Skip to main content
    AI System Inventory
    10 min readUpdated 2025-01-28

    Using the AI System Wizard

    Master the 20-step AI System Intake Wizard to capture comprehensive compliance information.

    The AI System Wizard

    The AI System Wizard is Klarvo's guided intake process, designed to capture all information needed for EU AI Act compliance in a structured, user-friendly flow.

    Wizard Design Philosophy

    The wizard follows these principles:

  1. < 10 minutes for a complete Full Assessment
  2. Every answer creates action: Classification decision, obligation flag, evidence request, or task
  3. Progressive disclosure: Complex questions only appear when relevant
  4. Save progress: Resume anytime without losing work
  5. The 20 Steps

    #### Part 1: Foundation (Steps 0-3)

    Step 0: Mode Selection

    Choose Quick Capture or Full Assessment. Quick Capture skips optional questions and creates follow-up tasks.

    Step 1: Basic Information

  6. System name and internal reference ID
  7. Lifecycle status (Idea, Pilot, Live, Retired)
  8. Primary owner assignment
  9. Step 2: Vendor Information

  10. Built in-house vs. third-party acquisition
  11. Vendor selection or creation
  12. Contract documentation links
  13. Step 3: Ownership & Accountability

  14. Backup owner
  15. Oversight owner
  16. Department/team assignment
  17. #### Part 2: Scope & Context (Steps 4-5)

    Step 4: Deployment Scope

  18. Deployment regions (EU, UK, US, Other)
  19. EU countries of operation
  20. Internal user groups
  21. Affected external parties
  22. Step 5: Value Chain Role

  23. Deployer, Provider, or Both
  24. External offering assessment
  25. Foundation model usage
  26. #### Part 3: Definition & Classification (Steps 6-9)

    Step 6: AI System Definition Test

  27. Infers outputs from inputs?
  28. Output types (predictions, recommendations, etc.)
  29. Operates autonomously?
  30. Adapts after deployment?
  31. Technical approach (ML, LLM, rules-based)
  32. Step 7: Use Case & Functionality

  33. Purpose category
  34. Workflow description
  35. Human involvement level
  36. Override capability
  37. Usage frequency and scale
  38. Step 8: Prohibited Practices Screening

    Eight critical questions covering Article 5:

  39. Manipulation/deception
  40. Exploitation of vulnerabilities
  41. Social scoring
  42. Criminal profiling
  43. Facial recognition scraping
  44. Workplace emotion inference
  45. Biometric categorisation
  46. Real-time remote biometric ID
  47. Step 9: High-Risk Screening

    Nine Annex III category checks:

  48. Biometrics
  49. Critical infrastructure
  50. Education
  51. Employment
  52. Essential services
  53. Law enforcement
  54. Migration/border
  55. Justice/democratic processes
  56. Safety components
  57. #### Part 4: Obligations (Steps 10-14)

    Step 10: Transparency Obligations

    Article 50 requirements:

  58. Direct interaction disclosure
  59. Synthetic content marking
  60. Emotion recognition notice
  61. Deepfake disclosure
  62. Public-interest text disclosure
  63. Step 11: Data & Privacy

  64. Personal data processing
  65. Special category data
  66. Minors involved
  67. Data sources and control
  68. Retention periods
  69. DPIA status
  70. Step 12: Human Oversight

  71. Oversight model (HITL/HOTL/HOOTL)
  72. Oversight owner authority
  73. Competence requirements
  74. Training status
  75. SOP documentation
  76. Step 13: Logging & Records

  77. Automatic logging capability
  78. Log storage location
  79. Access controls
  80. Retention period
  81. Export capability
  82. 6-month retention confirmation
  83. Step 14: Incidents & Monitoring

  84. Incident response process
  85. Severity levels
  86. Notification procedures
  87. Suspension capability
  88. #### Part 5: Special Contexts (Steps 15-17)

    Step 15: Workplace Context

  89. Workplace use assessment
  90. Worker notification status
  91. Step 16: Public Authority Context

  92. Public authority status
  93. Public service provision
  94. Registration status
  95. Step 17: Training & AI Literacy

  96. Staff roles involved
  97. Training program status
  98. Completion tracking
  99. #### Part 6: Finalization (Steps 18-20)

    Step 18: FRIA Assessment

  100. FRIA trigger evaluation
  101. FRIA status tracking
  102. Link to FRIA Wizard
  103. Step 19: Review & Sign-off

  104. Final classification confirmation
  105. Reviewer assignment
  106. Sign-off date
  107. Notes
  108. Step 20: Completion

  109. Summary of outputs
  110. Generated documents
  111. Next steps
  112. Action items
  113. Auto-Generated Outputs

    Upon completion, the wizard creates:

  114. AI System Record: Full database entry
  115. Classification Memo: PDF with rationale
  116. Gap Checklist: Missing controls/evidence
  117. Task Plan: Auto-assigned action items
  118. Evidence Requests: Specific document needs