Rekvira

Jobs / AI-governance or compliance lead

Customer AI questionnaire answered

“A customer has sent its AI due-diligence questionnaire and wants it back this week.”

1.8 min66 tool calls43 sources read35 citations verified

Recorded 23 September 2026 on the live service with Claude Code 2.1.280 (headless: claude -p), model claude-opus-5-5.

Today An average company can spend 5 to 15 hours on a single security questionnaire, and more when it sells into regulated industries. Vendor estimate: Vanta

The run

Each step is a Rekvira playbook your assistant reads and follows. Open a step to see every call it made and what came back.

  1. Connected, no account

    1 tool call · under 1 s
    Show the 1 calls
    RekviraConnected, no accountconnect0.0 s
    connect({})
  2. Answered each question from the held text, across the AI Act, DORA and the GDPR

    30 tool calls · 36 s
    Show the 30 calls
    RekviraOpened the playbook vendor-ai-questionnaireget_workflow0.1 s
    get_workflow({"workflow_id": "vendor-ai-questionnaire"})
    RekviraOpened the playbook cross-reg-compliance-scanget_workflow0.0 s
    get_workflow({"workflow_id": "cross-reg-compliance-scan"})
    RekviraRead what the corpus holds todaystart_here0.1 s
    start_here({})
    RekviraChecked which acts are loaded and their dateslist_regulations0.0 s
    list_regulations({})
    • eu-ai-act EU AI Act
    • dora DORA (Digital Operational Resilience Act)
    • gdpr GDPR (General Data Protection Regulation)
    RekviraSearched eu-ai-act for “high-risk AI system creditworthiness credit score natural persons”search_regulation0.1 s
    search_regulation({"regulation": "eu-ai-act", "query": "high-risk AI system creditworthiness credit score natural persons"})
    • ANNEX III(5)
    • Article 5(1)
    • Article 6(3)
    RekviraArticle 6, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 6})
    • Article 6 Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled: (a) the A
    RekviraANNEX III, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "annex", "number": "III"})
    • ANNEX III Biometrics, in so far as their use is permitted under relevant Union or national law: (a) (a) remote biometric identification systems. This shall not include AI systems intended to be u
    RekviraObligation headings for deployer in eu-ai-actlookup_obligations0.0 s
    lookup_obligations({"regulation": "eu-ai-act", "role": "deployer", "system_class": "high-risk"})
    • Article 26
    RekviraObligation headings for provider in eu-ai-actlookup_obligations0.0 s
    lookup_obligations({"regulation": "eu-ai-act", "role": "provider", "system_class": "high-risk"})
    • Article 16
    RekviraArticle 13, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 13})
    • Article 13 High-risk AI systems shall be designed and developed in such a way as to ensure that their operation is sufficiently transparent to enable deployers to interpret a system’s output and use it appropriately. An appropriate type and degree of transparency shall b
    RekviraArticle 12, full textread_unit0.0 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 12})
    • Article 12 High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system. In order to ensure a level of traceability of the functioning of a high-risk AI system that is appropriate to the intended purpose of th
    RekviraArticle 14, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 14})
    • Article 14 High-risk AI systems shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use. Human oversight shall aim to pre
    RekviraArticle 26, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 26})
    • Article 26 Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems, pursuant to paragraphs 3 and 6. Deployers shall assign human o
    RekviraArticle 19, full textread_unit0.0 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 19})
    • Article 19 Providers of high-risk AI systems shall keep the logs referred to in Article 12(1), automatically generated by their high-risk AI systems, to the extent such logs are under their control. Without prejudice to applicable Union or national law, the logs shall be
    RekviraArticle 16, full textread_unit0.0 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 16})
    • Article 16 Providers of high-risk AI systems shall: (a) ensure that their high-risk AI systems are compliant with the requirements set out in Section 2; (b) indicate on the high-risk AI system or, where that is not possible, on its packaging or its accompanying documenta
    RekviraSearched eu-ai-act for “narrow procedural task preparatory task profiling Annex III not high-risk”search_regulation0.1 s
    search_regulation({"regulation": "eu-ai-act", "query": "narrow procedural task preparatory task profiling Annex III not high-risk", "kinds": ["recital"]})
    • Recital (53)
    • Recital (59)
    • Recital (158)
    RekviraRecital (53), full textread_unit0.0 s
    read_unit({"regulation": "eu-ai-act", "kind": "recital", "number": 53})
