0.1.0 - ci-build

TrustAITransparencyIG - Local Development build (v0.1.0) built by the FHIR (HL7® FHIR® Standard) Build Tools. See the Directory of published versions

Requirements Traceability

This page renders the requirement analysis that underlies this Implementation Guide. It traces every legal documentation requirement from the EU AI Act, the GDPR, and the European Health Data Space (EHDS) to the FHIR profile element that represents it.

The content is taken from the project's documentation matrices (doc/documentation_matrices.xlsx in the source repository). The requirement texts are reproduced as they appear in the matrices. The FHIR Mapping and Status columns were added to link each requirement to this IG's artifacts.

How to Read This Page

  1. The Requirements Matrix lists the high-level requirements, grouped by category (System, Purpose, Performance, Risks, Oversight, Legal). It also shows whether each one is static, meaning it describes the AI system, or dynamic, meaning it is documented for each AI execution or decision.
  2. The three Logical Data Models break the requirements down into logical attributes with multiplicities. There is one model per architectural layer of the IG.
  3. Each attribute links to the profile element that implements it. The same requirement information also appears on each profile page.

Status legend:

  • ✅ Covered: the requirement is represented by a dedicated, constrained element.
  • ⚠️ Partial: the requirement is represented, but only as narrative, with weaker cardinality than the matrix requires, or without an enforcing invariant.
  • ❌ Not modelled: the requirement is not yet represented in the current profiles.

Coverage Summary

Layer Attributes ✅ Covered ⚠️ Partial ❌ Not modelled
Static System Context 36 30 6 0
AI Output Context 12 10 1 1
Clinical Decision Context (Human-in-the-Loop) 9 6 3 0
Total 57 46 10 1

Requirements Matrix

High-level documentation requirements derived from the legal sources.

