Solutions AYJIS EU AI Act Industries Vision Pricing Company Request Assessment
Compliance Hub

Speak the language of the regulator.

OneCompliant™ maps directly to the frameworks CISOs and compliance teams are already accountable to. EU AI Act. NIS2. ISO/IEC 42001. NIST AI RMF. GDPR. Not a new language to learn — a practical implementation of the standards you already know.

Compliance is not a document. It is the ability to show that controls are defined, implemented, monitored, and evidenced.

Start Here

What role does your organisation perform?

Your obligations under the EU AI Act depend on the role you play for each AI system — and most enterprises play more than one. Identify where you sit, then assess your exposure across every role you perform.

Deploying AI

You put an AI system into use under your own authority — for staff, customers, or internal operations.

Providing an AI System

You develop an AI system, or place one on the market or into service under your own name or brand.

Embedding AI into a Regulated Product

You integrate AI into a product already covered by sectoral or product-safety regulation.

Using a General-Purpose AI Model

You build on, fine-tune, or integrate a general-purpose AI model into your own systems or services.

Operating in More Than One Role

Most enterprises are simultaneously deployers, providers, and users. Obligations stack — and so does exposure.

Applicability depends on whether the organisation acts as a provider, deployer, importer, distributor, authorised representative, or product manufacturer, and on the classification and intended purpose of each AI system.

Assess Your AI Exposure
Framework Coverage

Core enterprise AI governance obligations — mapped to operational capabilities.

OneCompliant supports compliance readiness and the operational implementation of controls across the frameworks your teams already answer to. Our AI Risk Assessment — OASAT — establishes where AI is used and how it is classified; our AI Governance Architecture — OASF — defines the control framework; and Runtime Governance and Enforcement — AYJIS — applies policy and produces evidence at runtime. OneCompliant does not, on its own, satisfy every legal obligation — applicability depends on your organisation's roles and on the classification and intended purpose of each AI system.

Aligned

EU AI Act

High-risk classification, conformity obligations, human oversight, and audit trail requirements

Aligned

NIST AI RMF

Govern, Map, Measure, and Manage functions operationalised through OASF and AYJIS

Mapped

ISO 42001

AI management system requirements mapped to OneCompliant platform capabilities

Mapped

GDPR + AI

Personal data protection obligations in AI contexts — data minimisation, purpose limitation, and audit rights

The CISO question is always: "How does this map to what I'm already accountable for?" OneCompliant's answer is direct — OASF is a practical implementation of NIST AI RMF and EU AI Act obligations, not a replacement framework. The controls you implement with OneCompliant are the evidence your regulator requires.

EU AI Act Obligation Categories

The obligations, in plain terms.

The EU AI Act is organised around distinct categories of obligation. Which ones apply — and how — depends on your role and on the classification and intended purpose of each AI system. OneCompliant supports readiness and the implementation of operational controls for each category. It does not, by itself, discharge the underlying legal obligation.

Obligation CategoryIn Plain TermsHow OneCompliant Supports Readiness
Prohibited AI PracticesCertain uses of AI — such as manipulative, exploitative, or untargeted-surveillance practices — are banned outright.OASAT discovery surfaces AI use across the organisation so any prohibited practice can be identified and stopped.
AI LiteracyOrganisations must ensure the staff who work with AI have a sufficient level of AI understanding.Our AI Awareness Programme — OASAP — delivers role-based AI literacy across the workforce.
Provider ObligationsThose who develop or place AI systems on the market carry the heaviest duties — risk management, documentation, and conformity.OASF defines the governance and documentation controls providers must evidence; AYJIS produces the operational record.
Deployer ObligationsThose who put AI into use must operate it as intended, ensure human oversight, and monitor its use.AYJIS enforces usage policy and human-oversight rules at runtime and logs every governed interaction for accountability.
GPAI Provider ObligationsProviders of general-purpose AI models face specific transparency and documentation duties — and, for systemic-risk models, additional ones.OASF maps GPAI documentation and transparency expectations; OASAT clarifies where GPAI models are relied upon.
Transparency RequirementsPeople must be told when they are interacting with AI, and certain AI-generated content must be disclosed or marked.OASF defines transparency controls; AYJIS logs model decisions and can flag interactions that require disclosure.
High-Risk AI System ControlsAI in higher-risk contexts requires risk management, data governance, logging, human oversight, and post-market monitoring.OASAT classifies risk; OASF defines the control set; AYJIS enforces controls and provides continuous audit evidence.
Governance & Supporting Security ControlsUnderlying governance, accountability, and security controls — including GDPR, NIS2, and sectoral requirements — continue to apply.OASF establishes governance and accountability; AYJIS provides data-protection controls, enforcement, and evidence at runtime.
EU AI Act

EU AI Act — Operational Mapping

The EU AI Act creates binding obligations across the AI value chain — for providers, deployers, importers, distributors, authorised representatives, and product manufacturers. It applies in phases rather than on a single deadline. OneCompliant maps to the key operative requirements regulated enterprises must evidence and supports readiness against each — it does not guarantee legal compliance.

EU AI Act Compliance Roadmap

The EU AI Act applies in phases. Some obligations are already in force, while high-risk requirements follow later milestones. Organisations should not wait for the final deadline to establish inventories, ownership, controls, documentation, and evidence.

In force now

Prohibited AI practices; AI literacy obligations; GPAI obligations where applicable; governance and enforcement provisions; applicable transparency obligations; and continuing GDPR, NIS2, security, employment, consumer, and sectoral requirements. Not every obligation applies to every organisation or every AI system.