    • Recital (53) It is also important to clarify that there may be specific cases in which AI systems referred to in pre-defined areas specified in this Regulation do not lead to a significant risk of harm to the legal interests protected under those areas because they do not
    RekviraRecital (58), full textread_unit0.0 s
    read_unit({"regulation": "eu-ai-act", "kind": "recital", "number": 58})
    • Recital (58) Another area in which the use of AI systems deserves special consideration is the access to and enjoyment of certain essential private and public services and benefits necessary for people to fully participate in society or to improve one’s standard of living.
    RekviraSearched eu-ai-act for “'provider' means 'deployer' means definitions”search_regulation0.0 s
    search_regulation({"regulation": "eu-ai-act", "query": "'provider' means 'deployer' means definitions", "kinds": ["paragraph"]})
    • Article 3, amendment (8)
    • Article 3, amendment (15)
    • Article 3, amendment (16)
    RekviraArticle 49(2), full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "pinpoint": "Article 49(2)"})
    • Article 49(2) Before placing on the market or putting into service an AI system for which the provider has concluded that it is not high-risk according to Article 6(3), that provider or, where applicable, the authorised representative shall register themselves and that syst
    RekviraArticle 25(1), full textread_unit0.0 s
    read_unit({"regulation": "eu-ai-act", "pinpoint": "Article 25(1)"})
    • Article 25(1) Any distributor, importer, deployer or other third-party shall be considered to be a provider of a high-risk AI system for the purposes of this Regulation and shall be subject to the obligations of the provider under Article 16, in any of the following circums
    RekviraArticle 27(1), full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "pinpoint": "Article 27(1)"})
    • Article 27(1) Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing
    RekviraSearched every loaded act for “contractual arrangements ICT third-party service provider audit exit strategy termination”search_regulations0.3 s
    search_regulations({"query": "contractual arrangements ICT third-party service provider audit exit strategy termination", "regulations": ["dora", "eu-ai-act", "gdpr"]})
    RekviraArticle 30, full textread_unit0.4 s
    read_unit({"regulation": "dora", "kind": "article", "number": 30})
    • Article 30 The rights and obligations of the financial entity and of the ICT third-party service provider shall be clearly allocated and set out in writing. The full contract shall include the service level agreements and be documented in one written document which shall
    RekviraArticle 28, full textread_unit0.4 s
    read_unit({"regulation": "dora", "kind": "article", "number": 28})
    • Article 28 Financial entities shall manage ICT third-party risk as an integral component of ICT risk within their ICT risk management framework as referred to in Article 6(1), and in accordance with the following principles: (a) financial entities that have in place cont
    RekviraObligation headings for processor in gdprlookup_obligations0.1 s
    lookup_obligations({"regulation": "gdpr", "role": "processor"})
    RekviraArticle 28, full textread_unit0.0 s
    read_unit({"regulation": "gdpr", "kind": "article", "number": 28})
    • Article 28 Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements
    RekviraSearched gdpr for “'processor' means processes personal data on behalf of the controller”search_regulation0.1 s
    search_regulation({"regulation": "gdpr", "query": "'processor' means processes personal data on behalf of the controller", "kinds": ["paragraph"]})
    • Article 4, amendment (8)
    • Article 28(3)
    • Article 30(2)
    RekviraSearched dora for “'ICT third-party service provider' means 'ICT services' means digital and data services”search_regulation0.1 s
    search_regulation({"regulation": "dora", "query": "'ICT third-party service provider' means 'ICT services' means digital and data services", "kinds": ["paragraph"]})
    • Article 3, amendment (1)
    • Article 3, amendment (21)
    • Article 5(2)
    RekviraArticle 4, amendment (4), full textread_unit0.0 s
    read_unit({"regulation": "gdpr", "kind": "paragraph", "number": 4, "article": 4})
    • Article 4, amendment (4) ‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performan
  3. You confirm. Supply the company facts the draft answers flag (role, logging period, oversight set-up).

    In this run: Checkpoint assumptions used throughout (none confirmed yet): Skaitis is the AI Act provider, and the bank is the deployer. The service only extracts figures. It does not score, rank or profile applicants. No log retention period has been set. A human reviews and can correct the extracted fields. The service processes applicants' income and account data on the bank's instructions.

