Back to case studies
AI AuditAI product / SaaSIndia / EU

Preparing an AI product company for EU AI Act scrutiny

Enterprise buyers in the EU were blocking deals on AI governance questions. We audited the product and produced assurance evidence procurement could accept.

Client
A B2B AI product company selling into Europe
Service
AI Audit
Frameworks
EU AI Act · ISO/IEC 42001 · NIST AI RMF

The challenge

  • Security questionnaires increasingly containing AI-specific governance questions
  • Uncertainty about the product's EU AI Act risk classification and provider obligations
  • Governance evidence scattered across docs, tickets and engineers' heads

What we did

  1. 01

    Classification

    Determined the applicable EU AI Act role and risk tier for each product capability.

  2. 02

    Evidence audit

    Reviewed technical documentation, data governance, logging, transparency and oversight controls.

  3. 03

    Control mapping

    Mapped one control set across the EU AI Act, ISO/IEC 42001 and NIST AI RMF.

  4. 04

    Assurance report

    Issued an independent report written for enterprise risk and procurement reviewers.

Outcomes

  • Clear, defensible view of applicable EU AI Act obligations per capability
  • One control set answering EU, ISO and NIST questions instead of three
  • An assurance report that shortened enterprise security review cycles
  • Governance gaps closed before they surfaced in a customer audit

Facing something similar?

A short conversation is usually enough to scope the right assurance work.

Book a free consulting
WhatsApp