Skip to Content
2 people sitting on chair near window during sunset
people sitting on chair inside building
A group of people working on computers in a room
person writing on white paper
person sitting in a chair in front of a man
a man standing on a ledge in front of a tall building

AI Act-audit 


Most organisations do not know precisely which AI systems are running inside their own walls, which risk category those systems fall into, or what evidence they could put before a regulator today. An audit answers those three questions.

Legal qualification by lawyers, technical assessment by our engineers.

 

How an audit works


01

Scope and inventory

Together we agree which legal entities, processes and systems the audit will cover.

We then map which AI systems your organisation develops, supplies or uses, including tools adopted outside official IT policy.

Data flows are inventoried as well.

02

Risk classification

Each system is classified under the risk categories of the EU AI Act, and your role for each system is established: provider or deployer.

Where an exemption appears to apply, we examine it and record the reasoning, whether or not it is upheld.

This qualification is provided by the affiliated lawyers, under their own professional indemnity insurance.

The result: a reasoned classification for each system.

03

Gap analysis and testing in practice

We compare current practice with the obligations that follow from the classification: risk management, data governance, technical documentation, logging, transparency, human oversight and accuracy.

Testing is based on observed behaviour, not on self-description. Does the person assigned to oversee the system have the time to do so? Are logs kept, and are they retained for long enough? Where does the data actually go?

Where relevant, we take the overlap with the GDPR into account.

04

Reporting and debrief

You receive an audit report setting out the findings, a risk assessment and a prioritised remediation plan. We then go through it with you.

The report is written so that you can share it with your board, your statutory auditor, your insurer or your bank.

The result: a report you can use to support decisions inside your organisation.


Practical details


Timeline

This depends on the scope: the number of legal entities, processes and AI systems the audit covers. We agree that scope in the scoping call, and only then do we confirm a timeline and a price. We do not start an audit with an open scope.

Who you will be speaking to

The lawyer who provides the qualification and the engineer who compiles the inventory. No intermediate layers.

Confidentiality

Professional secrecy for the legal work, contractual confidentiality for the technical work.

Access is limited to the agreed scope and ends when the engagement is complete.

Your sector

What falls within the scope of the EU AI Act differs considerably from one sector to the next.

In a bank, the line runs through the credit scoring environment. In manufacturing, it depends on whether a model is a safety component. We start from the systems that typically fall within scope in your sector, rather than from a general checklist.

See what applies in your sector →

After the audit


The remediation plan is yours. You can carry it out in-house, with your existing supplier, or with us.

For organisations that want to automate this work without their business data falling under non-EU jurisdiction, we are developing Thor. That is a separate engagement, not a required next step.

                                                                                                                                  Thor