primedefence

AI Assurance: EU AI Act and ISO 42001 readiness

Independent AI Assurance: we inventory your AI, classify it against Annex III and build evidence your regulator accepts. EU AI Act, Ley 31814 and ISO 42001.

AI Assurance: inventory, Annex III risk classification and evidence for the EU AI Act

What we assess

We start from a complete inventory of your AI systems and classify them by risk level. On that basis we measure the distance to the obligations that apply to you and turn it into evidence and a plan.

  • Inventory of AI systems and use cases
  • Risk classification against Annex III of the EU AI Act
  • Governance, data, technical documentation and human oversight
  • Prioritized gaps and a roadmap with owners and dates

Frameworks we cover

We use the framework that fits your geography and exposure. The method is the same; the authority and the deadlines change.

FrameworkScopeWhat we deliver
EU AI ActEuropean UnionAnnex III classification and readiness for high-risk AI
Ley 31814Peru and LATAMReadiness with the same method, local authority and deadlines
ISO/IEC 42001InternationalAI management system preparation, readiness only
NIST AI RMFReferenceAI risk management as a supporting framework

The high-risk clock

High-risk obligations under the EU AI Act land in August 2026. Starting with the inventory and the classification gives you room to build the evidence before the date bites, rather than improvising it at the end.

Adoption is running ahead of governance

The SOC Maturity Report 2026, SOC-CMM® measures the distance between AI enthusiasm and AI governance. 57% of SOCs have no AI adoption strategy. Co-pilot use grew 145% and AI agent use grew 118%, and yet perceived value remains limited. It is no surprise that AI best practices are the third most demanded resource in the community (61%). The conclusion for a board is direct: adoption is running ahead of governance, and that gap is exactly what an assurance program closes with inventory, classification and evidence. The full analysis is in AI and automation in the SOC and the data series in the SOC AI adoption statistics.

AI taker, not builder: the obligations arrive anyway

65% of SOCs are AI takers: they consume AI embedded in third-party products rather than building it. That does not reduce the obligations; it shifts them toward procurement and toward the deployer role defined by the EU AI Act. Whoever deploys a high-risk system answers for human oversight, logging and conformant use, even if someone else trained the model. For financial entities, DORA adds the ICT and third-party risk layer on top of the same systems. AI governance means knowing what you bought, where it runs, which decisions it touches and what evidence your regulator will demand.

How we work

We assess and validate. We oversee third-party AI testing, check it, and sign a report your board and regulator can read. Official conformity and the certificate are issued by the relevant body.

Who it is for

Regulated organizations deploying or buying AI: finance, insurance, healthcare, public sector and their providers. The buyer is usually the CISO, increasingly alongside a Chief AI Officer, and the board that answers to the regulator. If you train, integrate or buy AI systems that affect customers or regulated decisions, it applies to you.

What you receive

A pack your board can take into a meeting and your regulator can read without technical translation, not a decorative deck.

  • An inventory of AI systems with their risk classification
  • An Annex III classification report with per-system rationale
  • A gap analysis against the obligations that apply to you
  • A prioritized roadmap with owners, dates and indicative cost
  • A technical evidence pack and an executive summary for the board

Frequently asked questions

Independent by design

Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

Independent SOC-CMM assessment