What’s in the report?
Report metadata
Report metadata
- When the report was generated, by whom
- Project name and target model
- Report version (incremented each time you regenerate)
Risk classification
Risk classification
- The chosen tier and EU Annex category
- Intended purpose and deployment context
- Vulnerable group considerations
- Justification text
- Approval record (who approved, when)
Risk register summary
Risk register summary
- Total risks
- Breakdown by status, priority
- Average inherent and residual risk scores
Each individual risk
Each individual risk
- Risk code, title, scores
- Most recent assessment with failure rate and findings
- Every mitigation with status and effectiveness
Testing evidence
Testing evidence
- Total tests executed
- Overall safe rate
- Per-category breakdown
- Number of human overrides
Compliance checklist
Compliance checklist
A pass/fail checklist showing whether the project meets the basic Article 9 criteria. Lets the auditor see in seconds whether you’re in good shape.
Generating a report
1
Open Risk → Reports
Inside your project.
2
Click 'Generate Report'
Alethia compiles the data — usually takes a few seconds.
3
Review
The report opens in the viewer. Each section is collapsible.
4
Export
Three options:
- JSON — for downstream processing
- PDF — for sharing with auditors and stakeholders
- Permalink — a URL the recipient can open (with their own Alethia access)
When to generate a report
You can generate a report any time, but typical moments are:- Before deployment — gate the launch on a clean compliance report
- At the end of each quarter — keep a regular evidence cadence
- Ahead of an audit — generate a fresh report just before sharing
- After a significant change — model update, new mitigation, classification change
What a clean report looks like
A “clean” Article 9 report has these characteristics:- ✅ Classification approved with a clear justification
- ✅ Risk register populated — at least every category that’s been tested has an entry, even if the entry’s conclusion is “low risk, accepted”
- ✅ Recent assessments — most risks have an assessment within the last 90 days
- ✅ Mitigations tracked — risks with elevated scores have at least one mitigation, and verified mitigations show effectiveness
- ✅ Audit trail intact — every change has a user and timestamp
- ✅ Residual risks decided — for every risk, someone has marked it accepted, transferred, or closed (or it’s actively in mitigation)
What a problem report looks like
Things auditors will flag:- ❌ Risks with high inherent scores and no mitigation activity
- ❌ Old assessments (more than 6 months) on risks marked as still active
- ❌ Mitigations marked
implementedbut neververified - ❌ Many human overrides without documented reasoning
- ❌ Classification still in
draftwhile testing is happening
Sharing reports
With internal compliance
Use the Permalink option. They’ll need a Viewer role on the team. They can read but not edit.
With external auditors
Export as PDF. The PDF has all the data flattened, with the audit trail attached as an appendix.
Keeping reports defensible
A few principles to keep in mind:What the report does NOT do
- ❌ It doesn’t certify your AI as “compliant” — only your compliance team and (where required) a notified body can do that
- ❌ It doesn’t replace legal review
- ❌ It doesn’t satisfy domain-specific obligations (medical, financial, etc.) on its own