| # | Gap & Category | Recommended Action |
|---|---|---|
| 1 |
critical
Data Handling Policy
No written policy governing data shared with AI tools
|
Draft a Data Classification Policy that explicitly prohibits sharing PII, confidential client data, or proprietary information with third-party AI tools without DPA review. |
| 2 |
critical
Acceptable Use Policy
No formal AI Acceptable Use Policy in place
|
Adopt an AI Acceptable Use Policy covering: approved tools list, prohibited use cases, data handling requirements, output verification, and disciplinary consequences. |
| 3 |
critical
EU AI Act Readiness
Not prepared for EU AI Act enforcement (August 2026)
|
Conduct an EU AI Act gap assessment immediately. Identify high-risk AI systems, implement conformity assessments, and appoint an AI compliance officer if applicable. |
| 4 |
high
AI Inventory
No inventory of AI systems in use
|
Create and maintain a register of all AI tools used across departments. Include tool name, purpose, data accessed, and business owner. |
| 5 |
high
Employee Training
No mandatory AI training program for staff
|
Implement mandatory AI literacy training covering acceptable use, data privacy risks, output verification, and incident reporting. Annual refreshers recommended. |
| 6 |
high
Incident Response
No AI incident reporting process defined
|
Establish a clear AI incident reporting procedure. Define what constitutes an AI incident, escalation paths, and response timelines. Align with existing data breach notification obligations. |
| 7 |
high
Data Protection Compliance
GDPR / data protection compliance for AI use not assessed
|
Commission a Data Protection Impact Assessment (DPIA) for all AI tools processing personal data. Review vendor Data Processing Agreements (DPAs) and ensure lawful basis for processing. |
| 8 |
moderate
AI Tool Governance
No formal approval process for AI tools
|
Implement a lightweight AI tool intake process requiring security review, vendor DPA assessment, and business justification before deployment. |
| Obligation | Status / Note | |
|---|---|---|
| ✗ | High-risk AI system identification (Art. 6) | Classification assessment required before August 2026 |
| ✗ | Conformity assessment process (Art. 43) | Required for any high-risk AI systems |
| ✗ | AI system registry (Art. 51 transparency) | Mandatory register of AI systems deployed |
| ✗ | Operator obligations (Art. 26) | Written policies and human oversight measures required |
| Function / Category | Status / Note | |
|---|---|---|
| ✗ | GOVERN 1.1 — Policies, processes, and accountability | Data governance policies absent or incomplete |
| ✗ | GOVERN 5.2 — Organizational awareness and training | No mandatory AI training program |
| ✗ | MANAGE 2.4 — Incident response and recovery | AI incident reporting process undefined |
| → | MAP 1.1 — AI risk identification and classification | Conduct formal risk mapping exercise by Day 60 |
This is a sample plan for Charlotte Capital Advisors, a fictional persona. Your personalized plan is generated from your own assessment answers and delivered instantly for $299.
Start Your Free Assessment →