SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    Services

    Get the assessment your decision requires.

    Commission a threat model, DPIA, gap analysis, or AI Act assessment. We retrieve the evidence through the same governed gateway used by the product, and a senior practitioner reviews the material findings, judgments, and limits before delivery.

    Fixed scope · quote and date after a 30-minute call.
    The deliverables

    Different deliverables. One evidence discipline.

    Each engagement links factual findings to the provision, technique, control, or customer evidence that supports them. Missing support remains visible in the delivered assessment.

    AI Act Readiness Assessment

    Classify your AI systems against the EU AI Act, then know exactly which obligations apply before they bite.

    • System inventory and risk classification against Article 5, Article 6, and Annex III
    • Obligations mapped to your role: provider, deployer, importer, or distributor
    • Gap register with per-obligation status, evidence, and owner
    • Board-ready readout and a prioritised remediation plan

    See a real run: an EU AI Act high-risk classification for credit scoring the same classification questions this assessment answers, cited to the Act with unresolved national points marked — captured verbatim.

    Read the full sample deliverable → a fictional AI Act assessment worked through the full method; senior review is pending.

    Threat Model as a Service

    A structured threat model for your system, built on STRIDE and LINDDUN and your real architecture — typically delivered in 1–2 weeks at a fixed price.

    • Data-flow and trust-boundary mapping for the system in scope
    • Threat enumeration with STRIDE and LINDDUN
    • Prioritised mitigations, each cited to a source framework
    • Delivered as a structured report

    See a real run: a STRIDE threat model of an authentication flow threats enumerated and mitigations cited to the source frameworks — captured verbatim.

    Read the full sample deliverable → a fictional worked sample in the report format; senior review is pending.

    DPIA as a Service

    A Data Protection Impact Assessment, done for you and defensible to your regulator.

    • Processing description and a necessity-and-proportionality test
    • Risk assessment from the data subject's perspective
    • Mitigations mapped to GDPR Article 35 and EDPB guidance
    • Article 36 readiness note and an exportable evidence pack

    See a real run: a full GDPR Article 35 DPIA for an HR vendor 23 workflow steps, CNIL severity-and-likelihood scoring, and an Article 36 determination — captured verbatim.

    Read the full sample deliverable → a fictional Article 35 DPIA worked through the full method; senior review is pending.

    Compliance Gap Analysis

    Where you stand against NIS2, DORA, ISO 27001, GDPR, and the EU AI Act — as a cited report, scoped at article and control level.

    • Scoped to your frameworks: ISO 27001, NIS2, DORA, GDPR, the EU AI Act, and sector regulators
    • Cited findings, each tracing to the provision and your own evidence
    • Delivered as PDF, CSV, and GRC-tool import format
    • Senior-reviewed before it ships

    See a real run: a gap analysis built from a security policy requirements retrieved and cited to NIS2 and DORA at article level — captured verbatim.

    Read the full sample deliverable → a fictional NIS2 gap analysis worked through the full method; senior review is pending.

    How an engagement runs

    Fixed scope, priced per engagement.

    A one-framework check and an estate-wide assessment require different scopes. The scoping call ends with a fixed price and delivery date in writing.

    1. 1

      Scoping call

      30 minutes. We define the decision, evidence, review standard, price, and delivery date.

    2. 2

      Intake

      Under your NDA, through EU-hosted upload. You provide the architecture, processing records, policies, and other agreed evidence.

    3. 3

      Assessment

      We retrieve served sources through the Ansvar gateway and record the evidence used for each material factual finding.

    4. 4

      Senior review

      A practitioner checks citations, judgments, missing support, and the result before approving the deliverable.

    5. 5

      Readout

      A walkthrough of the findings, then the deliverable and its evidence pack are yours to keep.

    The quality contract

    The reviewer can inspect the evidence behind each finding.

    Every engagement follows the same review contract, regardless of the assessment method.

    01

    Evidence-linked

    Factual findings link to evidence retrieved through the Ansvar gateway or to the customer material supplied for the engagement. A citation identifier is checked before it is used.

    02

    Expert-validated

    A senior practitioner checks the material findings, citations, judgments, and stated limits before approving the deliverable.

    03

    Refusal discipline

    When a required source is unavailable or the evidence does not establish a conclusion, the report records the limitation instead of presenting the claim as established.

    Evidence metadata included. The delivery package identifies the sources, validation state, and provenance behind the findings for your compliance and audit records.
    Questions buyers ask

    Before you book the call

    Who actually does the work?
    The research runs on the Ansvar gateway — the same cited engine our customers use — and every finding is validated and reviewed by the senior practitioner who delivers it. Nothing ships on model output alone.
    What do we need to provide?
    Enough to scope honestly: an architecture sketch or data-flow diagram for a threat model; processing records and the DPO's view for a DPIA; existing policies and evidence for a gap analysis. We work under your NDA, and intake runs over EU-hosted upload.
    How long does an engagement take?
    Scope drives it, so you get the delivery date in writing together with the fixed quote. The scoping call itself is 30 minutes.
    Is this legal advice?
    No. Ansvar is not a law firm and the deliverables are not legal advice — they are cited compliance analysis: every conclusion traces to the provision it rests on, and judgment calls are marked as judgment calls instead of buried in prose. That format is deliberate, so your counsel can check every line and take the legal position.
    Can we run these ourselves instead?
    Yes. The same workflows — gap analysis, DPIA, threat models, AI Act readiness — run self-serve on the Team tier and produce the same cited artefacts. The service exists for when you need it done, reviewed, and signed by someone who does this daily.
    What lands in our hands at the end?
    The deliverable itself plus a compliance-metadata package — the sources, validation, and provenance behind each finding — built for your own audit records. Everything is yours to keep.

    Tell us what has a date on it.

    A threat model, a DPIA, a gap register, an AI Act classification, or another scoped assessment. We reply within two working days with an initial view on fit.

    Prefer self-serve? See Team