AI systems audit
Which AI your company runs, under which legal role, and what risk class each system falls into.
- What you get
- Systems inventory + risk classification + gap report
- Timeline
- 7–10 working days
- Who it is for
- Companies already running AI internally or customer-facing, with no formal inventory.
The duty
Anexo III
High-risk systems
Recruitment, credit, education, biometrics. Point 4 covers employment — the one that catches HR software.
Applies from 2 December 2027 · deferred from 2 August 2026
Almost no company knows how many AI systems it is running. There are usually more than the vendor contract shows: browser extensions, AI features switched on by default in tools you already paid for, models someone stood up over a weekend. The audit starts there, because you cannot classify what is not listed.
What it includes
- Inventory of AI systems, including the ones nobody registered
- Role per system: provider, deployer, or both
- Preliminary risk classification citing the applicable article or annex
- Gap report prioritised by the date each duty bites
- 60-minute session walking through the findings
How it runs
Discovery
Short interviews per area, plus contract and SaaS-access review. Nothing to install.
Classification
Each system against the text, with the specific citation. What is unclear is marked unclear.
Report
Gaps ordered by date, not by theoretical severity. What bites soonest comes first.
What it is not
Saying this before you sign avoids the awkward conversation after.
- Not a certification. The AI Act has none, and anyone selling you one is selling smoke.
- Not legal advice unless a qualified lawyer reviews and signs the work.
- Not a substitute for the conformity assessment Annex III will require once applicable.
Is this the one you need?
Twenty minutes to confirm scope. If this service is not what you need, we say so there.
If you need none of these services, we will tell you on the call.