibition

The use of **real-time remote biometric identification systems** in publicly accessible spaces for law enforcement purposes, **except** in specific, narrowly defined circumstances:

**Permitted exceptions (all conditions must be met):**
1. Targeted search for specific crime victims (missing children, trafficking victims)
2. Prevention of specific imminent threat to life or physical safety or terrorist attack
3. Detection, identification, or prosecution of perpetrators of specific serious criminal offences (life sentence crimes)

**Even permitted use requires:** Prior judicial or independent administrative authorisation (except in urgent cases, where retrospective authorisation is sought promptly).

#### Self-Assessment Questions

| # | Question | Yes | No | Unsure |
|---|----------|-----|----|--------|
| 4.1 | Does the system perform biometric identification (matching against a database)? | ☐ | ☐ | ☐ |
| 4.2 | Is identification performed in real-time (not post-hoc on stored footage)? | ☐ | ☐ | ☐ |
| 4.3 | Is the system used or intended to be used in publicly accessible spaces? | ☐ | ☐ | ☐ |
| 4.4 | Is the system used or intended to be used for law enforcement purposes? | ☐ | ☐ | ☐ |
| 4.5 | If exceptions apply, has prior judicial/administrative authorisation been obtained? | ☐ | ☐ | ☐ |

#### Examples of Prohibited Conduct

- Deploying facial recognition cameras in a city centre to identify persons of interest from a criminal watchlist (without exception authorisation)
- Real-time matching of faces at transport hubs against a general database
- Using real-time biometric ID for general crime deterrence without specific threat

#### Edge Cases — Seek Legal Advice If

- Your system involves any biometric processing in publicly accessible spaces
- Your client is a law enforcement agency
- Your system combines CCTV analysis with face database matching even with time delay
- Your system operates at borders, airports, or other high-footfall public infrastructure

#### Determination

☐ Practice does NOT apply to this system
☐ UNCERTAIN — escalating to legal counsel on `____-__-__`
☐ Practice MAY apply — STOP — do not proceed without legal clearance

**Evidence / Rationale:**
```
[Document your reasoning and supporting evidence]
```

---

### Prohibited Practice 5 — AI-Generated or Manipulated "Deepfake" Biometric Data to Evade Identity Checks

*Article 5(1)(e)*

#### The Prohibition

AI systems specifically designed to generate or manipulate **image, audio, or video content** that features the likeness or voice of persons for the purpose of deceiving persons or automated systems to **circumvent identity verification systems** or other security mechanisms.

#### Self-Assessment Questions

| # | Question | Yes | No | Unsure |
|---|----------|-----|----|--------|
| 5.1 | Does the system generate synthetic face, voice, or body representations of real persons? | ☐ | ☐ | ☐ |
| 5.2 | Could the system's outputs be used to deceive face recognition, voice authentication, or liveness detection systems? | ☐ | ☐ | ☐ |
| 5.3 | Has the system been designed to bypass automated security checks? | ☐ | ☐ | ☐ |
| 5.4 | Are there contractual or technical guardrails preventing use of the system for identity fraud? | ☐ | ☐ | ☐ |
| 5.5 | Has foreseeable misuse for identity deception been assessed and mitigated? | ☐ | ☐ | ☐ |

#### Examples of Prohibited Conduct

- A deepfake video generation tool specifically marketed for bypassing KYC (Know Your Customer) verification
- Voice cloning tools designed to deceive voice authentication systems
- Face-swap tools marketed to help users pass facial liveness detection checks

**Note:** Legitimate use cases for synthetic media (entertainment, accessibility, privacy protection) are not prohibited by this article — the prohibition targets the **specific purpose** of circumventing identity/security checks.

#### Determination

☐ Practice does NOT apply to this system
☐ UNCERTAIN — escalating to legal counsel on `____-__-__`
☐ Practice MAY apply — STOP — do not proceed without legal clearance

**Evidence / Rationale:**
```
[Document your reasoning and supporting evidence]
```

---

### Prohibited Practice 6 — Emotion Recognition in Workplace and Education

*Article 5(1)(f)*

#### The Prohibition

AI systems that infer the **emotions of natural persons** in the workplace or in educational institutions, **except** where the AI system is intended for medical or safety reasons (e.g., detecting drowsiness in vehicle operators).

#### Self-Assessment Questions

| # | Question | Yes | No | Unsure |
|---|----------|-----|----|--------|
| 6.1 | Does the system attempt to detect, infer, or classify emotional states of persons? | ☐ | ☐ | ☐ |
| 6.2 | Is the system used or intended to be used in a workplace setting? | ☐ | ☐ | ☐ |
| 6.3 | Is the system used or intended to be used in an educational institution? | ☐ | ☐ | ☐ |
| 6.4 | If emotion recognition is used, is it solely for a documented medical or safety reason? | ☐ | ☐ | ☐ |
| 6.5 | If safety use, is it limited to that specific safety function (e.g., fatigue detection only)? | ☐ | ☐ | ☐ |

#### Examples of Prohibited Conduct

- HR software that uses facial expression analysis to assess employee engagement or satisfaction
- Examination proctoring software that flags emotional states as indicators of cheating
- Call centre software that uses vocal analysis to infer agent emotional states for performance management

#### Examples of Permitted Use (Safety Exception)

- Driver monitoring systems in commercial vehicles detecting drowsiness (medical/safety purpose)
- Industrial machinery operator monitoring for fatigue in safety-critical roles

#### Edge Cases — Seek Legal Advice If

- Your system processes video or audio data of employees or students
- Your system uses "engagement" or "attention" scoring in workplace or educational contexts
- Your sentiment analysis tools are used in employment or educational assessment decisions

#### Determination

☐ Practice does NOT apply to this system
☐ Practice is for medical/safety reason only — exception applies (document below)
☐ UNCERTAIN — escalating to legal counsel on `____-__-__`
☐ Practice MAY apply — STOP — do not proceed without legal clearance

**Medical/Safety Exception Documentation (if applicable):**
```
[Document the specific safety/medical purpose, how the exception is limited in scope,
and how use is controlled to prevent expansion beyond the excepted purpose]
```

---

### Prohibited Practice 7 — Biometric Categorisation Based on Sensitive Characteristics

*Article 5(1)(g)*

#### The Prohibition

AI systems that categorise natural persons based on their **biometric data** in order to **deduce or infer** sensitive personal characteristics such as:
- Race or ethnic origin
- Political opinions
- Trade union membership
- Religious or philosophical beliefs
- Sexual orientation or sex life

#### Self-Assessment Questions

| # | Question | Yes | No | Unsure |
|---|----------|-----|----|--------|
| 7.1 | Does the system process biometric data (facial features, gait, voice, fingerprints, etc.)? | ☐ | ☐ | ☐ |
| 7.2 | Does the system infer or predict any sensitive characteristic from biometric data? | ☐ | ☐ | ☐ |
| 7.3 | Is the categorisation used to make decisions about individuals based on those inferred characteristics? | ☐ | ☐ | ☐ |
| 7.4 | Even if not the primary purpose, could the system's outputs reveal sensitive characteristics as a by-product? | ☐ | ☐ | ☐ |
| 7.5 | Have all model outputs been tested for inference of sensitive characteristics? | ☐ | ☐ | ☐ |

#### Examples of Prohibited Conduct

- Facial analysis systems claiming to predict sexual orientation from facial geometry
- AI systems inferring political views from face images for targeted political messaging
- Race or ethnicity inference from facial or voice biometric data used in access control decisions

#### Determination

☐ Practice does NOT apply to this system
☐ UNCERTAIN — escalating to legal counsel on `____-__-__`
☐ Practice MAY apply — STOP — do not proceed without legal clearance

**Evidence / Rationale:**
```
[Document your reasoning and supporting evidence]
```

---

### Prohibited Practice 8 — Untargeted Facial Image Scraping

*Article 5(1)(h)*

#### The Prohibition

The creation or expansion of **facial recognition databases** through the untargeted scraping of facial images from the internet or CCTV footage.

#### Self-Assessment Questions

| # | Question | Yes | No | Unsure |
|---|----------|-----|----|--------|
| 8.1 | Does the system scrape or collect facial images from internet sources? | ☐ | ☐ | ☐ |
| 8.2 | Does the system collect facial images from CCTV or public camera footage? | ☐ | ☐ | ☐ |
| 8.3 | Are collected images used to build or expand a facial recognition database? | ☐ | ☐ | ☐ |
| 8.4 | Is the collection targeted (specific named individuals with lawful basis) or untargeted (bulk collection)? | ☐ | ☐ | ☐ |
| 8.5 | Do data subjects provide explicit consent for facial image collection and database use? | ☐ | ☐ | ☐ |

#### Examples of Prohibited Conduct

- Automated web crawlers collecting social media profile photos to train facial recognition models
- Systems harvesting CCTV footage to extract and catalogue faces without individual consent
- Creating stock facial recognition training datasets from public internet images

#### Determination

☐ Practice does NOT apply to this system
☐ UNCERTAIN — escalating to legal counsel on `____-__-__`
☐ Practice MAY apply — STOP — do not proceed without legal clearance

**Evidence / Rationale:**
```
[Document your reasoning and supporting evidence]
```

---

### Overall Assessment Summary

| Prohibited Practice | Article | Determination |
|--------------------|---------|---------------|
| 1. Subliminal/Manipulative Techniques | 5(1)(a) | ☐ Does not apply ☐ Uncertain ☐ May apply |
| 2. Exploitation of Vulnerable Groups | 5(1)(b) | ☐ Does not apply ☐ Uncertain ☐ May apply |
| 3. Social Scoring by Public Authorities | 5(1)(c) | ☐ Does not apply ☐ Uncertain ☐ May apply |
| 4. Real-Time Biometric ID in Public Spaces | 5(1)(d) | ☐ Does not apply ☐ Uncertain ☐ May apply |
| 5. Identity Deception via Biometric Synthesis | 5(1)(e) | ☐ Does not apply ☐ Uncertain ☐ May apply |
| 6. Emotion Recognition (Workplace/Education) | 5(1)(f) | ☐ Does not apply ☐ Uncertain ☐ May apply |
| 7. Biometric Categorisation (Sensitive Chars.) | 5(1)(g) | ☐ Does not apply ☐ Uncertain ☐ May apply |
| 8. Untargeted Facial Image Scraping | 5(1)(h) | ☐ Does not apply ☐ Uncertain ☐ May apply |

**Overall Outcome:**
☐ **CLEAR** — No prohibited practices identified. Proceed with high-risk classification and conformity assessment.
☐ **UNCERTAIN** — One or more items require legal clarification before proceeding.
☐ **PROHIBITED** — One or more prohibited practices identified. The AI system or specific use case must be **discontinued or fundamentally redesigned**.

---

### What to Do If a Prohibited Practice Is Detected

#### Immediate Actions (within 24 hours)

1. **STOP** deployment and development activities that involve the prohibited practice
2. **Notify** the project lead and senior management immediately
3. **Document** the finding in writing with timestamp
4. **Preserve** evidence of the prohibited practice (do not delete logs or code)
5. **Engage legal counsel** immediately

#### Short-Term Actions (within 72 hours)

1. Assess whether any data subjects have already been affected
2. Consider whether data protection authority notification is required (GDPR Art. 33/34)
3. Identify scope — is the prohibition in the core design, or in a specific use case?
4. Determine whether the system can be redesigned to eliminate the prohibited practice
5. If system has been placed on the EU market, assess market withdrawal obligations

#### Escalation Matrix

| Situation | Who to Notify | Timeline |
|-----------|---------------|----------|
| Potential prohibited practice identified | Legal counsel, DPO | Immediately |
| Confirmed prohibited practice | Senior management, Legal, DPO | Within 24 hours |
| Prohibited system placed on market | National Market Surveillance Authority | As required by law |
| Data subjects harmed | DPA (if GDPR breach involved), Legal | 72 hours (GDPR) |
| Employees aware of prohibited use | HR, Legal, Whistleblower process | Immediately |

#### Redesign Options

If a prohibited practice is identified but the underlying business need is legitimate, consider these alternatives:

| Prohibited Approach | Possible Lawful Alternative |
|--------------------|---------------------------|
| Subliminal manipulation | Transparent persuasion with disclosure; A/B testing without exploitative dark patterns |
| Vulnerable group targeting | General service with accessibility features; explicit safeguards for vulnerable users |
| Social scoring | Transparent, purpose-limited creditworthiness scoring with GDPR lawful basis |
| Real-time biometric ID | Post-hoc analysis with judicial authorisation; alternative identification methods |
| Biometric synthesis for fraud | Improved liveness detection; multi-factor authentication |
| Workplace emotion recognition | Voluntary wellbeing surveys; aggregate team analytics without individual profiling |
| Sensitive biometric categorisation | Remove biometric inference; use declared/consented attributes only |
| Facial image scraping | Licensed training datasets; synthetic data generation; consensual data collection |

---

### Sign-Off

| Role | Name | Signature | Date |
|------|------|-----------|------|
| Assessor | `_______________` | `_______________` | `____-__-__` |
| Legal Counsel / DPO | `_______________` | `_______________` | `____-__-__` |
| Authorised Signatory | `_______________` | `_______________` | `____-__-__` |

**Next scheduled review:** `____-__-__`

---

*Template provided by VORLUX AI | vorluxai.com | This is guidance only, not legal advice.*

---

### Versión Española

## Lista de prácticas prohibidas para IA — Artículo 5 del Reglamento UE sobre la Inteligencia Artificial > **Aviso:** Esta es una guía solo, no asesoramiento legal. Consulte a un abogado calificado para sus obligaciones de cumplimiento específicas. Operar un sistema de IA prohibido conlleva penas significativas según el Reglamento UE sobre la Inteligencia Artificial, incluidas multas de hasta EUR 35.000.000 o 7% del total anual de ingresos mundiales.

