Skip to content
AI ADOPTION
You don’t know where you stand on AI compliance.

AI Audit & Roadmap
AI Compliance Gap Analysis

ISO 42001 and the EU AI Act are setting concrete expectations — and most organisations have no clear picture of their current exposure or what needs to change. The audit closes that gap.
ISO 42001
Aligned framework
EU AI Act
Compliant approach
Senior partner
Every engagement
Day 1
Practical tools
Is this you?

AI Audit is right for you if…

You’ve heard about the EU AI Act but don’t know what applies to you

The regulation is in force. The risk classification system is complex. Most organisations can’t answer ‘which category are your AI systems in?’ — yet.

Your board has asked about AI risk and you don’t have a clear answer

Board and investor scrutiny of AI risk is increasing. A gap analysis provides the evidenced answer that reassures or redirects.

You want to get ahead of compliance before it becomes an enforcement issue

Proactive compliance costs a fraction of reactive compliance. The EU AI Act enforcement timelines are not distant — for high-risk systems, obligations are already live.
Results

What AI Audit & Roadmap delivers

01

Current AI exposure mapped

A complete inventory of your AI systems, their EU AI Act risk classification, and your current compliance status against each applicable requirement.
AI system inventory · Risk classification · Compliance status
02

Gaps identified and prioritised

The specific gaps between your current posture and regulatory requirements — ranked by risk level, regulatory urgency, and remediation effort.
Gap analysis · Priority matrix · Risk-ranked findings
03

Concrete compliance roadmap

A phased action plan to bring your organisation into alignment — with realistic timelines, resource estimates, and clear sequencing.
Compliance roadmap · Resource plan · Regulatory timeline
The process

How AI Audit & Roadmap works

01
Phase 1

Inventory & Classify

Audit of all AI systems in use across your organisation — discovered through structured interviews, system documentation, and shadow AI identification. Each system is classified under the EU AI Act risk framework.
02
Phase 2

Gap Analysis

Structured assessment of each AI system against ISO 42001 management system requirements and EU AI Act obligations. Every gap is documented with its regulatory basis and risk implication.
03
Phase 3

Roadmap & Summary

Prioritised compliance roadmap with phased actions, resource requirements, and regulatory deadlines. Executive summary formatted for board or investor presentation.
Deliverables

What you receive

✓ AI system inventory with risk classification
✓ Gap analysis report (per system, per requirement)
✓ Compliance risk map
✓ Prioritised compliance roadmap
✓ Executive summary (board-ready format)
Duration
Scoped per organisation (typically 4–8 weeks)
Scoped after the free diagnostic based on AI footprint size.
Our approach

Built on method, not instinct.

Our AI methodology is anchored in ISO/IEC 42001 (the international standard for AI management systems) and the EU AI Act risk framework. We translate regulatory requirements into practical, operational guidance — not legal abstractions. Every engagement is designed to build internal capability, not external dependency.

Frequently asked questions

How do we know which AI systems are in scope?

We conduct the inventory together — starting from known systems and systematically uncovering shadow AI use. Most organisations discover AI usage during this process that wasn’t formally tracked.

Is the EU AI Act already in force?

Yes. The EU AI Act entered into force in August 2024. High-risk system obligations are already live for some categories. The audit clarifies which timelines apply to your specific systems.

Can we use this audit to prepare for ISO 42001 certification?

Yes — the gap analysis is structured to map directly to ISO 42001 requirements, making it a natural first step toward certification.

What if our AI usage is limited?

Even limited AI usage has compliance implications under the EU AI Act. The audit will be proportionate to your actual footprint — and will give you clarity about where you are, not just where you should be.

How does this differ from AI Governance?

The audit tells you where you stand. AI Governance builds the structure to get you where you need to be. Many organisations run both — audit first to understand the gap, governance design to close it.
You might also need

Related services

AI Governance

Build the governance structure the audit defines.

AI Operational

Equip teams to operate safely within the roadmap.

Sprint RISK

Operationalise AI risk alongside your broader risk framework.

Start with a conversation.

The free diagnostic is half a day — on your premises, with your team. We identify where performance is leaking and what to do about it. No commitment. No ambiguity.
Book your free diagnostic