EU AI Act Transparency Deadline: 2 August 2026. No extension granted.

AI Governance That Protects Your People, Your Data, and Your Business.

A governance readiness assessment covering eight EU regulatory frameworks, the EU AI Act, GDPR, DORA, NIS2, the Medical Device Regulation, AMLD6, the EBA loan-origination guidelines and PSD2, mapped against supporting standards including ISO 42001 and NIST AI RMF. Designed for different people across your organisation to complete their relevant sections over days or weeks. Free to complete. The full verified report is scoped in a 1:1 call with our team, and priced to fit the depth and scope you need.

107 Questions13 Domains8 Frameworks

What Compass delivers

A clear picture of where your organisation stands on AI governance, and exactly what to do next.

Know your exposure

Understand which AI systems, processes, and decisions are creating regulatory and operational risk right now, before an auditor or regulator does.

Meet your obligations

Get a mapped view of your compliance gaps against the EU AI Act, GDPR, DORA, NIS2, the Medical Device Regulation, AMLD6, the EBA loan-origination guidelines (EBA/GL/2020/06), and PSD2, with specific actions tied to each finding, not generic recommendations.

Move with confidence

Walk away with a prioritised roadmap your legal, compliance, and technical teams can act on immediately, no consultant dependency required.

How it works

1

Share each section with the right person

Each section is designed for a specific role - IT Director, CISO, CTO, DPO, and so on. Answers save automatically so different people can complete different sections over days or weeks.

2

We score your answers against eight EU regulatory frameworks

Yes, No, Partial, Unknown, and Not Applicable roll up into section scores, a maturity level, and an overall readiness percentage.

3

Receive a report built for your board

Critical findings, a risk heat map, and a prioritised remediation roadmap across three time horizons. Free executive summary. Full verified report scoped and priced in a 1:1 call.

Built from the law itself.

Every question in this assessment is drawn directly from the verbatim text of EU law, the EU AI Act, GDPR, DORA, NIS2, the Medical Device Regulation, anti-money-laundering law, the EBA guidelines and PSD2, and translated into plain English you can answer without a legal team. Each question maps to a specific article, so you always know exactly which obligation you are being measured against and what is at stake if there is a gap. The result is an assessment rigorous enough to stand up to regulatory scrutiny and clear enough for anyone in your organisation to complete.

Not sure what a question is asking? We have written a plain English guide explaining every question with real-world examples for your sector. Visit the Guide page before or during the assessment to look up any question by its reference number.

View the Assessment Guide →

Pricing

Free Assessment

EUR 0

Start immediately. No account required.

  • ✓ Full access to all questions
  • ✓ Answers save automatically
  • ✓ Section scores and overall readiness percentage
  • ✓ Executive summary of top findings
  • ✓ Share links for colleagues
  • 🔒 Full findings report
  • 🔒 Remediation roadmap
  • 🔒 Risk heat map
  • 🔒 Compliance and legal sign-off
Tailored engagement

Full Verified Report

Tailored

We start with a 1:1 call to understand your organisation, scope the work, and agree a price that reflects the depth of review you need.

  • ✓ 1:1 scoping call with a Greyguard specialist to tailor the engagement
  • ✓ Reviewed and verified by compliance and legal specialists
  • ✓ Each finding checked against the specific article of law it relates to
  • ✓ Typically delivered within two to three weeks of scoping
  • ✓ Secure, password-protected web link
  • ✓ PowerPoint board summary
  • ✓ Excel remediation tracker
  • ✓ Supporting documentation as required by the engagement
  • ✓ Sector-specific findings for financial services or healthcare
Book a 1:1 call

Every Verified Report is checked and signed off by compliance and legal professionals, not generated automatically.

Your report is generated from your own answers. This is not legal advice and does not constitute a compliance filing. Greyguard accepts no liability for compliance decisions made on the basis of this report.

Need more than a report? Greyguard works with organisations to implement the remediation roadmap, bringing in compliance, legal, and technical specialists to close every gap we find.

Book a free 30-minute call →

Who should complete each section

SectionTitleRelevant IndustriesWho Should Complete It
AAI Inventory and Shadow AIAllIT Director, CTO, or Head of IT
BData GovernanceAllIT Director, DPO, or CISO
CRisk ManagementAllCISO, Compliance Lead, or Risk Manager
DHuman OversightAllCTO, COO, or Head of Operations
ETransparency ObligationsAllMarketing Lead, Legal Counsel, or DPO
FOrganisational ReadinessAllCEO, COO, or Head of Compliance
GAI Security PostureAllCISO, Head of Security, or IT Director
HAgentic AI and Autonomous SystemsAllCTO or Head of Engineering
IThird-Party and Supply Chain RiskAllHead of Procurement, Legal Counsel, or IT Director
JHuman Accountability and Decision ArchitectureAllCEO, CTO, or Board-level sponsor
KAI in Software DevelopmentAll - if applicableHead of Engineering, Lead Developer, or CTO
LFinancial Services and PaymentsFinancial Services onlyChief Risk Officer, Head of Compliance, or DPO
MHealthcare and Life SciencesHealthcare onlyChief Medical Officer, Clinical Governance Lead, or DPO

Sections L and M only appear if you select the relevant sector at the start of the assessment. Each section takes 3 to 8 minutes for the right person to complete. Most organisations complete the full assessment over 1 to 2 weeks with different departments contributing their sections at different times.

This tool is a structured self-assessment to support your AI governance programme. It covers the EU AI Act, GDPR, DORA, NIS2, the Medical Device Regulation, AMLD6, the EBA loan-origination guidelines (EBA/GL/2020/06), and PSD2, mapped against supporting standards including ISO 42001 and NIST AI RMF. It is not legal advice. Regulatory interpretation should be confirmed with qualified legal counsel. greyguardconsulting.com