EU AI Act · ISO/IEC 42001 · AI governance

AI Governance Check: Your AI Compliance Baseline

A fixed, time-boxed inventory: we catalogue your AI applications, classify them under the EU AI Act and deliver a prioritised action plan with effort estimates. This gives your executive management a clear view of where the company stands and what to do next, robustly documented and handled under Swiss professional secrecy (Art. 321 SCC).

Fixed price from CHF 3'900 Results in 3–5 weeks EU AI Act + ISO/IEC 42001 from a single source

Initial consultation free & without obligation · Reply within 24 h · Swiss professional secrecy (Art. 321 SCC)

AI Governance Check, an assessment of AI compliance for a Swiss company
Fixed price and fixed scope, no open-ended hourly billing.

Working for regulated industries and SMEs

Dr. iur., LL.M., CIPP/E Law and data protection in one person
Attorney (NY) · Solicitor (UK) Mandates across CH · EU · UK · US
ISO/IEC 42001 & 27001 AI and information security closely integrated
Our own Priverion Platform AI inventory as tooling, not as slides
Mohamed Afhim

Responsible for this mandate

Mohamed Afhim

Senior Consultant · Data and data protection law (FADP, GDPR, EU AI Act)

As Senior Consultant, Mohamed Afhim is responsible for your AI governance assessment: he inventories your AI applications, classifies them under the EU AI Act and integrates the results with the FADP, the GDPR and ISO/IEC 42001. For cross-jurisdictional questions (CH, EU, UK, US) and the final legal assessment, he works closely with Dr. Dominic Staiger (CIPP/E, Attorney at Law).

LinkedIn profile

What is an AI Governance Check?

In brief

What it is: A one-time assessment of your AI compliance with a fixed scope, including an AI inventory, risk classification under the EU AI Act and a gap analysis against ISO/IEC 42001.

What you receive: A prioritised plan of measures (roadmap) with an effort estimate, plus a summary for the board of directors and executive management.

What it is not: It is not a certification and does not guarantee compliance; the goal is demonstrable risk reduction and accountability.

Unlike a self-assessment checklist, the Check delivers a legally robust assessment. Specifically, we tell you which of your applications you may not deploy at all, which are deemed high-risk and where you must inform users transparently (prohibited practices Art. 5; high-risk Art. 6 et seq./Annex III; transparency obligations Art. 50 EU AI Act). We likewise show you where automated decisions trigger obligations under Art. 22 GDPR or Art. 21 FADP.

The result is a defensible baseline, the foundation for deploying resources precisely where the risk is greatest. No guaranteed compliance can be derived from it; the goal is demonstrable risk reduction and accountability.

Do you need an AI Governance Check?

The Check pays off as soon as AI enters your company, usually faster than governance and documentation can keep up. The following four triggers clearly argue in its favour:

1

Your board of directors or executive management asks about your AI risk exposure and expects a documented, traceable answer rather than a gut-feeling assessment.

2

You use Copilot, generative language models, scoring or HR pre-selection tools without having a complete inventory and risk classification of these applications.

3

An EU customer, an audit or a supplier questionnaire requires evidence of your AI governance, and you may fall within the scope anyway via the output clause (Art. 2(1)(c) EU AI Act).

4

You process personal data using AI or make automated individual decisions and must comply with Art. 21 FADP or Art. 22 GDPR, regardless of the EU AI Act deadlines.

What makes us unique

Law, software engineering and in-house AI development, in a single team

At our firm, these three disciplines interlock within a single team. Neither a pure law firm nor a conventional consultancy can deliver this combination. This makes your assessment both legally robust and technically sound, rather than a checklist without depth.

Deep legal expertise

Lawyers with doctorates holding CIPP/E, Attorney at Law (NY) and Solicitor (UK) qualifications. We classify AI with legal certainty under the EU AI Act, the FADP and the GDPR, drawing on ongoing mandates rather than textbooks.

Our own software engineers

Our own development centre and the Priverion Platform. We know how AI systems are built today, and we examine what a system technically really does instead of relying on self-declarations.