ID Category Requirement (Law / Source) Metadata Field Description Static / Dynamic Implemented in Status
SYS-01 System AI Act Annex IV 1 System Name & Version The exact commercial name and version number of the AI model. Static Trust_AIDevice
Details: SYS-01.1, SYS-01.2
✅ Covered
SYS-02 System GDPR Art. 13 / AI Act Annex IV 1 Manufacturer / Provider Name and contact details of the legal entity responsible for the AI. Static Trust_AIDevice
Trust_AIOrganization
Details: SYS-02.1, SYS-02.2
✅ Covered
SYS-03a System AI Act Art. 47 EU Declaration of Conformity URI/Link to the combined machine-readable EU Declaration of Conformity Static Trust_AIDevice
Details: SYS-03a
✅ Covered
SYS-03b System AI Act Art. 48 Digital CE Marking & Notified Body ID Boolean flag for the presence of the digital CE mark and the 4-digit ID of the Notified Body. Static Trust_AIDevice
Details: SYS-03b.1, SYS-03b.2
✅ Covered
SYS-03c System AI Act Art. 15 Cybersecurity Status Reference/URI to the specific cybersecurity testing report, applied standards, or security architecture document. Static Trust_AIDevice
Details: SYS-03c
⚠️ Partial
SYS-04 System AI Act Annex IV 1 Hardware/Software Interfaces Required technical specifications to run the AI. Static Trust_AIModelCard
Details: SYS-04
✅ Covered
SYS-05 System AI Act Art. 11 / Annex IV Full Technical Documentation Ref. A URI/link to the complete, unabridged technical documentation. Static Trust_AIModelCard
Details: SYS-05
✅ Covered
SYS-06 System AI Act Art. 13(3) Explainability / Interpretation Aids Description or links to tools provided to the user to understand the output. Static Trust_AIModelCard
Details: SYS-06
✅ Covered
SYS-07 System AI Act Art. 13(3) Expected Lifetime & Maintenance Information on how long the model is valid and when software updates are required. Static Trust_AIDevice
Trust_AIModelCard
Details: SYS-07.1, SYS-07.2
✅ Covered
SYS-08 System GDPR Art. 13(1) DPO Contact Details Email or phone number of the Data Protection Officer for patient inquiries. Static Trust_AIOrganization
Details: SYS-08
✅ Covered
SYS-09 System GDPR Art. 35 DPIA (Data Protection Impact Assessment) Link to the formal privacy assessment document. Static Trust_AIOrganization
Details: SYS-09
✅ Covered
SYS-10 System AI Act Art. 12 / EHDS ANNEX II (3) Audit Trail & Access Logging System-level logs of who accessed the AI and when. Dynamic Trust_AIAuditEvent
Trust_AIProvenance
Trust_AIObservation
Details: SYS-10.1, SYS-10.2, SYS-10.3
✅ Covered
SYS-11 System AI Act Art. 49 EU Database Registration ID The unique registration number of the high-risk AI system in the official EU database. Static Trust_AIDevice
Details: SYS-11
✅ Covered
SYS-12 System AI Act Art. 17 QMS Certification Reference to the established Quality Management System. Static Trust_AIDevice
Trust_AIOrganization
Details: SYS-12
✅ Covered
USE-01 Purpose AI Act Art. 13 (3) / GDPR Art. 5 Intended Purpose A concise, medically and legally binding description of what the AI is certified to do. Static Trust_AIDevice
Details: USE-01.1, USE-01.2
✅ Covered
USE-02 Purpose AI Act Art. 13 (3) Limitations & Contraindications Specific scenarios or patient conditions where the AI must NOT be used. Static Trust_AIModelCard
Details: USE-02.1, USE-02.2
⚠️ Partial
USE-03 Purpose GDPR Art. 13(1) / AI Act Art. 13 (3) Scope and Clinical Consequences What clinical impact the AI's decision has on the patient. Static Trust_AIModelCard
Details: USE-03
✅ Covered
USE-04 Purpose GDPR Art. 5(1) Case-Specific Indication The actual clinical reason why the AI was used for this patient. Dynamic Trust_AIProvenance
Details: USE-04
✅ Covered
QUAL-01 Performance AI Act Art. 13(3) Performance Metrics Quantitative metrics and robustness and overall accuracy. Static Trust_AIModelCard
Details: QUAL-01.1, QUAL-01.2