**Plantilla proporcionada por VORLUX AI** | [vorluxai.com](https://vorluxai.com) --- ## Propósito y alcance El artículo 5 del Reglamento UE sobre la Inteligencia Artificial prohíbe ciertas prácticas de IA en firme — no pueden ser autorizadas, eximidas o justificadas por proporcionalidad. No existe ningún procedimiento de evaluación de conformidad que las haga legales. Debe completarse esta lista:

- **Antes de desarrollar o implementar cualquier sistema de IA**
- **Cuando el propósito o capacidades previstas de un sistema existente cambien**
- **Cuando se identifique una nueva aplicación para un sistema de IA existente**
- **Anualmente como parte de la revisión continua de cumplimiento** | Campo | Valor | |-------|-------| | Nombre del sistema / caso de uso | `___________________________` | | Fecha de evaluación | `____-__-__` | | Nombre del evaluador | `___________________________` | | Rol del evaluador | `___________________________` | | Revisado por (Legal) | `___________________________` | | Fecha de revisión | `____-__-__` | --- ## Cómo completar esta lista Para cada una de las 8 prácticas prohibidas:

1. **Lee la descripción de la prohibición** con cuidado
2. **Responde todas las preguntas de autoevaluación** honestamente
3. **Revisa los casos límite** — si alguno se aplica a su sistema, busque asesoramiento legal antes de proceder
4. **Registra tu determinación:** ☐ La práctica NO se aplica | ☐ INCERTIDUMBRE — escalada | ☐ La práctica PUEDE aplicarse — DETENER **Cualquier "INCERTIDUMBRE" o "PUEDE aplicarse" debe ser elevado a un asesor legal antes de que el sistema sea desarrollado, implementado o continuado en operación.**

### Práctica prohibida 1 — Técnicas subliminales o manipulativas *Artículo 5(1)(a)* ### La Prohibición Los sistemas de IA que despliegan técnicas subliminales más allá del nivel de conciencia de una persona, o explotan deliberadamente debilidades psicológicas o vulnerabilidades de individuos o grupos específicos, de manera que es **probable que cause daño** a esas personas al distorsionar su comportamiento.

#### Preguntas de autoevaluación | # | Pregunta | Sí | No | Desconocido | |---|----------|-----|----|--------| | 1.1 | El sistema presenta información o estímulos diseñados para operar por debajo del nivel de conciencia consciente? | ☐ | ☐ | ☐ | | 1.2 | El sistema utiliza perfilado psicológico para identificar y explotar debilidades individuales

**Actividad de medios - Sistemas de autoridades fiscales que utilizan puntuaciones de estilo de vida predichas para determinar la probabilidad de auditoría y denegar beneficios - Servicios migratorios que utilizan puntuaciones sociales generadas algorítmicamente a partir de datos de comportamiento de terceros países**

**Casos límite — Busque asesoramiento legal si:**

- Su cliente es una autoridad pública y su sistema produce cualquier tipo de calificación o clasificación de personas
- Su sistema se utiliza en decisiones de elegibilidad para servicios públicos
- Su sistema produce salidas que podrían alimentar las decisiones gubernamentales sobre individuos

**Determinación**
☐ La práctica NO aplica a este sistema (no es un contexto de autoridad pública)
☐ INCERTIDUMBRE — escalando a asesoramiento legal en `____-__-__`
☐ La práctica PUEDE aplicar — DETÉNGASE — no continúe sin autorización legal

