AI inventory and classification
We map internally developed systems and third-party AI tools, their purpose, users, suppliers, affected people and the organisation’s role. Each use case receives a preliminary classification under the EU AI Act.
We assess AI systems, data, suppliers, responsibilities and controls to turn EU AI Act and GDPR obligations into a practical, documented and actionable plan.
The same model can create very different risks depending on its purpose, data, users, affected people and role in business decisions.
We map internally developed systems and third-party AI tools, their purpose, users, suppliers, affected people and the organisation’s role. Each use case receives a preliminary classification under the EU AI Act.
We assess personal data categories, purpose, legal basis, data minimisation, retention, access, international transfers, individual rights and whether a Data Protection Impact Assessment may be required.
We review responsibilities, approval of AI use cases, human oversight, change management, records, monitoring, incident management, complaints and AI literacy.
We examine contracts, technical documentation, data used for training, subprocessors, security measures, service levels, known limitations and the evidence supplied by each provider.
AI governance defines who may approve a system, which information may be used, when human review is required, how performance is monitored and what happens when the system fails.
A policy on its own is not governance. The organisation must be able to show that responsibilities, controls and escalation procedures are understood and applied in practice.
Supplier documentation is one part of the assessment, but it cannot describe how the organisation uses the system in practice.
The organisation knows the specific purpose, the data entered, the people affected, the decisions supported and how the output becomes part of a business process. We compare documented controls with actual use.
A control that exists in a policy but is unknown to the people using the tool does not reduce operational or regulatory risk.
The EU AI Act defines obligations according to the organisation’s role and the risk associated with the AI system.
GDPR applies whenever personal data is processed, covering purpose, legal basis, transparency, minimisation, security, individual rights and automated decision-making.
The same AI system may also involve employment law, consumer protection, intellectual property, cybersecurity, public procurement or sector-specific regulation. This is why our assessments bring together architecture, data, processes, security, AI governance and legal advice.
The outcome is not an undifferentiated list of problems.
Each gap is linked to the relevant system, risk, requirement, available evidence, recommended action, responsible owner and implementation priority.
Where a use case cannot be controlled appropriately, the recommendation may be to redesign it, restrict its use or stop it. Good AI governance also means knowing when not to proceed.
BigLearn provides an AI readiness and compliance assessment. We collect evidence, identify gaps and support remediation.
The audit is not an official certification, a decision by a competent authority or an abstract guarantee of legal compliance.
BigLearn conducts the technical and organisational assessment. The legal analysis is supported by a qualified lawyer and coordinated with the organisation’s Data Protection Officer, legal team and other responsible stakeholders when applicable.
AI governance is the set of responsibilities, policies, processes and controls that allows an organisation to decide which AI systems it may use, for which purposes, with which data and under whose responsibility.
It is not limited to legal compliance. An effective AI governance framework connects strategy, risk, technology, security, data protection and operations. It defines how use cases are approved, which evidence must exist, when human oversight is required and how incidents, changes and complaints are handled.
Named owners for each system, approval of new use cases, and the criteria for accepting, restricting, redesigning or rejecting a use of AI.
Practical rules for employees, permitted data, approved tools, human oversight, validation of outputs and the use of generative AI.
System inventory, risk classification, impact assessments, decision records, technical documentation and the evidence needed to demonstrate control.
Performance tracking, model changes, incidents, complaints, suppliers and the effectiveness of controls across the system lifecycle.
We identify the systems, processes, legal entities, teams, suppliers and decisions covered by the assessment. The scope may include one use case, one business area or the organisation’s complete AI portfolio.
We examine policies, contracts, data flows, technical documentation, access controls, system records, tests, operating instructions and human oversight mechanisms.
We compare real-world use with the applicable requirements and assess impact, likelihood, existing controls and available evidence.
We prioritise actions, owners and implementation dates. BigLearn can support documentation, policies, technical controls, system changes, training, handover and follow-up assessments.
A structured record of systems, models, tools, suppliers, purposes, owners, data and affected people.
The organisation’s role, preliminary risk classification, applicable requirements and the evidence that exists or remains missing.
Findings for each system, their impact and priority, dependencies and issues requiring legal or management decisions.
Recommended technical, organisational, contractual and documentary measures, with owners and implementation priorities.
Responsibilities, an internal AI policy, a use-case approval process, risk criteria, controls, documentation and monitoring mechanisms.
Role-based training so that controls are applied in practice and the organisation can maintain its governance framework and evidence.
An AI audit loses value when the legal team receives only a commercial description of the technology, or when the technical team receives only a list of legal provisions. We work with the real process, data, architecture, contracts and operating environment.
BigLearn assesses the technical and organisational components and can implement the agreed controls. The legal framework is considered alongside a qualified lawyer and the organisation’s internal stakeholders.
Miguel Abreu Peixoto is a Portuguese lawyer, professional registration no. 12901L, with more than 30 years of legal experience. His background includes two decades in the banking sector across legal advisory, compliance, operational risk, internal audit and customer complaint management.
At BigLearn, he supports the legal framework and governance of artificial intelligence projects, with a focus on GDPR, the EU AI Act and the connection between regulatory obligations and operational controls. View Miguel Abreu Peixoto’s profile or his LinkedIn.
AI governance is the system an organisation uses to direct and control its use of artificial intelligence. It defines responsibilities, policies, approval processes, risk criteria, documentation, human oversight, monitoring and incident response. The goal is to make it possible to use AI with control, evidence and accountability.
An AI audit is a structured assessment of the AI systems used or developed by an organisation. It identifies purposes, data, suppliers, affected people, supported decisions, risk classification, documentation and controls. It concludes with a gap report and remediation roadmap.
The AI Act regulates AI systems and models through a risk-based framework. GDPR regulates the processing of personal data. The same system may be subject to both frameworks, as well as employment, consumer, intellectual property, security or sector-specific rules.
Yes. The regulation entered into force on 1 August 2024 and became generally applicable on 2 August 2026, with phased obligations and exceptions. Prohibited AI practices and AI literacy obligations have applied since 2 February 2025. Some requirements for high-risk AI systems have later application dates. The applicable timeline must be confirmed for each system at the time of assessment.
Yes. The level of assessment depends on how the tool is used. Summarising public information is different from processing personal data, assessing candidates, supporting credit decisions, communicating with customers or influencing decisions that have a significant effect on people. The organisation should know which tools are being used, what data enters them, who supplies them and which decisions they support.
No. The audit identifies the applicable framework, reviews evidence, assesses controls and documents gaps. It is not an official certification or an abstract guarantee of compliance. The technical and organisational assessment is conducted by BigLearn. The legal framework is supported by a qualified lawyer and assessed according to the specific use case.
The organisation receives an inventory of the systems assessed, a preliminary classification of its role and risk, a requirements and evidence matrix, identified gaps, remediation priorities, recommended owners and an implementation roadmap.
Our assessments use the following primary sources:
The applicable framework and implementation dates must always be confirmed for the specific system and the date of the assessment.
Role-based training on safe use, data governance, human oversight, GDPR, the EU AI Act and internal policies.
See AI trainingArchitecture, access controls, records, human oversight, integrations and monitoring to address identified gaps.
See bespoke solutionsEnhanced assessment of recruitment, evaluation, worker management, personal data and decisions that may significantly affect people.
See AI for HR