✅ Covered
QUAL-02a Performance AI Act Art. 10 Training Data Info Details on the dataset used for training, including its origin Static Trust_AIModelCard
Details: QUAL-02a
✅ Covered
QUAL-02b Performance EHDS Art. 512 Secondary Use Category & Permit Identification of the data category and reference to the required Data Permit for training/validation. Static Trust_AIModelCard
Details: QUAL-02b, QUAL-02c
✅ Covered
QUAL-03 Performance EHDS Art. 78 Data Quality Label A standardized label indicating the structural quality and representativeness of the training data. Static Trust_AIModelCard
Details: QUAL-03
⚠️ Partial
QUAL-04 Performance AI Act Art. 13(3)(b)(v) Target Group Performance Known performance variations across different demographics. Static Trust_AIModelCard
Details: QUAL-04
✅ Covered
RISK-01 Risks AI Act Art. 9(2) / Art. 13(3)(b) Health & Fundamental Rights Risks Risk Management Report and the specific section in the Instructions for Use regarding residual risks. Static Trust_AIModelCard
Details: RISK-02.1, RISK-02.2, RISK-02.3
⚠️ Partial
HL-01 Oversight AI Act Art. 14(1) Responsible Actor (User) Infos form the specific human who reviewed the AI's output for this patient. Dynamic Trust_AIHumanOversightAssessment
Trust_AIPractitionerRole
Details: HL-01
✅ Covered
HL-02 Oversight AI Act Art. 14(5) Qualification of Actor The medical specialty or required training level of the reviewing human. Dynamic Trust_AIPractitionerRole
Details: HL-02.1, HL-02.2
⚠️ Partial
HL-03 Oversight AI Act Art. 14(4) Type of Intervention A forced dropdown indicating the human's action. Dynamic Trust_AIHumanOversightAssessment
Details: HL-03.1, HL-03.2
⚠️ Partial
HL-04 Oversight AI Act Art. 14(3) Oversight Instructions Instructions for the human reviewer on how to correctly interpret and supervise the AI output. Static Trust_AIModelCard
Details: HL-04
✅ Covered
HL-05 Oversight AI Act Art. 14(4)(c) Specific Evidence Shown Reference to the specific explanation or interpretability tool provided to the human reviewer to support oversight. Dynamic Trust_AIHumanOversightAssessment
Details: HL-05
✅ Covered
LAW-01a Legal GDPR Art. 6(1) Legal Basis (General) The GDPR basis used and confirmation that the patient received the required info. Dynamic Trust_AIProvenance
Trust_AIPatientExplanation
Details: LAW-01a, LAW-01c
✅ Covered
LAW-01b Legal GDPR Art. 9(2) Health Data Exception The GDPR basis used and confirmation that the patient received the required info. Dynamic Trust_AIProvenance
Trust_AIPatientExplanation
Details: LAW-01b, LAW-01c
✅ Covered
LAW-02 Legal GDPR Art. 22 Automated Decision Flag A Boolean flag indicating if the decision was made solely by the AI without human intervention. Dynamic Trust_AIProvenance
Details: LAW-02
✅ Covered
LAW-03 Legal EHDS Art. 51 / 52 Data Provenance (Primary/Secondary) Flag indicating if input data is primary or secondary use Dynamic Trust_AIProvenance
Details: LAW-03.1, LAW-03.2
✅ Covered
LAW-04 Legal GDPR Art. 13(1)(f) / Art. 44 Third-Country Data Transfer Flag/location indicating if data leaves the EU. Static Trust_AIDevice
Details: LAW-04.1, LAW-04.2
✅ Covered
LAW-05 Legal EHDS Art 71 Patient Opt-Out Flag Indicates if the specific patient has opted out of secondary use for their data. Dynamic —
Details: LAW-05
❌ Not modelled
LAW-06 Legal GDPR Art. 13(2) Data Retention Period How long the generated data/images will be stored before deletion. Static Trust_AIModelCard
Details: LAW-06
✅ Covered
LAW-07 Legal AI Act Art. 86 Right to Explanation Flag indicating if the patient requested or was provided an individual explanation. Dynamic Trust_AIPatientExplanation
Details: LAW-07.1, LAW-07.2, LAW-07.3
⚠️ Partial
LAW-08 Legal AI Act Art. 12(3) Log Integrity Operation/Monitoring Log Dynamic Trust_AIAuditEvent
Details: LAW-08
⚠️ Partial

