7 dimensions · Key controls from a 120+ control audit · EU AI Act & ISO/IEC 42001

AI Compliance Readiness Checklist

The compliance controls ShipSmith checks across the 7 governance dimensions, grounded in the EU AI Act and ISO/IEC 42001. Below are the top 5 controls in each — a preview of the full 120+ control assessment.

85–100%
Fully Compliant
65–84%
Largely Compliant
40–64%
Developing
0–39%
Non-Compliant

Start with the automated scan, free

Connect your codebase and ShipSmith discovers every AI workflow, classifies each into its EU AI Act risk tier, and automatically checks the controls it can verify from your code — free for your first workflow. The policy and process controls that need a judgment call are resolved with our team in the full 120+ control assessment, producing a compliance grade mapped to the EU AI Act and ISO/IEC 42001. And we keep that control set current as the regulations evolve, so you don't have to.

Scan Your Repo, Free →

First, know your risk tier

The EU AI Act scales obligations to risk. A workflow's tier determines which of these controls actually apply.

Minimal Risk

No specific EU AI Act obligations beyond general good practice.

Limited Risk

Transparency obligations apply — users must be told they're interacting with AI.

High Risk

Full obligations: conformity assessment, registration, human oversight and robust documentation.

GPAI Model

General-purpose model obligations: transparency, copyright compliance, and safeguards for systemic risk.

01

Governance

ISO/IEC 42001EU AI Act
Top 5 of 23
01An approved AI policy is documented and communicated to all staff
02A named AIMS owner and a separate AI risk owner hold documented authority
03Every AI system has a business justification and an impact assessment
04A risk-register entry exists for each AI system
05Third-party LLM providers have a signed DPA and a documented retention policy
+18 more controls in this dimension — assessed in full when ShipSmith reviews your workflows.
02

Risk Management

ISO/IEC 42001EU AI Act
Top 5 of 18
01An AI risk methodology and register cover AI-specific harms
02Risk classification is aligned to the EU AI Act tiers
03Failure modes are identified and documented per system
04Bias, fairness and adversarial-input risks are assessed
05High-risk systems have a documented Risk Management System
+13 more controls in this dimension — assessed in full when ShipSmith reviews your workflows.
03

Human Oversight

EU AI ActISO/IEC 42001
Top 5 of 16
01A human review gate sits before consequential decisions
02A working human override mechanism exists
03An emergency-stop / kill switch can halt the system
04Irreversible agentic actions require human confirmation
05Step limits prevent runaway agent loops
+11 more controls in this dimension — assessed in full when ShipSmith reviews your workflows.
04

Auditability

ISO/IEC 42001EU AI Act
Top 5 of 16
01Every AI decision is logged with enough context to reconstruct it
02Audit-log infrastructure is wired and active per system
03Log retention of at least 6 months is documented and enforced
04Agent tool calls are logged with their triggering reasoning
05Structured, machine-readable logging is in use
+11 more controls in this dimension — assessed in full when ShipSmith reviews your workflows.
05

Data & Privacy

GDPREU AI ActISO/IEC 42001
Top 5 of 21
01PII entering the system is identified and documented
02PII is masked or excluded from LLM context where feasible
03A DPIA is conducted for each system that needs one
04Training data provenance is documented
05Tenant-scoped data isolation protects RAG retrieval
+16 more controls in this dimension — assessed in full when ShipSmith reviews your workflows.
06

Transparency

EU AI ActISO/IEC 42001
Top 5 of 15
01Users are persistently told when they're interacting with AI
02Conversational AI discloses that it's a chatbot
03AI-generated synthetic content is labeled as such
04Affected individuals can get an explanation of an AI decision
05A public AI transparency statement or policy page exists
+10 more controls in this dimension — assessed in full when ShipSmith reviews your workflows.
07

Lifecycle

ISO/IEC 42001EU AI Act
Top 5 of 20
01Model, prompt and config changes are gated and reviewed
02Changes can be rolled back
03Incident detection and alerting are active per system
04An incident runbook covers this system's failure modes
05Model drift and output quality are monitored, not just uptime
+15 more controls in this dimension — assessed in full when ShipSmith reviews your workflows.

See the controls here.
Get the full assessment on your workflows.

Start with the free automated scan, then get the full 120+ control assessment — each workflow classified to its EU AI Act risk tier, the policy and process controls resolved with our team, and a compliance gap list you can act on, not just a score.

Scan Your Repo, Free →