**Evidencia / Razonamiento:**
``` [Documente su razonamiento y evidencia de apoyo] ```
---

### **Práctica Prohibida 4 - Identificación biométrica remota en tiempo real en espacios públicos**

*Artículo 5(1)(d)*

**La prohibición**

El uso de **sistemas de identificación biométrica remota en tiempo real** en espacios accesibles al público para fines de aplicación de la ley, **excepto** en circunstancias específicas y estrechamente definidas:

**Exceptos permitidos (toda condición debe cumplirse):**

1. Búsqueda dirigida de víctimas de delitos específicos (niños desaparecidos, víctimas de tráfico)
2. Prevención de amenazas específicas inminentes a la vida o seguridad física o ataque terrorista
3. Deteción, identificación o persecución de perpetradores de delitos criminales graves específicos (delitos con sentencia de cadena perpetua)

**Incluso el uso permitido requiere:**

Autorización judicial o administrativa independiente previa (excepto en casos urgentes, donde se solicita autorización retrospectiva pronto).

#### Preguntas de autoevaluación

| # | Pregunta | Sí | No | Desconocido |
|---|----------|-----|----|--------|
| 4.1 | ¿El sistema realiza identificación biométrica (coincidencia con una base de datos)? | ☐ | ☐ | ☐ |
| 4.2 | ¿La identificación se realiza en tiempo real (no post-hoc en grabaciones almacenadas)? | ☐ | ☐ | ☐ |
| 4.3 | ¿El sistema se utiliza o está destinado a utilizarse en espacios accesibles al público? | ☐ | ☐ | ☐ |
| 4.4 | ¿El sistema se utiliza o está destinado a utilizarse para fines de aplicación de la ley? | ☐ | ☐ | ☐ |
| 4.5 | Si aplican excepciones, se ha obtenido autorización judicial/administrativa previa? | ☐ | ☐ | ☐ |

#### Ejemplos de conducta prohibida

- Desplegar cámaras de reconocimiento facial en un centro comercial para identificar personas de interés de una lista de vigilancia criminal (sin autorización de excepción)
- Coincidencia en tiempo real de caras en puntos de transporte contra una base de datos

**Sistemas que clasifican a personas naturales basadas en sus datos biométricos con el fin de deducir o inferir características personales sensibles como:**

- Raza o origen étnico
- Opiniones políticas
- Afiliación sindical
- Creencias religiosas o filosóficas
- Orientación sexual o vida sexual

#### Preguntas de Autoevaluación | # | Pregunta | Sí | No | Incierto | |---|----------|-----|----|--------| | 7.1 | ¿El sistema procesa datos biométricos (características faciales, gait, voz, huellas dactilares, etc.)? | ☐ | ☐ | ☐ | | 7.2 | ¿El sistema infiere o predice alguna característica sensible a partir de datos biométricos? | ☐ | ☐ | ☐ | | 7.3 | ¿La clasificación se utiliza para tomar decisiones sobre individuos basadas en aquellas características inferidas? | ☐ | ☐ | ☐ | | 7.4 | Incluso si no es el propósito principal, podría revelar características sensibles como subproducto de los resultados del sistema? | ☐ | ☐ | ☐ | | 7.5 | Se han probado todos los resultados del modelo para la inferencia de características sensibles? | ☐ | ☐ | ☐ |

#### Ejemplos de Conducta Prohibida

- Sistemas de análisis facial que pretenden predecir la orientación sexual a partir de geometría facial
- Sistemas AI que infieren opiniones políticas a partir de imágenes faciales para mensajería política dirigida
- Inferencia de raza o etnia a partir de datos biométricos faciales o vocales utilizados en decisiones de control de acceso

#### Determinación ☐ La práctica NO se aplica a este sistema ☐ UNCERTAIN — elevando a asesoramiento legal en `____-__-__` ☐ La práctica PUEDE aplicarse — DETENER — no proceda sin autorización legal **Evidencia / Razonamiento:** ``` [Documente su razonamiento y evidencia de apoyo] ```

---

### Práctica Prohibida 8 — Scraping de imágenes faciales no dirigidas

*Artículo 5(1)(h)*

#### La prohibición

La creación o expansión de **bases de datos de reconocimiento facial** a través del scraping no dirigido de imágenes faciales desde Internet o CCTV.

#### Preguntas de Autoevaluación | # | Pregunta | Sí | No | Incierto | |---|----------|-----|----|--------| | 8.1 | ¿El sistema scrapea o recopila imágenes faciales de fuentes de Internet? | ☐ | ☐ | ☐ | | 8.2 | ¿El sistema recopila imágenes faciales de CCTV o cámara de seguridad pública? | ☐ | ☐ | ☐ | | 8.3 | Las imágenes recolectadas se utilizan para construir o expandir una base de datos de reconocimiento facial? | ☐ | ☐ | ☐ | | 8.4 | ¿La recopilación es dirigida (individuos con nombre específicos y base legal) o no dirigida (recopilación en masa)? | ☐ | ☐ | ☐ | | 8.5 | Los sujetos de datos proporcionan consentimiento explícito para la recolección de imágenes faciales y el uso de la base de datos? | ☐ | ☐ | ☐ |

#### Ejemplos de Conducta Prohibida

- Crawlers web automatizados que recopilan

---

# Shadow AI Detection Checklist
_Lista de verificación para detectar IA en la sombra_

> A comprehensive operational checklist for identifying, remediating, and preventing shadow AI use across the organisation — covering detection methods, department surveys, remediation steps, and monitoring tools.
> Online: https://vorluxai.com/templates/shadow-ai-detection/

> **Disclaimer:** This is guidance only, not legal advice. Consult qualified legal counsel before adopting this framework. | *Este documento es solo orientativo, no constituye asesoramiento jurídico.*

---

## Shadow AI Detection Checklist

**Document Reference:** [ORG-CHECK-AI-002]
**Version:** 1.0
**Effective Date:** [DATE]
**Owner:** AI Officer / CISO
**Classification:** Internal — Restricted

---

### Part 1: Understanding Shadow AI

#### 1.1 What Is Shadow AI?

Shadow AI refers to the use of artificial intelligence tools and services by employees or teams within an organisation **without the knowledge, approval, or oversight of IT, security, or governance functions**.

Shadow AI is distinct from:
- **Approved AI tools** — formally assessed and registered tools
- **Experimental AI** — tools being evaluated through formal processes
- **Legacy automation** — rule-based automation systems predating the AI era

Shadow AI typically arises when:
- Employees discover AI tools that solve genuine productivity problems
- The formal AI approval process is perceived as too slow or burdensome
- Employees are unaware of the policy requirement to seek approval
- Business pressure incentivises speed over compliance
- Consumer AI tools are so accessible and free that the barrier to use is essentially zero

#### 1.2 Why Shadow AI Is a Material Risk

| Risk Category | Specific Risks |
|--------------|---------------|
| **Data Protection (GDPR)** | Personal data entered into unapproved tools with no DPA; data processed outside EU/EEA without adequate safeguards; accidental disclosure to AI model training datasets |
| **EU AI Act Compliance** | Organisation may be using high-risk AI systems without required assessments, documentation, or human oversight |
| **Confidentiality** | Proprietary business information, client data, trade secrets uploaded to third-party AI tools with unknown retention and training policies |
| **Legal Liability** | AI-generated content used without review may be defamatory, infringe IP rights, or be factually incorrect — liability falls on the organisation |
| **Security** | Unapproved tools may have poor security posture; credentials may be entered in prompts; API keys may be exposed |
| **Reputational** | Client data processed without authorisation; public-facing AI outputs not meeting quality or accuracy standards |
| **Operational** | Undocumented AI dependencies; "key person" risk when only one employee knows an AI workflow; decisions made on unchecked AI output |
| **Contractual** | Terms of service of consumer AI tools often prohibit commercial use; IP ownership of AI-generated content may be unclear or vest in the provider |

#### 1.3 Common Shadow AI Examples Seen in Organisations

- Employees using **ChatGPT (free/personal)** to draft client proposals, summarise contracts, or analyse data
- Developers using **AI coding assistants** (personal subscriptions) that process internal codebase
- HR using **AI screening tools** found online to filter CVs without formal procurement
- Marketing using **personal Midjourney/DALL-E accounts** for campaign imagery
- Finance using **AI analytics tools** to process financial data without IT knowledge
- Employees using **AI meeting summary tools** (personal accounts) to transcribe sensitive meetings
- Customer service using **AI chatbot builders** to create unofficial customer-facing bots
- Project managers using **AI workflow tools** that integrate with corporate systems via personal OAuth connections

---

### Part 2: Detection Methods

#### 2.1 Technical Detection Methods

Use the following technical approaches to identify shadow AI use. Assign ownership and frequency before commencing.

##### Network and Traffic Analysis

| Check | Method | Frequency | Owner |
|-------|--------|-----------|-------|
| DNS query logs — identify requests to known AI domains (see Annex A) | Review firewall/DNS logs for domains in Annex A | Weekly | IT/CISO |
| HTTPS inspection for AI API calls | Configure SSL inspection appliance to flag AI API endpoints | Continuous | IT/CISO |
| Bandwidth usage spikes from individual workstations | Analyse per-device bandwidth to identify large uploads to AI services | Weekly | IT |
| Browser extension inventory | Audit installed browser extensions across managed devices; flag AI assistants | Monthly | IT |
| SaaS application discovery | Use CASB (Cloud Access Security Broker) or equivalent to identify SaaS connections | Continuous | CISO |
| OAuth authorisation review | Audit OAuth tokens granted to third-party applications — revoke unknown AI tool connections | Monthly | IT |
| Email forwarding rules | Check for email forwarding rules that may send data to AI-connected email services | Monthly | IT |
| Clipboard/file transfer monitoring | Review DLP alerts for data transfers to known AI domains | Continuous | CISO/DLP |

##### Endpoint and Application Analysis

| Check | Method | Frequency | Owner |
|-------|--------|-----------|-------|
| Installed software inventory | Compare installed apps against approved software list; flag AI tools | Monthly | IT |
| Browser bookmarks and saved passwords | Targeted review on high-risk devices (IT must have authorised access policy) | Quarterly | IT |
| Meeting transcription tool connections | Review calendar integration apps for AI transcription services | Monthly | IT |
| IDE and coding environment plugins | Review developer IDE plugins for unapproved AI code assistants | Monthly | IT/DevOps |
| Mobile device management (MDM) review | Check work-enrolled mobile devices for AI applications | Monthly | IT |

##### Cloud and SaaS Monitoring

| Check | Method | Frequency | Owner |
|-------|--------|-----------|-------|
| Microsoft 365 / Google Workspace app integrations | Review third-party apps connected via OAuth to corporate M365/GWS | Monthly | IT |
| API gateway logs | Review API calls from internal systems to external AI providers | Weekly | IT/DevOps |
| Credit card / expense report review | Flag expenses for AI subscriptions (monthly SaaS charges) | Monthly | Finance + AI Officer |
| Procurement records | Check purchasing records for AI tool licences not channelled through IT | Quarterly | Finance + IT |

#### 2.2 Human Intelligence Detection Methods

Technical tools alone will not catch all shadow AI. These human intelligence methods complement technical monitoring:

| Method | Description | Frequency | Owner |
|--------|-------------|-----------|-------|
| **Manager briefings** | Brief all line managers on shadow AI risks; ask them to proactively flag observed tool use | Quarterly | HR + AI Officer |
| **All-hands Q&A** | Hold open Q&A sessions on AI policy; employees often self-disclose shadow AI when given amnesty | Semi-annual | AI Officer |
| **Onboarding interviews** | Ask new joiners about AI tools used at their previous employer and whether they plan to continue using them | Each onboarding | HR |
| **Exit interviews** | Ask departing employees if they are aware of any AI tools used by their team without approval | Each exit | HR |
| **IT helpdesk ticket analysis** | Review IT helpdesk tickets for requests to integrate, install, or troubleshoot AI tools | Monthly | IT/AI Officer |
| **Informal team observations** | AI Champions conduct informal team observation; report patterns of AI use not covered by policy | Quarterly | AI Champions |
| **Anonymous reporting channel** | Maintain an anonymous tip line or email for employees to report shadow AI concerns | Continuous | AI Officer |

---

### Part 3: Department Survey Questions

Conduct this survey annually (minimum) and after any period of significant change. The survey should be anonymous unless the organisation has strong cultural reasons to make it non-anonymous. Aim for >75% response rate per department.

#### Instructions for Survey Administrators

- Distribute via [Survey Tool — e.g., Microsoft Forms, anonymous Google Form]
- Allow 2 weeks for completion
- Communicate clearly: the purpose is to improve tools and policy, not to identify and punish
- Share anonymised, aggregated results with the AI Governance Committee
- Use findings to update the approved tool list and training priorities

---

#### Section A: General AI Use

**Q1.** In your day-to-day work, how often do you currently use any AI tools (this includes tools like ChatGPT, Copilot, Gemini, Grammarly AI, translation tools, AI in Excel, etc.)?
- [ ] Never
- [ ] Occasionally (a few times a month)
- [ ] Regularly (several times a week)
- [ ] Daily

**Q2.** Which of the following categories of AI tools have you used for work purposes in the last 6 months? (Select all that apply)
- [ ] AI writing assistants (e.g., ChatGPT, Claude, Gemini, Copilot)
- [ ] AI coding assistants (e.g., GitHub Copilot, Cursor, Tabnine)
- [ ] AI image generators (e.g., Midjourney, DALL-E, Adobe Firefly)
- [ ] AI meeting transcription/summary tools (e.g., Otter.ai, Fireflies, Teams Copilot)
- [ ] AI translation tools (e.g., DeepL, Google Translate AI)
- [ ] AI data analysis tools (e.g., AI features in Excel, Tableau, PowerBI)
- [ ] AI search tools (e.g., Perplexity AI, Bing AI)
- [ ] AI HR or recruitment tools
- [ ] AI customer service or chatbot tools
- [ ] Other (please specify): ___________
- [ ] None

**Q3.** For the tools you have used for work, are they:
- [ ] Officially approved and provided by the organisation
- [ ] Personal accounts/free versions I use on my own initiative
- [ ] A mix of approved and personal tools
- [ ] I am not sure whether the tools I use are approved

**Q4.** If you use personal or non-approved AI tools for work, what is the main reason? (Select all that apply)
- [ ] I did not know I needed approval
- [ ] The approval process takes too long
- [ ] There is no approved alternative that does what I need
- [ ] The approved tools do not work as well
- [ ] My team or manager encouraged it
- [ ] It is faster to use a free tool than go through IT
- [ ] Other: ___________

---