Logical Data Models

The logical data models refine the requirements into attributes with multiplicities. Each model corresponds to one architectural layer of the IG.

Static System Context

Profiles in this layer: Trust_AIDevice, Trust_AIOrganization, Trust_AIModelCard.

ID Logical Attribute Card. Description / Value Set Rationale FHIR Mapping Status
SYS-01.1 System Name 1..1 The exact commercial name of the AI model. Traceability, clear identification. Trust_AIDevice: Device.name ✅ Covered
SYS-01.2 System Version 1..1 The specific version number of the AI model. AI Act compliance, version control, lifecycle tracking. Trust_AIDevice: Device.version ✅ Covered
SYS-02.1 Manufacturer Name 1..1 Name of the legal entity responsible for the AI. Accountability, provider identification. Trust_AIDevice: Device.manufacturer, Device.owner
owner references the responsible Trust_AIOrganization.
✅ Covered
SYS-02.2 Manufacturer Contact Details 1..* Official contact channels (email, phone) for the manufacturer. GDPR transparency, incident reporting routing. Trust_AIOrganization: Organization.contact:officialContact
Reached from the Device via Device.owner.
✅ Covered
SYS-03a EU Declaration of Conformity 1..1 URI/Link to the combined machine-readable EU Declaration of Conformity. Regulatory compliance verification. Trust_AIDevice: Device.extension:conformityDeclaration
Extension trust-ai-conformity-reference → DocumentReference of the declaration.
✅ Covered
SYS-03b.1 CE Marking Flag 1..1 Flag indicating the presence of a valid CE mark. Legal market access verification. Trust_AIDevice: Device.property:ceMark ✅ Covered
SYS-03b.2 Notified Body ID 0..1 The 4-digit ID of the Notified Body (if applicable). Certification tracking, Notified Body traceability. Trust_AIDevice: Device.property:notifiedBody ✅ Covered
SYS-03c Cybersecurity Status 1..1 Reference to cybersecurity testing report or security architecture. System security, cyber resilience evidence. Trust_AIDevice: Device.conformsTo
No dedicated element; applied security standards can be listed in conformsTo, but a reference to the cybersecurity test report is not modelled.
⚠️ Partial
SYS-04 Hardware/Software Interfaces 1..* Required technical specifications (e.g., PACS version, GPU limits). Safe operation parameters, interoperability. Trust_AIModelCard: DocumentReference.content.attachment
Documented in the linked technical documentation.
✅ Covered
SYS-05 Full Technical Doc. Ref. 1..1 A URI/link to the complete, unabridged technical documentation. Transparency, exhaustive system documentation. Trust_AIModelCard: DocumentReference.content.attachment
attachment.url points to the full technical documentation.
✅ Covered
SYS-06 Explainability/Interpretation Aids 0..* Description or links to tools provided to understand the output. Explainability, mitigating automation bias. Trust_AIModelCard: DocumentReference.content.attachment ✅ Covered
SYS-07.1 Expected Lifetime 1..1 Information on how long the model's clinical validity is guaranteed. Lifecycle management, system deprecation warnings. Trust_AIDevice: Device.property:expectedLifetime ✅ Covered
SYS-07.2 Maintenance Requirements 1..1 Information on required software updates and maintenance cycles. Maintaining safety and performance over time. Trust_AIDevice: Device.conformsTo
Trust_AIModelCard: DocumentReference.content.attachment
Maintenance and update requirements are part of the technical documentation.
✅ Covered
SYS-08 DPO Contact Details 1..1 Email or phone number of the Data Protection Officer. Patient rights facilitation, GDPR communication. Trust_AIOrganization: Organization.contact:dpo ✅ Covered
SYS-09 DPIA Reference 0..1 Link to the formal Data Protection Impact Assessment document. Privacy risk management, GDPR accountability. Trust_AIOrganization: Organization.extension:DPIAReference
Extension trust-ai-dpia-reference.
✅ Covered
SYS-11 EU Database Registration ID 1..1 Unique registration number of the high-risk AI system in the EU database. High-risk AI traceability, public registry alignment. Trust_AIDevice: Device.identifier:euDatabaseId ✅ Covered
SYS-12 QMS Certification 1..1 Reference to the established Quality Management System (e.g., ISO 13485). Quality assurance, medical device standard compliance. Trust_AIDevice: Device.conformsTo
Trust_AIOrganization: Organization.contact:incident
QMS certification in conformsTo; the AI incident reporting contact supports the QMS.
✅ Covered
