Taking new engagements — Q4 hello@datadefenz.com Employee Login
ServicesAll servicesGRC & Compliance8Security Culture1Risk Management3Technical Security5Leadership Advisory1Fast-Turnaround1
ProductsResourcesPracticeAboutLet's Work TogetherBook a 30-minute callContact
Services / GRC & Compliance / EU AI Act & ISO/IEC 42001

EU AI Act Readiness & ISO/IEC 42001

The Act is 113 articles and 13 annexes. Most of it will never apply to you. We establish which parts do, prove it with evidence, and build the management system that keeps it true.

113articles and 13 annexes, mapped
247requirement rows in the master register
48evidence documents an auditor expects
36reporting and retention clocks

In plain terms

The EU AI Act is big on paper. One hundred and thirteen articles, thirteen annexes, a hundred and eighty recitals, and a set of deadlines that started passing in February 2025. Read end to end it is overwhelming, which is why most organisations either freeze or buy a policy template and hope.

Most of it will never apply to you. What you need is a defensible answer to three questions: which of our AI systems are in scope, what role do we hold for each one, and what must we be able to put in front of an auditor. Answer those three and the Act shrinks from 113 articles to a list you can actually work through — for most companies, somewhere between forty and a hundred and twenty requirements.

That is the whole approach. We scope first and write the reasoning down, because a classification you cannot defend is worse than no classification. Then we assess against the requirements that survived, evidence by evidence, and hand you a register with an owner and a date on every open row.

What you get

  • A documented scoping and role determination per AI system — deployer, provider, importer, distributor, authorised representative, GPAI provider — with the article reasoning behind each one, including the Article 25 traps that quietly turn a buyer into a provider
  • Classification against Annex III and Annex I, with the Article 6(3) exception argument written out where you rely on it
  • A requirement-level gap register: every applicable obligation, its current status, the evidence that proves it, the gap, the remediation action, the owner and the date
  • An evidence catalogue — the 48 documents an auditor expects, and which of them you already have under another name
  • Reporting clocks (Articles 73, 26(5), 50) folded into your existing incident process next to GDPR's 72 hours and NIS2's 24 and 72
  • A roadmap sequenced by legal deadline, not by what is convenient this quarter
  • Where you want certification: ISO/IEC 42001 management system design, internal audit, and support through the certification body's two stages

ISO/IEC 42001, and what it is honestly worth

ISO/IEC 42001:2023 is the AI management system standard, and it is the closest structural fit to what the AI Act asks an organisation to run. We build the AIMS around clauses 4 to 10 and the Annex A controls, draw on ISO/IEC 23894 for AI risk management and ISO/IEC 42005 for AI system impact assessment, and take it through internal audit to certification.

One thing we will not tell you is that the certificate makes you compliant. It does not. ISO/IEC 42001 is not a harmonised standard under Article 40, so it carries no presumption of conformity, and no certification body can grant you one. What it gives you is the governance backbone — ownership, a risk method, change control, an audit trail — that turns AI Act evidence into a by-product of how you already work, instead of a project you repeat from scratch every year.

You have already paid for most of this

If you run ISO 27001, GDPR or NIS2, a real part of the AI Act is already sitting in your evidence library under a different name. We map it before we ask you to build anything — and we are explicit about where the mapping stops.

ISO/IEC 27001:2022
7.2 Competence · A.6.3 Awareness, education and training
AI literacy — Article 4
The competence process extends to AI roles; the content has to be AI-specific.
Partially reusable
ISO/IEC 27001:2022
A.5.1 Policies · A.5.2 Roles · A.5.9 Asset inventory
AI policy, ownership and AI system inventory
The policy and roles framework carries over. The asset inventory can carry an AI flag, but AI-specific attributes are missing.
Partially reusable
ISO/IEC 27001:2022
6.1.2 Risk assessment · 6.1.3 Risk treatment
Risk management system — Article 9
The method is reusable. The harm criteria are not: Article 9 is about health, safety and fundamental rights, not confidentiality, integrity and availability.
Partially reusable
ISO/IEC 27001:2022
A.5.26 Response to information security incidents
Serious incident reporting — Article 73, Article 26(5)
Your incident process can carry the AI Act escalation path and its 2, 10 and 15-day clocks.
Supporting evidence
GDPR
Article 35 DPIA · records of processing
Deployer DPIA — Article 26(9) · FRIA — Article 27
A DPIA is not a FRIA. The fundamental-rights scope is wider than data protection, and Article 27 has its own trigger list.
Partially reusable
NIS2
Article 23 incident notification
Incident clocks alongside Article 73
One incident process, three sets of deadlines. Running them separately is how one gets missed.
Supporting evidence
ISO/IEC 42001:2023
Clauses 4–10 · Annex A controls
The management system behind the whole programme
The closest structural fit there is — but not a harmonised standard under Article 40, so it carries no presumption of conformity.
Directly relevant