  4. Checked every citation against the official text

    35 tool calls · 28 s
    Show the 35 calls
    RekviraArticle 6(3) EU AI Act: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 6(3) EU AI Act", "quote": "an AI system referred to in Annex III shall always be considered to be high-risk where the AI system performs profiling of natural persons"})
    • Article 6(3) exists: held · quote: found
    RekviraAnnex III point 5(b) EU AI Act: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Annex III point 5(b) EU AI Act", "quote": "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score", "regulation": "eu-ai-act"})
    • ANNEX III(5) exists: held · quote: found
    RekviraRecital 53 EU AI Act: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Recital 53 EU AI Act", "quote": "an AI system that transforms unstructured data into structured data"})
    • Recital (53) exists: held · quote: found
    RekviraArticle 6(4) EU AI Act: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 6(4) EU AI Act", "quote": "A provider who considers that an AI system referred to in Annex III is not high-risk shall document its assessment before that system is placed on the market or put into service"})
    • Article 6(4) exists: held · quote: found
    RekviraArticle 49(2) EU AI Act: heldverify_citation0.1 s
    verify_citation({"citation": "Article 49(2) EU AI Act"})
    • Article 49(2) exists: held
    RekviraArticle 13(3) EU AI Act: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 13(3) EU AI Act", "quote": "The instructions for use shall contain at least the following information"})
    • Article 13(3) exists: held · quote: found
    RekviraArticle 12(1) EU AI Act: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 12(1) EU AI Act", "quote": "High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system."})
    • Article 12(1) exists: held · quote: found
    RekviraArticle 19(1) EU AI Act: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 19(1) EU AI Act", "quote": "of at least six months, unless provided otherwise in the applicable Union or national law"})
    • Article 19(1) exists: held · quote: found
    RekviraArticle 26(6) EU AI Act: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 26(6) EU AI Act", "quote": "shall maintain the logs as part of the documentation kept pursuant to the relevant Union financial service law"})
    • Article 26(6) exists: held · quote: found
    RekviraArticle 14(4) EU AI Act: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 14(4) EU AI Act", "quote": "to decide, in any particular situation, not to use the high-risk AI system or to otherwise disregard, override or reverse the output"})
    • Article 14(4) exists: held · quote: found
    RekviraArticle 14(3) EU AI Act: heldverify_citation0.0 s
    verify_citation({"citation": "Article 14(3) EU AI Act"})
    • Article 14(3) exists: held
    RekviraArticle 26(2) EU AI Act: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 26(2) EU AI Act", "quote": "Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority"})
    • Article 26(2) exists: held · quote: found
    RekviraArticle 25(1) EU AI Act: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 25(1) EU AI Act", "quote": "they modify the intended purpose of an AI system"})
    • Article 25(1) exists: held · quote: found
    RekviraArticle 27(1) EU AI Act: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 27(1) EU AI Act", "quote": "deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III"})
    • Article 27(1) exists: held · quote: found
    RekviraArticle 30(2) DORA: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 30(2) DORA", "quote": "termination rights and related minimum notice periods for the termination of the contractual arrangements", "regulation": "dora"})
    • Article 30(2) exists: held · quote: found
    RekviraArticle 30(3) DORA: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 30(3) DORA", "quote": "unrestricted rights of access, inspection and audit by the financial entity, or an appointed third party, and by the competent authority", "regulation": "dora"})
    • Article 30(3) exists: held · quote: found