#### Section B: Data Handling

**Q5.** Have you ever entered any of the following types of information into an AI tool that was not officially approved? (Select all that apply)
- [ ] Client names or contact details
- [ ] Internal project names or strategies
- [ ] Financial data or forecasts
- [ ] Employee names or HR information
- [ ] Proprietary product or technical information
- [ ] Contract text or legal documents
- [ ] None of the above
- [ ] I prefer not to say

**Q6.** When using AI writing tools, do you typically:
- [ ] Write prompts from scratch with no sensitive information
- [ ] Paste in sections of internal documents to help me edit or summarise
- [ ] Paste in complete documents for the AI to work with
- [ ] I do not use AI writing tools

**Q7.** Are you aware that entering personal data (e.g., client or employee information) into an unapproved AI tool may constitute a GDPR breach?
- [ ] Yes, and I understand the implications
- [ ] Yes, but I am not sure exactly what counts as personal data
- [ ] No, I was not aware of this
- [ ] I am not sure

---

#### Section C: Policy Awareness

**Q8.** Are you aware that the organisation has an AI use policy?
- [ ] Yes, I have read it
- [ ] Yes, I know it exists but have not read it in detail
- [ ] I have heard of it but do not know what it says
- [ ] No, I was not aware there was one

**Q9.** Do you know how to request approval for a new AI tool you want to use for work?
- [ ] Yes — I know the process and who to contact
- [ ] I think I know but I am not certain
- [ ] No — I do not know how to do this

**Q10.** Have you received training on responsible AI use in the last 12 months?
- [ ] Yes, formal training (e.g., online course, workshop)
- [ ] Yes, informal (e.g., team briefing, email guidance)
- [ ] No

**Q11.** How confident do you feel in identifying when AI-generated content contains errors, bias, or "hallucinations"?
- [ ] Very confident
- [ ] Fairly confident
- [ ] Not very confident
- [ ] Not at all confident — I often take AI outputs at face value

---

#### Section D: Team and Culture

**Q12.** Does your direct manager use AI tools in their work that you are aware of?
- [ ] Yes — with tools that appear to be officially approved
- [ ] Yes — with tools that I am not sure are approved
- [ ] No / Not that I am aware of
- [ ] I do not know

**Q13.** Would you feel comfortable raising a concern if you saw a colleague using an AI tool in a way that seemed risky or inappropriate?
- [ ] Yes, definitely
- [ ] Probably yes
- [ ] I am not sure
- [ ] Probably not
- [ ] Definitely not

**Q14.** What would make you feel more supported in using AI tools correctly? (Select all that apply)
- [ ] Faster approval processes for new tools
- [ ] Better guidance on what I can and cannot do with approved tools
- [ ] More training on AI risks and responsible use
- [ ] A wider range of approved tools to choose from
- [ ] A dedicated person I can ask questions to
- [ ] Nothing — the current support is sufficient

**Q15.** Is there a specific AI tool or type of tool that you wish was available for your work that is not currently approved?
- [ ] Yes (please describe if comfortable): ___________
- [ ] No

**Q16.** Have you ever observed a situation where AI tools were used to make a decision about a person (hiring, performance assessment, customer service outcome) without what seemed like meaningful human review?
- [ ] Yes — and it concerned me
- [ ] Yes — but it seemed fine
- [ ] No
- [ ] Not sure

**Q17.** Do you have any other comments about AI tools and their use in our organisation? (Free text)

---

### Part 4: Remediation Steps

When shadow AI is detected, follow this structured remediation process.

#### 4.1 Immediate Response (Day 1–3)

| Step | Action | Owner | Documented in |
|------|--------|-------|--------------|
| R1 | Contain: suspend access to unapproved tool for relevant user(s) where risk is High or Critical | IT/CISO | Incident log |
| R2 | Assess data exposure: determine what data was entered and what the tool's data retention/training policy is | AI Officer + DPO | Incident log |
| R3 | Determine if personal data was involved | DPO | GDPR incident form |
| R4 | Notify line manager and HR | AI Officer | HR system |
| R5 | Secure any outputs produced by the unapproved tool | System Owner | Incident log |

#### 4.2 Investigation (Day 3–10)

| Step | Action | Owner |
|------|--------|-------|
| R6 | Interview the user(s) involved — focus on understanding motivation, not blame | HR + AI Officer |
| R7 | Review scope: are other employees using the same tool? | AI Officer + IT |
| R8 | Assess whether data breach notification is required (AEPD 72-hour window) | DPO |
| R9 | Review whether the tool should be considered for formal approval | AI Officer |
| R10 | Document root cause: why did this happen? (Awareness gap, process gap, tool gap?) | AI Officer |

#### 4.3 Remediation (Day 10–30)

| Step | Action | Owner |
|------|--------|-------|
| R11 | If personal data breach confirmed: notify AEPD within 72 hours (from detection); notify affected individuals if required | DPO + Legal |
| R12 | If tool has merit: fast-track through approval process | AI Officer + IT |
| R13 | Targeted training for affected department | HR + AI Officer |
| R14 | Issue policy reminder to all staff if incident reflects a widespread misunderstanding | HR + AI Officer |
| R15 | Update DNS/firewall blocklist if tool is not approved and risk is unacceptable | IT/CISO |
| R16 | Apply proportionate disciplinary action per HR policy (considering intent, harm caused, cooperation) | HR + Line Manager |

#### 4.4 Post-Incident Review (Day 30–45)

| Step | Action | Owner |
|------|--------|-------|
| R17 | Produce Post-Incident Report | AI Officer |
| R18 | Present findings to AI Governance Committee | AI Officer |
| R19 | Update risk register | AI Officer |
| R20 | Update shadow AI monitoring procedures if gaps identified | CISO + AI Officer |
| R21 | Consider whether to update approved tool list or accelerate approvals | AI Governance Committee |

---

### Part 5: Prevention Measures

#### 5.1 Policy and Communication

| Measure | Frequency | Owner |
|---------|-----------|-------|
| Communicate AI policy at onboarding | Every onboarding | HR |
| Annual all-staff AI policy reminder (email + intranet) | Annual | AI Officer + HR |
| Publish and maintain an easy-to-find list of approved tools on intranet | Continuous | AI Officer |
| Brief line managers on shadow AI risks and their reporting responsibility | Quarterly | AI Officer |
| Maintain a fast-track (5-day) AI tool request process for low-risk tools | Continuous | AI Officer |
| Publish "top tools employees ask for" on intranet to reduce need for workarounds | Quarterly | AI Officer |

#### 5.2 Technical Controls

| Control | Description | Priority | Owner |
|---------|-------------|----------|-------|
| DNS filtering | Block known unapproved consumer AI domains on corporate network | High | IT/CISO |
| DLP rules | Configure DLP to alert on data uploads to known AI endpoints | High | CISO |
| Browser extension management | Restrict installation of unapproved browser extensions on managed devices | Medium | IT |
| OAuth audit | Review and revoke third-party OAuth connections monthly | High | IT |
| CASB deployment | Implement Cloud Access Security Broker for comprehensive SaaS visibility | High | CISO |
| Endpoint agent | Deploy endpoint monitoring agent to detect AI tool installations | Medium | IT |
| MDM for mobile | Enrol all devices with work data in MDM; restrict unapproved app stores | Medium | IT |
| Expense monitoring | Flag AI-related SaaS charges in expense reporting system | Medium | Finance + AI Officer |

#### 5.3 Culture and Incentives

| Measure | Description | Owner |
|---------|-------------|-------|
| **Positive framing** | Present the AI approval process as a service, not a gate — "we help you get the tools you need safely" | AI Officer + Communications |
| **Fast-track for good-faith requests** | Employees who submit a tool request receive a response within 5 days for low-risk tools | AI Officer |
| **Recognition** | Recognise employees who identify and report shadow AI in good faith | AI Officer + HR |
| **Tool request feedback** | When a request is declined, provide clear reasons and suggest alternatives | AI Officer |
| **Quarterly AI newsletter** | Share approved tools, tips, and regulatory updates to keep AI visible and positive | AI Officer |

---

### Part 6: Monitoring Tools

#### 6.1 Recommended Technical Tools

| Tool Category | Purpose | Examples | Notes |
|--------------|---------|---------|-------|
| **CASB (Cloud Access Security Broker)** | Discover and monitor SaaS and AI tool usage across the organisation | Microsoft Defender for Cloud Apps, Netskope, Palo Alto SASE | Enterprise investment; high ROI for shadow AI visibility |
| **DNS Filtering** | Block unapproved AI domains; log DNS queries | Cisco Umbrella, Cloudflare Gateway, DNSFilter | Lower cost; good first step |
| **DLP (Data Loss Prevention)** | Detect uploads of sensitive data to AI endpoints | Microsoft Purview DLP, Forcepoint, Symantec DLP | Effective but generates false positives requiring tuning |
| **Endpoint Detection and Response (EDR)** | Detect AI tool installations and suspicious behaviour on endpoints | CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint | Broad security tool with shadow AI use case |
| **Network Traffic Analysis** | Identify AI API calls and data flows in network traffic | Darktrace, ExtraHop, Vectra AI | Advanced; requires expertise to interpret |
| **Browser Management** | Control and audit browser extensions | Chrome Enterprise, Microsoft Edge management | Effective for managed device fleets |
| **MDM/EMM** | Control applications on mobile and remote devices | Microsoft Intune, Jamf, VMware Workspace ONE | Essential for BYOD environments |
| **SIEM** | Correlate security events; detect shadow AI patterns | Microsoft Sentinel, Splunk, IBM QRadar | Requires rule development for AI-specific use cases |

#### 6.2 Known AI Domains to Monitor

*(This list requires regular updates as the AI tool landscape evolves — AI Officer to review quarterly)*

**High-risk consumer AI services (commonly used for work):**

| Service | Domain(s) | Risk Level | Notes |
|---------|-----------|-----------|-------|
| ChatGPT (consumer) | chat.openai.com, openai.com | High | Free consumer version may train on inputs |
| Claude (consumer) | claude.ai | High | Consumer version — no business DPA |
| Google Gemini (consumer) | gemini.google.com, bard.google.com | High | Consumer version |
| Perplexity AI | perplexity.ai | High | Consumer AI search |
| Midjourney | midjourney.com, discord.com (AI channels) | Medium | Image generation |
| Otter.ai (personal) | otter.ai | High | Meeting transcription — audio data |
| Fireflies.ai (personal) | fireflies.ai | High | Meeting transcription |
| Notion AI (personal) | notion.so | Medium | Note-taking with AI features |
| Grammarly (personal) | grammarly.com | Medium | Writing assistant — processes all text |
| DeepL (personal) | deepl.com | Medium | Translation tool |
| Copy.ai | copy.ai | Medium | AI writing |
| Jasper AI | jasper.ai | Medium | AI writing |
| Runway ML | runwayml.com | Medium | Video/image generation |
| Character.ai | character.ai | Low-Medium | Conversational AI |
| Pi.ai | pi.ai | Low-Medium | Conversational AI |

*This is an illustrative list. Maintain and update a live version in the AI System Inventory.*

#### 6.3 Detection Metrics to Track

| Metric | Target | Measurement | Frequency |
|--------|--------|------------|-----------|
| Number of shadow AI instances detected | Trending towards 0 | IT monitoring + survey | Quarterly |
| Time from detection to containment (High risk) | <4 hours | Incident log | Per incident |
| % employees who know how to request AI tool approval | >85% | Annual survey Q9 | Annual |
| Employee AI survey completion rate | >75% | Survey tool | Annual |
| Number of unapproved AI tool expenses detected | Trending towards 0 | Finance review | Monthly |
| % managers briefed on shadow AI risks | 100% | Training records | Annual |

---

### Annex A — Shadow AI Quick Reference Card

*(Print and post in team areas; include in onboarding pack)*

#### IS THIS SHADOW AI?

**Ask yourself:**
1. Is this AI tool on the Approved Tools List? [Link to intranet page]
2. Did IT or the AI Officer approve this tool?
3. Did I submit a Tool Request Form?

**If the answer to all three is NO — stop and submit a request first.**

#### WHAT TO DO IF YOU SPOT SHADOW AI IN YOUR TEAM

1. Do not confront the colleague directly
2. Speak to your AI Champion or Line Manager
3. Or email [ai-incidents@organisation.com] (reports can be anonymous)

#### QUICK GUIDE: WHAT NOT TO PUT IN ANY AI TOOL (APPROVED OR NOT)

- Client names, addresses, or contact details
- Employee personal data (salary, performance, health)
- Passwords, API keys, or credentials of any kind
- Classified or Restricted documents
- Legal privilege documents

---

*Template provided by VORLUX AI | vorluxai.com*
*This is guidance only, not legal advice.*
*Version 1.0 | For EU AI Act compliance use | Last updated: 2026-04-05*

---

### Versión Española

## Lista de Verificación para Detección de Shadow AI

**Referencia:** [ORG-CHECK-AI-002]
**Versión:** 1.0
**Fecha de vigencia:** [FECHA]
**Propietario:** AI Officer / CISO
**Clasificación:** Interno — Restringido

---

### Parte 1: Comprensión del Shadow AI

#### 1.1 ¿Qué es el Shadow AI?

El Shadow AI se refiere al uso de herramientas y servicios de inteligencia artificial por parte de empleados o equipos **sin el conocimiento, aprobación o supervisión de las funciones de TI, seguridad o gobernanza**.

Se distingue de: herramientas de IA aprobadas, IA experimental en evaluación formal y automatización legacy basada en reglas.

Surge habitualmente cuando:
- Los empleados descubren herramientas de IA que resuelven problemas reales de productividad
- El proceso de aprobación se percibe como lento o gravoso
- Los empleados desconocen la política de aprobación
- La presión empresarial prioriza la velocidad sobre el cumplimiento
- Las herramientas de IA de consumo son gratuitas y de acceso inmediato

#### 1.2 Por qué el Shadow AI es un Riesgo Material

| Categoría de riesgo | Riesgos específicos |
|---------------------|---------------------|
| **Protección de datos (GDPR)** | Datos personales introducidos en herramientas sin DPA; procesamiento fuera del EEE sin garantías; divulgación accidental a datasets de entrenamiento |
| **Cumplimiento EU AI Act** | Uso de sistemas de IA de alto riesgo sin evaluaciones, documentación ni supervisión humana requeridas |
| **Confidencialidad** | Información propietaria, datos de clientes y secretos comerciales subidos a herramientas de terceros con políticas de retención desconocidas |
| **Responsabilidad legal** | Contenido generado por IA usado sin revisión puede ser difamatorio, infringir PI o ser incorrecto — la responsabilidad recae en la organización |
| **Seguridad** | Herramientas no aprobadas con postura de seguridad deficiente; credenciales en prompts; API keys expuestas |
| **Reputacional** | Datos de clientes procesados sin autorización; salidas de IA públicas sin estándares de calidad |
