Records · Incidents & vendors
Two small but useful records that round out your compliance picture: a log of anything that went wrong with an AI tool, and a register of your AI vendors and what you know about their posture. Both feed straight into your evidence pack.
Who it is for
Here is the honest answer. Formal serious-incident reporting under Article 73 is largely an obligation on AI providers, not on most SMEs who simply use AI. So this is rarely a hard legal requirement for you. But it is good housekeeping, and it is the kind of thing an auditor or an enterprise buyer expects a credible supplier to have.
These records help if:
If neither feels relevant yet, that is fine - these are the lightest part of the picture. The classifier will tell you what is actually required versus simply sensible.
When an AI tool misfires, a short, dated note is worth more than memory. The incident log keeps it simple.
Your AI tools come from vendors, and buyers increasingly ask about them. The vendor register keeps your notes in one place.
Incidents and vendors appear in the same sealed, dated evidence pack as your register, classifications, policy and disclosures.
How it works
A note takes a moment; closure is tracked.
Start from the seeded list, add your notes.
Both come out inside the evidence pack when you need it.
Usually not. The Article 73 serious-incident reporting duty falls mainly on providers of high-risk AI, not on most companies that simply use AI tools. Keeping an internal log is good practice and good evidence, but it is generally not a hard reporting obligation for an SME deployer.
Because it is cheap insurance and good evidence. If a customer or auditor asks how you handle AI going wrong, here is our log and how each issue was resolved is a far stronger answer than a shrug. It also helps you spot a tool that keeps causing problems.
It is a record of the vendors behind your AI tools and what you know about how they handle AI and data. It is register-only for now - somewhere to keep notes and answer procurement questions - not an automated vendor-questionnaire workflow.
No. It is a lightweight record, not a TPRM platform. It captures what you know about each vendor so it is to hand, and feeds your evidence pack.
No. Add to them as things happen. They are the lightest features in Normis by design - the heavy lifting is your register, classifications, policy and sign-offs.
No. These are record-keeping tools with plain-English guidance. For a specific incident with legal or safety implications, take advice.
The classifier is free, no signup, no card. It tells you what is genuinely required and what is simply good practice, so you spend effort where it counts.