A fixed-scope, four-week assessment of how your organisation governs artificial intelligence — measured against the EU AI Act, the NIST AI Risk Management Framework and ISO/IEC 42001 at once. You leave with a readiness position on all three, the obligation areas where you are exposed, and a roadmap your board can own.
The AI Act applies to every organisation that uses AI, not only those that build it. Providers and deployers "shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf" — regardless of the risk tier of the systems involved.
Article 4(1) of the AI Act as amended by the Digital Omnibus on AI, in force since 27 July 2026. The Omnibus also moved the high-risk obligations to December 2027 and August 2028 — it did not move the general application date of 2 August 2026.
The AI Act has applied in stages since 2024, and its general application date passed on 2 August 2026. The Digital Omnibus gave high-risk systems more time — but literacy, transparency, prohibited practices and the expectation that AI is governed like any other material risk are all live now.
The AI Act's general application date, unchanged by the Omnibus. Prohibited practices and AI literacy have applied since February 2025; transparency duties for chatbots and generated content apply from this date.
Stand-alone high-risk uses — employment, credit, essential services and the other Annex III categories — now apply from 2 December 2027; AI embedded in regulated products from 2 August 2028. Sixteen months, not a reprieve.
Ireland has designated fifteen sectoral competent authorities — the Central Bank, the DPC, Coimisiún na Meán and others — coordinated by a national AI Office. The regulator that asks about your AI is one you already know.
"Are we compliant with the AI Act?" is the wrong first question. The right one is "do we know where AI is used, who owns it, and could we evidence how it is governed if asked?"
That question is answerable in four weeks — and it is the same question NIST AI RMF and ISO/IEC 42001 ask, which is why this assessment measures all three at once.The Act is written for providers and deployers, not IT departments. Its obligations on a deployer — human oversight, transparency, record keeping, literacy — are organisational commitments that only a management body can make and only evidence can prove.
Across the three frameworks, leadership is expected to establish and be able to evidence:
The pattern we see most often is capability without ownership: monitoring and operational controls are ahead of leadership, governance and performance evaluation. That is exactly the gap a regulator, an auditor or an incident investigation will find first.
Almost every organisation is a deployer under the AI Act. The ones that need this most fall into two groups.
A law, a risk framework and a management standard. They overlap heavily, which is the point: assess once, and you have a position on all three.
Regulation (EU) 2024/1689, risk-based: prohibited, high, limited and minimal. For deployers the assessment reads nine obligation areas, from the risk management system and data governance through human oversight and transparency to post-market monitoring.
Not a legal determination of compliance — a readiness indication your counsel and your regulator can work from.
Voluntary and globally recognised. Built on four functions — Govern, Map, Measure, Manage — which the assessment scores as governance and accountability, context and risk identification, analysis and measurement, and response and treatment.
Where "doing" AI risk management is separated from "owning" it.
The first international AI management system standard. The assessment scores its seven domains: context, leadership and governance, planning and risk, support and resources, operational controls, performance evaluation, continuous improvement.
The certification route if you want one — and the gap view before you commit.
An AI policy, a vendor's assurance and a well-meaning working group are not governance. Governance is an inventory, named owners, a risk appetite, human oversight that has actually been exercised, and evidence a regulator could examine. Four weeks is enough to establish where you stand on all of it.
Fixed scope. Four weeks. Delivered on the CyberPrism platform with a CRI practitioner guiding your team throughout — so the work is done with you, not to you.
"In every AI assessment we run, the operational controls are ahead of the boardroom. People are monitoring models nobody at the top has formally owned. The Act doesn't punish you for using AI — it asks whether someone accountable can explain how."
Paul C Dwyer — CEO, Cyber Risk International; President, ICTTF; author of Cyber Risk LeadershipEvery deliverable is written for the management body that will be asked to explain its AI — and the report is the artefact it signs off.
Where AI is used across the organisation, including inside vendor products, and which AI Act tier each use falls into.
Your position across the obligation areas — achieved, in progress and not achieved — with the strongest and weakest areas named.
Maturity across governance and accountability, context and risk, analysis and measurement, response and treatment.
Your management-system position across all seven domains — and the gap to certification if that is where you are heading.
The shape of your AI estate: agentic or assistive, human-in-the-loop, model inventory, drift monitoring, third-party dependency.
Written for a board, not a data science team. Where you stand on all three frameworks, what matters most, and the governance implications.
Priority actions from all three views consolidated into one plan, ordered by exposure, with owners and timeframes.
A session with your board or executive team on what the results mean, what the regulator will ask, and what to decide first.
CyberPrism holds your assessment, evidence, dashboards and reports in one place — and keeps them current after the assessment ends, rather than leaving you with a document that dates on the day it is delivered.
AI governance is a native module. The EU AI Act, NIST AI RMF and ISO/IEC 42001 are overlays on one declarations library, alongside NIS2, DORA and NIST CSF 2.0 — so the AI view sits beside your cyber view, and the board sees both on the same platform.
The assessment ends with a decision, not a filing cabinet. Most organisations choose one of two paths.
Keep your CyberPrism environment live. Track remediation, re-assess as AI use grows and the high-risk dates approach, and give your board a standing AI governance view — with the evidence base ready when a supervisor, an auditor or an ISO/IEC 42001 certifier asks.
Take the report and roadmap and work through it with your own team, counsel or existing providers. Nothing in the assessment ties you to CRI, and the roadmap is written so it can be handed to whoever will deliver it.
Yes. The Act distinguishes providers, who build or place AI on the market, from deployers, who use it under their own authority. Almost every organisation is a deployer. Deployer obligations — literacy measures, transparency, human oversight and, for high-risk uses, record keeping and monitoring — attach to how you use the system, not to whether you wrote it.
The Digital Omnibus moved the high-risk obligations to 2 December 2027 for Annex III uses and 2 August 2028 for AI in regulated products. It did not move the general application date of 2 August 2026, the prohibited practices, the transparency duties or the AI literacy obligation. And the high-risk requirements — a risk management system, technical documentation, logging, human oversight — take longer than sixteen months to build from nothing. The deferral is time to do it properly, not time to wait.
No. It is a readiness assessment based on your organisation's declarations and the evidence behind them, designed to show leadership where AI is well governed and where it is not. It is not legal advice and not a determination of compliance with the AI Act, and it is not ISO/IEC 42001 certification. It is, however, exactly the evidence base your counsel, your regulator and a certifier will expect you to have.
Because they ask the same questions from different angles, and different stakeholders want different answers. A regulator will ask about the Act. A US customer or a group parent may ask about NIST AI RMF. A certifier or a procurement team may ask about ISO/IEC 42001. One set of declarations on CyberPrism produces all three views, so you are not assessed three times.
Typically two to three hours a week from a coordinator, plus one short session each with the people who own the relevant areas — the business functions using AI, IT and data, risk and compliance, HR, procurement, legal. Our practitioner does the structuring, mapping and analysis so your team is answering questions, not writing reports. Four weeks works because the platform holds the frameworks; nobody is building spreadsheets.
The programme is fixed-price for a defined scope, which is confirmed on the scoping call. We will not sell you a longer engagement than you need.
Four weeks suits most organisations with a single legal entity and a coordinator who can give it a few hours a week. Larger groups, organisations with many AI systems in scope or those that build AI as well as use it may need longer, and the programme can be extended by agreement at scoping or during week one. The scope, timetable and price are settled before work starts, so an extension is never a surprise.
A 30-minute scoping call is enough to confirm where AI is likely to sit in your organisation, which regulator will ask, what the four weeks would cover, and when it could start.