01
AI Act Compliance
Risk classification, documentation and adaptation plan for the European AI Regulation. Includes the Fundamental Rights Impact Assessment (FRIA) when the system requires it, and the AI system inventory and registry, a deliverable that is also a direct obligation of the Regulation itself.
For whom: Legal and compliance officers at companies that use or deploy AI systems.
02
Shadow AI Assessment
Identifies which AI the team uses without supervision and the real risk it implies: which tools, with which data, and with what exposure for the company. Delivered with an executive report designed for management or the DPO, not just a technical list of findings.
For whom: CTOs and IT leads who suspect unauthorized use of AI tools.
03
NIS2 Governance and Board Accountability
Management answers personally: make sure it is covered, not exposed
Design, documentation and oversight of the cybersecurity risk management measures required by article 20 of NIS2, including their formal approval by the management body. Covers governance and the personal accountability of directors and board members (the training itself is delivered from our Training pillar) and leaves a documented, auditable approval and oversight process.
For whom: Boards and management of NIS2-sector entities (essential or important, 50+ employees or over 10M€ revenue) that need to prove cybersecurity measures were approved and supervised by the management body, not just delegated to IT.
04
AI Compliance Evidence Report and Audit
Complying is not enough if you cannot prove it
Periodic generation of an evidence report (mapped to ISO 27001, ENS and the EU AI Act) that documents in an auditable way which AI systems are used, with which controls and with what result. It closes the cycle of the one-off audits in this catalog: it turns a diagnosis into a verifiable history you can hand to an auditor, a board or a client that requires it by contract. Delivered today as a consulting engagement, progressively automated as Moviwa incorporates native report export.
For whom: Compliance officers and CISOs who need to show continuous compliance evidence, not a one-off report that expires the day it is delivered.