Your counsel decides which obligations and systems are in scope. We test whether the matching evidence, controls, owners, exceptions, and remediation records exist and are current, and the compliance conclusion stays theirs.

Your qualified authority defines which EU AI Act obligations and systems are in scope. We test whether the corresponding organizational evidence, controls, owners, exceptions, and remediation records exist and are current. The legal and compliance conclusion remains theirs.

Nothing in the report says whether you comply. It says which readiness statements survived a check against sampled systems, which exceptions are critical, and who committed to close them.

Illustration of EU AI Act Readiness Assessment: a team reviewing AI policy and risk controls in a governance framework

Some of the 500+ brands we've worked with

See all references
  • KPMG
  • Arabam.com
  • BNP Paribas Cardif
  • Exquise
  • DYO
  • S Sport Plus

The client-supplied interpretation fixes the legal boundary. Within it, we follow each readiness statement to current evidence and test selected systems directly instead of accepting a self-reported status.

  1. Confirm the interpreted scope

    Your qualified authority supplies the applicable obligations, systems, roles, and acceptance owner. We translate that supplied boundary into technical assessment points without adding our own legal interpretation.

    AI assist
    The model organizes supplied obligations and systems into a scope summary. It does not interpret them.
    Human gate
    Is the supplied set of obligations, systems, and assessment points specific enough for your authority to confirm the test boundary? Your qualified authority confirms the interpretation and the boundary for the technical review.
  2. Follow every statement to evidence

    Policies, role records, technical artifacts, operating controls, incidents, exceptions, and dependencies are linked to the assessment points agreed at the start. Missing or outdated evidence remains visible.

    AI assist
    Approved policies, records, and control evidence are placed beside the agreed assessment points.
    Human gate
    Does every readiness statement have a current source and an owner who can explain it? Your qualified authority decides which readiness statements still lack sufficient current evidence.
  3. Check representative systems directly

    We sample selected systems and controls to see whether the operating evidence matches the stated readiness position. Contradictory, missing, or weak proof is recorded as an exception and cannot count as a pass.

    AI assist
    The sampled evidence is compared with the stated controls to flag gaps and contradictions for a specialist.
    Human gate
    Which critical exceptions prevent the sampled evidence from supporting an honest readiness position? Your qualified authority decides which exception blocks acceptance of the readiness record.
  4. Assign remediation ownership

    Observed gaps are prioritized and attached to owners, dependencies, and next actions. Work that remains unresolved receives a decision state and a date when your authority will review the position again.

    AI assist
    Tested findings, owners, and dependencies become a draft gap register and remediation sequence for review.
    Human gate
    Does every open critical gap have an owner, next action, dependency state, and review date? Your qualified authority accepts the handoff and confirms who owns every open gap.

The final record shows what we observed against your interpreted scope and which evidence was reviewed. It does not contain Zeo's legal or compliance opinion.

  • Risk register

    Readiness gaps and the remediation plan behind them

    Observed gaps for the agreed obligations, with their evidence, priority, owner, dependency, and next action.

  • Test evidence

    Source list and open assumptions behind the readiness call

    The sources used during review, their limits and versions, open assumptions, and dependencies affecting the readiness position.

  • Report

    Sampled-systems readout and the critical exceptions

    The systems sampled, controls checked, contradictory evidence, critical exceptions, and conditions found in the review.

  • Decision record

    Accepted scope, remediation commitments, and next review

    The accepted assessment scope, open conditions, remediation commitments, decision owner, and next review date.

This review helps when a legal interpretation exists but the supporting evidence is scattered across policy files, system records, owners, and open exceptions.

A good fit when

  • Your counsel has interpreted which obligations apply, but the evidence that would satisfy them is spread across policy files, system records, and inboxes.
  • A control is marked in place against an obligation, and nobody can say which system it covers, who maintains it, or when it was last checked.
  • The organization is preparing a broad readiness claim before representative systems and controls have been checked.
  • Which obligations apply is settled, but the assessment boundary they imply has never been drawn around named systems and named owners.
  • Evidence, controls, owners, dependencies, and exceptions all exist in some form, yet nothing maps them onto the obligations your authority interpreted.
  • Readiness has been asserted from documents alone, so nobody has opened a representative system and checked the control actually running in it.
  • A gap list would need owners, dates, and a route back to whoever accepts residual exposure, though none of that exists yet.

Better handled as other work when

  • You want us to say whether you comply. We report whether the evidence behind your authority's interpretation exists, and the determination stays theirs.
  • You are after a certificate or a promise that conformity will hold at some future date. Neither is something a readiness review can issue.
  • You want the gaps closed as part of this work. Remediation runs outside the agreed review unless it is commissioned alongside it.

If one of these is closer to your situation, start here instead: View the governance service

We've worked with more than 500 brands since Zeo started in 2011. The people helping you decide where AI fits, and where it doesn't yet, are senior engineers and strategists who build and operate production AI systems. The advice stays grounded in work that actually shipped.

  • OneTrust

    the EU AI Act evidence register used to organize the readiness review

  • Airtable

    the tracker linking each gap to its evidence status and remediation owner

  • Credo AI

    the EU AI Act policy pack a gap finding traces back to a specific article

Your interpreted obligations and supporting records set the boundary. The review tests representative systems and shows which controls, exceptions, and owners remain open.
Assess readiness

Your qualified authority must provide its interpretation of the applicable obligations and the systems, roles, and assessment points in scope. We also need current policy, technical, operational, control, incident, and exception records, plus the people authorized to accept the result.