All services

AI systems audit

Which AI your company runs, under which legal role, and what risk class each system falls into.

What you get
Systems inventory + risk classification + gap report
Timeline
7–10 working days
Who it is for
Companies already running AI internally or customer-facing, with no formal inventory.

The duty

Anexo III

High-risk systems

Recruitment, credit, education, biometrics. Point 4 covers employment — the one that catches HR software.

Applies from 2 December 2027 · deferred from 2 August 2026

Almost no company knows how many AI systems it is running. There are usually more than the vendor contract shows: browser extensions, AI features switched on by default in tools you already paid for, models someone stood up over a weekend. The audit starts there, because you cannot classify what is not listed.

What it includes

  • Inventory of AI systems, including the ones nobody registered
  • Role per system: provider, deployer, or both
  • Preliminary risk classification citing the applicable article or annex
  • Gap report prioritised by the date each duty bites
  • 60-minute session walking through the findings

How it runs

  1. Discovery

    Short interviews per area, plus contract and SaaS-access review. Nothing to install.

  2. Classification

    Each system against the text, with the specific citation. What is unclear is marked unclear.

  3. Report

    Gaps ordered by date, not by theoretical severity. What bites soonest comes first.

What it is not

Saying this before you sign avoids the awkward conversation after.

  • Not a certification. The AI Act has none, and anyone selling you one is selling smoke.
  • Not legal advice unless a qualified lawyer reviews and signs the work.
  • Not a substitute for the conformity assessment Annex III will require once applicable.

Is this the one you need?

Twenty minutes to confirm scope. If this service is not what you need, we say so there.

Book 20 minutes

If you need none of these services, we will tell you on the call.