| **Operativo** | Dependencias de IA no documentadas; riesgo de "persona clave"; decisiones basadas en salidas no verificadas |
| **Contractual** | Términos de servicio de IA de consumo a menudo prohíben uso comercial; propiedad intelectual del contenido generado puede ser del proveedor |

#### 1.3 Ejemplos comunes de Shadow AI

- Empleados usando **ChatGPT (gratuito/personal)** para redactar propuestas, resumir contratos o analizar datos
- Desarrolladores con **asistentes de código IA** (suscripciones personales) que procesan código interno
- RRHH usando **herramientas de screening IA** para filtrar CVs sin proceso de adquisición
- Marketing usando **cuentas personales de Midjourney/DALL-E** para imágenes de campaña
- Finanzas usando **herramientas analíticas IA** para procesar datos financieros sin conocimiento de TI
- Empleados usando **herramientas de resumen de reuniones IA** (cuentas personales) para transcribir reuniones sensibles
- Atención al cliente creando **chatbots IA** no oficiales para clientes
- Project managers usando **herramientas de workflow IA** integradas con sistemas corporativos mediante OAuth personal

---

### Parte 2: Métodos de Detección

#### 2.1 Métodos de Detección Técnica

##### Análisis de Red y Tráfico

| Verificación | Método | Frecuencia | Propietario |
|-------------|--------|------------|-------------|
| Logs de consultas DNS — identificar solicitudes a dominios de IA conocidos (ver Anexo A) | Revisar logs de firewall/DNS para dominios del Anexo A | Semanal | TI/CISO |
| Inspección HTTPS para llamadas a API de IA | Configurar dispositivo de inspección SSL para marcar endpoints de API de IA | Continuo | TI/CISO |
| Picos de ancho de banda por estación de trabajo | Analizar ancho de banda por dispositivo para identificar grandes cargas a servicios de IA | Semanal | TI |
| Inventario de extensiones de navegador | Auditar extensiones instaladas en dispositivos gestionados; marcar asistentes de IA | Mensual | TI |
| Descubrimiento de aplicaciones SaaS | Usar CASB para identificar conexiones SaaS | Continuo | CISO |
| Revisión de autorizaciones OAuth | Auditar tokens OAuth otorgados a terceros — revocar conexiones de herramientas de IA desconocidas | Mensual | TI |
| Reglas de reenvío de correo | Verificar reglas de reenvío hacia servicios de correo con IA | Mensual | TI |
| Monitoreo de transferencia de archivos/portapapeles | Revisar alertas DLP para transferencias a dominios de IA | Continuo | CISO/DLP |

##### Análisis de Endpoint y Aplicaciones

| Verificación | Método | Frecuencia | Propietario |
|-------------|--------|------------|-------------|
| Inventario de software instalado | Comparar apps instaladas con la lista aprobada; marcar herramientas de IA | Mensual | TI |
| Marcadores y contraseñas guardadas del navegador | Revisión dirigida en dispositivos de alto riesgo | Trimestral | TI |
| Conexiones de herramientas de transcripción de reuniones | Revisar apps de integración de calendario para servicios de transcripción IA | Mensual | TI |
| Plugins de IDE y entorno de desarrollo | Revisar plugins de IDE para asistentes de código IA no aprobados | Mensual | TI/DevOps |
| Revisión MDM de dispositivos móviles | Verificar aplicaciones de IA en dispositivos móviles corporativos | Mensual | TI |

##### Monitoreo Cloud y SaaS

| Verificación | Método | Frecuencia | Propietario |
|-------------|--------|------------|-------------|
| Integraciones de apps Microsoft 365 / Google Workspace | Revisar apps de terceros conectadas vía OAuth | Mensual | TI |
| Logs de API gateway | Revisar llamadas API internas a proveedores de IA externos | Semanal | TI/DevOps |
| Revisión de tarjetas de crédito / informes de gastos | Marcar gastos por suscripciones de IA | Mensual | Finanzas + AI Officer |
| Registros de adquisiciones | Verificar licencias de herramientas de IA no canalizadas por TI | Trimestral | Finanzas + TI |

#### 2.2 Métodos de Detección por Inteligencia Humana

| Método | Descripción | Frecuencia | Propietario |
|--------|-------------|------------|-------------|
| **Briefings a managers** | Informar a todos los responsables sobre riesgos de Shadow AI; pedir que reporten uso observado | Trimestral | RRHH + AI Officer |
| **Q&A abierta** | Sesiones abiertas sobre política de IA; los empleados suelen auto-reportar Shadow AI con amnistía | Semestral | AI Officer |
| **Entrevistas de incorporación** | Preguntar a nuevos empleados sobre herramientas de IA usadas en su empleador anterior | Cada incorporación | RRHH |
| **Entrevistas de salida** | Preguntar a empleados salientes si conocen herramientas de IA usadas sin aprobación | Cada salida | RRHH |
| **Análisis de tickets de helpdesk** | Revisar tickets para solicitudes de integrar, instalar o resolver problemas con herramientas de IA | Mensual | TI/AI Officer |
| **Observaciones informales de equipo** | AI Champions realizan observación informal; reportan patrones de uso no cubiertos por la política | Trimestral | AI Champions |
| **Canal de reporte anónimo** | Mantener línea de reporte anónima para preocupaciones sobre Shadow AI | Continuo | AI Officer |

---

### Parte 3: Preguntas de Encuesta Departamental

Realice esta encuesta anualmente (mínimo) y tras cualquier período de cambio significativo. La encuesta debe ser anónima salvo razones culturales justificadas. Objetivo: >75% de tasa de respuesta por departamento.

#### Instrucciones para Administradores de la Encuesta

- Distribuir vía [herramienta de encuesta — p. ej., Microsoft Forms, Google Forms anónimo]
- Permitir 2 semanas para completarla
- Comunicar claramente: el propósito es mejorar herramientas y política, no identificar y sancionar
- Compartir resultados anonimizados y agregados con el Comité de Gobernanza de IA

---

#### Sección A: Uso General de IA

**P1.** ¿Con qué frecuencia utiliza actualmente herramientas de IA en su trabajo diario?
- [ ] Nunca
- [ ] Ocasionalmente (algunas veces al mes)
- [ ] Regularmente (varias veces por semana)
- [ ] Diariamente

**P2.** ¿Qué categorías de herramientas de IA ha utilizado con fines laborales en los últimos 6 meses? (Seleccione todas las aplicables)
- [ ] Asistentes de escritura IA (p. ej., ChatGPT, Claude, Gemini, Copilot)
- [ ] Asistentes de código IA (p. ej., GitHub Copilot, Cursor, Tabnine)
- [ ] Generadores de imágenes IA (p. ej., Midjourney, DALL-E, Adobe Firefly)
- [ ] Herramientas de transcripción/resumen de reuniones IA (p. ej., Otter.ai, Fireflies, Teams Copilot)
- [ ] Herramientas de traducción IA (p. ej., DeepL, Google Translate AI)
- [ ] Herramientas de análisis de datos IA (p. ej., funciones IA en Excel, Tableau, PowerBI)
- [ ] Herramientas de búsqueda IA (p. ej., Perplexity AI, Bing AI)
- [ ] Herramientas de RRHH o reclutamiento IA
- [ ] Herramientas de atención al cliente o chatbot IA
- [ ] Otra (especifique): ___________
- [ ] Ninguna

**P3.** Las herramientas que ha usado para el trabajo, ¿son?
- [ ] Oficialmente aprobadas y proporcionadas por la organización
- [ ] Cuentas personales/versiones gratuitas que uso por iniciativa propia
- [ ] Una mezcla de herramientas aprobadas y personales
- [ ] No estoy seguro/a de si las herramientas que uso están aprobadas

**P4.** Si utiliza herramientas de IA personales o no aprobadas para el trabajo, ¿cuál es el motivo principal? (Seleccione todas las aplicables)
- [ ] No sabía que necesitaba aprobación
- [ ] El proceso de aprobación tarda demasiado
- [ ] No hay alternativa aprobada que haga lo que necesito
- [ ] Las herramientas aprobadas no funcionan tan bien
- [ ] Mi equipo o responsable lo fomentó
- [ ] Es más rápido usar una herramienta gratuita que pasar por TI
- [ ] Otro: ___________

---

#### Sección B: Manejo de Datos

**P5.** ¿Ha introducido alguna vez alguno de los siguientes tipos de información en una herramienta de IA no aprobada oficialmente? (Seleccione todas las aplicables)
- [ ] Nombres o datos de contacto de clientes
- [ ] Nombres de proyectos internos o estrategias
- [ ] Datos financieros o previsiones
- [ ] Nombres de empleados o información de RRHH
- [ ] Información propietaria de productos o técnica
- [ ] Textos contractuales o documentos legales
- [ ] Ninguna de las anteriores
- [ ] Prefiero no responder

**P6.** Cuando usa herramientas de escritura IA, ¿típicamente?
- [ ] Escribo prompts desde cero sin información sensible
- [ ] Pego secciones de documentos internos para que me ayude a editar o resumir
- [ ] Pego documentos completos para que la IA trabaje con ellos
- [ ] No uso herramientas de escritura IA

**P7.** ¿Sabe usted que introducir datos personales en una herramienta de IA no aprobada puede constituir una infracción del GDPR?
- [ ] Sí, y entiendo las implicaciones
- [ ] Sí, pero no estoy seguro/a de qué cuenta como dato personal
- [ ] No, no era consciente de ello
- [ ] No estoy seguro/a

---

#### Sección C: Conocimiento de la Política

**P8.** ¿Sabe usted que la organización tiene una política de uso de IA?
- [ ] Sí, la he leído
- [ ] Sí, sé que existe pero no la he leído en detalle
- [ ] He oído hablar de ella pero no sé qué dice
- [ ] No, no sabía que existía

**P9.** ¿Sabe cómo solicitar aprobación para una nueva herramienta de IA que desee usar en el trabajo?
- [ ] Sí — conozco el proceso y a quién contactar
- [ ] Creo que sí, pero no estoy seguro/a
- [ ] No — no sé cómo hacerlo

**P10.** ¿Ha recibido formación sobre uso responsable de IA en los últimos 12 meses?
- [ ] Sí, formación formal (p. ej., curso online, taller)
- [ ] Sí, informal (p. ej., briefing de equipo, correo orientativo)
- [ ] No

**P11.** ¿Cuán seguro/a se siente al identificar cuándo el contenido generado por IA contiene errores, sesgos o "alucinaciones"?
- [ ] Muy seguro/a
- [ ] Bastante seguro/a
- [ ] No muy seguro/a
- [ ] Nada seguro/a — a menudo acepto las salidas de IA sin cuestionar

---

#### Sección D: Equipo y Cultura

**P12.** ¿Su responsable directo utiliza herramientas de IA en su trabajo que usted conozca?
- [ ] Sí — con herramientas que parecen aprobadas oficialmente
- [ ] Sí — con herramientas que no estoy seguro/a de que estén aprobadas
- [ ] No / No que yo sepa
- [ ] No lo sé

**P13.** ¿Se sentiría cómodo/a planteando una preocupación si viera a un colega usando una herramienta de IA de manera arriesgada o inapropiada?
- [ ] Sí, definitivamente
- [ ] Probablemente sí
- [ ] No estoy seguro/a
- [ ] Probablemente no
- [ ] Definitivamente no

**P14.** ¿Qué le haría sentir más apoyado/a para usar herramientas de IA correctamente? (Seleccione todas las aplicables)
- [ ] Procesos de aprobación más rápidos para nuevas herramientas
- [ ] Mejor orientación sobre qué puedo y qué no puedo hacer con las herramientas aprobadas
- [ ] Más formación sobre riesgos de IA y uso responsable
- [ ] Una gama más amplia de herramientas aprobadas para elegir
- [ ] Una persona dedicada a la que pueda consultar
- [ ] Nada — el apoyo actual es suficiente

**P15.** ¿Hay alguna herramienta de IA específica o tipo de herramienta que desearía tener disponible para su trabajo y que actualmente no está aprobada?
- [ ] Sí (describa si se siente cómodo/a): ___________
- [ ] No

**P16.** ¿Ha observado alguna vez una situación en la que se usaron herramientas de IA para tomar una decisión sobre una persona (contratación, evaluación de rendimiento, resultado de atención al cliente) sin lo que pareciera una revisión humana significativa?
- [ ] Sí — y me preocupó
- [ ] Sí — pero pareció correcto
- [ ] No
- [ ] No estoy seguro/a

**P17.** ¿Tiene algún otro comentario sobre las herramientas de IA y su uso en nuestra organización? (Texto libre)

---

### Parte 4: Pasos de Remediación

#### 4.1 Respuesta Inmediata (Día 1–3)

| Paso | Acción | Propietario | Documentado en |
|------|--------|-------------|----------------|
| R1 | Contener: suspender acceso a la herramienta no aprobada cuando el riesgo sea Alto o Crítico | TI/CISO | Registro de incidentes |
| R2 | Evaluar exposición de datos: determinar qué datos se introdujeron y cuál es la política de retención/entrenamiento de la herramienta | AI Officer + DPO | Registro de incidentes |
| R3 | Determinar si hubo datos personales involucrados | DPO | Formulario de incidentes GDPR |
| R4 | Notificar al responsable directo y RRHH | AI Officer | Sistema de RRHH |
| R5 | Asegurar cualquier salida producida por la herramienta no aprobada | Propietario del sistema | Registro de incidentes |

#### 4.2 Investigación (Día 3–10)

| Paso | Acción | Propietario |
|------|--------|-------------|
| R6 | Entrevistar a los usuarios involucrados — centrado en entender la motivación, no en culpar | RRHH + AI Officer |
| R7 | Revisar alcance: ¿otros empleados usan la misma herramienta? | AI Officer + TI |
| R8 | Evaluar si se requiere notificación de brecha de datos (ventana de 72 horas de la AEPD) | DPO |
| R9 | Revisar si la herramienta debería considerarse para aprobación formal | AI Officer |
| R10 | Documentar causa raíz: ¿por qué sucedió? (¿Brecha de conocimiento, proceso o herramienta?) | AI Officer |

#### 4.3 Remediación (Día 10–30)

| Paso | Acción | Propietario |
|------|--------|-------------|
| R11 | Si se confirma brecha de datos personales: notificar a la AEPD en 72 horas (desde la detección); notificar a los afectados si es necesario | DPO + Legal |
| R12 | Si la herramienta tiene mérito: vía rápida en el proceso de aprobación | AI Officer + TI |
| R13 | Formación dirigida al departamento afectado | RRHH + AI Officer |
| R14 | Recordatorio de política a todo el personal si el incidente refleja un malentendido generalizado | RRHH + AI Officer |
| R15 | Actualizar lista de bloqueo DNS/firewall si la herramienta no está aprobada y el riesgo es inaceptable | TI/CISO |
| R16 | Acción disciplinaria proporcionada según política de RRHH (considerando intención, daño causado, cooperación) | RRHH + Responsable directo |

#### 4.4 Revisión Post-Incidente (Día 30–45)

| Paso | Acción | Propietario |
|------|--------|-------------|
| R17 | Elaborar Informe Post-Incidente | AI Officer |
| R18 | Presentar hallazgos al Comité de Gobernanza de IA | AI Officer |
| R19 | Actualizar registro de riesgos | AI Officer |
| R20 | Actualizar procedimientos de monitoreo de Shadow AI si se identificaron brechas | CISO + AI Officer |
| R21 | Considerar si actualizar la lista de herramientas aprobadas o acelerar aprobaciones | Comité de Gobernanza de IA |

---

### Parte 5: Medidas de Prevención

#### 5.1 Política y Comunicación

| Medida | Frecuencia | Propietario |
|--------|------------|-------------|
| Comunicar política de IA en la incorporación | Cada incorporación | RRHH |
| Recordatorio anual de la política de IA a todo el personal (correo + intranet) | Anual | AI Officer + RRHH |
| Publicar y mantener una lista fácil de encontrar de herramientas aprobadas en la intranet | Continuo | AI Officer |
| Informar a los responsables sobre riesgos de Shadow AI y su responsabilidad de reporte | Trimestral | AI Officer |
| Mantener un proceso de solicitud de herramienta IA rápido (5 días) para herramientas de bajo riesgo | Continuo | AI Officer |
| Publicar "herramientas más solicitadas" en la intranet para reducir la necesidad de alternativas no autorizadas | Trimestral | AI Officer |

