Validation build: prices are simulated and no cover is in force. What that means

Obligations · what the law already asks for

The law already asks for the record. It does not say how you will prove it.

Five EU laws ask a regulated firm to do something, and later to show it did: specify a customer’s needs, explain a recommendation, keep an AI system’s logs, record an incident. Each lets you keep that record in your own systems. None says how you will show, years later, that the record you produce is the one that existed at the time. Every system that stores a record can also edit it, so on the day a record is disputed, that is the question that decides.

This page sets out, for each law, what its articles ask, when the record gets tested, and what a record sealed in the evidence log adds. The summaries are ours and the linked EUR-Lex text is the law. It is orientation, not legal advice: whether an article applies to you, and from when, is yours to establish.

Five laws, one question

LawWhen the record is testedWhat a sealed record adds
Insurance Distribution DirectiveA complaint to the insurer or the ombudsman, a claim refused because the cover did not match the need, a supervisor's inspection.The demands-and-needs note and the recommendation are sealed when they are written, so the note you produce is shown to be the one that existed before the contract, not one written after the complaint.
MiFID IIA client disputes the advice after a loss; the supervisor asks you to reconstitute each stage of it.A correction is a new sealed record that names the record it corrects, and the earlier one stays, so what was changed and what stood before can be ascertained, as Article 72(1) describes.
EU AI ActA person affected by a decision asks for an explanation; a market surveillance authority asks for the logs.Each log segment is sealed as it is written, with its event count and the segment before it, so a shortened, edited or missing segment shows.
GDPR Article 22A person contests an automated decision; the data protection authority asks you to demonstrate compliance.The basis of the decision, and any human review of it, are shown to have been recorded at the time, while the record, which holds personal data, stays with you and erasable.
DORAYour authority reviews a major incident; an auditor compares the report you hold with the report you sent.The incident record and each report are sealed when they are made, so the report you hold today is shown to be the one you held on the day you submitted it.

Insurance Distribution Directive

Who it concerns
Insurance distributors: brokers, agents, and insurers selling directly. Whether it applies to you, and from when, is yours to establish from the text.
When it is tested
A complaint to the insurer or the ombudsman, a claim refused because the cover did not match the need, a supervisor's inspection.
What a sealed record adds
The demands-and-needs note and the recommendation are sealed when they are written, so the note you produce is shown to be the one that existed before the contract, not one written after the complaint.
How long to keep it
This pack does not state how long to keep these records. Check the period that applies to you with your supervisor or your professional federation. In Belgium the directive is transposed by the Act of 4 April 2014 on insurance, and the FSMA supervises its conduct rules.
What to record
The Insurance Distribution Directive pack: idd.demands-needs, idd.recommendation, idd.ipid-provided
Article (links to the text on EUR-Lex)What it asks (our summary; the linked text is the law)
Directive (EU) 2016/97, Article 20(1), first subparagraphBefore a contract is concluded, specify the customer's demands and needs on the basis of information obtained from the customer, and give objective information about the product in a comprehensible form.
Directive (EU) 2016/97, Article 20(1), second subparagraphAny contract proposed must be consistent with the customer's insurance demands and needs.
Directive (EU) 2016/97, Article 20(1), third subparagraphWhere advice is given before a specific contract is concluded, give the customer a personalised recommendation explaining why a particular product would best meet their demands and needs.
Directive (EU) 2016/97, Article 20, paragraphs 4 to 9For non-life products, give the product information by way of the standardised insurance product information document (IPID).
Directive (EU) 2016/97, Article 23How information reaches the customer: on paper, or on another durable medium or a website where the conditions for that are met.

MiFID II

Who it concerns
Investment firms that give investment advice or manage portfolios. Whether it applies to you, and from when, is yours to establish from the text.
When it is tested
A client disputes the advice after a loss; the supervisor asks you to reconstitute each stage of it.
What a sealed record adds
A correction is a new sealed record that names the record it corrects, and the earlier one stays, so what was changed and what stood before can be ascertained, as Article 72(1) describes.
How long to keep it
This pack does not state how long to keep these records. Check the period that applies to you with your competent authority; in Belgium the FSMA supervises these conduct rules.
What to record
The MiFID II pack: mifid.suitability, mifid.suitability-statement
Article (links to the text on EUR-Lex)What it asks (our summary; the linked text is the law)
Directive 2014/65/EU, Article 25(2)When providing investment advice or portfolio management, obtain the information needed on the client's knowledge and experience in the relevant investment field, financial situation including ability to bear losses, and investment objectives including risk tolerance, so as to recommend what is suitable.
Directive 2014/65/EU, Article 25(6)When providing investment advice, before the transaction is made, give the retail client a statement on suitability in a durable medium, specifying the advice given and how it meets the client's preferences, objectives and other characteristics.
Commission Delegated Regulation (EU) 2017/565, Article 54How the suitability assessment is carried out, and what the suitability report must contain.
Commission Delegated Regulation (EU) 2017/565, Article 72(1)Records are kept so the competent authority can access them readily and reconstitute each key stage, so any corrections or amendments and the contents before them can be easily ascertained, and so they cannot otherwise be manipulated or altered.

