120+ controls · 7 dimensions · EU AI Act & ISO/IEC 42001

7 Dimensions of AI Compliance Readiness

Compliance readiness is a separate assessment from our production readiness scan. Connect your codebase and each AI workflow is assessed against these 7 governance dimensions and 120+ controls — spanning both what's in the code and the policies and process behind it — grounded in the EU AI Act and ISO/IEC 42001, and kept current as those standards evolve. A compliance grade and gap list, not just a score.

Scan Your Repo, Free →
01

Governance

Who owns the AI, what the policy says, and how it's held accountable.

ISO/IEC 42001EU AI Act
23 controls

What we check for

An approved AI policy is documented and communicated to all staff
A named AIMS owner and a separate AI risk owner hold documented authority
Every AI system has a business justification and an impact assessment
A risk-register entry exists for each AI system
Third-party LLM providers have a signed DPA and a documented retention policy
Model, prompt and config changes pass an AI-specific change-management gate
02

Risk Management

Finding where an AI system can cause harm — and having a plan before it does.

ISO/IEC 42001EU AI Act
18 controls

What we check for

An AI risk methodology and register cover AI-specific harms
Risk classification is aligned to the EU AI Act tiers
Failure modes are identified and documented per system
Bias, fairness and adversarial-input risks are assessed
High-risk systems have a documented Risk Management System
A post-market monitoring plan tracks risk after launch
03

Human Oversight

A person stays in control — able to review, override and stop the system.

EU AI ActISO/IEC 42001
16 controls

What we check for

A human review gate sits before consequential decisions
A working human override mechanism exists
An emergency-stop / kill switch can halt the system
Irreversible agentic actions require human confirmation
Step limits prevent runaway agent loops
Agent tool permissions are scoped to the minimum required
04

Auditability

If a regulator asks what happened, the logs can reconstruct it.

ISO/IEC 42001EU AI Act
16 controls

What we check for

Every AI decision is logged with enough context to reconstruct it
Audit-log infrastructure is wired and active per system
Log retention of at least 6 months is documented and enforced
Agent tool calls are logged with their triggering reasoning
Structured, machine-readable logging is in use
An AI system inventory is maintained and current
05

Data & Privacy

Where personal data enters the model, and the safeguards around it.

GDPREU AI ActISO/IEC 42001
21 controls

What we check for

PII entering the system is identified and documented
PII is masked or excluded from LLM context where feasible
A DPIA is conducted for each system that needs one
Training data provenance is documented
Tenant-scoped data isolation protects RAG retrieval
Output is screened for PII after generation
06

Transparency

People affected by the AI know it's AI — and can get an explanation.

EU AI ActISO/IEC 42001
15 controls

What we check for

Users are persistently told when they're interacting with AI
Conversational AI discloses that it's a chatbot
AI-generated synthetic content is labeled as such
Affected individuals can get an explanation of an AI decision
A public AI transparency statement or policy page exists
System capabilities and limitations are communicated to users
07

Lifecycle

Keeping the system safe as it changes, and handling incidents when they happen.

ISO/IEC 42001EU AI Act
20 controls

What we check for

Model, prompt and config changes are gated and reviewed
Changes can be rolled back
Incident detection and alerting are active per system
An incident runbook covers this system's failure modes
Model drift and output quality are monitored, not just uptime
A serious-incident reporting process to authorities is defined

Not every control lives in the code. Many of these dimensions also depend on controls in your policies and process — an approved AI policy, a named risk owner, DPIAs, an incident process. The free scan surfaces what's in the codebase; the full product also assesses those policy and process controls, so a whole dimension never scores on code alone. And because the rules keep moving, we continuously maintain this control set — 120+ today, and growing as the EU AI Act and ISO/IEC 42001 evolve — so you don't have to track what changed.

Scored to your EU AI Act risk tier

Not every workflow carries the same obligations. Each system is first classified into an EU AI Act risk tier, and the controls that apply are scaled to it — so you're measured against what actually applies to you.

Minimal Risk

No specific EU AI Act obligations beyond general good practice.

Limited Risk

Transparency obligations apply — users must be told they're interacting with AI.

High Risk

Full obligations: conformity assessment, registration, human oversight and robust documentation.

GPAI Model

General-purpose model obligations: transparency, copyright compliance, and safeguards for systemic risk.

See where your AI stands across all 7 compliance dimensions.

Connect your codebase and get a compliance grade and gap list for every workflow — evidence you can put in front of a security review or a regulator.

Scan Your Repo, Free →