Compliance Posture Intake
Saved

Resume your previous session?

We found a saved session from a previous visit.

EU AI Act · NIST AI RMF · ISO 42001 · UK Regulatory Frameworks

Map your AI governance
posture — before an auditor does.

This intake maps your organisation's compliance posture across up to 45 controls drawn from the EU AI Act, NIST AI RMF, ISO 42001, and UK Regulatory Frameworks (SM&CR, Consumer Duty, ICO/DUAA 2025). Select the frameworks relevant to your organisation, register your AI systems, and receive an instant gap analysis — including a preliminary position on the AARI Compliance Theatre quadrant.

What this tool covers

📋
17 EU AI Act ControlsArticles 4, 9–15, 17, 26, 50, 61, 72–73 — mandatory obligations for providers and deployers of high-risk AI systems.
🕑
10 NIST AI RMF ControlsGOVERN, MAP, MEASURE, and MANAGE functions — the US federal governance framework increasingly adopted globally.
📄
8 ISO 42001 ControlsThe international AI management system standard — increasingly required in enterprise procurement and supply chain due diligence.
🏛
10 UK Regulatory ControlsSM&CR personal accountability (SMF24/SMF4/SMF16), Consumer Duty AI outcomes, ICO/DUAA 2025 automated decision-making, and UK AI Governance Principles — for FCA/PRA-regulated firms and any UK enterprise deploying consequential AI.
Integrated Quadrant PositioningYour compliance posture mapped against AARI team capability data — showing where documentation meets (or fails to meet) human governance reality.

Select frameworks to assess

Select the frameworks relevant to your organisation. At least one must remain selected. UK-only firms may select UK Regulatory Frameworks without EU AI Act. Controls in Step 2 will reflect your selection.

EU AI Act
17 controls · Optional
NIST AI RMF
10 controls · Optional
ISO 42001
8 controls · Optional
UK Regulatory Frameworks
10 controls · Optional

Enter your Engagement ID above to begin.

Step 1 of 3 — AI System Register

Which AI systems are in scope?

Register the AI systems this assessment covers. Use the Risk Classification Wizard to determine each system's EU AI Act risk tier. You will be prompted to use it if the classification or role is not yet determined.

Complete name, risk classification, and EU AI Act role for each system.
Step 2 of 3 — Compliance Controls

How are your controls implemented?

For each control, indicate whether it is fully implemented, partially implemented, or not yet in place. For implemented controls, rate the strength of your supporting evidence. Use the ⓘ button for detailed article guidance on each control.

Answer all controls and rate evidence for implemented items to continue.
Step 3 of 3 — Human Oversight Register

Who is designated to oversee each system?

EU AI Act Article 14 and SM&CR (UK FCA/PRA) both require deployers and regulated firms to formally designate accountable individuals as human overseers with documented authority to intervene. This step captures the oversight register for each system.

Complete all oversight fields above to enable the report.

Compliance Posture Report

Self-reported compliance posture. This is a diagnostic indicator — not a certification or audit opinion.

Per-System Oversight (EU AI Act Art. 14 / SM&CR)

Priority Gaps & Actions