OneCompliant™ maps directly to the frameworks CISOs and compliance teams are already accountable to. EU AI Act. NIS2. ISO/IEC 42001. NIST AI RMF. GDPR. Not a new language to learn — a practical implementation of the standards you already know.
Compliance is not a document. It is the ability to show that controls are defined, implemented, monitored, and evidenced.
Your obligations under the EU AI Act depend on the role you play for each AI system — and most enterprises play more than one. Identify where you sit, then assess your exposure across every role you perform.
You put an AI system into use under your own authority — for staff, customers, or internal operations.
You develop an AI system, or place one on the market or into service under your own name or brand.
You integrate AI into a product already covered by sectoral or product-safety regulation.
You build on, fine-tune, or integrate a general-purpose AI model into your own systems or services.
Most enterprises are simultaneously deployers, providers, and users. Obligations stack — and so does exposure.
Applicability depends on whether the organisation acts as a provider, deployer, importer, distributor, authorised representative, or product manufacturer, and on the classification and intended purpose of each AI system.
OneCompliant supports compliance readiness and the operational implementation of controls across the frameworks your teams already answer to. Our AI Risk Assessment — OASAT — establishes where AI is used and how it is classified; our AI Governance Architecture — OASF — defines the control framework; and Runtime Governance and Enforcement — AYJIS — applies policy and produces evidence at runtime. OneCompliant does not, on its own, satisfy every legal obligation — applicability depends on your organisation's roles and on the classification and intended purpose of each AI system.
High-risk classification, conformity obligations, human oversight, and audit trail requirements
Govern, Map, Measure, and Manage functions operationalised through OASF and AYJIS
AI management system requirements mapped to OneCompliant platform capabilities
Personal data protection obligations in AI contexts — data minimisation, purpose limitation, and audit rights
The CISO question is always: "How does this map to what I'm already accountable for?" OneCompliant's answer is direct — OASF is a practical implementation of NIST AI RMF and EU AI Act obligations, not a replacement framework. The controls you implement with OneCompliant are the evidence your regulator requires.
The EU AI Act is organised around distinct categories of obligation. Which ones apply — and how — depends on your role and on the classification and intended purpose of each AI system. OneCompliant supports readiness and the implementation of operational controls for each category. It does not, by itself, discharge the underlying legal obligation.
| Obligation Category | In Plain Terms | How OneCompliant Supports Readiness |
|---|---|---|
| Prohibited AI Practices | Certain uses of AI — such as manipulative, exploitative, or untargeted-surveillance practices — are banned outright. | OASAT discovery surfaces AI use across the organisation so any prohibited practice can be identified and stopped. |
| AI Literacy | Organisations must ensure the staff who work with AI have a sufficient level of AI understanding. | Our AI Awareness Programme — OASAP — delivers role-based AI literacy across the workforce. |
| Provider Obligations | Those who develop or place AI systems on the market carry the heaviest duties — risk management, documentation, and conformity. | OASF defines the governance and documentation controls providers must evidence; AYJIS produces the operational record. |
| Deployer Obligations | Those who put AI into use must operate it as intended, ensure human oversight, and monitor its use. | AYJIS enforces usage policy and human-oversight rules at runtime and logs every governed interaction for accountability. |
| GPAI Provider Obligations | Providers of general-purpose AI models face specific transparency and documentation duties — and, for systemic-risk models, additional ones. | OASF maps GPAI documentation and transparency expectations; OASAT clarifies where GPAI models are relied upon. |
| Transparency Requirements | People must be told when they are interacting with AI, and certain AI-generated content must be disclosed or marked. | OASF defines transparency controls; AYJIS logs model decisions and can flag interactions that require disclosure. |
| High-Risk AI System Controls | AI in higher-risk contexts requires risk management, data governance, logging, human oversight, and post-market monitoring. | OASAT classifies risk; OASF defines the control set; AYJIS enforces controls and provides continuous audit evidence. |
| Governance & Supporting Security Controls | Underlying governance, accountability, and security controls — including GDPR, NIS2, and sectoral requirements — continue to apply. | OASF establishes governance and accountability; AYJIS provides data-protection controls, enforcement, and evidence at runtime. |
The EU AI Act creates binding obligations across the AI value chain — for providers, deployers, importers, distributors, authorised representatives, and product manufacturers. It applies in phases rather than on a single deadline. OneCompliant maps to the key operative requirements regulated enterprises must evidence and supports readiness against each — it does not guarantee legal compliance.
The EU AI Act applies in phases. Some obligations are already in force, while high-risk requirements follow later milestones. Organisations should not wait for the final deadline to establish inventories, ownership, controls, documentation, and evidence.
Prohibited AI practices; AI literacy obligations; GPAI obligations where applicable; governance and enforcement provisions; applicable transparency obligations; and continuing GDPR, NIS2, security, employment, consumer, and sectoral requirements. Not every obligation applies to every organisation or every AI system.
AI system inventory; approved and shadow AI discovery; role classification; provider and deployer responsibilities; AI risk classification; ownership and accountability; human oversight; technical and operational documentation; logging and traceability; incident management; post-deployment monitoring; and third-party and model governance.
