AI Compliance and Security
EU AI Act, ISO/IEC 42001, risk assessment and governance frameworks for AI systems.
Request an initial assessmentOrganizations are adopting artificial intelligence faster than they are building rules for it. The EU AI Act classifies AI systems by risk and sets obligations for those who develop and use them, including companies outside the EU when their systems are offered or used on the EU market.
Our AI Compliance and Security services cover the EU AI Act, the GDPR, Law 124 (Albania) and ISO/IEC 42001. We provide AI risk assessments, governance frameworks and security measures that keep your AI operations sound.
What it covers
- AI system inventory and risk classification
- Gap analysis against the EU AI Act
- AI governance framework based on ISO/IEC 42001
- Risk and impact assessment for AI systems
- Personal data protection in AI systems (GDPR and Law 124)
- Policy for staff use of AI
- Security measures for models and data
Frequently asked questions
AI Compliance and Security
Does the EU AI Act affect us as an Albanian company?
It can. The regulation also applies to companies outside the EU when their AI systems are offered on the EU market or their output is used there. We assess your case based on the products and customers you have.
What is ISO/IEC 42001?
It is the international standard for artificial intelligence management systems. It gives a structure for governing AI responsibly, much as ISO 27001 does for information security.
We only use off-the-shelf AI tools. Do we need anything?
Yes, at least clear rules: which tools are allowed, what data may be entered into them, and who checks the output. Personal data entered into these tools remains subject to the GDPR and Law 124.
Services
Other services
Governance, Risk and Compliance (GRC)
Integrated GRC frameworks, risk assessments, compliance audits and GRC platforms.
Learn moreCloud Security Architecture
Secure-by-design AWS, Azure and GCP environments, with monitoring and DevSecOps.
Learn moreSOX and J-SOX Compliance
Internal control assessments, risk management and audits.
Learn moreESG and Sustainability Reporting
ESG risk assessments, GRI and SASB reporting, and climate strategy.
Learn moreIT Strategy and Service Management
IT strategy, COBIT 2019, ITIL, ISO 20000 and technology adoption advisory.
Learn moreLaw 124 and GDPR Compliance
Data mapping, record of processing activities, policies, DPIAs and readiness for an inspection by the Commissioner.
Learn moreLet's talk about your next engagement.
Tell us about your engagement — we typically respond within one business day.
