The AI Act has record-keeping duties.
Find out whether you can meet them.
Article 12 of the EU AI Act requires high-risk AI systems to automatically log inputs, outputs, and agentic actions with immutable audit trails. Most organizations discover they cannot produce that evidence during an assessment rather than before one. This review tells you where you stand against the AI Act, ISO/IEC 42001, and NIST AI RMF — with a gap register you can actually work through.
What you get, in writing
Every deliverable below is named in the statement of work. Nothing here is aspirational.
Gap register mapped to requirements
Every applicable article and control assessed, with its current state, the gap, a named owner, and the evidence needed to close it. Structured for an assessor to read directly.
AI system risk classification
Which of your AI systems fall into which risk tier under the AI Act, and which obligations follow from that — the question that determines how much of the regulation applies to you at all.
Record-keeping and traceability assessment
Whether your current logging can satisfy Article 12 record-keeping and Article 13 traceability: immutability, completeness of inputs and outputs, and retention.
Remediation roadmap
A sequenced plan with effort estimates, separating what is a tooling change, what is a policy change, and what needs an architectural decision.
A defined path, with a defined end
Scope
Agree which frameworks apply and which AI systems and data stores are in scope.
Assess
Requirement-by-requirement assessment against current controls, logging, and documentation.
Map evidence
Each gap is tied to the specific evidence that closes it, so remediation is verifiable rather than asserted.
Deliver
You receive the gap register and roadmap, and we walk your compliance and engineering owners through both.
This is for you if
- You operate AI systems that may be high-risk under the EU AI Act
- You are pursuing ISO/IEC 42001 certification and need a pre-assessment
- A customer contract now requires AI governance attestations
- Your AI systems read regulated data and nobody has mapped the obligations
Not sure it fits? Ask anyway — if it isn't a fit, we'll say so on the scope call.
Priced up front, quoted in 24 hours
Fixed fee per framework, with a reduced rate for additional frameworks assessed in the same engagement. Credited against a licence on conversion.
Get a Compliance QuoteGet a fixed-scope quote in 24 hours
Enter your business email. We'll come back within 24 hours with a written quote for AI Compliance Review — scope, price, and end date included.