TestDevLabEU AI Act AuditBook a scoping call
Regulation (EU) 2024/1689

EU AI Act compliance audit for enterprises

One audit tells you where every AI system in your organization stands against Regulation (EU) 2024/1689: classified by risk, checked against its obligations, with the evidence a regulator, an enterprise customer or your board would ask for.

Full obligations for high-risk AI systems apply from 2 December 2027. That is 491 days from today, and remediation in a large enterprise typically takes 12 to 18 months.

ISO 27001 · ISO 9001 · ISO 22301 certified  ·  Fixed scope, fixed quote, 8 to 12 weeks  ·  No software subscription, no remediation lock-in

€35M / 7%
Maximum fine under Article 99, whichever is higher
2 Dec 2027
Full obligations apply to Annex III high-risk systems
1 - 1.5 years
Typical time to build conformity in a large enterprise
2 - 3 months
From scoping call to final audit report
The problem

Enforcement has started. So have your customers' questionnaires.

Most provisions of the EU AI Act have applied since 2 August 2025. Prohibited practices under Article 5 have been banned since early 2025, and transparency obligations for general-purpose AI are live. Under Article 99, fines reach €35 million or 7% of global annual turnover, whichever is higher.

And the regulator is not the only one asking. Enterprise customers now send AI-governance questionnaires during procurement, deployers push documentation requirements down onto their vendors, and boards and insurers want a written position on AI risk.

For many companies, the first AI Act deadline that matters is a customer's security review, not a date in the regulation.

Most organizations, when asked, cannot answer four basic questions:

01How many AI systems do we actually run, including vendor-embedded and shadow AI?
02Which risk tier does each one fall into under Annex III?
03Could we prove compliance to a regulator today, with evidence?
04Could we answer a customer's AI questionnaire this week without improvising?

If any answer is missing, you have a compliance gap.
The audit measures it and gives you the plan to close it.

What the audit covers

What the audit covers

Five stages, run in this order, over 8 to 12 weeks. The scope follows the obligations set out in Articles 9 to 17 and Annex IV of the Act.

1

AI system inventory

We map every AI system your organization builds, buys or embeds in third-party tools. Independent research consistently finds that enterprises discover two to three times more AI systems than they expected.

2

Risk classification

Each system is classified under the Act's four tiers (prohibited, high-risk, limited, minimal), and your role per system (provider or deployer) is defined, because obligations depend on both.

3

Gap assessment

Every in-scope system is checked against its actual obligations: risk management, data governance, technical documentation, logging, human oversight, transparency, robustness, post-market monitoring.

4

Evidence review

Regulators do not accept intentions. We test whether your documentation, logs and oversight records would survive a market surveillance request.

5

Remediation roadmap

A prioritized plan mapped to the statutory dates: what to fix first, what can wait, and what it will cost.

The deliverable: an audit report your board can read, plus a working compliance register your team owns after we leave. The same material doubles as your standing answer pack for customer AI questionnaires: filled in once, reused in every procurement review.

Who it's for

Built for enterprises where AI touches people and decisions

If your AI affects hiring, money, health or identity, the Act affects you. The regulation sorts every AI system into four tiers, and the obligations concentrate sharply at the top:

High-risk
AUDIT FOCUS
Article 6 · Annex III — the heaviest obligations, the audit's focus.
Prohibited
Article 5 — banned outright since February 2025.
Minimal risk
No new obligations — where most systems land.
Limited risk
Article 50 — transparency duties only.

High-risk exposure is most common in

Hiring, HR and workforce management
Credit scoring, insurance and financial services
Healthcare and medical products
Biometrics and identity verification
Critical infrastructure and utilities
Customer-facing chatbots and generative AI

Territorial scope is wider than most teams assume

The Act applies to EU companies and to any company whose AI systems or outputs reach EU users. US and UK enterprises serving the EU market are in scope.

Deadlines

The 2026 to 2028 deadlines, in plain terms

Some rules already apply. The rest are closer than they look.

In force
since Feb / Aug 2025
Prohibited practices and GPAI obligations

Prohibited practices banned since February 2025. General-purpose AI model obligations and transparency rules for chatbots have been live since August 2025.

2 Dec 2026
Content labeling and new prohibitions

Labeling of AI-generated content for systems already on the market, plus additional prohibitions.

2 Dec 2027
The operative deadline
Full high-risk obligations

This is the date that decides your 2026 roadmap. Full obligations for Annex III high-risk systems such as hiring, credit and biometrics: conformity assessment, technical documentation, quality management system, post-market monitoring.

491days left
2 Aug 2028
Regulated products

High-risk obligations for AI embedded in regulated products: medical devices, machinery, vehicles.

The 2027 extension is not extra time to wait. Conformity assessments, technical documentation and quality management systems take 12 to 18 months to build in a large enterprise, which means the audit has to happen in 2026 for the deadline to be workable.

Book a scoping call
Why us

Auditors who test AI systems, not just read policies

The Act does not only ask what your policies say. Articles 13 to 15 ask for testing evidence: accuracy, robustness, bias behavior, and proof that human oversight works in practice. Most auditors cannot produce that evidence. We can, because producing it is TestDevLab's core business.

Law firms tell you what the Act says. GRC software gives you dashboards to fill in. We do the part in between. We examine your AI systems, test them, and verify the evidence.

The same engineers who run TestDevLab's AI product testing practice (LLM output evaluation, model drift, bias and robustness testing) perform the technical portions of the audit.

Fifteen years of enterprise quality engineering

Software testing for fintech, healthcare, telecom and energy clients whose products serve billions of sessions daily. ISO 27001, ISO 9001 and ISO 22301 certified.

Mapped to the frameworks regulators use

Findings are mapped to EU AI Act articles, ISO/IEC 42001 and the NIST AI RMF, so one assessment serves multiple regimes.

Independent by design

We sell no compliance platform and no remediation retainer. The audit stands on its own and the register is yours.

The process

From first call to final report in 8 to 12 weeks

Scoping call

We define which entities, systems and markets are in scope, and you receive a fixed quote and timeline.

Week 0

Discovery

The AI inventory is built through workshops, system access and vendor documentation review.

Weeks 1–2

Audit

Classification, gap assessment, evidence review, and technical testing where the risk tier demands it.

Weeks 2–6

Delivery

Audit report, compliance register, and an executive briefing for your board or leadership team.

Weeks 7–8
What happens next

The audit is the map. What happens next is your call.

Included

The audit

Inventory, classification, gap assessment, evidence review and roadmap, written so your own teams can execute it without us.

Get a quote
Optional

In-depth technical audit

Per-system deep dives where stakes demand it: bias and robustness testing, oversight verification, accuracy evidence for conformity files.

AI product testing
Optional

Remediation support

Quality management system build-out and ISO/IEC 42001 certification preparation through our ISO advisory practice.

ISO advisory

Most clients remediate in-house from the roadmap alone. When you want help, we introduce a partner we would stake our name on, and step back.

FAQ

Questions compliance teams ask first

A structured assessment of every AI system your organization builds, buys or embeds: classified by risk tier under Regulation (EU) 2024/1689, checked against its specific obligations, with documented gaps and a remediation plan mapped to the statutory deadlines.

Get started

Find out where you stand before a regulator asks

Tell us a little about your organization and we will reply within one business day to set up a 30-minute scoping call. You'll leave that call with a scope, a timeline and a fixed quote.

Prefer to pick a time yourself? Book a slot directly in the calendar.

We reply within one business day. Your details are handled under our privacy policy and are never shared.