Montevive

/ Compliance and Governance /

Montevive

In Compliance and Governance we translate the regulatory framework (AI Act, NIS2, GDPR, ENS) into documentation, processes and verifiable evidence, not a PDF nobody opens again. We help management and compliance officers decide with judgment and prove it when it matters.

Some of the services within this area of action:

01

AI Act Compliance

Risk classification, documentation and adaptation plan for the European AI Regulation. Includes the Fundamental Rights Impact Assessment (FRIA) when the system requires it, and the AI system inventory and registry, a deliverable that is also a direct obligation of the Regulation itself.

For whom: Legal and compliance officers at companies that use or deploy AI systems.

02

Shadow AI Assessment

Identifies which AI the team uses without supervision and the real risk it implies: which tools, with which data, and with what exposure for the company. Delivered with an executive report designed for management or the DPO, not just a technical list of findings.

For whom: CTOs and IT leads who suspect unauthorized use of AI tools.

03

NIS2 Governance and Board Accountability

Management answers personally: make sure it is covered, not exposed

Design, documentation and oversight of the cybersecurity risk management measures required by article 20 of NIS2, including their formal approval by the management body. Covers governance and the personal accountability of directors and board members (the training itself is delivered from our Training pillar) and leaves a documented, auditable approval and oversight process.

For whom: Boards and management of NIS2-sector entities (essential or important, 50+ employees or over 10M€ revenue) that need to prove cybersecurity measures were approved and supervised by the management body, not just delegated to IT.

04

AI Compliance Evidence Report and Audit

Complying is not enough if you cannot prove it

Periodic generation of an evidence report (mapped to ISO 27001, ENS and the EU AI Act) that documents in an auditable way which AI systems are used, with which controls and with what result. It closes the cycle of the one-off audits in this catalog: it turns a diagnosis into a verifiable history you can hand to an auditor, a board or a client that requires it by contract. Delivered today as a consulting engagement, progressively automated as Moviwa incorporates native report export.

For whom: Compliance officers and CISOs who need to show continuous compliance evidence, not a one-off report that expires the day it is delivered.

[ How can we help you? ]

Let's talk about the risk you don't see and the opportunity you're not yet leveraging

Let's talk about your secure, legal and responsible AI strategy. We'll respond in less than 24 hours.

ISO 27001GDPRNIS2Reply in <24h

Request your diagnostic

We'll reply within 24h.