In-house AI development

We develop and operate our own LLM and AI systems. As a result, we know the best practices and pitfalls firsthand, from RAG to prompt security.

What do we take care of?

The check is clearly defined in scope and completed within a few weeks. We do not deliver a generic template, but rather an inventory tailored to your company together with a concrete plan of measures.

The full scope of services set out below corresponds to the Standard Check; the Basic Check from CHF 3'900 covers the core steps (AI inventory, risk classification, gap analysis against the central obligations, short roadmap).

  • Complete AI inventory of all AI applications in use and planned, including clarification of roles (provider vs. deployer, EU nexus).
  • Risk classification of each application under the EU AI Act: prohibited practices (Art. 5), high risk (Art. 6 et seq., Annex III), transparency obligations (Art. 50), GPAI relevance.
  • Gap analysis against the deployer obligations of the EU AI Act (including Art. 4, Art. 26, Art. 27 FRIA, Art. 15 robustness/cybersecurity).
  • Gap analysis against ISO/IEC 42001:2023 (AIMS) with a comparison to any existing ISMS in accordance with ISO/IEC 27001.
  • Assessment of the AI competence level (AI literacy, Art. 4 EU AI Act) of your staff.
  • Identification of the data protection touchpoints: automated individual decisions and profiling (Art. 21 revised FADP, Art. 22 GDPR), interplay between DPIA (Art. 35 GDPR) and FRIA (Art. 27 EU AI Act).
  • Classification of the extraterritorial reach (Art. 2 EU AI Act) and of any US/APAC obligations in the event of corresponding market activity.
  • Prioritised plan of measures (roadmap) with effort estimates and sequencing according to risk and the applicable obligations.
  • Summary for the board of directors and executive management to document the duty of organisation and due diligence (cf. Art. 717/754 CO).
  • Structured storage of the inventory and classification in the Priverion Platform as a verifiable basis.

Effort and scope

The AI Governance Check is time-limited and has a clearly defined scope, so you know in advance what you will receive and what it will cost. The effort depends on the number of AI applications and the complexity of your data flows; we set out the precise scope explicitly in the proposal.

3–5 weeks

typical duration until the action plan

from CHF 3'900

fixed-price entry point, scope explicitly defined

2 frameworks

EU AI Act and ISO/IEC 42001 in a single report

Packages

Three clearly delimited scopes, from a compact readiness check to an extended assessment with a fully developed roadmap. All prices are entry-level figures; the final fixed price depends on the agreed scope.

Basic Check

from CHF 3'900

Up to ~5 AI applications, one framework. A compact assessment for companies with limited AI use.

  • AI inventory of up to 5 applications
  • Risk classification under the EU AI Act (Art. 5/6/50)
  • Gap analysis against the core deployer obligations
  • Prioritised short roadmap
  • Summary for the board of directors / executive management (compact)

Enterprise Check

on request

For groups, regulated industries and multi-jurisdiction contexts. An extended assessment.

  • AI inventory with no fixed volume limit
  • Multi-jurisdiction classification (EU, CH, UK, US, APAC)
  • AI literacy programme (Art. 4) and role model
  • Workshop with the board of directors / executive management
  • Transition into AI Officer mandate or remediation project

A note on the FRIA: A fundamental rights impact assessment (FRIA, Art. 27 EU AI Act) is mandatory only for certain deployers (public bodies, providers of public services, certain Annex III systems such as creditworthiness and life/health insurance). We assess whether it applies to you in every package.

How the check works

Structured, with minimal burden on your team and a clear outcome. The assessment is advice, not a certification; a later conformity assessment remains separate from it.

Kick-off and scoping

Together we define the scope, the applications to be included and the contact persons.

AI inventory survey

Structured capture of all AI applications via interviews and questionnaires, stored in the Priverion Platform.

Classification and gap analysis

Legal risk classification under the EU AI Act and alignment against ISO/IEC 42001 as well as the FADP/GDPR.