High-risk systems

If something you build or use lands in Annex III, the work changes shape. This is where the Act stops being paperwork and starts being engineering:

  • Fundamental rights impact assessment (Article 27) where the trigger applies — public bodies, public services, credit scoring, life and health insurance pricing
  • Annex IV technical documentation, built as a maintained file rather than written once before an audit
  • Human oversight that works: designed into the system under Article 14, assigned to named and competent people under Article 26(2), with genuine authority to overrule the output
  • Logging and retention under Articles 12, 19 and 26(6) — including the common discovery that the vendor keeps your logs for thirty days and the law wants six months
  • Conformity assessment and registration (Articles 43, 47, 49) and the EU declaration of conformity
  • Post-market monitoring (Article 72) and serious incident reporting (Article 73)
  • Worker and affected-person information (Articles 26(7) and 26(11)), plus the Article 86 right to an explanation — with national co-determination law checked alongside, because the EU text is not the whole duty

AI literacy — Article 4

Article 4 has applied since February 2025, and a single all-staff video does not meet it. We build role-based tracks: one for the people who buy AI, one for the people who build it, one for whoever is named as the human overseer of a high-risk system, and a short one for the board — because Article 99 penalties are a board-level risk and should appear in the risk register as one. Attendance records are part of the deliverable; without them the training is unevidenced.

The AI Governance Workbench

The assessment runs in the open

Most compliance work disappears into a consultant's laptop and comes back as a PDF. Ours does not. Every classification shows the article it rests on, every requirement shows why it switched on for you, and you can follow any finding back to the legal text behind it.

The assessment itself

Three panes, one conversation

The consultant talks to the customer in plain language on the left. The centre shows the AI Act reasoning behind every question, with the article and recital it comes from. The right-hand pane shows requirements switching on in real time as the answers land — so the customer watches their obligation set being built rather than receiving it as a verdict weeks later.

Executive view

Where the organisation stands today

Overall compliance against the requirements that actually apply, split between what is already in force and what is not yet due. Top five actions ranked by risk, the next legal deadline with days remaining, and compliance broken down by chapter, tier and AI system. This is the page a board sees.

AI system register

Inventory by use case, not by vendor

Every AI system with its purpose, owner, role, the people it affects, whether personal or sensitive data is involved, its risk track, and the Annex III category where one applies. Shadow AI — the model inside a SaaS product nobody registered — is the single most common finding, and this is where it surfaces.

Gap register

Every open obligation, with an owner and a date

Requirement, entity, when it applies, current compliance state, what is true today, the evidence held against the evidence needed, risk rating, remediation action, owner, due date and status. Filterable by entity, tier, risk and date; exports to Excel or CSV so it can live in your own GRC tool.

Framework mapping

Where your existing work already counts

AI Act obligations mapped to ISO/IEC 27001:2022, ISO/IEC 42001:2023, GDPR, NIS2, NIST AI RMF, NIST CSF 2.0, SOC 2 and ISO/IEC 27701, each graded: directly relevant, partially reusable, supporting evidence, or not sufficient by itself. A mapping shows where existing work can help — never that one framework satisfies another.

The source layer

Every article, annex and recital behind the answer

113 articles, 13 annexes, 180 recitals and all 68 Article 3 definitions, with the legal text alongside the consultant interpretation — labelled as interpretation, never blended into the quote. Amendments made by the AI Omnibus are tracked separately, so you can always see what changed and when.

The workbench runs against live customer assessments and holds client data, so it is not open to the public. These are real screenshots of the running application, taken against Brightfjord Software AB — a fictional demo company we also use in the sample report below, so the two line up. Clients get their own workspace and a customer portal view for the duration of the engagement.

Artefacts

Take the work away and read it

Two things come out of this engagement. Here is one of each — the report you receive, and the workpaper we assess against.

PDF
EU AI Act Readiness ReportSample · 16 pages

The deliverable, start to finish, on a fictional company. Executive summary, scoping, classification with the article reasoning for every system, compliance status by tier and entity, the open gaps with owners and dates, the evidence still needed, the reporting clocks, framework reuse, and a roadmap sequenced by legal deadline.

