AI GOVERNANCE · TECHNICAL READINESS

For organisations that need AI systems
to survive legal, risk and procurement review.

AI regulation
readiness.

A bounded technical review.
Clear controls and a delivery plan.

5—10 / DAYS
( 01 — REVIEW OUTPUT )

Know where you stand.
Know what to build.

The review converts regulatory questions into an engineering backlog. No generic policy deck and no unsupported compliance claim.

01

System inventory

Models, use cases, owners, data, users, integrations and deployment boundaries.

02

Role & risk map

Provider and deployer roles, prohibited uses, transparency duties and potential high-risk exposure.

03

Control gaps

Missing oversight, records, evaluations, access controls, incident paths and vendor evidence.

04

Remediation plan

Prioritised controls, target architecture, owners, sequencing and a realistic production path.

( 02 — CONTROL MODEL )

From obligation
to evidence.

Each obligation is mapped to an observable system behaviour, a responsible owner and evidence that can be reviewed.

01 / CLASSIFY

Use case and role

Purpose · actors · data · affected users · deployment

Defined scope
02 / CONTROL

Technical safeguards

Identity · permissions · oversight · evaluations · monitoring

Enforced behaviour
03 / EVIDENCE

Reviewable records

Versions · decisions · approvals · incidents · vendor artefacts

Audit trail
CURRENT EU TIMELINE / AUGUST 2026

Regulation (EU) 2026/1744 is in force. The high-risk requirements in Chapter III Sections 1–3 apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product systems. Other AI Act duties already in application are assessed separately.

Official Journal ↗
See AI transformation
( 03 — CONNECTED OBLIGATIONS )

One system.
Several rulebooks.

The review starts with the AI system and maps every applicable obligation to the same owners, controls and evidence. Coverage is scoped with counsel and sector specialists.

EU

EU AI Act

Roles, prohibited uses, transparency, high-risk controls, GPAI dependencies and post-market evidence.

DATA

GDPR · Data Act

Lawful data flows, access, minimisation, retention, portability and rights-aware operations.

RESILIENCE

NIS2 · DORA

Security ownership, supplier risk, incidents, continuity and operational resilience where applicable.

MANAGEMENT

ISO/IEC 42001

AI management-system responsibilities, lifecycle controls, records and continual improvement.

US

NIST AI RMF

Govern, Map, Measure and Manage outcomes, plus the Generative AI Profile where relevant.

SECTOR

Client obligations

Procurement, internal policy, contractual commitments and sector-specific control requirements.

( 04 — 5–10 DAY REVIEW )

A bounded review.
A usable result.

Senior-led delivery with a documented evidence trail, shared working files and an explicit handover. Typical fixed fee: €8,000–€15,000, confirmed before access to systems.

DAY 01—02

Inventory.

Collect use cases, architecture, model providers, data flows, owners and existing policies.

DAY 03—06

Assess.

Map roles, risk indicators, transparency duties, controls and evidence gaps.

DAY 07—10

Plan.

Agree priorities, target controls, responsible owners and the production remediation sequence.

( 05 — COMMON QUESTIONS )

Before the
review.

Is this a legal compliance assessment?

No. It is a technical readiness review. Your counsel owns legal interpretation; we identify and implement the system controls required by that interpretation.

Which rules does the review cover?

The default control map covers the EU AI Act and its 2026 amendment, with GDPR, Data Act, NIS2, DORA, ISO/IEC 42001 and NIST AI RMF crosswalks included where they affect the system or client obligations.

Who is it for?

Organisations already deploying AI or preparing a production launch, especially where risk, compliance, procurement or audit teams need reviewable evidence.

What happens after the review?

You can implement the plan internally, take it to another supplier or ask N137.AI to build the control layer and remediation work.

START WITH ONE SYSTEM

Request a
readiness review.

Tell us what the system does, who uses it and what regulatory question is blocking production.

hello@n137.ai
AI REGULATION READINESSUsually replies within one business day

Submitted directly to N137.AI. No advertising cookies or third-party form provider.