Prioritisation

We assess the gaps by risk and obligations and derive a sequence with an effort estimate.

Action plan and summary

Handover of the roadmap and the summary for the board of directors and executive management.

Debriefing

Joint review of the findings and clarification of the next steps (AI Officer, remediation, training).

Why SIDD?

What the three disciplines above mean for your assessment:

Legally robust, not just checkboxes

Instead of a self-assessment checklist, we tell you with legal certainty what is prohibited under Art. 5, high-risk under Annex III, or covered at all via the output clause (Art. 2 EU AI Act) at all.

Two frameworks in one report

The EU AI Act and ISO/IEC 42001 in a single assessment, aligned with any ISMS in accordance with ISO/IEC 27001, instead of two separate projects.

Swiss professional secrecy (Art. 321 SCC)

Findings and inventory data under legal privilege, a level of protection that pure information-security providers do not offer.

Advisory and certification kept separate

The assessment is advisory; any subsequent conformity assessment is carried out by an independent body. This keeps the results audit-credible.

Demonstrable, not PowerPoint

Inventory and classification as maintained, auditable tooling on the Priverion Platform, not as a one-off presentation.

Low-risk entry with continuity

Fixed scope, fixed price, with a seamless transition into a AI Officer mandate or a remediation project.

Which rules apply to whom?

AI obligations depend on where and for whom you deploy AI. The check positions your company within this picture.

JurisdictionApplicable frameworkStatus (as of 06/2026)Relevance for Swiss operators
EUEU AI Act (Regulation (EU) 2024/1689)Art. 5 (prohibitions) and Art. 4 (AI literacy) since 02.02.2025; GPAI since 02.08.2025 (existing models until 02.08.2027). Transparency (Art. 50) from 02.08.2026 (labelling of artificially generated content, Art. 50(2), from 02.12.2026), not postponed by the Omnibus. The high-risk deadlines (Annex III/I) are expected to be postponed to 02.12.2027 and 02.08.2028 respectively under the "Digital AI Omnibus", not yet published in the Official Journal and therefore not final; until then, 02.08.2026 (Annex III) and 02.08.2027 (Annex I) formally apply.Covered via Art. 2(1)(a) (placing on the market) and (c) (output clause), regardless of the server location.
SwitzerlandFADP/revised FADP, CO, FINMA, sectoral lawNo AI-specific federal law. The CoE Convention was signed in 2025 but not yet ratified; a consultation draft is expected by the end of 2026.Already applicable today: Art. 21 revised FADP (automated individual decisions/profiling), liability under the Swiss Code of Obligations (Art. 41 et seq., 97 et seq., 717/754), FINMA supervision.
USANo uniform federal regime; state lawsEO 14110 revoked (20.01.2025); states such as CA, TX and IL with their own rules (some in force since 01.01.2026). The situation remains volatile.Covered as soon as you serve customers there; aligning with the EU AI Act and ISO/IEC 42001 covers large parts of this.
APACHeterogeneous, mostly lightweight regimesSouth Korea: AI Basic Act (extraterritorial, domestic representative), in force in 2026. China: labelling obligations since 2025.When supplying multiple markets: a technology-neutral foundation (ISO/IEC 42001) plus jurisdiction-specific obligations.

As of 18.06.2026, updated on an ongoing basis. This overview does not replace legal advice in individual cases. The Omnibus deadlines are provisional; until publication in the Official Journal, we run both scenarios in parallel.

References

Regulated industrial company

AI inventory integrated into an existing ISMS

For a client in a heavily regulated industry, we inventoried AI usage, classified it under the EU AI Act and integrated it into an existing ISO/IEC 27001 ISMS. The result: a defensible baseline and a prioritised roadmap for the board of directors and executive management.

Healthcare/medtech environment

DPIA and FRIA in a single report

For a healthcare provider, we examined the data-protection touchpoints of AI-supported processing of sensitive data (Art. 21 revised FADP, Art. 22 GDPR) and mapped the interplay between the DPIA and the FRIA (Art. 27 EU AI Act) in a single integrated report.

