Obligations · what the law already asks for
The law already asks for the record. It does not say how you will prove it.
Five EU laws ask a regulated firm to do something, and later to show it did: specify a customer’s needs, explain a recommendation, keep an AI system’s logs, record an incident. Each lets you keep that record in your own systems. None says how you will show, years later, that the record you produce is the one that existed at the time. Every system that stores a record can also edit it, so on the day a record is disputed, that is the question that decides.
This page sets out, for each law, what its articles ask, when the record gets tested, and what a record sealed in the evidence log adds. The summaries are ours and the linked EUR-Lex text is the law. It is orientation, not legal advice: whether an article applies to you, and from when, is yours to establish.
Five laws, one question
| Law | When the record is tested | What a sealed record adds |
|---|---|---|
| Insurance Distribution Directive | A complaint to the insurer or the ombudsman, a claim refused because the cover did not match the need, a supervisor's inspection. | The demands-and-needs note and the recommendation are sealed when they are written, so the note you produce is shown to be the one that existed before the contract, not one written after the complaint. |
| MiFID II | A client disputes the advice after a loss; the supervisor asks you to reconstitute each stage of it. | A correction is a new sealed record that names the record it corrects, and the earlier one stays, so what was changed and what stood before can be ascertained, as Article 72(1) describes. |
| EU AI Act | A person affected by a decision asks for an explanation; a market surveillance authority asks for the logs. | Each log segment is sealed as it is written, with its event count and the segment before it, so a shortened, edited or missing segment shows. |
| GDPR Article 22 | A person contests an automated decision; the data protection authority asks you to demonstrate compliance. | The basis of the decision, and any human review of it, are shown to have been recorded at the time, while the record, which holds personal data, stays with you and erasable. |
| DORA | Your authority reviews a major incident; an auditor compares the report you hold with the report you sent. | The incident record and each report are sealed when they are made, so the report you hold today is shown to be the one you held on the day you submitted it. |
Insurance Distribution Directive
- Who it concerns
- Insurance distributors: brokers, agents, and insurers selling directly. Whether it applies to you, and from when, is yours to establish from the text.
- When it is tested
- A complaint to the insurer or the ombudsman, a claim refused because the cover did not match the need, a supervisor's inspection.
- What a sealed record adds
- The demands-and-needs note and the recommendation are sealed when they are written, so the note you produce is shown to be the one that existed before the contract, not one written after the complaint.
- How long to keep it
- This pack does not state how long to keep these records. Check the period that applies to you with your supervisor or your professional federation. In Belgium the directive is transposed by the Act of 4 April 2014 on insurance, and the FSMA supervises its conduct rules.
- What to record
- The Insurance Distribution Directive pack:
idd.demands-needs,idd.recommendation,idd.ipid-provided
| Article (links to the text on EUR-Lex) | What it asks (our summary; the linked text is the law) |
|---|---|
| Directive (EU) 2016/97, Article 20(1), first subparagraph | Before a contract is concluded, specify the customer's demands and needs on the basis of information obtained from the customer, and give objective information about the product in a comprehensible form. |
| Directive (EU) 2016/97, Article 20(1), second subparagraph | Any contract proposed must be consistent with the customer's insurance demands and needs. |
| Directive (EU) 2016/97, Article 20(1), third subparagraph | Where advice is given before a specific contract is concluded, give the customer a personalised recommendation explaining why a particular product would best meet their demands and needs. |
| Directive (EU) 2016/97, Article 20, paragraphs 4 to 9 | For non-life products, give the product information by way of the standardised insurance product information document (IPID). |
| Directive (EU) 2016/97, Article 23 | How information reaches the customer: on paper, or on another durable medium or a website where the conditions for that are met. |
MiFID II
- Who it concerns
- Investment firms that give investment advice or manage portfolios. Whether it applies to you, and from when, is yours to establish from the text.
- When it is tested
- A client disputes the advice after a loss; the supervisor asks you to reconstitute each stage of it.
