AI Assurance: EU AI Act and ISO 42001 readiness
Independent AI Assurance: we inventory your AI, classify it against Annex III and build evidence your regulator accepts. EU AI Act, Ley 31814 and ISO 42001.

What we assess
We start from a complete inventory of your AI systems and classify them by risk level. On that basis we measure the distance to the obligations that apply to you and turn it into evidence and a plan.
- Inventory of AI systems and use cases
- Risk classification against Annex III of the EU AI Act
- Governance, data, technical documentation and human oversight
- Prioritized gaps and a roadmap with owners and dates
Frameworks we cover
We use the framework that fits your geography and exposure. The method is the same; the authority and the deadlines change.
| Framework | Scope | What we deliver |
|---|---|---|
| EU AI Act | European Union | Annex III classification and readiness for high-risk AI |
| Ley 31814 | Peru and LATAM | Readiness with the same method, local authority and deadlines |
| ISO/IEC 42001 | International | AI management system preparation, readiness only |
| NIST AI RMF | Reference | AI risk management as a supporting framework |
The high-risk clock
High-risk obligations under the EU AI Act land in August 2026. Starting with the inventory and the classification gives you room to build the evidence before the date bites, rather than improvising it at the end.
Adoption is running ahead of governance
The SOC Maturity Report 2026, SOC-CMM® measures the distance between AI enthusiasm and AI governance. 57% of SOCs have no AI adoption strategy. Co-pilot use grew 145% and AI agent use grew 118%, and yet perceived value remains limited. It is no surprise that AI best practices are the third most demanded resource in the community (61%). The conclusion for a board is direct: adoption is running ahead of governance, and that gap is exactly what an assurance program closes with inventory, classification and evidence. The full analysis is in AI and automation in the SOC and the data series in the SOC AI adoption statistics.
AI taker, not builder: the obligations arrive anyway
65% of SOCs are AI takers: they consume AI embedded in third-party products rather than building it. That does not reduce the obligations; it shifts them toward procurement and toward the deployer role defined by the EU AI Act. Whoever deploys a high-risk system answers for human oversight, logging and conformant use, even if someone else trained the model. For financial entities, DORA adds the ICT and third-party risk layer on top of the same systems. AI governance means knowing what you bought, where it runs, which decisions it touches and what evidence your regulator will demand.
How we work
We assess and validate. We oversee third-party AI testing, check it, and sign a report your board and regulator can read. Official conformity and the certificate are issued by the relevant body.
Who it is for
Regulated organizations deploying or buying AI: finance, insurance, healthcare, public sector and their providers. The buyer is usually the CISO, increasingly alongside a Chief AI Officer, and the board that answers to the regulator. If you train, integrate or buy AI systems that affect customers or regulated decisions, it applies to you.
What you receive
A pack your board can take into a meeting and your regulator can read without technical translation, not a decorative deck.
- An inventory of AI systems with their risk classification
- An Annex III classification report with per-system rationale
- A gap analysis against the obligations that apply to you
- A prioritized roadmap with owners, dates and indicative cost
- A technical evidence pack and an executive summary for the board
Frequently asked questions
Independent by design
Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