Prepare now

AI system inventory; approved and shadow AI discovery; role classification; provider and deployer responsibilities; AI risk classification; ownership and accountability; human oversight; technical and operational documentation; logging and traceability; incident management; post-deployment monitoring; and third-party and model governance.

Future milestones

2 December 2027 — relevant standalone high-risk AI system requirements.
2 August 2028 — high-risk AI systems embedded in regulated products.

The dates may have moved. The work did not disappear. Organisations still need the inventory, governance, controls, documentation, and evidence required to meet those obligations.

Applicability depends on whether the organisation acts as a provider, deployer, importer, distributor, authorised representative, or product manufacturer, and on the classification and intended purpose of each AI system.

EU AI Act RequirementWhat It RequiresOneCompliant Capability
Article 9 — Risk ManagementOngoing risk identification, analysis, and mitigation for high-risk AI systemsOASAT assessment provides the risk identification and scoring. AYJIS Risk module provides ongoing governance scoring and reporting.
Article 10 — Data GovernanceAppropriate data governance practices for training, validation, and testing dataOASF data governance domain defines data handling controls. AYJIS Guard inspects and protects sensitive data at runtime.
Article 12 — Record KeepingAutomatic logging of events throughout the AI system's lifecycleAYJIS Audit provides complete, tamper-evident interaction logging for every AI event — who, what, when, which model, what was redacted.
Article 13 — TransparencyAI systems must be designed to enable deployers to interpret outputs and use them appropriatelyAYJIS routing transparency — every model selection and policy decision is logged with rationale.
Article 14 — Human OversightHigh-risk AI systems must allow effective human oversight and interventionAYJIS Policy enforces human oversight requirements — blocking or flagging interactions that require human review before proceeding.
Article 17 — Quality ManagementDocumented quality management system covering design, testing, risk management, and post-market monitoringOASF provides the governance framework documentation. AYJIS provides the operational evidence of controls in place.
NIST AI RMF

NIST AI RMF — Function Mapping

The NIST AI Risk Management Framework defines four core functions: Govern, Map, Measure, and Manage. OneCompliant operationalises each function through its platform components — moving the NIST AI RMF from a document into enforced operational controls.

NIST AI RMF FunctionWhat It RequiresOneCompliant Capability
GOVERNPolicies, processes, and accountability structures for AI risk management across the organisationOASF defines the governance framework — policy domains, control categories, accountability boundaries, and decision authorities.
MAPIdentify and classify AI risks in context — use cases, stakeholders, data, and impactOASAT assessment maps AI usage across the organisation, classifies risk by domain and business unit, and contextualises against regulatory obligations.
MEASUREAnalyse, assess, and track AI risks using quantitative and qualitative methodsOASAT provides risk scoring and maturity measurement. AYJIS Risk provides continuous governance measurement through live usage data.
MANAGEPrioritise and respond to AI risks — implement controls, monitor continuously, and escalate incidentsAYJIS provides runtime management — policy enforcement, prompt inspection, model routing, and continuous audit logging.
ISO 42001

ISO 42001 — AI Management System Mapping

ISO 42001 is the international standard for AI management systems — defining requirements for organisations that develop, provide, or use AI. OneCompliant maps to the key clauses that regulated enterprises must address.

ISO 42001 ClauseRequirementOneCompliant Capability
Clause 6 — PlanningAI risk and opportunity identification, AI objectives, and planning to achieve themOASAT assessment provides the risk identification and opportunity mapping required for ISO 42001 planning obligations.
Clause 8 — OperationOperational planning and control, including AI system lifecycle managementOASF and AYJIS provide the operational controls for AI system use — access management, data governance, policy enforcement.
Clause 9 — Performance EvaluationMonitoring, measurement, analysis, and evaluation of the AI management systemAYJIS Audit and AYJIS Risk provide the continuous monitoring and measurement evidence required for ISO 42001 evaluation.
Clause 10 — ImprovementNonconformity, corrective action, and continual improvement of the AI management systemOASAT provides periodic reassessment capability. AYJIS governance reporting identifies policy violations and control gaps for remediation.
Annex A — AI ControlsSpecific AI controls covering impact assessment, data quality, human oversight, transparencyOASF control domains map directly to ISO 42001 Annex A controls — providing the documented control evidence required for certification.
GDPR + AI

GDPR in AI Contexts — Data Protection Obligations

GDPR does not have an AI exemption. When personal data is processed through AI systems — including being sent to external LLMs — all GDPR obligations apply. Most enterprises have significant unaddressed GDPR risk in their AI workflows.

GDPR PrincipleAI Context RiskOneCompliant Control
Data MinimisationEmployees routinely include more personal data in AI prompts than necessary for the taskAYJIS Guard inspects prompts and redacts excessive PII before transmission — enforcing data minimisation at runtime.
Purpose LimitationPersonal data collected for one purpose is being processed through AI systems for different purposesOASF policy engine defines permitted AI use cases per data category. AYJIS enforces those boundaries at the point of every governed interaction.
AccountabilityOrganisations cannot demonstrate what personal data was processed by which AI system, when, and whyAYJIS Audit provides the processing record for AI use through AYJIS — every interaction logged with data classification, model used, and policy outcome.
Third Country TransfersSending personal data to US-based LLM providers may constitute a third-country transfer under GDPRAYJIS Routing can enforce data residency constraints — routing sensitive data only to EU-hosted or approved model providers.

Know your compliance gaps before the regulator does.

An OASAT Assessment maps your current AI usage against EU AI Act, NIST AI RMF, ISO 42001, and GDPR obligations — and produces a prioritised remediation roadmap. Fixed price. Delivered in weeks.

Assess Your AI Exposure View Solutions