2 December 2027 — relevant standalone high-risk AI system requirements.
2 August 2028 — high-risk AI systems embedded in regulated products.
The dates may have moved. The work did not disappear. Organisations still need the inventory, governance, controls, documentation, and evidence required to meet those obligations.
Applicability depends on whether the organisation acts as a provider, deployer, importer, distributor, authorised representative, or product manufacturer, and on the classification and intended purpose of each AI system.
| EU AI Act Requirement | What It Requires | OneCompliant Capability |
|---|---|---|
| Article 9 — Risk Management | Ongoing risk identification, analysis, and mitigation for high-risk AI systems | OASAT assessment provides the risk identification and scoring. AYJIS Risk module provides ongoing governance scoring and reporting. |
| Article 10 — Data Governance | Appropriate data governance practices for training, validation, and testing data | OASF data governance domain defines data handling controls. AYJIS Guard inspects and protects sensitive data at runtime. |
| Article 12 — Record Keeping | Automatic logging of events throughout the AI system's lifecycle | AYJIS Audit provides complete, tamper-evident interaction logging for every AI event — who, what, when, which model, what was redacted. |
| Article 13 — Transparency | AI systems must be designed to enable deployers to interpret outputs and use them appropriately | AYJIS routing transparency — every model selection and policy decision is logged with rationale. |
| Article 14 — Human Oversight | High-risk AI systems must allow effective human oversight and intervention | AYJIS Policy enforces human oversight requirements — blocking or flagging interactions that require human review before proceeding. |
| Article 17 — Quality Management | Documented quality management system covering design, testing, risk management, and post-market monitoring | OASF provides the governance framework documentation. AYJIS provides the operational evidence of controls in place. |
The NIST AI Risk Management Framework defines four core functions: Govern, Map, Measure, and Manage. OneCompliant operationalises each function through its platform components — moving the NIST AI RMF from a document into enforced operational controls.
| NIST AI RMF Function | What It Requires | OneCompliant Capability |
|---|---|---|
| GOVERN | Policies, processes, and accountability structures for AI risk management across the organisation | OASF defines the governance framework — policy domains, control categories, accountability boundaries, and decision authorities. |
| MAP | Identify and classify AI risks in context — use cases, stakeholders, data, and impact | OASAT assessment maps AI usage across the organisation, classifies risk by domain and business unit, and contextualises against regulatory obligations. |
| MEASURE | Analyse, assess, and track AI risks using quantitative and qualitative methods | OASAT provides risk scoring and maturity measurement. AYJIS Risk provides continuous governance measurement through live usage data. |
| MANAGE | Prioritise and respond to AI risks — implement controls, monitor continuously, and escalate incidents | AYJIS provides runtime management — policy enforcement, prompt inspection, model routing, and continuous audit logging. |
ISO 42001 is the international standard for AI management systems — defining requirements for organisations that develop, provide, or use AI. OneCompliant maps to the key clauses that regulated enterprises must address.
| ISO 42001 Clause | Requirement | OneCompliant Capability |
|---|---|---|
| Clause 6 — Planning | AI risk and opportunity identification, AI objectives, and planning to achieve them | OASAT assessment provides the risk identification and opportunity mapping required for ISO 42001 planning obligations. |
| Clause 8 — Operation | Operational planning and control, including AI system lifecycle management | OASF and AYJIS provide the operational controls for AI system use — access management, data governance, policy enforcement. |
| Clause 9 — Performance Evaluation | Monitoring, measurement, analysis, and evaluation of the AI management system | AYJIS Audit and AYJIS Risk provide the continuous monitoring and measurement evidence required for ISO 42001 evaluation. |
| Clause 10 — Improvement | Nonconformity, corrective action, and continual improvement of the AI management system | OASAT provides periodic reassessment capability. AYJIS governance reporting identifies policy violations and control gaps for remediation. |
| Annex A — AI Controls | Specific AI controls covering impact assessment, data quality, human oversight, transparency | OASF control domains map directly to ISO 42001 Annex A controls — providing the documented control evidence required for certification. |
GDPR does not have an AI exemption. When personal data is processed through AI systems — including being sent to external LLMs — all GDPR obligations apply. Most enterprises have significant unaddressed GDPR risk in their AI workflows.
| GDPR Principle | AI Context Risk | OneCompliant Control |
|---|---|---|
| Data Minimisation | Employees routinely include more personal data in AI prompts than necessary for the task | AYJIS Guard inspects prompts and redacts excessive PII before transmission — enforcing data minimisation at runtime. |
| Purpose Limitation | Personal data collected for one purpose is being processed through AI systems for different purposes | OASF policy engine defines permitted AI use cases per data category. AYJIS enforces those boundaries at the point of every governed interaction. |
| Accountability | Organisations cannot demonstrate what personal data was processed by which AI system, when, and why | AYJIS Audit provides the processing record for AI use through AYJIS — every interaction logged with data classification, model used, and policy outcome. |
| Third Country Transfers | Sending personal data to US-based LLM providers may constitute a third-country transfer under GDPR | AYJIS Routing can enforce data residency constraints — routing sensitive data only to EU-hosted or approved model providers. |
An OASAT Assessment maps your current AI usage against EU AI Act, NIST AI RMF, ISO 42001, and GDPR obligations — and produces a prioritised remediation roadmap. Fixed price. Delivered in weeks.