    RekviraArticle 28(8) DORA: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 28(8) DORA", "quote": "For ICT services supporting critical or important functions, financial entities shall put in place exit strategies.", "regulation": "dora"})
    • Article 28(8) exists: held · quote: found
    RekviraArticle 28(7) DORA: heldverify_citation0.0 s
    verify_citation({"citation": "Article 28(7) DORA", "regulation": "dora"})
    • Article 28(7) exists: held
    RekviraArticle 3(19) DORA: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 3(19) DORA", "quote": "‘ICT third-party service provider’ means an undertaking providing ICT services", "regulation": "dora"})
    • Article 3, amendment (19) exists: held · quote: found
    RekviraArticle 30(1) DORA: heldverify_citation0.1 s
    verify_citation({"citation": "Article 30(1) DORA", "regulation": "dora"})
    • Article 30(1) exists: held
    RekviraArticle 28(3) GDPR: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 28(3) GDPR", "quote": "processes the personal data only on documented instructions from the controller", "regulation": "gdpr"})
    • Article 28(3) exists: held · quote: found
    RekviraArticle 28(10) GDPR: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 28(10) GDPR", "quote": "the processor shall be considered to be a controller in respect of that processing", "regulation": "gdpr"})
    • Article 28(10) exists: held · quote: found
    RekviraArticle 4(8) GDPR: heldverify_citation0.0 s
    verify_citation({"citation": "Article 4(8) GDPR", "regulation": "gdpr"})
    • Article 4, amendment (8) exists: held
    RekviraArticle 4(4) GDPR: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 4(4) GDPR", "regulation": "gdpr", "quote": "economic situation"})
    • Article 4, amendment (4) exists: held · quote: found
    RekviraArticle 28(2) GDPR: heldverify_citation0.0 s
    verify_citation({"citation": "Article 28(2) GDPR", "regulation": "gdpr"})
    • Article 28(2) exists: held
    RekviraArticle 33(2) GDPR: heldverify_citation0.1 s
    verify_citation({"citation": "Article 33(2) GDPR", "regulation": "gdpr"})
    • Article 33(2) exists: held
    RekviraArticle 3(3) EU AI Act: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 3(3) EU AI Act", "quote": "places it on the market or puts the AI system into service under its own name or trademark"})
    • Article 3, amendment (3) exists: held · quote: found
    RekviraArticle 3(4) EU AI Act: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 3(4) EU AI Act", "quote": "using an AI system under its authority"})
    • Article 3, amendment (4) exists: held · quote: found
    RekviraArticle 16 EU AI Act: heldverify_citation0.0 s
    verify_citation({"citation": "Article 16 EU AI Act"})
    • Article 16 exists: held
    RekviraArticle 26(5) EU AI Act: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 26(5) EU AI Act", "quote": "the monitoring obligation set out in the first subparagraph shall be deemed to be fulfilled"})
    • Article 26(5) exists: held · quote: found
    RekviraArticle 26(1) EU AI Act: heldverify_citation0.1 s
    verify_citation({"citation": "Article 26(1) EU AI Act"})
    • Article 26(1) exists: held
    RekviraArticle 12(2) EU AI Act: heldverify_citation0.0 s
    verify_citation({"citation": "Article 12(2) EU AI Act"})
    • Article 12(2) exists: held
    RekviraArticle 30(2) DORA: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 30(2) DORA", "quote": "provisions on ensuring access, recovery and return in an easily accessible format of personal and non-personal data", "regulation": "dora"})
    • Article 30(2) exists: held · quote: found
    RekviraRecital 58 EU AI Act: held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Recital 58 EU AI Act", "quote": "AI systems used to evaluate the credit score or creditworthiness of natural persons should be classified as high-risk AI systems"})
    • Recital (58) exists: held · quote: found
    RekviraArticle 28(1) DORA: held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 28(1) DORA", "regulation": "dora", "quote": "remain fully responsible for compliance with"})
    • Article 28(1) exists: held · quote: found

