SAMPLE Personalized for your business after completing the free assessment
Create a workspace Guided intake Get yours for $299 →
GovernIQ

Compliance Action Plan

Charlotte Capital Advisors · Registered Investment Advisor (RIA)
Generated 12 September 2026
18
Critical Risk
This plan is personalized to your assessment responses. It identifies your highest-priority compliance gaps and provides a concrete 30/60/90-day remediation roadmap aligned to EU AI Act requirements and the NIST AI Risk Management Framework.
Priority Gap Remediation
Gaps ranked by compliance risk. Address critical items in the first 30 days.
# Gap & Category Recommended Action
1 critical
Data Handling Policy
No written policy governing data shared with AI tools
Draft a Data Classification Policy that explicitly prohibits sharing PII, confidential client data, or proprietary information with third-party AI tools without DPA review.
2 critical
Acceptable Use Policy
No formal AI Acceptable Use Policy in place
Adopt an AI Acceptable Use Policy covering: approved tools list, prohibited use cases, data handling requirements, output verification, and disciplinary consequences.
3 critical
EU AI Act Readiness
Not prepared for EU AI Act enforcement (August 2026)
Conduct an EU AI Act gap assessment immediately. Identify high-risk AI systems, implement conformity assessments, and appoint an AI compliance officer if applicable.
4 high
AI Inventory
No inventory of AI systems in use
Create and maintain a register of all AI tools used across departments. Include tool name, purpose, data accessed, and business owner.
5 high
Employee Training
No mandatory AI training program for staff
Implement mandatory AI literacy training covering acceptable use, data privacy risks, output verification, and incident reporting. Annual refreshers recommended.
6 high
Incident Response
No AI incident reporting process defined
Establish a clear AI incident reporting procedure. Define what constitutes an AI incident, escalation paths, and response timelines. Align with existing data breach notification obligations.
7 high
Data Protection Compliance
GDPR / data protection compliance for AI use not assessed
Commission a Data Protection Impact Assessment (DPIA) for all AI tools processing personal data. Review vendor Data Processing Agreements (DPAs) and ensure lawful basis for processing.
8 moderate
AI Tool Governance
No formal approval process for AI tools
Implement a lightweight AI tool intake process requiring security review, vendor DPA assessment, and business justification before deployment.
Recommended Policies
These policy documents address your specific gaps. Adopt in priority order.
critical
AI Acceptable Use Policy (AUP)
Defines approved tools, prohibited use cases, data handling requirements, output verification obligations, and disciplinary consequences for misuse.
critical
Data Handling & Classification Policy
Classifies data tiers (public, internal, confidential, restricted) and specifies which categories may never be submitted to third-party AI systems.
high
Vendor AI Review Checklist
Standardized intake form for evaluating AI tools: security review, Data Processing Agreement assessment, business justification, and approval workflow.
high
AI Incident Response Procedure
Defines what constitutes an AI incident, escalation paths, response timelines, and notification obligations aligned with data breach regulations.
moderate
AI Governance Framework
Assigns AI oversight accountability, establishes review cadences, and creates an AI Steering Committee or designated AI Officer role.
30/60/90-Day Rollout Roadmap
A phased implementation timeline built around your highest-risk gaps.
Days 1–30: Foundation
Stop the bleeding — address critical compliance gaps immediately
  • Draft and adopt: Data Handling Policy — written policy governing data shared with AI tools remediation
  • Draft and adopt: Acceptable Use Policy — formal AI Acceptable Use Policy in place remediation
  • Draft and adopt: EU AI Act Readiness — Not prepared for EU AI Act enforcement (August 2026) remediation
  • Appoint an AI Compliance Lead (existing staff, part-time acceptable at this stage)
  • Circulate emergency AI use guidance to all staff while formal policies are being drafted
Days 31–60: Structure
Formalize policies, train staff, begin documented governance
  • Implement: Create and maintain a register of all AI tools used across departments
  • Implement: Implement mandatory AI literacy training covering acceptable use, data privacy risks, output verification, and incident reporting
  • Implement: Establish a clear AI incident reporting procedure
  • Implement: Commission a Data Protection Impact Assessment (DPIA) for all AI tools processing personal data
  • Launch mandatory AI training for all staff (minimum 1-hour module)
Days 61–90: Maturity
Audit, test, and lock in ongoing governance cadence
  • Optimize: Implement a lightweight AI tool intake process requiring security review, vendor DPA assessment, and business justification before deployment
  • Conduct internal AI policy compliance audit — verify staff awareness and adherence
  • Establish quarterly AI governance review meeting with documented minutes
  • Publish internal AI Register — accessible to relevant staff
  • Prepare for NIST AI RMF self-assessment (Govern, Map, Measure, Manage)
EU AI Act & NIST AI RMF Alignment
How your current posture maps to key regulatory and framework requirements.
EU AI Act (Regulation 2024/1689)
ObligationStatus / Note
High-risk AI system identification (Art. 6) Classification assessment required before August 2026
Conformity assessment process (Art. 43) Required for any high-risk AI systems
AI system registry (Art. 51 transparency) Mandatory register of AI systems deployed
Operator obligations (Art. 26) Written policies and human oversight measures required
NIST AI Risk Management Framework (AI RMF 1.0)
Function / CategoryStatus / Note
GOVERN 1.1 — Policies, processes, and accountability Data governance policies absent or incomplete
GOVERN 5.2 — Organizational awareness and training No mandatory AI training program
MANAGE 2.4 — Incident response and recovery AI incident reporting process undefined
MAP 1.1 — AI risk identification and classification Conduct formal risk mapping exercise by Day 60

Want your own personalized plan?

This is a sample plan for Charlotte Capital Advisors, a fictional persona. Your personalized plan is generated from your own assessment answers and delivered instantly for $299.

Start Your Free Assessment →