I can conduct a quarterly compliance assessment for your company—a periodic review performed every three months on your software products to provide reasonable assurance that your applications, algorithms, and data flows comply with the legal framework and do not violate European regulations.
Software applications change constantly as development teams add new features, AI modules, or additional databases, and the European regulatory framework is evolving alongside them.
This quarterly compliance assessment covers the four major regulations in the field: the AI Act (Artificial Intelligence Act), the NIS2 Directive (Cybersecurity Directive), DORA (Digital Operational Resilience Act), and GDPR (General Data Protection Regulation).
1. AI Act Assessment (Artificial Intelligence Act)
What I specifically review: Whether your application uses Machine Learning models, generative algorithms, or automated decision-making systems.
What I do during the audit:
- Determine the risk category of the AI system (Unacceptable Risk, High Risk, Specific/Transparency Risk, or Minimal Risk).
- Audit the training data used for the models to ensure it is non-discriminatory and legally sourced.
- Verify user transparency (e.g., whether a chatbot clearly discloses that it is AI) and ensure the availability of human oversight (human-in-the-loop mechanisms).
2. NIS2 Assessment (Cybersecurity Directive)
What I specifically review: The security measures of the software infrastructure and the supply chain.
What I do during the audit:
- Verify whether the software provider maintains clear policies for security incident management and data encryption.
- Review how the company reports potential vulnerabilities or security breaches to authorities (taking into account NIS2’s strict 24-hour reporting threshold).
- Audit contracts between the IT company and third-party vendors for cloud or related services.
3. DORA Assessment (Digital Operational Resilience Act)
What I specifically review: Compliance in cases where the IT company develops software for the banking, financial, insurance, or crypto-asset sectors.
What I do during the audit:
- Evaluate the Business Continuity Plan and the software system’s capacity to withstand cyberattacks without disrupting clients’ financial or banking operations.
- Verify whether the software undergoes regular stress testing (penetration testing) and review data backup archiving procedures.
4. GDPR Assessment (General Data Protection Regulation)
What I specifically review: How the application collects, stores, processes, and deletes users’ personal data.
What I do during the audit:
- Audit the code architecture against the Privacy by Design principle (ensuring data protection is built in from the coding phase).
- Review consent forms, privacy policies, and Data Processing Agreements (DPAs) executed with processors.
- Verify whether the system technically enables users to exercise their rights (e.g., „Delete Account” / right to be forgotten buttons, data export functionality).
What does the final deliverable look like after 3 months?
Rather than drafting a 100-page legal treatise, I deliver a concise 5–10 page Compliance Audit Report (Executive Summary) tailored for executive leadership (CEO/CTO):
- Risk Dashboard with a Visual Matrix: Highlights areas marked „Green” (compliant), „Yellow” (requires adjustment in the next software update), and „Red” (critical vulnerability that could incur regulatory fines).
- Recommendations for the IT Team: A concise list of technical-legal requirements translated into developer terms (e.g., „AI Module X requires a decision log pursuant to Art. 12 of the AI Act; please add the logging variable to the database”).
- Record Registry Update: Updating internal company documentation to demonstrate to regulatory authorities that the company continuously audits its operations.
This quarterly service forms the core pillar of your retainer, providing assurance that your product can be sold to enterprise clients or buyers within the European Union without legal risk.
For further details, please write to: avocat@ulici.ro