EU AI Act

Who it concerns
Providers and deployers of high-risk AI systems, which include risk assessment and pricing for natural persons in life and health insurance, and assessing the creditworthiness of natural persons (Annex III, point 5). Whether it applies to you, and from when, is yours to establish from the text.
When it is tested
A person affected by a decision asks for an explanation; a market surveillance authority asks for the logs.
What a sealed record adds
Each log segment is sealed as it is written, with its event count and the segment before it, so a shortened, edited or missing segment shows.
How long to keep it
Articles 19(1) and 26(6) set a minimum of six months for the logs they cover, unless other law provides otherwise; this pack does not decide your period. Whether your system is high-risk, and from when these obligations apply to it, is yours to establish from the Regulation.
What to record
The EU AI Act pack: ai.log-segment, ai.decision, ai.oversight
Article (links to the text on EUR-Lex)What it asks (our summary; the linked text is the law)
Regulation (EU) 2024/1689, Article 12(1)High-risk AI systems must technically allow for the automatic recording of events (logs) over the lifetime of the system.
Regulation (EU) 2024/1689, Article 12(2)Logging must enable recording of events relevant for identifying situations that may result in the system presenting a risk or in a substantial modification, for post-market monitoring (Article 72), and for monitoring the system's operation (Article 26(5)).
Regulation (EU) 2024/1689, Article 14(4)(d)The people overseeing the system must be able to decide, in any particular situation, not to use it or to disregard, override or reverse its output.
Regulation (EU) 2024/1689, Article 19(1)Providers keep the logs their high-risk AI systems generate automatically, to the extent the logs are under their control, for a period appropriate to the system's intended purpose and of at least six months, unless Union or national law, in particular on personal data, provides otherwise.
Regulation (EU) 2024/1689, Article 19(2)Providers that are financial institutions subject to internal-governance requirements under Union financial services law keep those logs as part of the documentation kept under that law.
Regulation (EU) 2024/1689, Article 26(6)Deployers keep the logs the system generates automatically, to the extent the logs are under their control, for a period appropriate to the system's intended purpose and of at least six months, unless applicable law provides otherwise.
Regulation (EU) 2024/1689, Article 86(1)A person affected by a decision a deployer takes on the basis of output from a high-risk AI system listed in Annex III (other than point 2), with legal or similarly significant adverse effects, may obtain clear and meaningful explanations of the role of the AI system in the decision and of the main elements of the decision taken.

GDPR Article 22

Who it concerns
Any controller whose decisions about people are made, wholly or partly, by automated processing. Whether it applies to you, and from when, is yours to establish from the text.
When it is tested
A person contests an automated decision; the data protection authority asks you to demonstrate compliance.
What a sealed record adds
The basis of the decision, and any human review of it, are shown to have been recorded at the time, while the record, which holds personal data, stays with you and erasable.
How long to keep it
This pack does not state how long to keep these records. The records are yours and hold personal data under your control: keep them no longer than your purposes need, and they stay erasable because they never leave you. Only a salted digest is in the log, and without the record and its salt nobody, including us, can link it to anyone.
What to record
The GDPR Article 22 pack: gdpr.automated-decision, gdpr.human-intervention
Article (links to the text on EUR-Lex)What it asks (our summary; the linked text is the law)
Regulation (EU) 2016/679, Article 5(2)The controller is responsible for, and must be able to demonstrate, compliance with the principles in Article 5(1).
Regulation (EU) 2016/679, Article 13(2)(f) and Article 14(2)(g)Inform the person of the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4), and at least in those cases give meaningful information about the logic involved and the significance and envisaged consequences.
Regulation (EU) 2016/679, Article 22(1)A person has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
Regulation (EU) 2016/679, Article 22(2)That does not apply where the decision is necessary for entering into or performing a contract, is authorised by Union or Member State law with suitable safeguards, or is based on the person's explicit consent.
Regulation (EU) 2016/679, Article 22(3)Where the contract or explicit-consent exception applies, the controller implements suitable measures, at least the right to obtain human intervention, to express one's point of view and to contest the decision.

DORA

Who it concerns
Financial entities within DORA's scope, including insurers and insurance intermediaries, other than intermediaries that are micro, small or medium-sized enterprises (Article 2(3)). Whether it applies to you, and from when, is yours to establish from the text.
When it is tested
Your authority reviews a major incident; an auditor compares the report you hold with the report you sent.
What a sealed record adds
The incident record and each report are sealed when they are made, so the report you hold today is shown to be the one you held on the day you submitted it.
How long to keep it
This pack does not state how long to keep these records. Check the period with your competent authority.
What to record
The DORA pack: dora.incident, dora.incident-report, dora.register-snapshot
Article (links to the text on EUR-Lex)What it asks (our summary; the linked text is the law)
Regulation (EU) 2022/2554, Article 17(1)Define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents.
Regulation (EU) 2022/2554, Article 17(2)Record all ICT-related incidents and significant cyber threats, with procedures for consistent monitoring, handling and follow-up so root causes are identified, documented and addressed.
Regulation (EU) 2022/2554, Article 18Classify ICT-related incidents and determine their impact against the criteria the article sets.
Regulation (EU) 2022/2554, Article 19(4)For a major ICT-related incident, submit to the competent authority an initial notification, an intermediate report and a final report.
Regulation (EU) 2022/2554, Article 28(3)Maintain and update a register of information on all contractual arrangements for ICT services provided by ICT third-party service providers.

What no law requires, and what the log does not do

No law names a product
None of these laws requires RiskRouter or any other product. You can meet every duty on this page without us. What we offer is a way to show you met it that does not depend on anyone’s word, including ours.
It proves when, not whether
A sealed record is shown to have existed, unchanged, no later than a signed and anchored head. The log does not know what the record says, so it cannot make a record correct, complete or sufficient, and recording something does not make anyone compliant.
The record stays with you
Only a salted fingerprint of each record is sent. The record, and any personal data in it, never reach us, so it stays yours to keep and to erase. Data protection
It outlives us
Every proof checks offline with the open-source verifier, against keys and anchors that are published. Continuity

To start, take a sandbox key and record a fingerprint in a few minutes, or read what to record, rule by rule.