Skip to content
Skip to content
Management workshop guide

EU Digital Regulation Radar Checklist

Structure the AI Act, NIS2, Cyber Resilience Act and Data Act through company characteristics, ownership, available evidence and open specialist reviews.

Overhead management workshop table with a structured planning canvas for four digital-regulation workstreams.

Twelve questions for the first management review

Answer Yes, Partly or No, then record what evidence exists and who will resolve each open point.

Company profile Are relevant entities, locations, sectors, products, services and customer roles captured and current? Company and service profile with owners.
Ownership Is there a management sponsor and operational owners for every relevant regulation lane? Responsibility matrix and escalation path.
AI governance Is there a reliable inventory of AI systems that are used, procured or provided? AI inventory with purpose, role, owner and status.
AI governance Are risk, approval, competence and usage rules documented for relevant AI systems? Policy, assessment, approval and training evidence.
NIS2 Has potential applicability been assessed using the current company and service profile? Documented review with source, assumptions and reviewer.
NIS2 Are risks, material suppliers, incident paths and management review organised and traceable? Risk and measures view, supplier list and incident process.
CRA Are product roles and products with digital elements clearly mapped in the portfolio? Product and role overview with qualified assessment.
CRA Are software components, vulnerabilities, updates and technical approvals connected across the lifecycle? Component view, vulnerability process, update and approval evidence.
Data Act Are connected products, related services, data sources and relevant roles mapped? Product/service map and data-flow overview.
Data Act Have data access, contracts, safeguards and technical handoffs been reviewed together? Contract and interface view with open legal questions.
Evidence Are decisions, assumptions, approvals, training and tests findable and versioned? Evidence register with owner and review date.
Review Do changes to products, AI use, services, suppliers or data flows trigger a new assessment? Review calendar and defined change triggers.

How to use the radar checklist

Bring the management team together

Include legal, information security, IT, product, procurement, data protection and affected functions as relevant to the business.

Separate answers from evidence

A positive self-assessment is not enough. Record what reliable evidence exists and when it was last reviewed.

Make blockers visible

Flag missing owners, unclear applicability, unknown products or data flows, and untested reporting or update paths.

Commission specialist reviews

Hand legal, technical and contractual questions to qualified reviewers together with specific company information.

Track actions

Prioritise gaps, name owners, and revisit progress and new change triggers on a recurring cadence.

Four readiness bands, not a compliance score

Unclear

  • Applicability, role or owner remains unclear
  • Material inventories or data sources are missing

Oriented

  • Company profile and initial owners are identified
  • Specialist reviews and material gaps are visible

Implementing

  • Priority actions have owners and dates
  • Evidence, tests and approvals are being developed

Repeatable

  • Controls and evidence are embedded in operations
  • Changes trigger defined reviews

Prepare the full PDF checklist

What the checklist does — and does not do

Questions about the radar checklist

Who is the checklist for?
Does a green readiness band prove compliance?
Which functions should participate?