#### 5.2 Controles Técnicos

| Control | Descripción | Prioridad | Propietario |
|---------|-------------|-----------|-------------|
| Filtrado DNS | Bloquear dominios de IA de consumo no aprobados en la red corporativa | Alta | TI/CISO |
| Reglas DLP | Configurar DLP para alertar sobre cargas de datos a endpoints de IA | Alta | CISO |
| Gestión de extensiones del navegador | Restringir instalación de extensiones no aprobadas en dispositivos gestionados | Media | TI |
| Auditoría OAuth | Revisar y revocar conexiones OAuth de terceros mensualmente | Alta | TI |
| Despliegue de CASB | Implementar Cloud Access Security Broker para visibilidad SaaS completa | Alta | CISO |
| Agente de endpoint | Desplegar agente de monitoreo para detectar instalaciones de herramientas de IA | Media | TI |
| MDM para móviles | Inscribir todos los dispositivos con datos laborales en MDM; restringir tiendas de apps no aprobadas | Media | TI |
| Monitoreo de gastos | Marcar cargos SaaS relacionados con IA en el sistema de informes de gastos | Media | Finanzas + AI Officer |

#### 5.3 Cultura e Incentivos

| Medida | Descripción | Propietario |
|--------|-------------|-------------|
| **Enfoque positivo** | Presentar el proceso de aprobación como un servicio, no como una barrera — "le ayudamos a obtener las herramientas que necesita de forma segura" | AI Officer + Comunicación |
| **Vía rápida para solicitudes de buena fe** | Los empleados que solicitan una herramienta reciben respuesta en 5 días para herramientas de bajo riesgo | AI Officer |
| **Reconocimiento** | Reconocer a los empleados que identifican y reportan Shadow AI de buena fe | AI Officer + RRHH |
| **Feedback en solicitudes** | Cuando se rechaza una solicitud, proporcionar razones claras y sugerir alternativas | AI Officer |
| **Newsletter trimestral de IA** | Compartir herramientas aprobadas, consejos y actualizaciones regulatorias | AI Officer |

---

### Parte 6: Herramientas de Monitoreo

#### 6.1 Herramientas Técnicas Recomendadas

| Categoría | Propósito | Ejemplos | Notas |
|-----------|-----------|----------|-------|
| **CASB** | Descubrir y monitorear uso de SaaS y herramientas de IA | Microsoft Defender for Cloud Apps, Netskope, Palo Alto SASE | Inversión empresarial; alto ROI para visibilidad de Shadow AI |
| **Filtrado DNS** | Bloquear dominios de IA no aprobados; registrar consultas DNS | Cisco Umbrella, Cloudflare Gateway, DNSFilter | Menor coste; buen primer paso |
| **DLP** | Detectar cargas de datos sensibles a endpoints de IA | Microsoft Purview DLP, Forcepoint, Symantec DLP | Efectivo pero genera falsos positivos que requieren ajuste |
| **EDR** | Detectar instalaciones de herramientas de IA y comportamiento sospechoso en endpoints | CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint | Herramienta de seguridad amplia con caso de uso para Shadow AI |
| **Análisis de tráfico de red** | Identificar llamadas API de IA y flujos de datos | Darktrace, ExtraHop, Vectra AI | Avanzado; requiere experiencia para interpretar |
| **Gestión de navegador** | Controlar y auditar extensiones de navegador | Chrome Enterprise, Microsoft Edge management | Efectivo para flotas de dispositivos gestionados |
| **MDM/EMM** | Controlar aplicaciones en dispositivos móviles y remotos | Microsoft Intune, Jamf, VMware Workspace ONE | Esencial para entornos BYOD |
| **SIEM** | Correlacionar eventos de seguridad; detectar patrones de Shadow AI | Microsoft Sentinel, Splunk, IBM QRadar | Requiere desarrollo de reglas específicas para IA |

#### 6.2 Dominios de IA Conocidos a Monitorear

*(Esta lista requiere actualizaciones regulares — el AI Officer debe revisarla trimestralmente)*

| Servicio | Dominio(s) | Nivel de riesgo | Notas |
|----------|-----------|-----------------|-------|
| ChatGPT (consumo) | chat.openai.com, openai.com | Alto | Versión gratuita puede entrenar con inputs |
| Claude (consumo) | claude.ai | Alto | Versión de consumo — sin DPA empresarial |
| Google Gemini (consumo) | gemini.google.com, bard.google.com | Alto | Versión de consumo |
| Perplexity AI | perplexity.ai | Alto | Búsqueda IA de consumo |
| Midjourney | midjourney.com, discord.com | Medio | Generación de imágenes |
| Otter.ai (personal) | otter.ai | Alto | Transcripción de reuniones — datos de audio |
| Fireflies.ai (personal) | fireflies.ai | Alto | Transcripción de reuniones |
| Notion AI (personal) | notion.so | Medio | Toma de notas con funciones de IA |
| Grammarly (personal) | grammarly.com | Medio | Asistente de escritura — procesa todo el texto |
| DeepL (personal) | deepl.com | Medio | Herramienta de traducción |
| Copy.ai | copy.ai | Medio | Escritura IA |
| Jasper AI | jasper.ai | Medio | Escritura IA |
| Runway ML | runwayml.com | Medio | Generación de vídeo/imagen |
| Character.ai | character.ai | Bajo-Medio | IA conversacional |
| Pi.ai | pi.ai | Bajo-Medio | IA conversacional |

#### 6.3 Métricas de Detección a Seguir

| Métrica | Objetivo | Medición | Frecuencia |
|---------|----------|----------|------------|
| Nº de instancias de Shadow AI detectadas | Tendencia hacia 0 | Monitoreo TI + encuesta | Trimestral |
| Tiempo desde detección hasta contención (riesgo Alto) | <4 horas | Registro de incidentes | Por incidente |
| % empleados que saben solicitar aprobación de herramienta IA | >85% | Encuesta anual P9 | Anual |
| Tasa de finalización de encuesta de IA | >75% | Herramienta de encuesta | Anual |
| Nº de gastos en herramientas IA no aprobadas detectados | Tendencia hacia 0 | Revisión financiera | Mensual |
| % managers informados sobre riesgos de Shadow AI | 100% | Registros de formación | Anual |

---

### Anexo A — Tarjeta de Referencia Rápida de Shadow AI

*(Imprimir y colocar en áreas de equipo; incluir en el pack de incorporación)*

#### ¿ES ESTO SHADOW AI?

**Pregúntese:**
1. ¿Esta herramienta de IA está en la Lista de Herramientas Aprobadas? [Enlace a la intranet]
2. ¿TI o el AI Officer aprobaron esta herramienta?
3. ¿Presenté un Formulario de Solicitud de Herramienta?

**Si la respuesta a las tres es NO — deténgase y presente una solicitud primero.**

#### QUÉ HACER SI DETECTA SHADOW AI EN SU EQUIPO

1. No confronte al colega directamente
2. Hable con su AI Champion o Responsable directo
3. O envíe un correo a [ai-incidents@organización.com] (los reportes pueden ser anónimos)

#### GUÍA RÁPIDA: QUÉ NO INTRODUCIR EN NINGUNA HERRAMIENTA DE IA (APROBADA O NO)

- Nombres, direcciones o datos de contacto de clientes
- Datos personales de empleados (salario, rendimiento, salud)
- Contraseñas, API keys o credenciales de cualquier tipo
- Documentos clasificados o restringidos
- Documentos con privilegio legal

---

*Plantilla proporcionada por VORLUX AI | vorluxai.com*
*Este documento es solo orientativo, no constituye asesoramiento jurídico.*
*Versión 1.0 | Para uso de cumplimiento del EU AI Act | Última actualización: 2026-04-05*

---

# Technical Documentation Checklist (Annex IV)
_Lista de verificación de documentación técnica (anexo IV)_

> Complete checklist for EU AI Act Annex IV technical documentation requirements covering all 15 mandatory sections for high-risk AI systems.
> Online: https://vorluxai.com/templates/technical-documentation-annex-iv/

## Technical Documentation Checklist — EU AI Act Annex IV

> **Disclaimer:** This is guidance only, not legal advice. Consult qualified legal counsel for your specific compliance obligations.

**Template provided by VORLUX AI** | [vorluxai.com](https://vorluxai.com)

---

### How to Use This Template

This checklist maps directly to Annex IV of the EU AI Act (Regulation (EU) 2024/1689). Each section must be completed **before** placing a high-risk AI system on the EU market or putting it into service. Documentation must be kept up to date throughout the system's lifecycle and made available to competent authorities on request.

| Field | Value |
|-------|-------|
| AI System Name | `___________________________` |
| Version / Build | `___________________________` |
| Provider Organisation | `___________________________` |
| Document Owner | `___________________________` |
| Document Version | `___________________________` |
| Last Updated | `___________________________` |
| Classification | High-Risk AI System (Annex III, item `____`) |

---

### Section 1 — General Description of the AI System

*Art. 11 & Annex IV §1*

#### 1.1 Intended Purpose

- [ ] Clear statement of the intended purpose of the AI system
- [ ] Identification of the natural persons or groups of persons to whom the system is intended to be used
- [ ] Description of the specific context(s) of use
- [ ] Identification of users (operators/deployers) and affected persons

**Intended Purpose Statement:**
```
[Describe in plain language what this AI system does and for whom]
```

**Target Users:**
```
[List intended operator types and end-user categories]
```

**Use Context:**
```
[Describe the operational environment — sector, geography, workflow integration]
```

#### 1.2 System Category & Annex III Classification

- [ ] Confirm which Annex III category applies (tick all that apply):

| Annex III Item | Description | Applies? |
|----------------|-------------|----------|
| 1 | Biometric identification and categorisation | ☐ Yes ☐ No |
| 2 | Critical infrastructure management | ☐ Yes ☐ No |
| 3 | Education and vocational training | ☐ Yes ☐ No |
| 4 | Employment and workers management | ☐ Yes ☐ No |
| 5 | Access to essential services | ☐ Yes ☐ No |
| 6 | Law enforcement | ☐ Yes ☐ No |
| 7 | Migration and asylum management | ☐ Yes ☐ No |
| 8 | Administration of justice | ☐ Yes ☐ No |

**Confirmed Classification:** Annex III, Item `____`

#### 1.3 System Version History

| Version | Date | Summary of Changes | Author |
|---------|------|--------------------|--------|
| `v___` | `____-__-__` | Initial release | `___` |
| `v___` | `____-__-__` | `________________________` | `___` |

---

### Section 2 — Detailed Description of System Elements

*Annex IV §2*

#### 2.1 Development Methods and Logic

- [ ] Description of the methods used to develop the AI system
- [ ] Description of the design specifications (objectives, classification, regression targets)
- [ ] Description of the main design choices and trade-offs made
- [ ] Rationale for selecting the ML approach/architecture used

**Development Approach:**
```
[Describe: supervised/unsupervised/reinforcement learning, model type, framework]
```

**Key Design Decisions:**
```
[Document major architectural choices and the reasoning behind them]
```

#### 2.2 System Architecture

- [ ] Overall system architecture diagram attached
- [ ] Description of each component and its role
- [ ] Data flow diagram showing inputs, processing steps, outputs
- [ ] Description of integration points with external systems

**Architecture Diagram Reference:** `[Attach or link diagram — file: ___________]`

**Component Inventory:**

| Component | Role | Technology | Version |
|-----------|------|------------|---------|
| `___________` | `___________` | `___________` | `___` |
| `___________` | `___________` | `___________` | `___` |
| `___________` | `___________` | `___________` | `___` |

#### 2.3 Computational Resources

- [ ] Description of compute infrastructure (cloud/on-premise/edge)
- [ ] Hardware specifications for inference and training
- [ ] Estimated resource consumption at scale

**Infrastructure:**
```
[Cloud provider, region, instance types; or on-premise hardware specs]
```

---

### Section 3 — Monitoring, Functioning, and Control

*Annex IV §3*

#### 3.1 Real-Time Monitoring Capabilities

- [ ] Description of monitoring mechanisms built into the system
- [ ] List of metrics monitored in production (performance, drift, errors)
- [ ] Alert thresholds and escalation procedures defined
- [ ] Logging mechanisms for audit trails

**Monitoring Metrics:**

| Metric | Threshold | Alert Action | Owner |
|--------|-----------|--------------|-------|
| Prediction accuracy | `> ____%` | `___________` | `___` |
| Response latency (P99) | `< ___ms` | `___________` | `___` |
| Data drift index | `< ___` | `___________` | `___` |
| Error rate | `< ____%` | `___________` | `___` |

#### 3.2 Human Control Mechanisms

- [ ] Description of human override capabilities (Article 14 requirements)
- [ ] Stop/pause/rollback procedures documented
- [ ] Operator intervention interfaces described
- [ ] Escalation path to human decision-maker defined

**Override Procedure Reference:** `[Link to Human Oversight Guide]`

#### 3.3 Logging and Audit Trail

- [ ] All inputs and outputs logged (where proportionate)
- [ ] Log retention period defined: `___ days / months / years`
- [ ] Log access controls defined
- [ ] Log integrity protection (tamper-evidence) in place

---

### Section 4 — Risk Management System

*Art. 9 & Annex IV §4*

#### 4.1 Risk Identification

- [ ] Systematic risk identification process completed
- [ ] All known risks to health, safety, and fundamental rights documented
- [ ] Foreseeable misuse scenarios documented
- [ ] Risks arising from interaction with other systems identified

**Risk Register:**

| Risk ID | Risk Description | Likelihood (1-5) | Impact (1-5) | Risk Score | Mitigation |
|---------|-----------------|------------------|--------------|------------|------------|
| `R-001` | `_______________` | `___` | `___` | `___` | `___________` |
| `R-002` | `_______________` | `___` | `___` | `___` | `___________` |
| `R-003` | `_______________` | `___` | `___` | `___` | `___________` |

#### 4.2 Risk Evaluation and Mitigation

- [ ] Risk evaluation against acceptable risk levels documented
- [ ] Risk mitigation measures identified and implemented
- [ ] Residual risks documented and accepted by accountable person
- [ ] Risk management process is iterative (reviewed post-change)

**Residual Risk Statement:**
```
[After mitigation, describe remaining risks and justification for acceptance]
```

#### 4.3 Risk Management Review Schedule

- [ ] Initial risk assessment completed: `____-__-__`
- [ ] Next scheduled review: `____-__-__`
- [ ] Trigger events for ad-hoc reviews defined (e.g., incidents, model updates)

---

### Section 5 — Data Governance

*Art. 10 & Annex IV §5*

#### 5.1 Training Data

- [ ] Description of training dataset(s) — source, size, format
- [ ] Data collection methodologies described
- [ ] Data selection criteria documented
- [ ] Labelling methodology and quality controls described
- [ ] Known limitations and gaps in training data documented

**Training Data Summary:**

| Dataset | Source | Size | Date Range | Licence | Known Gaps |
|---------|--------|------|------------|---------|------------|
| `_______` | `_______` | `___` | `__________` | `_______` | `___________` |

#### 5.2 Validation and Test Data

- [ ] Validation dataset described (separate from training data)
- [ ] Test dataset described (held-out, representative of real-world distribution)
- [ ] Data splits documented (e.g., 70/15/15 train/val/test)
- [ ] Geographic and demographic representativeness assessed

#### 5.3 Data Quality

- [ ] Data quality measures applied (deduplication, outlier removal, etc.)
- [ ] Data cleaning procedures documented
