Skip to content
SimpleAct Logo

Features in detail

How SimpleAct works

Step by step through all features — from capturing systems, through risk assessment, to the finished audit report.

How it works · All modules · Operational flow · Real-world examples

How it works

EU AI Act compliance in 5 steps

From capture to auditable evidence – and beyond: governance workflows, runtime monitoring, and incident management for your day-to-day AI operations.

  1. 1

    Login and setup

    Sign up and enter basic company data and the person responsible for your AI compliance management.

    • Quick registration and setup
    • Enter company data
    • Designate responsible person
  2. 2

    Capture AI systems

    Enter all AI tools in use: ChatGPT, VS Code AI, Canva AI, internal applications. Capture takes only 1–2 minutes per system.

    • Simple capture of name, provider, and purpose
    • Document scope of use (internal/external)
    • Capture takes only 1–2 minutes per system
  3. 3

    Assess risk

    Answer guided questions about your AI system. Based on your answers, the system automatically determines the appropriate risk class – no legal expertise required.

    • Guided questions on risk factors and context
    • Automatic classification under EU AI Act
    • Versioning for repeat assessments
    • No legal interpretation required
  4. 4

    Complete compliance checklist

    Depending on risk class, a specific compliance checklist is shown: Minimal Risk (basic documentation), Limited Risk, High Risk. Each checklist includes EU AI Act article references.

    • Minimal Risk: Basic documentation and privacy alignment
    • Limited Risk: Transparency obligations and content labelling
    • High Risk: Full checklist with Art. 9–14 references
    • Additional documentation for high-risk systems possible
  5. 5

    Operational governance

    After setup, the real governance begins: dashboard, audit playbook, incident management with CAPA, runtime monitoring with signals and change register, assurance workflows with bias findings and validation suites – all connected, all audit-ready.

    • Dashboard overview of all AI systems and status
    • Incident management: CAPA, re-assessment triggers, authority responses
    • Runtime monitoring: signals, change register, observability profiles
    • Assurance: bias findings, validation suites, human oversight
    • Integrations: Jira, Teams, ServiceNow, API keys, webhooks

Pilot project: 6 AI systems captured and assessed in

about 4 hours

Quick onboarding – then governance, monitoring, and incident management run permanently as your AI operating system

Get started

Sample report

The compliance report in detail

SimpleAct turns your AI inventory into a compliance report showing your implementation status: risk classes, checklists, open points and audit trail. Your evidence status for internal reviews and regulator enquiries is always at hand.

  • PDF export at the push of a button
  • Timestamps & audit trail
  • For internal reviews and regulator enquiries
Create your own report

Sample report with fictitious data · The report documents your implementation status and does not replace a conformity assessment.

Sample GmbHSAMPLE

EU AI Act
Compliance report (sample)

System inventory, high-risk documentation overview and audit trail

Created: 2026-04-18 · Version: v12 · All systems · Sample GmbH

5
Total systems
1
High risk
1
Limited risk
3
Minimal risk
4
Go-live ready
2
Open points
01

Executive Summary

!Implementation status: 2 open points for 1 high-risk system
  • 4 of 5 systems are go-live ready.
  • Candidate Matching (high risk): checklist 4/6, Art. 13 and Art. 14 still open.
  • Risk classification documented for all 5 systems.
  • Changes logged with timestamps in the audit trail.
04

System Inventory

01
GPT-4 AssistantOpenAI
Minimal riskGo-live ready
02
Document AnalysisMicrosoft
Minimal riskGo-live ready
03
Candidate MatchingInternal
High riskIn review
04
Customer Service ChatbotThird party
Limited riskGo-live ready
05
Invoice RecognitionInternal
Minimal riskGo-live ready
Candidate Matching · Checklist 4/6 done67% complete
✓Art. 9Risk management system
✓Art. 10Data governance
✓Art. 11Technical documentation
✓Art. 12Logging
○Art. 13Transparency and user info
○Art. 14Human oversight

Product modules

The modules behind compliance operations

The platform exposes the work already present in the product: from legal logic through governance and audit playbook to incidents, runtime signals, assurance workflows, and API connectivity.

Legal logic

SimpleAct derives role, deployment context, and review cadence per AI system. Teams see early which obligations apply and when a system must be reviewed again.

Open legal logic

Key capabilities

  • Review owner and cadence
  • Role model per system
  • Traceable obligation profile

SimpleAct Operating Model

From inventory to incident, everything stays in one system.

That is what separates SimpleAct from checklist-only or register-only tools. The platform connects assessment, control, operations, and evidence into one visible workflow.

