Frameworks · UK & Europe

EU AI Act compliance, run as a living system

The EU Artificial Intelligence Act regulates AI systems by risk class, imposing obligations on providers and deployers of high-risk systems along with transparency duties.

Who it applies to

Providers and deployers of AI systems placed on the market or used in the European Union.

What it demands

Classification

Determination of risk class per system, with documented rationale.

High-risk obligations

Risk management, data governance, technical documentation, logging, human oversight and accuracy.

Transparency & monitoring

Disclosure duties and post-market monitoring with serious incident reporting.

How Compli-Once runs it

  • 1

    Every AI system held in an inventory with class, owner, documentation and review date.

  • 2

    High-risk obligations modelled as controls, so evidence and oversight are auditable.

  • 3

    Crosswalked to ISO 42001 so a single AI management system carries both.

What you already satisfy

EU AI Act overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.

Implement once, satisfy many

Access control
ISO 27001 A.5.15SOC 2 CC6.1SEBI CSCRF PR.AARBI CSF Access Mgmt
Incident response
ISO 27001 A.5.24SOC 2 CC7.3SEBI CSCRF 6-hour report
Change management
ISO 27001 A.8.32SOC 2 CC8.1PCI DSS v4 6.5

In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.

Illustrative, computed live per tenant in the platform.

Frequently asked questions

Do all AI systems carry obligations?

No. Obligations follow the risk class, and the classification rationale is stored with the system record.

How is human oversight evidenced?

Through approval steps and review tasks recorded against the system, with the audit trail intact.

You're done. We're not.

The audit ends. The readiness doesn't. See it on your own data.