- [ ] Bias detection and mitigation steps documented
- [ ] Data lineage traceable

#### 5.4 Personal Data and Privacy

- [ ] Personal data in training sets identified
- [ ] GDPR lawful basis for processing confirmed: `___________`
- [ ] Data minimisation applied
- [ ] Anonymisation/pseudonymisation techniques documented
- [ ] Data Protection Impact Assessment (DPIA) status: `___________`

---

### Section 6 — Technical Specifications

*Annex IV §6*

#### 6.1 Input Specifications

- [ ] Data types accepted (structured/unstructured, modalities)
- [ ] Input format requirements (schema, encoding, size limits)
- [ ] Valid input ranges and constraints defined
- [ ] Handling of out-of-distribution inputs described

**Input Schema:**
```
[Define expected input structure, data types, constraints]
```

#### 6.2 Output Specifications

- [ ] Output format described (classification labels, scores, structured data, text, etc.)
- [ ] Confidence/uncertainty estimates provided: ☐ Yes ☐ No
- [ ] Output interpretation guidance documented
- [ ] Output post-processing steps described

**Output Schema:**
```
[Define output structure, value ranges, interpretation guidelines]
```

#### 6.3 Model Specifications

- [ ] Model type and architecture documented (e.g., transformer, random forest, CNN)
- [ ] Number of parameters: `___________`
- [ ] Model file formats and versions documented
- [ ] Dependencies and third-party libraries listed with versions

**Dependency Manifest:**

| Library/Model | Version | Licence | Purpose |
|---------------|---------|---------|---------|
| `___________` | `___` | `_______` | `___________` |
| `___________` | `___` | `_______` | `___________` |

---

### Section 7 — Quality Management

*Art. 17 & Annex IV §7*

#### 7.1 Performance Metrics

- [ ] Performance metrics selected and justified
- [ ] Baseline benchmarks documented
- [ ] Performance across relevant subgroups tested (demographic parity, etc.)
- [ ] Acceptable performance thresholds defined

**Performance Summary:**

| Metric | Value | Benchmark | Subgroup Results | Pass/Fail |
|--------|-------|-----------|------------------|-----------|
| Accuracy | `____%` | `____%` | `[attached]` | ☐ Pass ☐ Fail |
| Precision | `____%` | `____%` | `[attached]` | ☐ Pass ☐ Fail |
| Recall | `____%` | `____%` | `[attached]` | ☐ Pass ☐ Fail |
| F1 Score | `___` | `___` | `[attached]` | ☐ Pass ☐ Fail |

#### 7.2 Testing Procedures

- [ ] Unit testing procedures documented
- [ ] Integration testing procedures documented
- [ ] Pre-deployment acceptance testing documented
- [ ] Adversarial / robustness testing results documented

#### 7.3 Continuous Improvement

- [ ] Post-market monitoring plan in place (Art. 72)
- [ ] Feedback mechanisms to capture real-world performance
- [ ] Process for incorporating improvements / retraining defined
- [ ] Version control and release management procedures documented

---

### Section 8 — EU Declaration of Conformity

*Art. 47 & Annex V — see separate template*

- [ ] EU Declaration of Conformity drafted (see `declaration-of-conformity.md`)
- [ ] Declaration covers the specific AI system version documented here
- [ ] Declaration signed by authorised representative
- [ ] Declaration reference number: `DOC-____-____`

---

### Section 9 — Post-Market Monitoring Plan

*Art. 72*

- [ ] Post-market monitoring plan prepared
- [ ] KPIs for ongoing monitoring defined
- [ ] Incident reporting procedures established
- [ ] Serious incident notification to authorities documented (Art. 73)
- [ ] Review frequency: ☐ Monthly ☐ Quarterly ☐ Annually ☐ Event-triggered

**Monitoring Plan Reference:** `[File: ___________]`

---

### Section 10 — Cybersecurity

- [ ] Cybersecurity risks identified and documented
- [ ] Security testing (penetration testing, adversarial input testing) performed
- [ ] Access controls and authentication described
- [ ] Data encryption at rest and in transit documented
- [ ] Incident response plan in place

**Security Assessment Date:** `____-__-__`
**Security Assessment Provider:** `___________________________`

---

### Section 11 — Accuracy, Robustness, and Resilience

*Art. 15*

- [ ] Accuracy levels declared and substantiated
- [ ] Robustness to errors and inconsistencies in inputs tested
- [ ] Resilience against adversarial manipulation assessed
- [ ] Fallback behaviour when system operates outside design envelope defined

**Robustness Testing Summary:**
```
[Summarise robustness tests performed and results]
```

---

### Section 12 — Transparency and Explainability

- [ ] Level of explainability appropriate for the use case documented
- [ ] Explanation methods used (SHAP, LIME, attention maps, etc.) described
- [ ] User-facing explanations designed and tested
- [ ] Limitations of explanations disclosed

---

### Section 13 — Third-Party Components and Supply Chain

- [ ] All third-party AI components identified
- [ ] Suppliers' compliance documentation collected
- [ ] Supply chain risk assessment completed
- [ ] Licence compliance confirmed for all components

**Third-Party Component Register:**

| Component | Supplier | Version | EU AI Act Status | Licence Confirmed |
|-----------|----------|---------|------------------|-------------------|
| `___________` | `___________` | `___` | `___________` | ☐ Yes ☐ No |

---

### Section 14 — Instructions for Use

*Art. 13 & Annex IV §14*

- [ ] Instructions for use prepared for operators/deployers
- [ ] Instructions cover: intended purpose, known limitations, maintenance
- [ ] Instructions cover: human oversight requirements
- [ ] Instructions available in language(s) of Member States of deployment
- [ ] Instructions version-controlled and dated

**Languages Available:** `___________________________`
**Document Reference:** `[File: ___________]`

---

### Section 15 — Samples and Specimens

- [ ] Representative sample outputs included or referenced
- [ ] Test cases with expected vs. actual outputs documented
- [ ] Edge cases and failure mode examples documented

---

### Documentation Sign-Off

| Role | Name | Signature | Date |
|------|------|-----------|------|
| Technical Lead | `_______________` | `_______________` | `____-__-__` |
| Data Protection Officer | `_______________` | `_______________` | `____-__-__` |
| Quality Manager | `_______________` | `_______________` | `____-__-__` |
| Legal / Compliance | `_______________` | `_______________` | `____-__-__` |
| Authorised Signatory | `_______________` | `_______________` | `____-__-__` |

---

### Annex IV Completeness Tracker

| Section | Status | Owner | Last Updated |
|---------|--------|-------|--------------|
| 1. General Description | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 2. System Elements | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 3. Monitoring & Control | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 4. Risk Management | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 5. Data Governance | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 6. Technical Specifications | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 7. Quality Management | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 8. Declaration of Conformity | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 9. Post-Market Monitoring | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 10. Cybersecurity | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 11. Accuracy & Robustness | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 12. Transparency | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 13. Supply Chain | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 14. Instructions for Use | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |
| 15. Samples & Specimens | ☐ Draft ☐ Review ☐ Approved | `___` | `____-__-__` |

---

*Template provided by VORLUX AI | vorluxai.com | This is guidance only, not legal advice.*

---

### Versión Española

## Checklist de Documentación Técnica — Anexo IV del Reglamento (UE) 2024/1689 sobre Inteligencia Artificial

> **Nota:** Esta es una guía solo, no asesoramiento legal. Consulte a un abogado calificado para sus obligaciones de cumplimiento específicas.

**Plantilla proporcionada por VORLUX AI** | [vorluxai.com](https://vorluxai.com)

---

### Cómo Usar esta Plantilla

Esta lista de verificación se ajusta directamente al Anexo IV del Reglamento (UE) 2024/1689 sobre Inteligencia Artificial. Cada sección debe completarse **antes** de colocar un sistema de inteligencia artificial de alto riesgo en el mercado de la UE o ponerlo en servicio. La documentación debe mantenerse actualizada a lo largo del ciclo de vida del sistema y estar disponible para las autoridades competentes a petición.

| Campo | Valor |
|-------|-------|
| Nombre del Sistema AI | `___________________________` |
| Versión / Edición | `___________________________` |
| Organización Proveedor | `___________________________` |
| Propietario de la Documentación | `___________________________` |
| Versión de la Documentación | `___________________________` |
| Última Actualización | `___________________________` |
| Clasificación | Sistema AI de Alto Riesgo (Anexo III, ítem `____`) |

---

### Sección 1 — Descripción General del Sistema AI

*Art. 11 & Anexo IV §1*

#### 1.1 Propósito Intencionado

- [ ] Declaración clara del propósito intencionado del sistema AI
- [ ] Identificación de las personas naturales o grupos de personas a quienes el sistema está destinado a utilizarse
- [ ] Descripción del contexto específico(s) de uso
- [ ] Identificación de los usuarios (operadores/deployers) y las personas afectadas

**Declaración de Propósito Intencionado:**
```
[Describa en lenguaje llano qué hace este sistema AI y para quién]
```

**Usuarios Objetivos:**
```
[Liste tipos de operadores e identifique categorías de usuarios finales]
```

**Contexto de Uso:**
```
[Describa el entorno operativo — sector, geografía, integración en flujo de trabajo]
```

#### 1.2 Categoría del Sistema y Clasificación del Anexo III

- [ ] Confirme qué categoría del Anexo III se aplica (marque todas que apliquen):

| Item del Anexo III | Descripción | Aplica? |
|------------------|-------------|----------|
| 1 | Identificación biométrica y clasificación | ☐ Sí ☐ No |
| 2 | Gestión de infraestructura crítica | ☐ Sí ☐ No |
| 3 | Educación y formación profesional | ☐ Sí ☐ No |
| 4 | Gestión del empleo y los trabajadores | ☐ Sí ☐ No |
| 5 | Acceso a servicios esenciales | ☐ Sí ☐ No |
| 6 | Vigilancia de la ley | ☐ Sí ☐ No |
| 7 | Gestión de migración y asilo | ☐ Sí ☐ No |
| 8 | Administración de justicia | ☐ Sí ☐ No |

**Clasificación Confirmada:** Anexo III, ítem `____`

#### 1.3 Historial de Versiones del Sistema

| Versión | Fecha | Resumen de Cambios | Autor |
|---------|------|--------------------|--------|
| `v___` | `____-__-__` | Lanzamiento inicial | `___` |
| `v___` | `____-__-__` | `________________________` | `___` |

---

### Sección 2 — Descripción Detallada de los Elementos del Sistema

*Anexo IV §2*

#### 2.1 Métodos y Lógica de Desarrollo

- [ ] Descripción de los métodos utilizados para desarrollar el sistema AI
- [ ] Descripción de las especificaciones de diseño (objetivos, clasificación, objetivos de regresión)
- [ ] Descripción de las principales decisiones de diseño y equilibrios realizados
- [ ] Razonamiento para seleccionar la aproximación ML utilizada

**Enfoque de Desarrollo:**
```
[Describa: aprendizaje supervisado/autónomo/aprendizaje por refuerzo, tipo de modelo, framework]
```

**Decisiones de Diseño Clave:**
```
[Documente las principales decisiones arquitectónicas y la razón detrás de ellas]
```

#### 2.2 Arquitectura del Sistema

- [ ] Diagrama de arquitectura general adjunto
- [ ] Descripción de cada componente y su papel
- [ ] Diagrama de flujo de datos mostrando entradas, pasos de procesamiento y salidas
- [ ] Descripción de puntos de integración con sistemas externos

**Referencia del Diagrama de Arquitectura:** `[Adjunte o enlace diagrama — archivo: ___________]`

**Inventario de Componentes:**

| Componente | Papel | Tecnología | Versión |
|-----------|------|------------|---------|
| `___________` | `___________` | `___________` | `___` |
| `___________` | `___________` | `___________` | `___` |
| `___________` | `___________` | `___________` | `___` |

#### 2.3 Recursos Computacionales

- [ ] Descripción de recursos computacionales utilizados

**Salida:**

---

# AI Vendor Due Diligence Questionnaire
_Cuestionario de diligencia debida para proveedores de IA_

> Comprehensive AI vendor due diligence questionnaire with 35+ questions organised by compliance status, data processing, technical specifications, security, support, and contractual terms. Aligned with EU AI Act Article 25.
> Online: https://vorluxai.com/templates/vendor-due-diligence/

> **Disclaimer:** This template is provided for guidance purposes only. It does not constitute legal advice. Organisations should consult qualified legal counsel to ensure compliance with applicable laws and regulations.
>
> *Template provided by VORLUX AI — vorluxai.com*

---

## AI Vendor Due Diligence Questionnaire
### EU AI Act — Article 25 Compliance

**Your Organisation:** _______________
**Vendor / Supplier Name:** _______________
**AI System / Product Evaluated:** _______________
**Version / Release:** _______________
**Questionnaire Reference:** VDDQ-[YYYY]-[NNN]
**Completed by (your side):** _______________
**Completed by (vendor):** _______________
**Date Sent:** _______________
**Date Returned:** _______________
**Evaluation Status:** ☐ Pending ☐ In review ☐ Approved ☐ Rejected ☐ Conditional approval

---

### Instructions for Vendor

Please complete all sections fully. Where a question is not applicable, write **N/A** and provide a brief reason. Attach supporting documentation where indicated. Incomplete submissions will be returned.

Responses should be provided by: **[Name, Role, Email]** at your organisation.

Supporting documents to attach:
- [ ] EU Declaration of Conformity (if applicable)
- [ ] Technical documentation summary
- [ ] Data Processing Agreement (DPA) draft
- [ ] Most recent third-party audit report
- [ ] Sub-processor list
- [ ] Penetration testing summary (last 12 months)
- [ ] SOC 2 or ISO 27001 certificate
- [ ] Incident history summary (last 24 months)

---

### Part 1: Company and Product Overview

| # | Question | Vendor Response |
|---|----------|-----------------|
| 1.1 | Legal name of the company and country of incorporation | |
| 1.2 | Company registration number / tax ID | |
| 1.3 | Describe your company's primary business activity and number of employees | |
| 1.4 | How long has the company been developing or providing AI products? | |
| 1.5 | Provide the name and version of the specific AI product/system being evaluated | |
| 1.6 | Describe the AI system's primary purpose and intended use cases | |
| 1.7 | Describe the AI techniques used (e.g. LLM, supervised ML, computer vision, rules-based) | |
| 1.8 | List the three most similar deployers / customers currently using this system | |

---

### Part 2: EU AI Act Compliance Status

| # | Question | Vendor Response | Evidence Required |
|---|----------|-----------------|-------------------|