- What a sealed record adds
- A correction is a new sealed record that names the record it corrects, and the earlier one stays, so what was changed and what stood before can be ascertained, as Article 72(1) describes.
- How long to keep it
- This pack does not state how long to keep these records. Check the period that applies to you with your competent authority; in Belgium the FSMA supervises these conduct rules.
- What to record
- The MiFID II pack:
mifid.suitability,mifid.suitability-statement
| Article (links to the text on EUR-Lex) | What it asks (our summary; the linked text is the law) |
|---|---|
| Directive 2014/65/EU, Article 25(2) | When providing investment advice or portfolio management, obtain the information needed on the client's knowledge and experience in the relevant investment field, financial situation including ability to bear losses, and investment objectives including risk tolerance, so as to recommend what is suitable. |
| Directive 2014/65/EU, Article 25(6) | When providing investment advice, before the transaction is made, give the retail client a statement on suitability in a durable medium, specifying the advice given and how it meets the client's preferences, objectives and other characteristics. |
| Commission Delegated Regulation (EU) 2017/565, Article 54 | How the suitability assessment is carried out, and what the suitability report must contain. |
| Commission Delegated Regulation (EU) 2017/565, Article 72(1) | Records are kept so the competent authority can access them readily and reconstitute each key stage, so any corrections or amendments and the contents before them can be easily ascertained, and so they cannot otherwise be manipulated or altered. |
EU AI Act
- Who it concerns
- Providers and deployers of high-risk AI systems, which include risk assessment and pricing for natural persons in life and health insurance, and assessing the creditworthiness of natural persons (Annex III, point 5). Whether it applies to you, and from when, is yours to establish from the text.
- When it is tested
- A person affected by a decision asks for an explanation; a market surveillance authority asks for the logs.
- What a sealed record adds
- Each log segment is sealed as it is written, with its event count and the segment before it, so a shortened, edited or missing segment shows.
- How long to keep it
- Articles 19(1) and 26(6) set a minimum of six months for the logs they cover, unless other law provides otherwise; this pack does not decide your period. Whether your system is high-risk, and from when these obligations apply to it, is yours to establish from the Regulation.
- What to record
- The EU AI Act pack:
ai.log-segment,ai.decision,ai.oversight
| Article (links to the text on EUR-Lex) | What it asks (our summary; the linked text is the law) |
|---|---|
| Regulation (EU) 2024/1689, Article 12(1) | High-risk AI systems must technically allow for the automatic recording of events (logs) over the lifetime of the system. |
| Regulation (EU) 2024/1689, Article 12(2) | Logging must enable recording of events relevant for identifying situations that may result in the system presenting a risk or in a substantial modification, for post-market monitoring (Article 72), and for monitoring the system's operation (Article 26(5)). |
| Regulation (EU) 2024/1689, Article 14(4)(d) | The people overseeing the system must be able to decide, in any particular situation, not to use it or to disregard, override or reverse its output. |
| Regulation (EU) 2024/1689, Article 19(1) | Providers keep the logs their high-risk AI systems generate automatically, to the extent the logs are under their control, for a period appropriate to the system's intended purpose and of at least six months, unless Union or national law, in particular on personal data, provides otherwise. |
| Regulation (EU) 2024/1689, Article 19(2) | Providers that are financial institutions subject to internal-governance requirements under Union financial services law keep those logs as part of the documentation kept under that law. |
| Regulation (EU) 2024/1689, Article 26(6) | Deployers keep the logs the system generates automatically, to the extent the logs are under their control, for a period appropriate to the system's intended purpose and of at least six months, unless applicable law provides otherwise. |
| Regulation (EU) 2024/1689, Article 86(1) | A person affected by a decision a deployer takes on the basis of output from a high-risk AI system listed in Annex III (other than point 2), with legal or similarly significant adverse effects, may obtain clear and meaningful explanations of the role of the AI system in the decision and of the main elements of the decision taken. |
GDPR Article 22
- Who it concerns
- Any controller whose decisions about people are made, wholly or partly, by automated processing. Whether it applies to you, and from when, is yours to establish from the text.