FreeNo email required Fictional company
The legal content is the same content we use in live engagements. The company, systems and findings are invented.
Download the sample report
XLSX
Master Gap AssessmentWorkbook · 22 sheets

The workpaper itself, not a summary of it. Twenty-two sheets: a scoping questionnaire that resolves your roles, an AI inventory that classifies each system automatically, Article 5 prohibited screening, a master register of 242 requirement rows covering every article and annex, a point-by-point Article 9–15 checklist, filtered role views, reporting and retention clocks, a 48-document evidence catalogue, all 68 Article 3 definitions in plain English, and an AI Omnibus change log.

On request22 sheets 242 requirement rows
This one we send rather than publish. It is the live workpaper behind our engagements, and we would rather know who is using it — so we can tell you when the Omnibus moves something again.
Request the workbook

Dates

What has already happened, and what is next

Two of the three obligation sets below are in force today. The deadline people talk about — high-risk — is the one that has not arrived yet.

2 Feb 2025
In force

AI literacy and the prohibited practices

Article 4 and Article 5 have applied since this date. If you have never run a documented screening of your AI uses against the Article 5 list, or you have no role-based AI training records, you are already late — not preparing for something.

2 Aug 2025
In force

GPAI model obligations and governance

Chapter V duties for general-purpose AI model providers, the governance structures, notified bodies, and the penalty regime other than Article 101.

2 Aug 2026
In force

Transparency, sandboxes, market surveillance

Article 50 applies: people must be told when they are talking to AI, synthetic content must be machine-readably marked, and deepfakes and emotion recognition carry disclosure duties. This is the obligation most often missed, because a chatbot feels too ordinary to be regulated.

2 Dec 2026
Next deadline

New prohibition, end of the marking grace period

The AI Omnibus added an Article 5 ban covering AI for non-consensual intimate imagery and CSAM, and closed the Article 50(2) marking grace period for generative systems already on the market before 2 August 2026.

2 Dec 2027
High-risk · Annex III

Stand-alone high-risk obligations apply

Chapter III for Annex III uses — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice — together with conformity assessment, registration, post-market monitoring and incident reporting.

Moved from 2 August 2026 by the AI Omnibus. That is runway, not relief: a risk management system, an Annex IV technical file and working human oversight are a multi-month programme, and the obligations did not get smaller.
2 Aug 2028
High-risk · Annex I

Product high-risk obligations apply

Article 6(1) high-risk AI embedded as a safety component in Annex I products — machinery, medical devices, vehicles, lifts, toys and the rest of the product legislation.

Dates follow Article 113 of Regulation (EU) 2024/1689 as amended by the AI Omnibus, Regulation (EU) 2026/1744. Amendment dates should be confirmed against the consolidated text before they are relied on for a filing or a board decision — we do that confirmation as part of the engagement.

Fit

Who this is for

Deployers

You use AI inside the business — Copilot, an applicant tracking system, a CRM scoring model, a support chatbot. You are almost certainly in scope, and almost certainly do not have a complete inventory, because half of it arrived inside software you already owned.

Providers

You build AI into a product you sell, or you put your name on someone else's. Your duty set is the long one, and Article 25 can hand it to you without anyone deciding to take it on.

GPAI model builders

You train, fine-tune or release a general-purpose model. Chapter V has applied since August 2025, and the systemic-risk threshold brings a notification duty with a two-week clock.

ISO/IEC 42001 candidates

A customer or an investor has asked for the certificate. We build the management system so it carries the AI Act work too, rather than leaving you with two programmes and one budget.

Already certified to ISO 27001

You want to know how much of the AI Act you have already covered. Usually more than you expect on governance and competence, less than you hope on risk, data and technical documentation.

Not sure you are in scope at all

Then start here. The scoping questionnaire is fifteen questions and resolves both whether the Act applies and which role you hold. It is the cheapest part of the engagement and it changes everything after it.

Start here

A free 30-minute AI Act scoping call

Bring the list of AI you think you use. We will tell you what is missing from it, which role you most likely hold, and whether anything you run looks like it lands in Annex III. No slides, no pitch deck.

DATADEFENZ provides compliance consultancy, not legal advice. Classifications and applicability conclusions are stated as potentially applicable and require validation by qualified counsel, together with a check of national implementing law — penalties, designated authorities and labour-law consultation duties all vary by Member State.