Agent Register
Every agent · Customer-facing bots · PolyAI

PolyAI

A voice agent that answers customer calls and completes transactions.

executes autonomously
acts on
no
human in the loop by default
yes
data leaves the tenant by default
Inbound phone calls and the booking or account systems behind them
reaches by default

What that means for the register

It executes on its own, so it needs the controls of an account that acts: a log you can read, a scope in writing, and a person who can switch it off. Data leaves your tenant to the vendor by default. Pasted with only its name it lands as control until an owner is named.

This week

Confirm the call disclosure and the transaction limits.

What holding it is evidence for

Requirement text and artefacts from a human-verified corpus licensed to Agent Register.

Agents that execute without approval ISO 42001 A.6.2.6 · ISO 42001 A.9.4 · ISO 42001 A.6.2.8 · EU AI Act Art.14 · EU AI Act Art.26 · EU AI Act Art.12
ISO 42001 A.6.2.6 AI system operation and monitoring

AI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.

Evidence an auditor accepts: Operations runbooks; Monitoring dashboards; Incident logs
ISO 42001 A.9.4 Intended use of the AI system

The organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.

Evidence an auditor accepts: Intended use statements; Use case approval records; Monitoring of use
ISO 42001 A.6.2.8 AI system event logging

Event logs shall be generated and recorded during AI system operations to enable monitoring, accountability, and incident investigation.

Evidence an auditor accepts: Logging standards; Log samples; Log retention policy
EU AI Act Art.14 Human oversight

High-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of...

Evidence an auditor accepts: Human-oversight design (UI, controls, alerts); Oversight-personnel training and authority
EU AI Act Art.26 Obligations of deployers of high-risk AI systems

Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for...

Evidence an auditor accepts: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable
EU AI Act Art.12 Record-keeping (logs)

High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system, ensuring a level of traceability appropriate to the intended purpose; logging capabilities for biometric remote-identification AI systems include the period of each use, the ref...

Evidence an auditor accepts: Logging capability design evidence; Log-retention policy aligned with the intended purpose
Broad system reach or write access to a system of record ISO 42001 A.4.4 · ISO 42001 A.4.5 · ISO 42001 A.6.2.5 · ISO 42001 A.5.2 · EU AI Act Art.15 · EU AI Act Art.9
ISO 42001 A.4.4 Tooling resources

The organization shall document information about the tooling resources utilized for the AI system.

Evidence an auditor accepts: Tooling inventory; Tool risk assessments; Development frameworks, libraries, MLOps platforms
ISO 42001 A.4.5 System and computing resources

The organization shall document information about the system and computing resources utilized.

Evidence an auditor accepts: Infrastructure inventory; Capacity plans; Compute (CPU/GPU), storage, network resources
ISO 42001 A.6.2.5 AI system deployment

The organization shall document a deployment plan and ensure requirements are met before deployment.

Evidence an auditor accepts: Deployment plans; Go-live checklists; Approval records
ISO 42001 A.5.2 AI system impact assessment process

The organization shall establish a process to assess the potential consequences of the AI system for individuals or groups and societies.

Evidence an auditor accepts: AI impact assessment procedure; Assessment template; Methodology covering individuals, groups, societies
EU AI Act Art.15 Accuracy, robustness and cybersecurity

High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and shall perform consistently in those respects throughout their lifecycle. Resilience to errors, faults and inconsistencies; protection against atte...

Evidence an auditor accepts: Accuracy/robustness measurements relevant to the intended purpose; Adversarial/data-poisoning threat modelling and mitigation; Cybersecurity controls aligned with state-of-the-art
EU AI Act Art.9 Risk management system

Providers shall establish, implement, document and maintain a risk management system as a continuous iterative process planned and run throughout the entire lifecycle of a high-risk AI system, including identification and analysis of known and reasonably foreseeable risks, estimation/evaluation of r...

Evidence an auditor accepts: Risk management system documentation; Lifecycle risk analysis records; Post-deployment risk monitoring
Customer-facing or people-affecting without supervision ISO 42001 A.8.2 · ISO 42001 A.5.4 · ISO 42001 A.8.4 · EU AI Act Art.50 · EU AI Act Art.6 · EU AI Act Art.86 · EU AI Act Art.27
ISO 42001 A.8.2 System documentation and information for users

The organization shall determine and provide the necessary information for users of the AI system.

Evidence an auditor accepts: User documentation; Instructions for use; Training materials
ISO 42001 A.5.4 Assessing AI system impact on individuals or groups

The organization shall assess and document the potential impacts of AI systems to individuals or groups of individuals throughout the system's life cycle.

Evidence an auditor accepts: Per-system impact assessments; Fairness analysis; Privacy impact (link to PIA where relevant)
ISO 42001 A.8.4 Communication of incidents

The organization shall determine and document a plan for communicating incidents to relevant interested parties.

Evidence an auditor accepts: Incident communication plan; Incident notification records; Notification criteria and timing
EU AI Act Art.50 Transparency obligations for providers and deployers of certain AI systems

Providers and deployers of certain AI systems (incl those interacting with natural persons, emotion recognition, biometric categorisation, generative AI producing synthetic content, deepfakes, and AI-generated/manipulated text for public-interest information) shall inform users that they are interac...

