EU AI Act · NIST AI RMF · ISO/IEC 42001 · The 4-Week AI Governance Readiness Assessment

Your people are already using AI. Can your board show it is governed?

A fixed-scope, four-week assessment of how your organisation governs artificial intelligence — measured against the EU AI Act, the NIST AI Risk Management Framework and ISO/IEC 42001 at once. You leave with a readiness position on all three, the obligation areas where you are exposed, and a roadmap your board can own.

The AI Act applies to every organisation that uses AI, not only those that build it. Providers and deployers "shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf" — regardless of the risk tier of the systems involved.

Article 4(1) of the AI Act as amended by the Digital Omnibus on AI, in force since 27 July 2026. The Omnibus also moved the high-risk obligations to December 2027 and August 2028 — it did not move the general application date of 2 August 2026.
Source: Regulation (EU) 2024/1689 (AI Act), Article 4, as amended by Regulation (EU) 2026/1744eur-lex.europa.eu
Trusted expertise in regulated digital resilience
Operating since 2014 CyberPrism on Azure Marketplace Enterprise Ireland-backed technology Partnered with eir business
Awards and accreditations: IRM Global Risk Awards 2016, Bank of Ireland Startup Awards 2017 Fintech Award, HM Government G-Cloud approved supplier, CIR Risk Management Awards winner — Risk Management Specialist Company of the Year

The law is in force. The deadlines moved. The governance question did not.

The AI Act has applied in stages since 2024, and its general application date passed on 2 August 2026. The Digital Omnibus gave high-risk systems more time — but literacy, transparency, prohibited practices and the expectation that AI is governed like any other material risk are all live now.

2 AUG 2026

General application date

The AI Act's general application date, unchanged by the Omnibus. Prohibited practices and AI literacy have applied since February 2025; transparency duties for chatbots and generated content apply from this date.

2 DEC 2027

High-risk obligations (Annex III)

Stand-alone high-risk uses — employment, credit, essential services and the other Annex III categories — now apply from 2 December 2027; AI embedded in regulated products from 2 August 2028. Sixteen months, not a reprieve.

15 REGULATORS

Ireland's distributed model

Ireland has designated fifteen sectoral competent authorities — the Central Bank, the DPC, Coimisiún na Meán and others — coordinated by a national AI Office. The regulator that asks about your AI is one you already know.

"Are we compliant with the AI Act?" is the wrong first question. The right one is "do we know where AI is used, who owns it, and could we evidence how it is governed if asked?"

That question is answerable in four weeks — and it is the same question NIST AI RMF and ISO/IEC 42001 ask, which is why this assessment measures all three at once.

What the AI Act expects of the board

The Act is written for providers and deployers, not IT departments. Its obligations on a deployer — human oversight, transparency, record keeping, literacy — are organisational commitments that only a management body can make and only evidence can prove.

Across the three frameworks, leadership is expected to establish and be able to evidence:

  • An inventory of where AI is used, by whom, and at which risk tier
  • Accountable owners and decision rights for AI — named, recorded and current
  • An AI policy and risk appetite, integrated into enterprise risk management
  • Meaningful human oversight of AI decisions, especially in higher-risk uses
  • Transparency to staff, customers and clients that they are dealing with AI
  • Measures supporting AI literacy across everyone who operates or uses AI systems

The pattern we see most often is capability without ownership: monitoring and operational controls are ahead of leadership, governance and performance evaluation. That is exactly the gap a regulator, an auditor or an incident investigation will find first.

BOARD QUESTIONS

What a management body should be able to answer

  • Where is AI used in the organisation today — including inside vendor products and staff tools?
  • Which of those uses would the AI Act treat as high-risk, and who signed that off?
  • Who can overrule an AI-influenced decision, and has it ever happened?
  • Could we reconstruct how a specific AI decision was reached, six months later?
  • What have we done about AI literacy, and can we show it?
WHAT IS MEASURED

What the assessment measures

Three frameworks, one set of declarations, three readiness views
  • EU AI Act obligation areas — risk management system, data governance, technical documentation, record keeping, transparency, human oversight, accuracy and cybersecurity, post-market monitoring
  • NIST AI RMF functions — governance and accountability, context and risk identification, analysis and measurement, response and treatment
  • ISO/IEC 42001 domains — context, leadership and governance, planning and risk, support and resources, operational controls, performance evaluation, continuous improvement
  • Every declaration rated Achieved, In Progress or Not Achieved, with evidence
  • AI control profiling — presence and type of AI, governance overlay, lifecycle and change risk, risk characteristics, third-party AI risk
  • Strongest and weakest areas per framework, with the governance implications spelled out
  • Priority actions per framework and a single consolidated roadmap
  • An honest attestation caveat — a declared position, with the evidence gaps named
CyberPrism carries the EU AI Act, NIST AI RMF and ISO/IEC 42001 as overlays on one declarations library, so a control declared once is read through all three without a second questionnaire.

Who it is for

Almost every organisation is a deployer under the AI Act. The ones that need this most fall into two groups.

