← Q&A knowledge base
Obligations and evidence Updated 2026-08-28

What does Maditon produce once a system is classified?

A classification generates the complete obligation checklist for that risk tier, drawn from the regulation rather than a generic template. Each checklist item can carry evidence files, tracks its own status, and rolls up into an organisation-wide compliance dashboard and a list of urgent actions.

The classification is the input, not the deliverable. What it produces is a work list.

The obligation checklist. Every duty the tier triggers, as a discrete item you can close. A high-risk determination generates a long list — risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, registration. A transparency-only determination generates the Article 50 disclosure duties and little else. The list is derived from the classification, so it changes if the classification changes.

Evidence against each item. A checklist item without evidence is a claim. Attach the document, the screenshot, the policy, the test report — whatever substantiates it — and the item carries its proof.

A dashboard and an urgent-actions view. Across all systems: what is done, what is open, and what is time-critical.

The point of the structure is that on the day someone asks, you are not reconstructing a year of decisions from Slack and Drive. The work was recorded as it happened.

Related API endpoints

GET /api/compliance/dashboard bearer

Get the organisation compliance dashboard

GET /api/compliance/systems/{system_id} bearer

Get per-system compliance detail

GET /api/compliance/urgent-actions bearer

Get urgent compliance actions

PATCH /api/compliance/checklist-items/{item_id} bearer

Update a checklist item

Base URL https://api.maditon.app · full specification at openapi.json

Regulation references

Read next

A free Solo account runs a real classification on one of your own systems — no card, no sales call.

Run a free classification