Mandate details are subject to confidentiality (Art. 321 SCC) and are only disclosed with explicit consent.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For the AI Governance Check, concretely: LexCommand backs every risk classification in your AI inventory with the exact provision in the EU AI Act and maps overlapping duties across the AI Act, ISO/IEC 42001 and FADP/GDPR, so your roadmap rests on retrievable sources rather than judgement calls.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

What does the AI Governance Check cost?

The entry point is a fixed price of CHF 3'900 (basic check); the full standard check starts at CHF 7'500. The final price depends on the agreed scope, in particular the number of AI applications to be included and the complexity of your data flows. We set out the scope explicitly in the proposal so that no open items remain.

How long does the check take?

Typically 3 to 5 weeks from kick-off to handover of the action plan. The effort on your side is essentially limited to interviews and providing information about the applications in use.

How much internal time does the check cost us?

Essentially 1–2 interviews per relevant area plus the provision of existing documentation; we take care of the rest. The burden on your team thus remains low and predictable.

Where are our inventory and findings data stored?

On the Priverion Platform, hosted in Switzerland/the EU. The findings are additionally subject to attorney professional secrecy under Art. 321 SCC, a level of protection that pure information-security providers cannot offer.

Is the check worthwhile if we only use Copilot/ChatGPT?

Yes. Standard tools in particular trigger transparency (Art. 50 EU AI Act) and data-protection obligations, and they belong in the AI inventory. The basic check from CHF 3'900 clarifies exactly that, without you having to set up a large programme straight away.

Isn't a self-assessment checklist enough?

A checklist does not tell you whether an application is prohibited under Art. 5 EU AI Act, high-risk under Annex III, or covered at all via the output clause (Art. 2 EU AI Act). It is precisely this legal classification, including the interplay between the DPIA and the FRIA (Art. 27 EU AI Act), that forms the core of the check and cannot be delivered with a PDF questionnaire.

Does the check make us AI Act compliant?

No. The check provides a defensible status assessment and a prioritised action plan, i.e. demonstrable risk reduction and accountability. No serious provider can or may promise guaranteed compliance; it depends on the implementation of the measures.

From when do the EU AI Act obligations apply?

The prohibitions (Art. 5) and the AI literacy obligation (Art. 4) have applied since 02.02.2025, the GPAI obligations since 02.08.2025 (for existing models until 02.08.2027). The transparency obligations (Art. 50) apply from 02.08.2026 (labelling of artificially generated content under Art. 50(2) from 02.12.2026) and have not been postponed by the Omnibus. Most high-risk obligations (Annex III) were originally scheduled to apply from 02.08.2026. Following the provisional agreement on the "Digital AI Omnibus", they are expected to be postponed to 02.12.2027 (Annex III) and 02.08.2028 (Annex I) respectively. As of 18.06.2026, this agreement had not yet been published in the EU Official Journal and is therefore not final; until formal adoption, the original deadlines formally apply. As a precaution, we plan for both scenarios. Swiss FADP obligations (Art. 21 revised FADP) already apply today in any case.

How does the check relate to our existing DPO or CISO role?

It complements them. The check builds on existing data-protection und and information-security structures , reconciles the AI inventory against any existing ISMS (ISO/IEC 27001) and can set up AI governance in shared responsibility with your DPO/CISO role. Incidentally, the EU AI Act does not recognise any legally mandated "AI officer"; Art. 4 only requires AI literacy. Many companies nevertheless voluntarily bundle the Art. 4 competence and ongoing governance into a single role; we offer this as AI Officer mandate .

What happens after the check?

You receive a prioritized action plan with an effort estimate. On this basis, you can implement it yourself, commission an ongoing AI Officer mandate (AI Officer as a Service) or launch a specific remediation project. The check is deliberately designed as a low-risk entry point, with no follow-up obligation.

Know where you stand on AI compliance

Within a few weeks, you receive a complete AI inventory, a risk classification under the EU AI Act and a prioritized action plan for the board of directors and executive management.