Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Compliance13 services in this practice area

Get Ready for AI Regulation

EU AI Act Readiness and AI Regulation Compliance

The EU AI Act is the world's first broad law for artificial intelligence. We help you classify your AI systems, meet the duties for their risk level, and prepare for the deadlines.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

The EU AI Act regulates AI by risk. It bans a small set of practices, places heavy duties on high-risk systems, sets transparency rules for others, and adds obligations for general-purpose AI models. It matters because it reaches providers and deployers who touch the EU market, and its obligations phase in over the coming years with real penalties. We help you inventory and classify your AI, understand what each system must do, and build the technical documentation and oversight the Act requires.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the EU AI Act engagement, 6 phases in order, each one selectable. Phase 1, AI Inventory and Classification. We list your AI systems and classify each one by the Act's risk tiers, from prohibited to minimal risk. Activities: Inventory AI systems and models in use; Classify each against the Act's risk tiers; Confirm provider or deployer role per system; Flag anything close to a prohibited practice. Hands over AI System Inventory and Classification Register. Phase 2, Obligation Mapping. We map the specific duties for each system, whether it is high-risk, limited-risk, or a general-purpose model. Activities: Map high-risk duties to affected systems; Identify transparency obligations for limited-risk systems; Assess general-purpose model obligations; Match each duty to its enforcement deadline. Hands over Obligation Mapping Report. Phase 3, Gap Assessment. We measure your current practices against those duties and give you a prioritised roadmap to the deadlines. Activities: Assess current governance against each duty; Review data, documentation, and oversight practices; Rank gaps by deadline and enforcement risk; Build the remediation roadmap. Hands over Gap Assessment and Compliance Roadmap. Phase 4, Documentation and Oversight Design. We help you build the technical documentation, risk management, and human oversight high-risk systems need. Activities: Draft Annex IV technical documentation; Design the AI risk management process; Define human oversight measures per system; Prepare conformity assessment groundwork. Hands over Technical Documentation Pack and Oversight Design. Phase 5, Implementation Support. We help you embed transparency notices, logging, and monitoring across the relevant systems. Activities: Deploy transparency notices for AI interactions; Implement event logging on high-risk systems; Set up post-market monitoring processes; Train teams on the new obligations. Hands over Implemented Transparency, Logging, and Monitoring Controls. Phase 6, Readiness Review. We run a review so you can show a customer or a regulator that your AI governance is on track. Activities: Verify each obligation against implemented controls; Test documentation completeness per system; Compile the compliance evidence pack; Set the cadence for tracking new guidance. Hands over EU AI Act Readiness Report. Each phase begins from the artefact the phase before it produced.

Phase 01 AI Inventory and Classification

We list your AI systems and classify each one by the Act's risk tiers, from prohibited to minimal risk.

What Happens In This Phase

  • Inventory AI systems and models in use
  • Classify each against the Act's risk tiers
  • Confirm provider or deployer role per system
  • Flag anything close to a prohibited practice

The Handover

AI System Inventory and Classification Register

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    AI Inventory and Classification

    We list your AI systems and classify each one by the Act's risk tiers, from prohibited to minimal risk.

    OutputAI System Inventory and Classification Register

    Activities

    • Inventory AI systems and models in use
    • Classify each against the Act's risk tiers
    • Confirm provider or deployer role per system
    • Flag anything close to a prohibited practice
  2. 02

    Obligation Mapping

    We map the specific duties for each system, whether it is high-risk, limited-risk, or a general-purpose model.

    OutputObligation Mapping Report

    Activities

    • Map high-risk duties to affected systems
    • Identify transparency obligations for limited-risk systems
    • Assess general-purpose model obligations
    • Match each duty to its enforcement deadline
  3. 03

    Gap Assessment

    We measure your current practices against those duties and give you a prioritised roadmap to the deadlines.

    OutputGap Assessment and Compliance Roadmap

    Activities

    • Assess current governance against each duty
    • Review data, documentation, and oversight practices
    • Rank gaps by deadline and enforcement risk
    • Build the remediation roadmap
  4. 04

    Documentation and Oversight Design

    We help you build the technical documentation, risk management, and human oversight high-risk systems need.

    OutputTechnical Documentation Pack and Oversight Design

    Activities

    • Draft Annex IV technical documentation
    • Design the AI risk management process
    • Define human oversight measures per system
    • Prepare conformity assessment groundwork
  5. 05

    Implementation Support

    We help you embed transparency notices, logging, and monitoring across the relevant systems.

    OutputImplemented Transparency, Logging, and Monitoring Controls

    Activities

    • Deploy transparency notices for AI interactions
    • Implement event logging on high-risk systems
    • Set up post-market monitoring processes
    • Train teams on the new obligations
  6. 06

    Readiness Review

    We run a review so you can show a customer or a regulator that your AI governance is on track.

    OutputEU AI Act Readiness Report

    Activities

    • Verify each obligation against implemented controls
    • Test documentation completeness per system
    • Compile the compliance evidence pack
    • Set the cadence for tracking new guidance

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

TrustGrid

Our own GRC platform. Control mapping, evidence collection, policy workflow and third-party risk, all in one place.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the EU AI Act scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: Credo AI, Holistic AI, OneTrust AI Governance, Vanta, Jira, Confluence, MLflow. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: EU AI Act, ISO/IEC 42001:2023, ISO/IEC 23894, NIST AI Risk Management Framework, EU AI Act harmonised standards.

What We Run

7 tools

  • Credo AI
  • Holistic AI
  • OneTrust AI Governance
  • Vanta
  • Jira
  • Confluence
  • MLflow

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • AI ACTEuropean Union
  • ISO/IEC 42001:2023
  • ISO/IEC 23894
  • NIST AI Risk Management Framework
  • AI ACTEuropean UnionHarmonised standards
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • AI system inventory and classification
  • Obligation mapping report
  • Gap assessment and roadmap
  • Technical documentation templates
  • Human oversight design

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

How does the EU AI Act classify AI systems?

By risk: prohibited, high-risk, limited-risk, and minimal-risk, with separate rules for general-purpose AI models. The classification decides which duties apply, so we start there.

When do the obligations take effect?

They phase in over several years, with prohibited practices first and high-risk duties later. We build a roadmap to the deadlines that matter to you.

How does the Act relate to ISO 42001?

ISO 42001 gives you a management system that supports many EU AI Act duties. It is not automatic compliance, but it is a strong foundation, and we often pair them.

Keep Moving Through Compliance

Service 12 of 13 in this practice area