- When it is tested
- A person contests an automated decision; the data protection authority asks you to demonstrate compliance.
- What a sealed record adds
- The basis of the decision, and any human review of it, are shown to have been recorded at the time, while the record, which holds personal data, stays with you and erasable.
- How long to keep it
- This pack does not state how long to keep these records. The records are yours and hold personal data under your control: keep them no longer than your purposes need, and they stay erasable because they never leave you. Only a salted digest is in the log, and without the record and its salt nobody, including us, can link it to anyone.
- What to record
- The GDPR Article 22 pack:
gdpr.automated-decision,gdpr.human-intervention
| Article (links to the text on EUR-Lex) | What it asks (our summary; the linked text is the law) |
|---|---|
| Regulation (EU) 2016/679, Article 5(2) | The controller is responsible for, and must be able to demonstrate, compliance with the principles in Article 5(1). |
| Regulation (EU) 2016/679, Article 13(2)(f) and Article 14(2)(g) | Inform the person of the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4), and at least in those cases give meaningful information about the logic involved and the significance and envisaged consequences. |
| Regulation (EU) 2016/679, Article 22(1) | A person has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. |
| Regulation (EU) 2016/679, Article 22(2) | That does not apply where the decision is necessary for entering into or performing a contract, is authorised by Union or Member State law with suitable safeguards, or is based on the person's explicit consent. |
| Regulation (EU) 2016/679, Article 22(3) | Where the contract or explicit-consent exception applies, the controller implements suitable measures, at least the right to obtain human intervention, to express one's point of view and to contest the decision. |
DORA
- Who it concerns
- Financial entities within DORA's scope, including insurers and insurance intermediaries, other than intermediaries that are micro, small or medium-sized enterprises (Article 2(3)). Whether it applies to you, and from when, is yours to establish from the text.
- When it is tested
- Your authority reviews a major incident; an auditor compares the report you hold with the report you sent.
- What a sealed record adds
- The incident record and each report are sealed when they are made, so the report you hold today is shown to be the one you held on the day you submitted it.
- How long to keep it
- This pack does not state how long to keep these records. Check the period with your competent authority.
- What to record
- The DORA pack:
dora.incident,dora.incident-report,dora.register-snapshot
| Article (links to the text on EUR-Lex) | What it asks (our summary; the linked text is the law) |
|---|---|
| Regulation (EU) 2022/2554, Article 17(1) | Define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents. |
| Regulation (EU) 2022/2554, Article 17(2) | Record all ICT-related incidents and significant cyber threats, with procedures for consistent monitoring, handling and follow-up so root causes are identified, documented and addressed. |
| Regulation (EU) 2022/2554, Article 18 | Classify ICT-related incidents and determine their impact against the criteria the article sets. |
| Regulation (EU) 2022/2554, Article 19(4) | For a major ICT-related incident, submit to the competent authority an initial notification, an intermediate report and a final report. |
| Regulation (EU) 2022/2554, Article 28(3) | Maintain and update a register of information on all contractual arrangements for ICT services provided by ICT third-party service providers. |
What no law requires, and what the log does not do
- No law names a product
- None of these laws requires RiskRouter or any other product. You can meet every duty on this page without us. What we offer is a way to show you met it that does not depend on anyone’s word, including ours.
- It proves when, not whether
- A sealed record is shown to have existed, unchanged, no later than a signed and anchored head. The log does not know what the record says, so it cannot make a record correct, complete or sufficient, and recording something does not make anyone compliant.
- The record stays with you
- Only a salted fingerprint of each record is sent. The record, and any personal data in it, never reach us, so it stays yours to keep and to erase. Data protection
- It outlives us
- Every proof checks offline with the open-source verifier, against keys and anchors that are published. Continuity
To start, take a sandbox key and record a fingerprint in a few minutes, or read what to record, rule by rule.