Discovery, Risk and Impact Assessment
Visibility and Foundational Layer“You cannot manage what you cannot see.”
Core Components & Advisory Scope
- AI Inventory: Recording every AI system in the organisation — in-house models, SaaS, open source, agentic AI, shadow AI and APIs — in an ISO/IEC 42001 aligned register.
- Use Cases & Risk Classification: Classifying use cases such as chatbots, fraud detection and document intelligence as low, medium, high or prohibited under the EU AI Act.
- AI Impact Assessment: Evaluating legal (GDPR/IP), ethical (bias/transparency), security (prompt injection/poisoning) and operational impacts.
- Regulatory Mapping & Data Assessment: Mapping obligations across the EU AI Act, ISO 42001, NIST AI RMF, GDPR and DORA, plus data quality and lineage analysis.
- Maturity Assessment: Determining the organisation's AI governance maturity across ten distinct dimensions.
Governance deliverables: Corporate AI Inventory, AI Risk Matrix, AI Impact Assessment Report, Regulatory Compliance Matrix, AI Maturity Report.
ISO/IEC 42001EU AI ActNIST AI RMF