AI Governance That Protects Your People, Your Data, and Your Business.
A governance readiness assessment covering eight EU regulatory frameworks, the EU AI Act, GDPR, DORA, NIS2, the Medical Device Regulation, AMLD6, the EBA loan-origination guidelines and PSD2, mapped against supporting standards including ISO 42001 and NIST AI RMF. Designed for different people across your organisation to complete their relevant sections over days or weeks. Free to complete. The full verified report is scoped in a 1:1 call with our team, and priced to fit the depth and scope you need.
What Compass delivers
A clear picture of where your organisation stands on AI governance, and exactly what to do next.
Know your exposure
Understand which AI systems, processes, and decisions are creating regulatory and operational risk right now, before an auditor or regulator does.
Meet your obligations
Get a mapped view of your compliance gaps against the EU AI Act, GDPR, DORA, NIS2, the Medical Device Regulation, AMLD6, the EBA loan-origination guidelines (EBA/GL/2020/06), and PSD2, with specific actions tied to each finding, not generic recommendations.
Move with confidence
Walk away with a prioritised roadmap your legal, compliance, and technical teams can act on immediately, no consultant dependency required.
How it works
Share each section with the right person
Each section is designed for a specific role - IT Director, CISO, CTO, DPO, and so on. Answers save automatically so different people can complete different sections over days or weeks.
We score your answers against eight EU regulatory frameworks
Yes, No, Partial, Unknown, and Not Applicable roll up into section scores, a maturity level, and an overall readiness percentage.
Receive a report built for your board
Critical findings, a risk heat map, and a prioritised remediation roadmap across three time horizons. Free executive summary. Full verified report scoped and priced in a 1:1 call.
Built from the law itself.
Every question in this assessment is drawn directly from the verbatim text of EU law, the EU AI Act, GDPR, DORA, NIS2, the Medical Device Regulation, anti-money-laundering law, the EBA guidelines and PSD2, and translated into plain English you can answer without a legal team. Each question maps to a specific article, so you always know exactly which obligation you are being measured against and what is at stake if there is a gap. The result is an assessment rigorous enough to stand up to regulatory scrutiny and clear enough for anyone in your organisation to complete.
Not sure what a question is asking? We have written a plain English guide explaining every question with real-world examples for your sector. Visit the Guide page before or during the assessment to look up any question by its reference number.
View the Assessment Guide →Pricing
Free Assessment
Start immediately. No account required.
- ✓ Full access to all questions
- ✓ Answers save automatically
- ✓ Section scores and overall readiness percentage
- ✓ Executive summary of top findings
- ✓ Share links for colleagues
- 🔒 Full findings report
- 🔒 Remediation roadmap
- 🔒 Risk heat map
- 🔒 Compliance and legal sign-off
Full Verified Report
We start with a 1:1 call to understand your organisation, scope the work, and agree a price that reflects the depth of review you need.
- ✓ 1:1 scoping call with a Greyguard specialist to tailor the engagement
- ✓ Reviewed and verified by compliance and legal specialists
- ✓ Each finding checked against the specific article of law it relates to
- ✓ Typically delivered within two to three weeks of scoping
- ✓ Secure, password-protected web link
- ✓ PowerPoint board summary
- ✓ Excel remediation tracker
- ✓ Supporting documentation as required by the engagement
- ✓ Sector-specific findings for financial services or healthcare
Every Verified Report is checked and signed off by compliance and legal professionals, not generated automatically.
Your report is generated from your own answers. This is not legal advice and does not constitute a compliance filing. Greyguard accepts no liability for compliance decisions made on the basis of this report.
Need more than a report? Greyguard works with organisations to implement the remediation roadmap, bringing in compliance, legal, and technical specialists to close every gap we find.
Book a free 30-minute call →Who should complete each section
| Section | Title | Relevant Industries | Who Should Complete It |
|---|---|---|---|
| A | AI Inventory and Shadow AI | All | IT Director, CTO, or Head of IT |
| B | Data Governance | All | IT Director, DPO, or CISO |
| C | Risk Management | All | CISO, Compliance Lead, or Risk Manager |
| D | Human Oversight | All | CTO, COO, or Head of Operations |
| E | Transparency Obligations | All | Marketing Lead, Legal Counsel, or DPO |
| F | Organisational Readiness | All | CEO, COO, or Head of Compliance |
| G | AI Security Posture | All | CISO, Head of Security, or IT Director |
| H | Agentic AI and Autonomous Systems | All | CTO or Head of Engineering |
| I | Third-Party and Supply Chain Risk | All | Head of Procurement, Legal Counsel, or IT Director |
| J | Human Accountability and Decision Architecture | All | CEO, CTO, or Board-level sponsor |
| K | AI in Software Development | All - if applicable | Head of Engineering, Lead Developer, or CTO |
| L | Financial Services and Payments | Financial Services only | Chief Risk Officer, Head of Compliance, or DPO |
| M | Healthcare and Life Sciences | Healthcare only | Chief Medical Officer, Clinical Governance Lead, or DPO |
Sections L and M only appear if you select the relevant sector at the start of the assessment. Each section takes 3 to 8 minutes for the right person to complete. Most organisations complete the full assessment over 1 to 2 weeks with different departments contributing their sections at different times.
