| Company profile | Are relevant entities, locations, sectors, products, services and customer roles captured and current? | Company and service profile with owners. |
| Ownership | Is there a management sponsor and operational owners for every relevant regulation lane? | Responsibility matrix and escalation path. |
| AI governance | Is there a reliable inventory of AI systems that are used, procured or provided? | AI inventory with purpose, role, owner and status. |
| AI governance | Are risk, approval, competence and usage rules documented for relevant AI systems? | Policy, assessment, approval and training evidence. |
| NIS2 | Has potential applicability been assessed using the current company and service profile? | Documented review with source, assumptions and reviewer. |
| NIS2 | Are risks, material suppliers, incident paths and management review organised and traceable? | Risk and measures view, supplier list and incident process. |
| CRA | Are product roles and products with digital elements clearly mapped in the portfolio? | Product and role overview with qualified assessment. |
| CRA | Are software components, vulnerabilities, updates and technical approvals connected across the lifecycle? | Component view, vulnerability process, update and approval evidence. |
| Data Act | Are connected products, related services, data sources and relevant roles mapped? | Product/service map and data-flow overview. |
| Data Act | Have data access, contracts, safeguards and technical handoffs been reviewed together? | Contract and interface view with open legal questions. |
| Evidence | Are decisions, assumptions, approvals, training and tests findable and versioned? | Evidence register with owner and review date. |
| Review | Do changes to products, AI use, services, suppliers or data flows trigger a new assessment? | Review calendar and defined change triggers. |