Evidence an auditor accepts: User-facing AI-interaction notification; Machine-readable labelling of synthetic content; Deepfake/AI-text disclosure
EU AI Act Art.6 Classification rules for high-risk AI systems

Determine and record, for each AI system, whether it is high-risk. A system is high-risk where it is intended to be used as a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I and that product must undergo third-party conformity assessment,...

Evidence an auditor accepts: A classification record per AI system naming the Annex I legislation or the Annex III use case considered, and the conclusion reached; The documented Art.6(3) assessment where an Annex III system is judged not high-risk, dated before placing on the market; Evidence the profiling rule was applied, so any system profiling natural persons is classified high-risk regardless of the derogation
EU AI Act Art.86 Right to explanation of individual decision-making

A deployer must, at the request of an affected person who has been subject to a decision the deployer took on the basis of the output of an Annex III high-risk AI system other than one listed under Annex III point 2, and which produces legal effects or similarly significantly affects that person in ...

Evidence an auditor accepts: A documented procedure for receiving and answering explanation requests, with an owner and a response time; Explanation templates per decision type, covering both the role of the AI system in the procedure and the main elements of the decision; A register of requests received and the explanations given
EU AI Act Art.27 Fundamental rights impact assessment for high-risk AI systems

Before deploying a high-risk AI system referred to in Art.6(2) (Annex III), public-law-governed deployers (and certain private deployers providing public services + financial services) shall perform a fundamental rights impact assessment (FRIA) describing the deployment context, the categories of af...

Evidence an auditor accepts: FRIA per in-scope deployment; Notification to market surveillance authority
Data leaving the tenant to a model vendor ISO 42001 A.10.3 · ISO 42001 A.4.3 · ISO 42001 A.7.3 · ISO 42001 A.10.2 · EU AI Act Art.10 · EU AI Act Art.25
ISO 42001 A.10.3 Suppliers

Establish a process ensuring that the organization's use of services, products or materials provided by suppliers aligns with its approach to the responsible development and use of AI systems.

Evidence an auditor accepts: supplier assessment criteria covering responsible AI; completed assessments for AI suppliers including model, dataset and component providers; contract terms binding suppliers to the organization's AI requirements
ISO 42001 A.4.3 Data resources

As part of identifying resources, the organization shall document information about the data resources utilized for the AI system.

Evidence an auditor accepts: Data inventory; Data lineage records; Datasheets
ISO 42001 A.7.3 Acquisition of data

The organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.

Evidence an auditor accepts: Data acquisition records; Provenance documentation; Consent records
ISO 42001 A.10.2 Allocating responsibilities

Ensure responsibilities across the AI system life cycle are allocated between the organization, its partners, suppliers, customers and third parties.

Evidence an auditor accepts: RACI or equivalent covering each life cycle stage and each external party; contract clauses that state who is accountable for what; evidence the allocation is reviewed when the arrangement changes
EU AI Act Art.10 Data and data governance

High-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically ...

Evidence an auditor accepts: Data governance procedures; Bias examination records and remediation; Data-quality assessment per dataset
EU AI Act Art.25 Responsibilities along the AI value chain

Distributors/importers/deployers/other third parties become providers when they place on the market or put into service under their own name or trademark, substantially modify the system, or modify the intended purpose making it high-risk. The original provider shall cooperate with the new provider,...

Evidence an auditor accepts: Documented allocation of provider status across the value chain; Cooperation agreements between original and new providers
No human in the loop by default ISO 42001 A.6.2.6 · ISO 42001 A.3.3 · ISO 42001 A.8.3 · EU AI Act Art.14 · EU AI Act Art.26
ISO 42001 A.6.2.6 AI system operation and monitoring

AI systems shall be operated and monitored according to organizational and operational requirements throughout their lifetime. Operational guidance shall be available to operators.

Evidence an auditor accepts: Operations runbooks; Monitoring dashboards; Incident logs
ISO 42001 A.3.3 Reporting of concerns

A process shall be established to enable reporting of concerns about AI systems' development, deployment, or use.

Evidence an auditor accepts: Concern reporting procedure; Whistleblower channel evidence; Concern register
ISO 42001 A.8.3 External reporting

The organization shall provide mechanisms for external interested parties to report concerns or impacts.

Evidence an auditor accepts: External reporting channels; Concern register; Public-facing contact (email, form)
EU AI Act Art.14 Human oversight

High-risk AI systems shall be designed and developed in such a way that they can be effectively overseen by natural persons during the period in which they are in use. Oversight measures shall enable persons to understand the relevant capacities and limitations and monitor operation, remain aware of...

Evidence an auditor accepts: Human-oversight design (UI, controls, alerts); Oversight-personnel training and authority
EU AI Act Art.26 Obligations of deployers of high-risk AI systems

Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for...

Evidence an auditor accepts: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable

Do this for every tool your teams use

Paste the list and get this classification for every entry at once, with the owner column, the findings per department, and the controls the register is evidence for. Ten entries free, no account.

Build my agent register

Voiceflow · Tidio Lyro and small-business chat bots