What it produced: the questionnaire answers

Word for word what the assistant wrote at the end of the run. The company in it is invented for this demonstration; the regulation text, pinpoints and checks are what Rekvira returned.

Skaitis UAB: answers to the bank's AI due-diligence questionnaire (draft)

The answers are drafted from EU regulation text held in Rekvira, as of 2 September 2026. None of them is a "compliant" confirmation. Wherever the answer depends on a company fact, it is marked [FACT].

Checkpoint assumptions used throughout (none confirmed yet):

  • Skaitis is the AI Act provider, and the bank is the deployer.
  • The service only extracts figures. It does not score, rank or profile applicants.
  • No log retention period has been set.
  • A human reviews and can correct the extracted fields.
  • The service processes applicants' income and account data on the bank's instructions.

1. Answer per question

Q1: Is the service a high-risk AI system? It depends on facts we still need to confirm.

  • Credit scoring is listed as high-risk. Annex III(5)(b) covers "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score". Recital (58) gives the reason. Annex III systems are high-risk by default under Article 6(2).
  • There is a way out. Article 6(3) says an Annex III system is not high-risk if it does not "materially influenc[e] the outcome of decision making". One qualifying condition is performing (a) "a narrow procedural task" or (d) "a preparatory task". Recital (53) gives "an AI system that transforms unstructured data into structured data" as an example of a narrow procedural task. That matches what the service does.
  • The way out is blocked if the system profiles people. Under the last subparagraph of Article 6(3), a system "shall always be considered to be high-risk where the AI system performs profiling". GDPR Article 4(4) defines profiling as using personal data to "evaluate… a natural person's… economic situation".
  • [FACT] Does the output only extract figures, or does it also flag, score, rank or judge whether an applicant is affordable or consistent? If it does any of the latter, treat the service as high-risk.
  • Claiming non-high-risk has its own duties. Under Article 6(4), Skaitis must document the assessment before placing the system on the market. Under Article 49(2), it must register itself and the system in the EU database.
  • [FACT] Has that assessment been documented, and has the system been registered?
  • Article 25(1)(c) is worth pointing out to the bank. If the bank changes the intended purpose so the system becomes high-risk, the bank becomes the provider.

Q2: What information must you give us as deployer? This applies if the service is high-risk.

  • Article 13(3) lists the minimum contents of the instructions for use:
  • provider identity;
  • intended purpose;
  • accuracy metrics;
  • known risks;
  • input-data specifications;
  • how to interpret the output;
  • pre-determined changes;
  • human oversight measures;
  • resources and maintenance;
  • log-collection mechanisms.
  • Article 13(1) requires the system to be transparent enough for deployers to interpret its output.
  • The bank's own duties rely on this information:
  • Article 26(1): using the system in line with the instructions.
  • Article 26(9): the bank's GDPR impact assessment (DPIA).
  • Article 27(1): a fundamental rights impact assessment. This is mandatory for deployers of Annex III point 5(b) systems, so the bank will need our Article 13 information for it.
  • [FACT] Accuracy metrics, intended purpose wording, and input specifications (document types, languages, formats).
  • If the service is not high-risk, the held text does not require this list. Supplying it would be contractual.

Q3: Does the system keep logs, and for how long?

  • If high-risk, Article 12(1) requires the system to record events automatically over its lifetime, for the purposes set out in Article 12(2).
  • The provider must keep the logs under its control "of at least six months" (Article 19(1)).
  • The bank, as a financial institution, keeps its logs as part of its financial-services documentation (Article 26(6), second subparagraph).
  • [FACT] What is logged, where, the actual retention period, and who controls which logs.
  • If the service is not high-risk, the held text sets no logging duty.

Q4: How do you support human oversight?

  • If high-risk, Article 14(1) requires the system to be designed so people can effectively oversee it.
  • Article 14(3) splits oversight measures into those built in by the provider and those the provider identifies for the deployer to carry out.
  • Article 14(4)(a)–(e) says the people overseeing it must be able to:
  • understand its limits;
  • stay alert to automation bias;
  • interpret the output;
  • disregard or override the output;
  • stop the system.
  • The bank must assign competent staff to oversight (Article 26(2)).
  • [FACT] Describe the actual review screen, confidence flags, the correction workflow, and the stop mechanism.

Q5: Will you accept DORA contract terms, including audit and exit?

  • Accepting the terms is a commercial decision for Skaitis. The held text only sets what the contract must contain. Skaitis meets DORA's definition of an ICT third-party service provider, "an undertaking providing ICT services" (DORA Article 3(19)). The bank stays fully responsible for DORA compliance (Article 28(1)(a)).
  • The contract must be written (Article 30(1)). For every ICT service it must include (Article 30(2)(a)–(i)):
  • a description of the services and subcontracting;
  • data locations;
  • data protection;
  • access to and return of data on insolvency or termination;
  • service levels;
  • incident assistance;
  • cooperation with the authorities;
  • termination rights and notice periods;
  • training participation.
  • If the service supports a critical or important function, Article 30(3) adds more:
  • full service levels;
  • business-continuity plans;
  • taking part in the bank's threat-led penetration testing (TLPT);
  • unrestricted access, inspection and audit rights for the bank and the competent authority (point (e));
  • exit strategies with a mandatory transition period (point (f)).
  • The bank must also be able to terminate on the grounds in Article 28(7) and must have exit plans (Article 28(8)).
  • [FACT] Ask the bank whether it classifies this service as supporting a critical or important function. That is the bank's own assessment under Article 28(4)(a). We also need to supply our data locations and any subcontractors (for example, cloud hosting).

Q6: Are you our processor, and what must the contract contain?