USE-01.1 Medical Purpose Description 1..1 Concise description of what the AI is certified to do. Purpose limitation, clinical boundary definition. Trust_AIDevice: Device.property:intendedPurpose ✅ Covered
USE-01.2 Intended Target Population 1..* Specific demographic or clinical group the AI is certified for. Safe use enforcement, preventing off-label use. Trust_AIDevice: Device.property:targetPopulation ✅ Covered
USE-02.1 Medical Contraindications 0..* Patient conditions where the AI must NOT be used. Patient safety, clinical contraindication enforcement. Trust_AIModelCard: DocumentReference.description, DocumentReference.content.attachment
Narrative only; no coded, repeatable contraindication element.
⚠️ Partial
USE-02.2 Technical Limitations 0..* Technical constraints (e.g., specific image modalities) leading to invalid results. Operational safety, ensuring input data quality. Trust_AIModelCard: DocumentReference.description, DocumentReference.content.attachment
Narrative only; no coded, repeatable limitation element.
⚠️ Partial
USE-03 Scope and Clinical Consequences 1..1 Clinical impact the AI's decision has on the patient. Clinical impact transparency. Trust_AIModelCard: DocumentReference.description ✅ Covered
QUAL-01.1 Metric Type Code 1..* Identifying the type of performance metric (e.g., Sensitivity, AUC). Standardized evaluation. Trust_AIModelCard: DocumentReference.extension:performance
Sub-extension metric.type (TrustAIPerformanceMetricVS).
✅ Covered
QUAL-01.2 Metric Value 1..* The corresponding numeric value for the specific metric. Quantitative system accuracy visibility. Trust_AIModelCard: DocumentReference.extension:performance
Sub-extension metric.value (Quantity).
✅ Covered
QUAL-02a Data Provenance Description 1..1 Details on the origin and distribution of the training dataset. Data provenance, assessing training bias. Trust_AIModelCard: DocumentReference.extension:training
Sub-extension provenance.
✅ Covered
QUAL-02b EHDS Data Category 0..* Identification of the data category used for training. EHDS secondary use compliance. Trust_AIModelCard: DocumentReference.extension:training
Sub-extension Category (DataCategoryVS).
✅ Covered
QUAL-02c Training Data Permit Ref. 0..* Reference to the Data Permit ID used to access data for training. Legal authorization tracking. Trust_AIModelCard: DocumentReference.extension:training
Sub-extension Permit (Identifier).
✅ Covered
QUAL-03 Data Quality Label 1..1 Standardized label indicating the structural quality of training data. Data standard assessment. Trust_AIModelCard: DocumentReference.extension:training
Sub-extension dataQuality is 0..*, while the matrix requires 1..1.
⚠️ Partial
QUAL-04 Target Group Performance 0..* Known performance variations across different demographics. Fairness, demographic bias disclosure. Trust_AIModelCard: DocumentReference.extension:performance
Sub-extension biasDisclosure.
✅ Covered
RISK-02.1 Health/Safety Risks 0..* Identified clinical risks to patient health if the AI fails. Clinical safety awareness. Trust_AIModelCard: DocumentReference.description
Narrative summary only.
⚠️ Partial
RISK-02.2 Fundamental Rights Risks 0..* Identified risks concerning bias, discrimination, or privacy. Fundamental rights protection. Trust_AIModelCard: DocumentReference.description
Narrative summary only.
⚠️ Partial
RISK-02.3 Residual Risk Mitigation 1..1 Reference to Instructions for Use (IfU) detailing risk mitigation. Legal compliance, actionable risk management. Trust_AIModelCard: DocumentReference.content.attachment
Instructions for use / risk management documentation.
✅ Covered
HL-04 Oversight Instructions 1..1 Instructions for the human reviewer on how to supervise the AI. Human-in-the-loop enablement. Trust_AIModelCard: DocumentReference.content.attachment ✅ Covered
LAW-04.1 Third-Country Transfer Flag 1..1 Flag indicating if data leaves the EU. Data sovereignty. Trust_AIDevice: Device.extension:dataTransfer
Sub-extension transferFlag.
✅ Covered
LAW-04.2 Destination Country 0..* The specific country outside the EU where data is transferred. Assessing adequacy decisions per GDPR. Trust_AIDevice: Device.extension:dataTransfer
Sub-extension destinationCountry (ISO 3166).
✅ Covered
LAW-06 Data Retention Period 1..1 How long the generated data will be stored before deletion. Storage limitation, GDPR data minimization. Trust_AIModelCard: DocumentReference.extension:privacy
Sub-extension retention (Duration).
✅ Covered

