The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
AI governance
Find out which risk tier your artificial intelligence falls into, before someone asks.
AI rules classify systems by risk tier, and what is required of you depends on the tier. You do not need to arrive knowing which one you fall into: describe what your AI decides and we determine the classification, both for the European regulation and for the Brazilian bill moving through Congress.
The work starts with an inventory of your systems, including the embedded ones and the ones a department signed up for on its own, and with the classification of each one based on what it decides. From that baseline come the transparency notices telling people an AI is involved, delivered before any deeper remediation.
On your side, we need someone who can describe what each system does and decides, whatever technical documentation exists, and access to legal when the classification touches a contract. Nobody needs to study the regulation first: translating legal text into practical requirements is exactly our job.
The option you choose defines how far we go. In the diagnostic, you receive the prioritized gaps and the plan, and execute with your own team. In the remediation, we implement documentation, controls, evidence, and training. And when a conformity assessment by a notified body is required, we prepare and support you, but the assessment is always the body's.
The stages and deliverables below describe the Full compliance work modality. The other modalities appear when you request the proposal.
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
AI system inventory
We map what exists, including what arrived embedded in a system already under contract and what a department signed up for without telling anyone.
Risk classification
We place each system in the applicable tier from what it decides, rather than from what we would like it to be.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Implementation
We stand the controls up together with your team, write down what needs to exist on paper and train the people who will operate them. Nothing counts as implemented until it works in practice and someone on your side can sustain it.
Evidence routine
We set out how each control proves it worked, with an owner and a frequency, so the audit does not turn into a scramble.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.