7 Dimensions of AI Compliance Readiness
Compliance readiness is a separate assessment from our production readiness scan. Connect your codebase and each AI workflow is assessed against these 7 governance dimensions and 120+ controls — spanning both what's in the code and the policies and process behind it — grounded in the EU AI Act and ISO/IEC 42001, and kept current as those standards evolve. A compliance grade and gap list, not just a score.
Scan Your Repo, Free →Governance
Who owns the AI, what the policy says, and how it's held accountable.
What we check for
Risk Management
Finding where an AI system can cause harm — and having a plan before it does.
What we check for
Human Oversight
A person stays in control — able to review, override and stop the system.
What we check for
Auditability
If a regulator asks what happened, the logs can reconstruct it.
What we check for
Data & Privacy
Where personal data enters the model, and the safeguards around it.
What we check for
Transparency
People affected by the AI know it's AI — and can get an explanation.
What we check for
Lifecycle
Keeping the system safe as it changes, and handling incidents when they happen.
What we check for
Not every control lives in the code. Many of these dimensions also depend on controls in your policies and process — an approved AI policy, a named risk owner, DPIAs, an incident process. The free scan surfaces what's in the codebase; the full product also assesses those policy and process controls, so a whole dimension never scores on code alone. And because the rules keep moving, we continuously maintain this control set — 120+ today, and growing as the EU AI Act and ISO/IEC 42001 evolve — so you don't have to track what changed.
Scored to your EU AI Act risk tier
Not every workflow carries the same obligations. Each system is first classified into an EU AI Act risk tier, and the controls that apply are scaled to it — so you're measured against what actually applies to you.
No specific EU AI Act obligations beyond general good practice.
Transparency obligations apply — users must be told they're interacting with AI.
Full obligations: conformity assessment, registration, human oversight and robust documentation.
General-purpose model obligations: transparency, copyright compliance, and safeguards for systemic risk.
See where your AI stands across all 7 compliance dimensions.
Connect your codebase and get a compliance grade and gap list for every workflow — evidence you can put in front of a security review or a regulator.
Scan Your Repo, Free →