AI Output Context

Profiles in this layer: Trust_AIObservation, Trust_AIProvenance, Trust_AIAuditEvent.

ID Logical Attribute Card. Description / Value Set Rationale FHIR Mapping Status
SYS-10.1 Execution Period (Start/End) 1..1 Exact timestamp of AI invocation and completion. Traceability, precise operational logging of the AI event. Trust_AIAuditEvent: AuditEvent.occurredPeriod
Trust_AIProvenance: Provenance.occurredPeriod
Trust_AIObservation: Observation.effective[x]
✅ Covered
SYS-10.2 Input Data Reference 1..* Links to the specific patient data (e.g., ImagingStudy, Observation) processed by the AI. Traceability of inputs, crucial for reproducibility and error analysis. Trust_AIProvenance: Provenance.entity
entity.role = source.
✅ Covered
SYS-10.3 Reference Database 0..* Identification of specific reference databases or versions the system checked against during execution. Contextual operation logging, verifying the data basis of the execution. Trust_AIAuditEvent: AuditEvent.entity:referenceDb ✅ Covered
USE-04 Case-Specific Indication 1..* The actual clinical reason why the AI was used for this specific patient encounter. Clinical justification, ensuring adherence to the intended purpose (Purpose Limitation). Trust_AIProvenance: Provenance.extension:caseIndication
Extension case-specific-indication.
✅ Covered
LAW-01a Legal Basis Code 1..1 The GDPR basis used Lawfulness of processing, fundamental GDPR compliance. Trust_AIProvenance: Provenance.authorization:gdprArt6Basis
GDPRArt6LegalBasisVS.
✅ Covered
LAW-01b Special Category Exception Code 1..1 The GDPR exception used for processing sensitive health data. Lawfulness of processing special categories of personal data. Trust_AIProvenance: Provenance.authorization:gdprArt9Condition
GDPRArt9ConditionVS.
✅ Covered
LAW-01c Patient Info Provided Flag 1..1 Confirmation (Flag) or Link to the consent/information form proving the patient was informed about the AI use. Fulfilling transparency and information duties towards the data subject. Trust_AIPatientExplanation: Communication.extension:aifInfoProvided
Extension patient-ai-info-provided-flag.
✅ Covered
LAW-02 Automated Decision Flag 1..1 A flag indicating if the decision was made solely by the AI without human intervention. Tracking automated decision-making restrictions, safeguarding fundamental rights. Trust_AIProvenance: Provenance.extension:automatedDecision
Extension automated-decision-flag.
✅ Covered
LAW-03.1 Provenance Category 1..1 Value Set: Primary Care, Secondary Use. EHDS data origin tracking, context separation. Trust_AIProvenance: Provenance.extension:usageCategory
UsageCategoryVS.
✅ Covered
LAW-03.2 Data Permit Reference 0..1 The unique ID of the permit issued by a Health Data Access Body (only required if Provenance is 'Secondary Use'). Legal authorization tracking for secondary use of health data. Trust_AIProvenance: Provenance.extension:dataPermit
Complemented by secondaryUsePurpose.
✅ Covered
LAW-05 Patient Opt-Out Flag 1..1 Indicates if the specific patient has opted out of secondary use for their data. Patient autonomy, enforcement of EHDS opt-out rights. —
The Consent profile was removed; the patient opt-out is currently not represented.
❌ Not modelled
LAW-08 Log Integrity 1..1 Verification hash or cryptographic signature to ensure logs have not been tampered with. Tamper-proof logging, ensuring accountability and non-repudiation. Trust_AIAuditEvent: AuditEvent.extension:logIntegrity
Extension trust-ai-log-integrity is 0..1, while the matrix requires 1..1.
⚠️ Partial

Clinical Decision Context (Human-in-the-Loop)

Profiles in this layer: Trust_AIHumanOversightAssessment, Trust_AIPractitionerRole, Trust_AIPatientExplanation.