Organisations using AI in decisions that matter

Where high-risk obligations will land
  • Financial services — credit, insurance pricing, fraud and AML models, where the Central Bank is the AI Act authority
  • Employers using AI in recruitment, performance or workforce decisions
  • Health, education and public bodies making decisions about access to services
  • Any organisation whose vendors have quietly added AI to the products it relies on

Organisations that need to show they govern AI

Where a standard is the answer
  • Boards that have adopted an AI policy and now want to know whether it is followed
  • Firms whose customers, insurers or supervisors are asking for AI governance evidence
  • Organisations considering ISO/IEC 42001 certification and wanting a gap view first
  • Groups that want one AI governance measure across entities in different regimes
Three lenses, one evidence base — the EU AI Act, NIST AI RMF and ISO/IEC 42001 read from one set of declarations on CyberPrism
One set of declarations, three readiness views. Which framework to lead with is settled in week one.

The three frameworks — and what each asks of you

A law, a risk framework and a management standard. They overlap heavily, which is the point: assess once, and you have a position on all three.

EU AI ACT

The legal obligations

Regulation (EU) 2024/1689, risk-based: prohibited, high, limited and minimal. For deployers the assessment reads nine obligation areas, from the risk management system and data governance through human oversight and transparency to post-market monitoring.

Not a legal determination of compliance — a readiness indication your counsel and your regulator can work from.

NIST AI RMF

The risk framework

Voluntary and globally recognised. Built on four functions — Govern, Map, Measure, Manage — which the assessment scores as governance and accountability, context and risk identification, analysis and measurement, and response and treatment.

Where "doing" AI risk management is separated from "owning" it.

ISO/IEC 42001

The management standard

The first international AI management system standard. The assessment scores its seven domains: context, leadership and governance, planning and risk, support and resources, operational controls, performance evaluation, continuous improvement.

The certification route if you want one — and the gap view before you commit.

Illustrative summary of the EU AI Act's four risk tiers — unacceptable, high, limited and minimal — and the duties attached to each
Obligations scale with the use. Most organisations deploy AI at several tiers at once; knowing which systems sit where is the first question.

Most organisations cannot yet list where AI is used — let alone show a board that it is governed.

An AI policy, a vendor's assurance and a well-meaning working group are not governance. Governance is an inventory, named owners, a risk appetite, human oversight that has actually been exercised, and evidence a regulator could examine. Four weeks is enough to establish where you stand on all of it.

The AI Governance Readiness Assessment

Fixed scope. Four weeks. Delivered on the CyberPrism platform with a CRI practitioner guiding your team throughout — so the work is done with you, not to you.

WEEK 1

Onboarding and AI inventory

Find out where AI actually is
  • Capture business context, sector regulator and obligations
  • Inventory AI in use — built, bought and embedded in vendor products
  • First view of risk tiers under the AI Act and which framework to lead with
WEEK 2

Assessment

Declare and evidence
  • Structured working sessions across the obligation areas, functions and domains — your team answers, we structure
  • Every declaration rated Achieved, In Progress or Not Achieved
  • AI control profiling: presence, governance overlay, lifecycle, third-party risk
WEEK 3

Analysis and dashboards

Three readiness views
  • Live dashboards for the AI Act, NIST AI RMF and ISO/IEC 42001
  • Strongest and weakest areas identified per framework
  • Evidence gaps behind "achieved" declarations named
WEEK 4

Board and roadmap

Decide what happens next
  • AI Readiness Board & Executive Report delivered
  • Consolidated, prioritised remediation roadmap with owners
  • Board or executive briefing in person
Paul C Dwyer, CEO of Cyber Risk International

"In every AI assessment we run, the operational controls are ahead of the boardroom. People are monitoring models nobody at the top has formally owned. The Act doesn't punish you for using AI — it asks whether someone accountable can explain how."

Paul C Dwyer — CEO, Cyber Risk International; President, ICTTF; author of Cyber Risk Leadership

What you receive

Every deliverable is written for the management body that will be asked to explain its AI — and the report is the artefact it signs off.

AI inventory and risk-tier map

Where AI is used across the organisation, including inside vendor products, and which AI Act tier each use falls into.

EU AI Act readiness

Your position across the obligation areas — achieved, in progress and not achieved — with the strongest and weakest areas named.

NIST AI RMF readiness

Maturity across governance and accountability, context and risk, analysis and measurement, response and treatment.

ISO/IEC 42001 readiness

Your management-system position across all seven domains — and the gap to certification if that is where you are heading.

AI control profiling heatmap

The shape of your AI estate: agentic or assistive, human-in-the-loop, model inventory, drift monitoring, third-party dependency.

Board & Executive Report

Written for a board, not a data science team. Where you stand on all three frameworks, what matters most, and the governance implications.

Prioritised remediation roadmap

Priority actions from all three views consolidated into one plan, ordered by exposure, with owners and timeframes.

Board briefing

A session with your board or executive team on what the results mean, what the regulator will ask, and what to decide first.