| 2.1 | Under the EU AI Act, how do you classify this AI system? (Unacceptable / High-risk / Limited / Minimal) | | Risk classification document |
| 2.2 | If high-risk: have you completed a conformity assessment? Provide reference and date. | | Conformity assessment certificate or reference |
| 2.3 | If high-risk: has a CE marking been applied? Provide the notified body reference if applicable. | | CE declaration |
| 2.4 | Have you completed an EU Declaration of Conformity? If yes, attach. | | DoC document |
| 2.5 | Is the system registered in the EU AI database (where required)? Provide registration number. | | Registration confirmation |
| 2.6 | Have you implemented a Quality Management System (QMS) as required by Article 17? Describe it briefly. | | QMS summary |
| 2.7 | Is your organisation subject to a post-market monitoring plan as required by Article 72? Describe your monitoring activities. | | Post-market monitoring plan |
| 2.8 | Have you received any formal regulatory inquiries, warnings, or sanctions related to this AI system? | | Regulatory correspondence (if any) |
| 2.9 | Do you maintain a log of serious incidents related to this system? Have any been reported to authorities? | | Incident log summary |
| 2.10 | Describe how your system complies with Article 14 (human oversight measures). | | Human oversight documentation |

---

### Part 3: Data Processing and Privacy

| # | Question | Vendor Response | Evidence Required |
|---|----------|-----------------|-------------------|
| 3.1 | What personal data does the AI system process? List categories. | | Data inventory |
| 3.2 | Does the system process any special category data (health, biometrics, race, religion, etc.)? If yes, describe safeguards. | | DPIA or safeguards documentation |
| 3.3 | In which countries / regions is data stored, processed, or transferred? | | Data flow diagram |
| 3.4 | Do any third-country data transfers occur? If yes, what legal mechanism applies (e.g. SCCs, adequacy decision)? | | Transfer mechanism documentation |
| 3.5 | How is personal data used in training the AI model? Describe the training data pipeline. | | Training data governance policy |
| 3.6 | Can you confirm in the contract that our organisation's and our customers' data (prompts, files, outputs) is not used to train or improve your models unless we have agreed to it in writing? (If it is, you act as a controller for that use — GDPR Art. 28(10).) | | Contract clause / DPA |
| 3.7 | Does the model retain or learn from live inference inputs? If yes, explain the mechanism and opt-out options. | | Model update / retention policy |
| 3.8 | What is your data retention policy for inference logs and outputs? | | Data retention schedule |
| 3.9 | Can you provide a Data Processing Agreement (DPA) that meets GDPR Article 28 requirements? | | DPA draft |
| 3.10 | Who are your sub-processors? Are they GDPR-compliant? Provide the sub-processor list. | | Sub-processor list + compliance confirmation |

---

### Part 4: Technical Specifications and Model Performance

| # | Question | Vendor Response | Evidence Required |
|---|----------|-----------------|-------------------|
| 4.1 | What performance benchmarks have been conducted? Provide accuracy, precision, recall, F1, or relevant metrics. | | Model evaluation report |
| 4.2 | On what dataset(s) was the model trained? Describe data sources, size, and vintage. | | Training data card |
| 4.3 | Has the model been tested for bias across protected characteristics (gender, age, ethnicity, disability)? Provide results. | | Bias evaluation report |
| 4.4 | Describe known limitations and failure modes of the system. | | Technical documentation |
| 4.5 | How often is the model retrained or updated? Describe the update process and version control. | | Model update policy |
| 4.6 | How do you detect and mitigate data drift or model degradation in production? | | Monitoring architecture document |
| 4.7 | Does the system produce explainable outputs? Can it generate reasons for individual decisions? | | Explainability documentation |
| 4.8 | Describe the system's integration architecture (API, SDK, embedded model, etc.) and relevant API documentation. | | API / integration docs |
| 4.9 | What are the system's SLA guarantees (uptime, response time, throughput)? | | SLA document |
| 4.10 | What is the process for handling performance degradation below agreed thresholds? | | Escalation / SLA breach process |

---

### Part 5: Information Security

| # | Question | Vendor Response | Evidence Required |
|---|----------|-----------------|-------------------|
| 5.1 | Do you hold ISO 27001 certification or equivalent? Provide certificate and scope. | | ISO 27001 certificate |
| 5.2 | Have you completed a SOC 2 Type II audit in the last 12 months? Share the report summary. | | SOC 2 summary |
| 5.3 | Describe your penetration testing programme. When was the last test? Who conducted it? | | Pen test summary |
| 5.4 | How is data encrypted in transit and at rest? Specify encryption standards used. | | Security architecture document |
| 5.5 | How is access to the AI system and its underlying data controlled? Describe your IAM approach. | | IAM policy |
| 5.6 | Have you assessed the system against adversarial attacks (prompt injection, model inversion, data poisoning)? | | Adversarial testing documentation |
| 5.7 | Describe your vulnerability disclosure and patch management process. | | Security policy |
| 5.8 | What is your security incident response time (detection to containment for critical issues)? | | Incident response SLA |
| 5.9 | Do you conduct background checks on employees with access to production systems and customer data? | | HR security policy summary |
| 5.10 | Provide your most recent security breach history summary (last 3 years). | | Incident summary |

---

### Part 6: Support and Service Continuity

| # | Question | Vendor Response | Evidence Required |
|---|----------|-----------------|-------------------|
| 6.1 | What support tiers do you offer and what are the response times for each? | | Support SLA |
| 6.2 | Do you offer a named account or technical success manager for enterprise customers? | | |
| 6.3 | What is your product roadmap for this system over the next 12–24 months? | | Roadmap document (NDA may apply) |
| 6.4 | What is your end-of-life / deprecation policy? How much notice will be given? | | Product lifecycle policy |
| 6.5 | Describe your business continuity and disaster recovery plan for this product. | | BC/DR plan summary |
| 6.6 | What is your Recovery Time Objective (RTO) and Recovery Point Objective (RPO)? | | BC/DR plan |
| 6.7 | What is your process for notifying customers of planned and unplanned downtime? | | Incident and maintenance notification process |

---

### Part 7: Contractual and Legal Terms

| # | Question | Vendor Response |
|---|----------|-----------------|
| 7.1 | Are you willing to include EU AI Act compliance obligations in the contract? | ☐ Yes  ☐ No  ☐ Subject to negotiation |
| 7.2 | Do your terms include liability provisions for harm caused by AI system failure or error? | ☐ Yes  ☐ No  ☐ Partial |
| 7.3 | Are you willing to include audit rights for our organisation or regulators? | ☐ Yes  ☐ No  ☐ Subject to scope agreement |
| 7.4 | Do you offer an escrow arrangement for the AI model or system in the event of business failure? | ☐ Yes  ☐ No  ☐ On request |
| 7.5 | What governing law and jurisdiction apply to your contracts? Are EU/Spanish courts available? | |
| 7.6 | What are your data portability and exit provisions? Can we export our data and model outputs on termination? | |
| 7.7 | Do you have professional indemnity and cyber liability insurance? Provide limits. | |
| 7.8 | Are there any open legal disputes, regulatory investigations, or insolvency proceedings involving your company? | |

---

### Part 8: Ethical AI and Governance

| # | Question | Vendor Response | Evidence Required |
|---|----------|-----------------|-------------------|
| 8.1 | Does your company have an AI Ethics policy or code of conduct? Attach it. | | Ethics policy |
| 8.2 | Do you have a dedicated AI ethics board, committee, or responsible AI team? | | Governance structure |
| 8.3 | Have you committed to any external AI ethics frameworks (e.g. NIST AI RMF, IEEE, Partnership on AI)? | | |
| 8.4 | How do you engage with affected communities or civil society in the design of your AI systems? | | |
| 8.5 | Describe any measures taken to ensure the environmental sustainability of your AI systems (energy use, carbon footprint). | | |

---

### Evaluation Scoring Rubric

Use this rubric to score vendor responses after review:

| Section | Max Score | Score Awarded | Notes |
|---------|-----------|---------------|-------|
| Part 1: Company Overview | 10 | | |
| Part 2: EU AI Act Compliance | 30 | | |
| Part 3: Data Processing & Privacy | 25 | | |
| Part 4: Technical Specifications | 20 | | |
| Part 5: Information Security | 20 | | |
| Part 6: Support & Continuity | 15 | | |
| Part 7: Contractual Terms | 15 | | |
| Part 8: Ethical AI & Governance | 10 | | |
| **TOTAL** | **145** | | |

**Scoring Guide:**
| Total Score | Recommendation |
|-------------|----------------|
| 130–145 | Strong approval — proceed with standard contractual safeguards |
| 110–129 | Conditional approval — resolve flagged gaps before contract |
| 85–109 | High-risk — significant remediation required before approval |
| Below 85 | Do not approve — critical gaps present |

---

### Red Flags Log

Document any responses that require immediate escalation or disqualification:

| # | Question Reference | Red Flag Description | Escalated to | Resolution |
|---|-------------------|---------------------|-------------|------------|
| | | | | |
| | | | | |

---

### Final Assessment

**Overall Score:** _____ / 145
**Recommendation:** ☐ Approve  ☐ Conditional Approval  ☐ Reject

**Summary of Key Findings:**

_______________________________________________________________________________
_______________________________________________________________________________

**Conditions for Approval (if conditional):**

1. _______________
2. _______________
3. _______________

**Completed by:** _______________  **Date:** _______________
**Reviewed by (Legal):** _______________  **Date:** _______________
**Approved by:** _______________  **Date:** _______________

---

*Template provided by VORLUX AI | vorluxai.com*
*Version 1.0 — April 2026 | EU AI Act Article 25 compliant template*
*This is guidance only, not legal advice. Consult qualified legal counsel for your specific situation.*

---

### Versión Española

**Aviso importante:** Este modelo se proporciona solo con fines de orientación. No constituye asesoramiento legal. Las organizaciones deben consultar a un abogado calificado para asegurarse de que cumplan con las leyes y regulaciones aplicables.

---

## Cuestionario de Diligencia sobre Vendedores de Inteligencia Artificial
### Cumplimiento del Reglamento UE AI — Artículo 25

**Su Organización:** _______________
**Nombre del proveedor / suministrador:** _______________
**Sistema o producto de IA evaluado:** _______________
**Versión / Lanzamiento:** _______________
**Referencia al cuestionario:** VDDQ-[YYYY]-[NNN]
**Completado por (su lado):** _______________
**Completado por (proveedor):** _______________
**Fecha de envío:** _______________
**Fecha de devolución:** _______________
**Estado de la evaluación:** ☐ Pendiente ☐ En revisión ☐ Aprobado ☐ Rechazado ☐ Aprobación condicional

---

### Instrucciones para el proveedor

Por favor, complete todas las secciones. Si una pregunta no es aplicable, escriba **N/A** y proporcione una breve razón. Adjunte documentos de apoyo donde sea necesario. Las presentaciones incompletas serán devueltas.

Las respuestas deben proporcionarse por: **[Nombre, Cargo, Correo electrónico]** en su organización.

Documentos de apoyo para adjuntar:
- [ ] Declaración de conformidad UE (si es aplicable)
- [ ] Resumen de la documentación técnica
- [ ] Acuerdo de procesamiento de datos (DPA) borrador
- [ ] Informe de auditoría de terceros más reciente
- [ ] Lista de subprocesadores
- [ ] Resumen del análisis de penetración (últimos 12 meses)
- [ ] Certificado SOC 2 o ISO 27001
- [ ] Resumen de la historia de incidentes (últimos 24 meses)

---

### Parte 1: Visión general de la empresa y el producto

| # | Pregunta | Respuesta del proveedor |
|---|----------|-----------------|
| 1.1 | Nombre legal de la empresa y país de incorporación | |
| 1.2 | Número de registro de la empresa / ID de impuestos | |
| 1.3 | Describa la actividad principal de la empresa y el número de empleados | |
| 1.4 | ¿Cuánto tiempo ha estado desarrollando o proporcionando productos de IA la empresa? | |
| 1.5 | Proporcione el nombre y versión del producto específico de IA que se está evaluando | |
| 1.6 | Describa el propósito principal del sistema de IA y los casos de uso previstos | |
| 1.7 | Describa las técnicas de IA utilizadas (por ejemplo, LLM, ML supervisado, visión por computadora, reglas basadas) | |
| 1.8 | Enumere a los tres clientes o usuarios actuales más similares que están utilizando este sistema | |

---

### Parte 2: Estado de cumplimiento del Reglamento UE AI

| # | Pregunta | Respuesta del proveedor | Documentación requerida |
|---|----------|-----------------|-------------------|
| 2.1 | Bajo el Reglamento UE AI, ¿cómo clasifica este sistema de IA? (No aceptable / Alto riesgo / Limitado / Mínimo) | | Documento de clasificación de riesgos |
| 2.2 | Si alto riesgo: ¿ha completado una evaluación de conformidad? Proporcione la referencia y fecha. | | Certificado de evaluación de conformidad o referencia |
| 2.3 | Si alto riesgo: ¿se ha aplicado un marcado CE? Proporcione la referencia del organismo notificado si es aplicable. | | Declaración de CE |
| 2.4 | ¿Ha completado una Declaración de Conformidad UE? Si sí, adjunte. | | Documento DoC |
| 2.5 | ¿Está el sistema registrado en la base de datos de IA UE (si es necesario)? Proporcione el número de registro. | | Confirmación de registro |
| 2.6 | ¿Ha implementado un Sistema de Gestión de la Calidad (SGC) según lo requerido por el artículo 17? Describalo brevemente. | | Resumen del SGC |
| 2.7 | ¿Está su organización sujeta a un plan de monitoreo posterior al mercado según lo requerido por el artículo 72? Describe sus actividades de monitoreo. | | Plan de monitoreo posterior al mercado |
| 2.8 | ¿Ha recibido alguna consulta, advertencia o sanción regulatoria formal relacionada con este sistema de IA? | | Correspondencia regulatoria (si es aplicable) |
| 2.9 | ¿Mantiene un registro de incidentes graves relacionados con este sistema? ¿Algunos han sido informados a las autoridades? | | Resumen del registro de incidentes |
| 2.10 | Describa cómo su sistema cumple con el artículo 14 (medidas de supervisión humana). | | Documentación de supervisión humana |

---

### Parte 3: Procesamiento de datos y privacidad

| # | Pregunta | Respuesta del proveedor | Documentación requerida |
|---|----------|-----------------|-------------------|
| 3.1 | ¿Qué datos personales procesa el sistema de IA? Enumere las categorías...
