EAB Compliance · Platform Overview

One platform. Every obligation. One audit trail.

EAB is not a documentation tool. It is an operational governance system — turning regulatory obligations into controlled workflows, defensible decisions, and audit-ready evidence.

From the first AI system registration to re-screening after a legal change, every step is governed, attributed, and traceable. Across EU AI Act, GDPR, and NIS2 — in a single connected record.

3 regulatory modules 40+ governance features 113 operative articles mapped
Regulatory modules
3
EU AI Act · GDPR · NIS2 — one platform, one audit trail across all three.
Governance features
40+
Structured workflows, obligation tracking, evidence collection, and reporting — all connected.
Articles mapped
113
Every operative article of Regulation (EU) 2024/1689 translated into structured obligations.
Manual interpretation
Zero
Obligations are derived from screening results — not filled in by hand or left to judgment.
01 Register 02 Classify 03 Screen 04 Assign Role 05 Obligations 06 Evidence 07 Approve 08 Audit 09 Re-Screen 10 Report
Why one platform

Compliance that is connected, not assembled.

When AI governance, GDPR documentation, and NIS2 obligations live in separate tools, compliance becomes an assembly problem. Decisions are made without shared context. Evidence is duplicated. Audit trails exist across multiple systems with no common thread — and when an auditor arrives, someone spends a week pulling it together.

EAB is designed around a different premise: the same AI system may simultaneously be subject to EU AI Act classification, GDPR processing obligations, and NIS2 infrastructure requirements. Managing these separately produces gaps. Managing them in one operational layer produces a connected, defensible, and audit-ready compliance record — from the first registration to the last re-screening.

Every workflow in EAB feeds the same record. Every determination is attributed. Every evidence item is attached to the obligation it satisfies. When the auditor arrives, nothing needs to be assembled.

Three connection points
  • Same systemOne AI system, three regulatory frameworks — one registration feeds all three
  • Same trailEvery decision attributed, timestamped, and reconstructable across modules
  • Same evidenceEvidence collected once, referenced across EU AI Act, GDPR, and NIS2 where it overlaps
  • Same versionLegal source snapshots anchored per determination — not per export
The design principle

“A compliance record that required coordination to produce is not a compliance record. It is a reconstruction — and reconstructions have gaps.”

EAB Design Principle · Reconstructability
Platform architecture

Six governance capability clusters — one platform.

Each cluster covers a distinct governance function and connects to the others through shared data, workflow logic, and audit trail.

AI Act — Screening & Classification
6 features

Determine risk class, screen against EU AI Act obligations, and generate a governed classification record before any approval can be given.

Workflow & Approval
5 features

Move AI systems through a controlled review sequence with defined roles, mandatory screening, and attributable approval decisions at every stage.

Obligation & Evidence Management
6 features

Translate risk class and actor role into concrete obligation areas, then track evidence status at element level — derived from screening, not filled in by hand.

Audit & Reporting
5 features

Preserve a reconstructable governance trail and generate compliance reports that hold under external scrutiny — without any preparation when the auditor arrives.

GDPR & NIS2
7 features

Privacy governance and cybersecurity compliance within the same platform — connected to AI Act governance where obligations overlap, not siloed in a separate tool.

The three modules

One platform, three regulatory frameworks.

Each module is fully functional standalone. Together, they share one system inventory, one evidence layer, and one audit trail.

Core Module

EU AI Act

Risk classification, obligation management, screening workflow, evidence collection, and audit-ready traceability — anchored to CELEX 32024R1689 with automatic re-screening when the law changes.

  • Risk screening & classification
  • Obligation matrix per system
  • Legal version snapshots
  • Automated re-screening queue
Add-on Module

GDPR

Processing activity records (VVT), DPIA workflow, TOM profiles under Art. 32, vendor governance, and a direct bridge to AI Act obligations where processing activities involve AI systems.

  • VVT & processing records
  • DPIA workflow (AI-assisted)
  • TOM profiles (Art. 32)
  • Vendor governance & AVV
Add-on Module

NIS2

Cybersecurity governance and NIS2 readiness tracking — connected to the same system inventory and evidence layer as the AI Act and GDPR modules, not managed separately.

  • Cybersecurity governance
  • NIS2 readiness assessment
  • Incident response documentation
  • Shared evidence with AI Act
Get started

Operational compliance. Not another documentation layer.

EAB gives organizations a single governed infrastructure for AI compliance, privacy governance, and cybersecurity obligations — with workflow logic, evidence tracking, and audit-ready traceability built in from the start.

EU-hosted · Anchored to CELEX 32024R1689

Get in Touch
Request More Information

Tell us about your organization and what you’re looking to address. We’ll follow up with the relevant information.