AI governance, compliance and audit of artificial intelligence systems
AI Governance · Compliance · AI Audit · EU AI Act · GDPR

AI Governance, Compliance and Audit

We assess AI systems, data, suppliers, responsibilities and controls to turn EU AI Act and GDPR obligations into a practical, documented and actionable plan.

An AI audit starts with the systems an organisation actually uses, rather than a generic compliance checklist

The same model can create very different risks depending on its purpose, data, users, affected people and role in business decisions.

AI inventory and classification

We map internally developed systems and third-party AI tools, their purpose, users, suppliers, affected people and the organisation’s role. Each use case receives a preliminary classification under the EU AI Act.

Data and GDPR

We assess personal data categories, purpose, legal basis, data minimisation, retention, access, international transfers, individual rights and whether a Data Protection Impact Assessment may be required.

AI governance and control

We review responsibilities, approval of AI use cases, human oversight, change management, records, monitoring, incident management, complaints and AI literacy.

Suppliers and evidence

We examine contracts, technical documentation, data used for training, subprocessors, security measures, service levels, known limitations and the evidence supplied by each provider.

AI governance turns obligations into accountable decisions

AI governance defines who may approve a system, which information may be used, when human review is required, how performance is monitored and what happens when the system fails.

A policy on its own is not governance. The organisation must be able to show that responsibilities, controls and escalation procedures are understood and applied in practice.

AI compliance is more than a supplier questionnaire

Supplier documentation is one part of the assessment, but it cannot describe how the organisation uses the system in practice.

The organisation knows the specific purpose, the data entered, the people affected, the decisions supported and how the output becomes part of a business process. We compare documented controls with actual use.

A control that exists in a policy but is unknown to the people using the tool does not reduce operational or regulatory risk.

The EU AI Act and GDPR apply together

The EU AI Act defines obligations according to the organisation’s role and the risk associated with the AI system.

GDPR applies whenever personal data is processed, covering purpose, legal basis, transparency, minimisation, security, individual rights and automated decision-making.

The same AI system may also involve employment law, consumer protection, intellectual property, cybersecurity, public procurement or sector-specific regulation. This is why our assessments bring together architecture, data, processes, security, AI governance and legal advice.

An AI audit must produce priorities, owners and evidence

The outcome is not an undifferentiated list of problems.

Each gap is linked to the relevant system, risk, requirement, available evidence, recommended action, responsible owner and implementation priority.

Where a use case cannot be controlled appropriately, the recommendation may be to redesign it, restrict its use or stop it. Good AI governance also means knowing when not to proceed.

We do not sell a certification that does not exist

BigLearn provides an AI readiness and compliance assessment. We collect evidence, identify gaps and support remediation.

The audit is not an official certification, a decision by a competent authority or an abstract guarantee of legal compliance.

BigLearn conducts the technical and organisational assessment. The legal analysis is supported by a qualified lawyer and coordinated with the organisation’s Data Protection Officer, legal team and other responsible stakeholders when applicable.

AI governance: clear rules for deciding, using and controlling AI

AI governance is the set of responsibilities, policies, processes and controls that allows an organisation to decide which AI systems it may use, for which purposes, with which data and under whose responsibility.

It is not limited to legal compliance. An effective AI governance framework connects strategy, risk, technology, security, data protection and operations. It defines how use cases are approved, which evidence must exist, when human oversight is required and how incidents, changes and complaints are handled.

Responsibilities and decisions

Named owners for each system, approval of new use cases, and the criteria for accepting, restricting, redesigning or rejecting a use of AI.

Policies and internal use

Practical rules for employees, permitted data, approved tools, human oversight, validation of outputs and the use of generative AI.

Risk, documentation and evidence

System inventory, risk classification, impact assessments, decision records, technical documentation and the evidence needed to demonstrate control.

Monitoring and continuous improvement

Performance tracking, model changes, incidents, complaints, suppliers and the effectiveness of controls across the system lifecycle.

From discovery to remediation

1. Define the scope

We identify the systems, processes, legal entities, teams, suppliers and decisions covered by the assessment. The scope may include one use case, one business area or the organisation’s complete AI portfolio.

2. Collect evidence

We examine policies, contracts, data flows, technical documentation, access controls, system records, tests, operating instructions and human oversight mechanisms.