The CyberPrism AI Readiness Board and Executive Report: cover, EU AI Act obligation areas chart and AI control profiling heatmap
The AI Readiness — Board & Executive Report, sample pages
INSIDE THE REPORT

What your board will read

  • Executive summary — overall AI readiness position, key strengths, priority risks, governance and accountability implications, recommended executive actions
  • EU AI Act — readiness dashboards by obligation area, strongest and weakest areas, key risks, priority actions, executive assessment
  • NIST AI RMF — function maturity dashboards, governance and accountability analysis, AI risk management capability, next steps
  • ISO/IEC 42001 — domain maturity dashboards, leadership and governance assessment, operational effectiveness, next steps
  • AI control profiling heatmap — presence and type, governance overlay, lifecycle and change risk, risk characteristics, third-party AI risk
  • Closing statement — how to use the report, and why an attested position is not yet an evidenced one
3 frameworks9 obligation areas4 functions7 domains

Built on CyberPrism

CyberPrism holds your assessment, evidence, dashboards and reports in one place — and keeps them current after the assessment ends, rather than leaving you with a document that dates on the day it is delivered.

AI governance is a native module. The EU AI Act, NIST AI RMF and ISO/IEC 42001 are overlays on one declarations library, alongside NIS2, DORA and NIST CSF 2.0 — so the AI view sits beside your cyber view, and the board sees both on the same platform.

EU AI ActNIST AI RMFISO/IEC 42001NIS2DORAThreatLens
CyberPrism AI governance dashboard showing readiness across the EU AI Act, NIST AI RMF and ISO/IEC 42001
AI Governance — readiness across the EU AI Act, NIST AI RMF and ISO/IEC 42001.Click to enlarge

After the four weeks

The assessment ends with a decision, not a filing cabinet. Most organisations choose one of two paths.

CONTINUOUS ASSURANCE

Keep your CyberPrism environment live. Track remediation, re-assess as AI use grows and the high-risk dates approach, and give your board a standing AI governance view — with the evidence base ready when a supervisor, an auditor or an ISO/IEC 42001 certifier asks.

DELIVER IT YOURSELVES

Take the report and roadmap and work through it with your own team, counsel or existing providers. Nothing in the assessment ties you to CRI, and the roadmap is written so it can be handed to whoever will deliver it.

Board meeting in progress
AI governance is something a board maintains, not something it receives once.

Common questions

We only use AI tools we bought — does the AI Act apply to us?

Yes. The Act distinguishes providers, who build or place AI on the market, from deployers, who use it under their own authority. Almost every organisation is a deployer. Deployer obligations — literacy measures, transparency, human oversight and, for high-risk uses, record keeping and monitoring — attach to how you use the system, not to whether you wrote it.

The high-risk deadline moved to 2027. Can this wait?

The Digital Omnibus moved the high-risk obligations to 2 December 2027 for Annex III uses and 2 August 2028 for AI in regulated products. It did not move the general application date of 2 August 2026, the prohibited practices, the transparency duties or the AI literacy obligation. And the high-risk requirements — a risk management system, technical documentation, logging, human oversight — take longer than sixteen months to build from nothing. The deferral is time to do it properly, not time to wait.

Is this a legal determination of compliance?

No. It is a readiness assessment based on your organisation's declarations and the evidence behind them, designed to show leadership where AI is well governed and where it is not. It is not legal advice and not a determination of compliance with the AI Act, and it is not ISO/IEC 42001 certification. It is, however, exactly the evidence base your counsel, your regulator and a certifier will expect you to have.

Why measure against three frameworks at once?

Because they ask the same questions from different angles, and different stakeholders want different answers. A regulator will ask about the Act. A US customer or a group parent may ask about NIST AI RMF. A certifier or a procurement team may ask about ISO/IEC 42001. One set of declarations on CyberPrism produces all three views, so you are not assessed three times.

How much of our team's time does it take?

Typically two to three hours a week from a coordinator, plus one short session each with the people who own the relevant areas — the business functions using AI, IT and data, risk and compliance, HR, procurement, legal. Our practitioner does the structuring, mapping and analysis so your team is answering questions, not writing reports. Four weeks works because the platform holds the frameworks; nobody is building spreadsheets.

What does it cost?

The programme is fixed-price for a defined scope, which is confirmed on the scoping call. We will not sell you a longer engagement than you need.

What if four weeks is not enough for us?

Four weeks suits most organisations with a single legal entity and a coordinator who can give it a few hours a week. Larger groups, organisations with many AI systems in scope or those that build AI as well as use it may need longer, and the programme can be extended by agreement at scoping or during week one. The scope, timetable and price are settled before work starts, so an extension is never a surprise.

Know how your AI is governed before someone asks you to prove it.

A 30-minute scoping call is enough to confirm where AI is likely to sit in your organisation, which regulator will ask, what the four weeks would cover, and when it could start.

Book a scoping call
CRI partner with eir business
Prefer to talk? Call +353 (0)1 905 3260.