  • Owner, reviewer, approver
  • Runtime signals and incidents
  • Bias findings and validation suites
  • API keys, webhooks, and exports

Connected inside the product

How records become an operational compliance system

SimpleAct connects obligations, tasks, evidence, incidents, runtime signals, and integrations. Teams work inside one connected flow instead of isolated tools.

Operational product flow

How SimpleAct connects obligations, evidence, and follow-up work.

Inside the product, legal logic, governance, audit playbook, incident management, and runtime monitoring work together. That keeps it visible per AI system what has been reviewed, what remains open, and which actions come next.

  • Clear view of status, open points, and responsibilities
  • Evidence, reviews, and approvals stay attached to the system context
  • Incidents, changes, and monitoring signals trigger follow-up work in the same flow

Step 1

Inventory and risk classification

Teams capture AI systems, place them into business context, and create the base layer for everything that follows.

Step 2

Legal logic and review cadence

SimpleAct keeps role, recurring review questions, and review ownership visible per system.

Step 3

Governance and audit playbook

Owners, reviewers, open points, missing evidence, and approvals stay visible as one operational workflow.

Step 4

Runtime, incident, and CAPA

After rollout, runtime signals, incidents, changes, and CAPA measures stay attached to the affected system instead of separate ticket silos.

Operational Artifacts

Concrete artifacts teams can maintain inside SimpleAct

More than documentation

Evidence register
Files, links, notes, and approvals per system or topic.
Dataset register
Version, lineage, bias findings, and personal-data relation.
Validation suites
Benchmarks, revalidation triggers, red teaming, and shadow mode.
Observability profiles
Metrics, alert thresholds, sources, dashboard URL, and on-call roles.
Authority packs
Conformity, CE, EU database, contacts, and supporting artifacts.
API & webhooks
Connect governance, incident, and monitoring flows into external systems.

Depth from the app

What teams actually operate in SimpleAct

This content is not based on a theoretical roadmap. It follows modules, forms, and workflows that already exist in the product.

Governance and approvals

Owner, reviewer, approver, minimum approved evidence, and finalization gates per subject.

  • Evidence coverage visibility
  • Review status per object
  • Approval chain for FINAL

Assurance and high-risk work

Dataset register, bias findings, human oversight, validation suites, pipeline gates, authority pack, and registry.

  • Bias and lineage in dataset context
  • Validation and red teaming
  • Authority cases and CE/conformity state

Runtime and incident loop

Runtime signals, incident records, reassessment triggers, change register, CAPA, and compliance gate form one operating chain.

  • Runtime signal -> incident
  • Change -> reassessment
  • CAPA with owner and due date

Integrations and external systems

API keys, webhooks, ingestion endpoints, plus Jira, Teams, and ServiceNow connectivity for enterprise setups.

  • OpenAPI and events
  • Inbound ingestion for monitoring
  • Enterprise procurement material

FAQ

Frequently asked questions

SimpleAct classifies each AI system via a structured questionnaire that covers high-risk indicators (e.g. Annex III areas), transparency obligations under Art. 50 and the deployment context in turn. The result is a rule-based, traceable classification — not a black box.
Yes. Audit-ready reports can be exported per AI system or for the entire inventory — including risk classification, legal-logic outcome, and change history.
SimpleAct connects to Jira, Microsoft Teams, and ServiceNow so incidents and CAPA actions land directly in your existing team tools instead of a separate compliance silo.
Incidents are captured, linked to the affected AI system, prioritised, and tracked with CAPA actions — fully documented in the audit trail.

More questions? We're happy to help. Send email · Get started

Operational flow

How SimpleAct shows that obligations become real follow-up work

Not just inventory and export: the platform connects legal logic, governance, audit playbooks, runtime signals, and incidents into one operating flow.

Onboard a new AI system

A new system moves from classification to approval through one connected product flow.

  • Create inventory and risk context
  • Carry over obligations and review cadence from legal logic
  • Close articles, evidence, and approvals in one flow

Control changes and reassessments

Model changes and runtime signals do not stay isolated. They create review work and actions.

  • Capture the change or signal
  • Make review need and owners visible
  • Approve again only with refreshed evidence

Close incidents through evidence

Incidents are closed through CAPA, reassessment, and authority packs in the same system.

  • Capture severity and context
  • Trigger CAPA and compliance gate
  • Secure a defensible closure state

The detailed proof belongs on a dedicated page.

Anyone who wants the deeper explanation of what defines an AI governance system can open the full positioning and process page there.