  • A processor processes personal data "on behalf of the controller" (GDPR Article 4(8)).
  • The contract must set out (Article 28(3)):
  • the subject matter, duration, nature and purpose of the processing;
  • the types of data and data subjects.
  • It must also bind Skaitis to (Article 28(3)(a)–(h)):
  • process data only on documented instructions;
  • confidentiality;
  • security measures under Article 32;
  • sub-processor rules;
  • help with data-subject requests and with Articles 32–36;
  • delete or return the data at the end;
  • audits.
  • Using sub-processors needs the bank's authorisation (Article 28(2)). Skaitis must notify breaches without undue delay (Article 33(2)).
  • [FACT] Does Skaitis use the bank's customer data for its own purposes, such as training its models? If so, Article 28(10) makes Skaitis a controller for that processing, and the answer changes.

2. Facts the company must supply

  1. The output's exact scope: extraction only, or any scoring or judgement. This decides Q1 through Article 6(3) and the profiling override.
  2. Whether the Article 6(4) assessment is documented and the Article 49(2) registration done.
  3. Accuracy metrics, intended-purpose wording and input specifications, for Q2.
  4. What is logged, how long it is kept, and who controls the logs, for Q3.
  5. How oversight works in the interface (review, override, stop), for Q4.
  6. Data locations, subcontractors, service levels, and continuity and exit arrangements, for Q5.
  7. Whether customer data is reused for training or product improvement, for Q6.
  8. From the bank: whether it treats this as a critical or important function, for Q5.

3. Questions the held text does not answer

  • The Commission's Article 6(5) guidelines with high-risk and non-high-risk examples are not held. They could settle whether extraction counts as a "narrow procedural task".
  • DORA's detailed technical standards (RTS/ITS) on subcontracting and the register templates, and EBA guidance, are not held.
  • National law is not held, including Lithuanian and bank-side record-keeping periods that would set the log retention under Article 26(6).
  • Harmonised standards for the AI Act are not held.
  • Whether Skaitis will accept particular terms is a commercial decision, not something regulation text answers.

4. Citations checked

  • All 41 pinpoints above exist in the held text, and every quoted passage was found. The list, with quotes checked for most:
  • AI Act: Articles 3(3), 3(4), 6(3), 6(4), 12(1), 12(2), 13(3), 14(3), 14(4), 16, 19(1), 25(1), 26(1), 26(2), 26(5), 26(6), 27(1), 49(2); Annex III(5)(b); Recitals (53) and (58).
  • DORA: Articles 3(19), 28(1), 28(7), 28(8), 30(1), 30(2), 30(3).
  • GDPR: Articles 4(4), 4(8), 28(2), 28(3), 28(10), 33(2).
  • A few pinpoints were cited without being passed to verify_citation, but their text was read directly: AI Act Articles 6(2), 12(3), 13(1), 14(1) and 26(9), DORA Article 28(4), and GDPR Article 4(7).
  • Neither of the two identifiers the tool returned needs fixing: GDPR Art. 4(4)/(8) and DORA Art. 3(19) resolve to "Article 4/3, amendment (n)", which is how the tool labels definition points.
  • The customer's questionnaire cites no articles, so there were none of theirs to check.

I did not record any applicability verdicts with record_assessment. The playbook says to do that only after a compliance officer states applicability, and none was present for this run.

Start it yourself

Connect Rekvira to Claude, ChatGPT or Cursor (one step, no account), then paste this and add your facts:

Use Rekvira to answer this customer's AI due-diligence questionnaire. Tie each answer to the article it rests on and flag the facts we have to supply.

Where you decide

  • After vendor-ai-questionnaire: Supply the company facts the draft answers flag (role, logging period, oversight set-up).

What comes back

  1. Answer per question, with the article it rests on
  2. Facts the company must supply
  3. Questions the held text does not answer
  4. Citations checked

How it keeps it defensible

  • Every answer carries at least one pinpoint or says 'not found in held text'
  • Every pinpoint is checked with verify_citation
  • Flags each place where a company fact, not the law, decides the answer

What it will not do

  • Tick a 'compliant' box on your behalf
  • Invent company facts: they are flagged for you to fill in
  • Answer from memory where the held text is silent

Recorded on the live Rekvira service on 23 September 2026 without an account, with the job's playbooks named in the prompt. The prompt, every tool call and the finished text are stored as recorded; tool results above are shortened. The scenario is illustrative.