AI Compliance Readiness Checklist
The compliance controls ShipSmith checks across the 7 governance dimensions, grounded in the EU AI Act and ISO/IEC 42001. Below are the top 5 controls in each — a preview of the full 120+ control assessment.
Start with the automated scan, free
Connect your codebase and ShipSmith discovers every AI workflow, classifies each into its EU AI Act risk tier, and automatically checks the controls it can verify from your code — free for your first workflow. The policy and process controls that need a judgment call are resolved with our team in the full 120+ control assessment, producing a compliance grade mapped to the EU AI Act and ISO/IEC 42001. And we keep that control set current as the regulations evolve, so you don't have to.
Scan Your Repo, Free →First, know your risk tier
The EU AI Act scales obligations to risk. A workflow's tier determines which of these controls actually apply.
No specific EU AI Act obligations beyond general good practice.
Transparency obligations apply — users must be told they're interacting with AI.
Full obligations: conformity assessment, registration, human oversight and robust documentation.
General-purpose model obligations: transparency, copyright compliance, and safeguards for systemic risk.
Governance
Risk Management
Human Oversight
Auditability
Data & Privacy
Transparency
Lifecycle
See the controls here.
Get the full assessment on your workflows.
Start with the free automated scan, then get the full 120+ control assessment — each workflow classified to its EU AI Act risk tier, the policy and process controls resolved with our team, and a compliance gap list you can act on, not just a score.
Scan Your Repo, Free →