3. Assess risk and gaps

We compare real-world use with the applicable requirements and assess impact, likelihood, existing controls and available evidence.

4. Remediate and monitor

We prioritise actions, owners and implementation dates. BigLearn can support documentation, policies, technical controls, system changes, training, handover and follow-up assessments.

What the organisation receives

AI system inventory

A structured record of systems, models, tools, suppliers, purposes, owners, data and affected people.

Requirements and evidence matrix

The organisation’s role, preliminary risk classification, applicable requirements and the evidence that exists or remains missing.

Gap and risk report

Findings for each system, their impact and priority, dependencies and issues requiring legal or management decisions.

Remediation roadmap

Recommended technical, organisational, contractual and documentary measures, with owners and implementation priorities.

AI governance model

Responsibilities, an internal AI policy, a use-case approval process, risk criteria, controls, documentation and monitoring mechanisms.

Training and handover

Role-based training so that controls are applied in practice and the organisation can maintain its governance framework and evidence.

Technology and law assessed together

An AI audit loses value when the legal team receives only a commercial description of the technology, or when the technical team receives only a list of legal provisions. We work with the real process, data, architecture, contracts and operating environment.

BigLearn assesses the technical and organisational components and can implement the agreed controls. The legal framework is considered alongside a qualified lawyer and the organisation’s internal stakeholders.

Legal counsel: Miguel Abreu Peixoto

Miguel Abreu Peixoto is a Portuguese lawyer, professional registration no. 12901L, with more than 30 years of legal experience. His background includes two decades in the banking sector across legal advisory, compliance, operational risk, internal audit and customer complaint management.

At BigLearn, he supports the legal framework and governance of artificial intelligence projects, with a focus on GDPR, the EU AI Act and the connection between regulatory obligations and operational controls. View Miguel Abreu Peixoto’s profile or his LinkedIn.

Frequently asked questions

What is AI governance?

AI governance is the system an organisation uses to direct and control its use of artificial intelligence. It defines responsibilities, policies, approval processes, risk criteria, documentation, human oversight, monitoring and incident response. The goal is to make it possible to use AI with control, evidence and accountability.

What is an artificial intelligence audit?

An AI audit is a structured assessment of the AI systems used or developed by an organisation. It identifies purposes, data, suppliers, affected people, supported decisions, risk classification, documentation and controls. It concludes with a gap report and remediation roadmap.

What is the difference between the EU AI Act and GDPR?

The AI Act regulates AI systems and models through a risk-based framework. GDPR regulates the processing of personal data. The same system may be subject to both frameworks, as well as employment, consumer, intellectual property, security or sector-specific rules.

Does the EU AI Act already apply to businesses?

Yes. The regulation entered into force on 1 August 2024 and became generally applicable on 2 August 2026, with phased obligations and exceptions. Prohibited AI practices and AI literacy obligations have applied since 2 February 2025. Some requirements for high-risk AI systems have later application dates. The applicable timeline must be confirmed for each system at the time of assessment.

Should a company that only uses ChatGPT, Copilot or another third-party tool assess its risks?

Yes. The level of assessment depends on how the tool is used. Summarising public information is different from processing personal data, assessing candidates, supporting credit decisions, communicating with customers or influencing decisions that have a significant effect on people. The organisation should know which tools are being used, what data enters them, who supplies them and which decisions they support.

Does a BigLearn audit certify legal compliance?

No. The audit identifies the applicable framework, reviews evidence, assesses controls and documents gaps. It is not an official certification or an abstract guarantee of compliance. The technical and organisational assessment is conducted by BigLearn. The legal framework is supported by a qualified lawyer and assessed according to the specific use case.

What does the organisation receive at the end of the audit?

The organisation receives an inventory of the systems assessed, a preliminary classification of its role and risk, a requirements and evidence matrix, identified gaps, remediation priorities, recommended owners and an implementation roadmap.

Official framework and regulatory updates

Our assessments use the following primary sources:

The applicable framework and implementation dates must always be confirmed for the specific system and the date of the assessment.

Related services

Do you know which AI systems are being used across your organisation?

We start with an inventory and one concrete use case. We identify the risk, available evidence and the first issues that should be addressed.

Discuss AI governance and compliance with BigLearn