ID Logical Attribute Card. Description / Value Set Rationale FHIR Mapping Status
HL-01 Actor Reference 1..* Information identifying the specific human (e.g., Practitioner) who reviewed the AI's output. Human-in-the-loop accountability, identifying the final decision-maker. Trust_AIHumanOversightAssessment: ArtifactAssessment.content.author
Trust_AIPractitionerRole: PractitionerRole.practitioner
✅ Covered
HL-02.1 Actor Specialty Code 1..* The medical specialty or required training level of the reviewing human. Competence verification, ensuring the reviewer is qualified to oversee the specific AI. Trust_AIPractitionerRole: PractitionerRole.specialty ✅ Covered
HL-02.2 System-Specific Training Flag 1..1 Flag indicating whether the actor has received specific training for this exact AI tool. Ensuring competence, mitigating automation bias through adequate preparation. Trust_AIPractitionerRole: PractitionerRole.extension:trainingStatus
Extension ai-system-training-status is 0..1, while the matrix requires 1..1.
⚠️ Partial
HL-03.1 Intervention Action Code 1..1 Value Set: validation, override, correction Structured documentation of the human oversight outcome. Trust_AIHumanOversightAssessment: ArtifactAssessment.content.classifier
TrustAIHumanOversightActionVS.
✅ Covered
HL-03.2 Intervention Rationale 0..1* Medical or technical justification for overriding or ignoring the AI's output. (*1..1 required if Action is 'Overridden' or 'Ignored'). Traceability of clinical decisions, liability assessment, feedback loop for AI monitoring. Trust_AIHumanOversightAssessment: ArtifactAssessment.content.summary
The conditional 1..1 (for override) is not yet enforced by an invariant.
⚠️ Partial
HL-05 Specific Evidence Shown 0..* Reference to the specific explanation, heatmap, or interpretability tool provided to support oversight. Tracing the basis of the human decision, verifying explainability tools were actually utilized. Trust_AIHumanOversightAssessment: ArtifactAssessment.content.relatedArtifact ✅ Covered
LAW-07.1 Explanation Requested Flag 1..1 Flag indicating if the patient explicitly requested a clear and meaningful explanation of the AI's role. Patient rights fulfillment, tracking requests for transparency. Trust_AIPatientExplanation: Communication.about
about identifies the decision to be explained; an explicit "explanation requested" flag is not modelled.
⚠️ Partial
LAW-07.2 Explanation Provided Ref. 0..1 Reference to the document or log containing the actual, patient-friendly explanation provided. Documenting the fulfillment of the right to explanation. Trust_AIPatientExplanation: Communication.payload ✅ Covered
LAW-07.3 Date of Explanation 0..1 Timestamp of when the explanation was provided to the patient. Verification of timely response to patient rights requests. Trust_AIPatientExplanation: Communication.sent ✅ Covered

Open Points

The following attributes of the logical models are only partially covered or not yet represented by the current profiles:

  • SYS-03c (Cybersecurity Status): ⚠️ Partial. No dedicated element; applied security standards can be listed in conformsTo, but a reference to the cybersecurity test report is not modelled.
  • USE-02.1 (Medical Contraindications): ⚠️ Partial. Narrative only; no coded, repeatable contraindication element.
  • USE-02.2 (Technical Limitations): ⚠️ Partial. Narrative only; no coded, repeatable limitation element.
  • QUAL-03 (Data Quality Label): ⚠️ Partial. Sub-extension dataQuality is 0..*, while the matrix requires 1..1.
  • RISK-02.1 (Health/Safety Risks): ⚠️ Partial. Narrative summary only.
  • RISK-02.2 (Fundamental Rights Risks): ⚠️ Partial. Narrative summary only.
  • LAW-05 (Patient Opt-Out Flag): ❌ Not modelled. The Consent profile was removed; the patient opt-out is currently not represented.
  • LAW-08 (Log Integrity): ⚠️ Partial. Extension trust-ai-log-integrity is 0..1, while the matrix requires 1..1.
  • HL-02.2 (System-Specific Training Flag): ⚠️ Partial. Extension ai-system-training-status is 0..1, while the matrix requires 1..1.
  • HL-03.2 (Intervention Rationale): ⚠️ Partial. The conditional 1..1 (for override) is not yet enforced by an invariant.
  • LAW-07.1 (Explanation Requested Flag): ⚠️ Partial. about identifies the decision to be explained; an explicit "explanation requested" flag is not modelled.

In addition, the IG contains elements that go beyond the matrices, such as the AI-involvement flag in Observation.interpretation and the resource-independent TrustAIData security label.