EU AI Act compliance audit for enterprises
One audit tells you where every AI system in your organization stands against Regulation (EU) 2024/1689: classified by risk, checked against its obligations, with the evidence a regulator, an enterprise customer or your board would ask for.
Full obligations for high-risk AI systems apply from 2 December 2027. That is
ISO 27001 · ISO 9001 · ISO 22301 certified · Fixed scope, fixed quote, 8 to 12 weeks · No software subscription, no remediation lock-in
Enforcement has started. So have your customers' questionnaires.
Most provisions of the EU AI Act have applied since 2 August 2025. Prohibited practices under Article 5 have been banned since early 2025, and transparency obligations for general-purpose AI are live. Under Article 99, fines reach €35 million or 7% of global annual turnover, whichever is higher.
And the regulator is not the only one asking. Enterprise customers now send AI-governance questionnaires during procurement, deployers push documentation requirements down onto their vendors, and boards and insurers want a written position on AI risk.
For many companies, the first AI Act deadline that matters is a customer's security review, not a date in the regulation.
Most organizations, when asked, cannot answer four basic questions:
If any answer is missing, you have a compliance gap.
The audit measures it and gives you the plan to close it.
What the audit covers
Five stages, run in this order, over 8 to 12 weeks. The scope follows the obligations set out in Articles 9 to 17 and Annex IV of the Act.
AI system inventory
We map every AI system your organization builds, buys or embeds in third-party tools. Independent research consistently finds that enterprises discover two to three times more AI systems than they expected.
Risk classification
Each system is classified under the Act's four tiers (prohibited, high-risk, limited, minimal), and your role per system (provider or deployer) is defined, because obligations depend on both.
Gap assessment
Every in-scope system is checked against its actual obligations: risk management, data governance, technical documentation, logging, human oversight, transparency, robustness, post-market monitoring.
Evidence review
Regulators do not accept intentions. We test whether your documentation, logs and oversight records would survive a market surveillance request.
Remediation roadmap
A prioritized plan mapped to the statutory dates: what to fix first, what can wait, and what it will cost.
The deliverable: an audit report your board can read, plus a working compliance register your team owns after we leave. The same material doubles as your standing answer pack for customer AI questionnaires: filled in once, reused in every procurement review.
Built for enterprises where AI touches people and decisions
If your AI affects hiring, money, health or identity, the Act affects you. The regulation sorts every AI system into four tiers, and the obligations concentrate sharply at the top:
High-risk exposure is most common in
Territorial scope is wider than most teams assume
The Act applies to EU companies and to any company whose AI systems or outputs reach EU users. US and UK enterprises serving the EU market are in scope.
The 2026 to 2028 deadlines, in plain terms
Some rules already apply. The rest are closer than they look.
Prohibited practices banned since February 2025. General-purpose AI model obligations and transparency rules for chatbots have been live since August 2025.
Labeling of AI-generated content for systems already on the market, plus additional prohibitions.
This is the date that decides your 2026 roadmap. Full obligations for Annex III high-risk systems such as hiring, credit and biometrics: conformity assessment, technical documentation, quality management system, post-market monitoring.
High-risk obligations for AI embedded in regulated products: medical devices, machinery, vehicles.
The 2027 extension is not extra time to wait. Conformity assessments, technical documentation and quality management systems take 12 to 18 months to build in a large enterprise, which means the audit has to happen in 2026 for the deadline to be workable.
Book a scoping callAuditors who test AI systems, not just read policies
The Act does not only ask what your policies say. Articles 13 to 15 ask for testing evidence: accuracy, robustness, bias behavior, and proof that human oversight works in practice. Most auditors cannot produce that evidence. We can, because producing it is TestDevLab's core business.
Law firms tell you what the Act says. GRC software gives you dashboards to fill in. We do the part in between. We examine your AI systems, test them, and verify the evidence.
The same engineers who run TestDevLab's AI product testing practice (LLM output evaluation, model drift, bias and robustness testing) perform the technical portions of the audit.
Fifteen years of enterprise quality engineering
Software testing for fintech, healthcare, telecom and energy clients whose products serve billions of sessions daily. ISO 27001, ISO 9001 and ISO 22301 certified.
Mapped to the frameworks regulators use
Findings are mapped to EU AI Act articles, ISO/IEC 42001 and the NIST AI RMF, so one assessment serves multiple regimes.
Independent by design
We sell no compliance platform and no remediation retainer. The audit stands on its own and the register is yours.
From first call to final report in 8 to 12 weeks
Scoping call
We define which entities, systems and markets are in scope, and you receive a fixed quote and timeline.
Discovery
The AI inventory is built through workshops, system access and vendor documentation review.
Audit
Classification, gap assessment, evidence review, and technical testing where the risk tier demands it.
Delivery
Audit report, compliance register, and an executive briefing for your board or leadership team.
The audit is the map. What happens next is your call.
Most clients remediate in-house from the roadmap alone. When you want help, we introduce a partner we would stake our name on, and step back.
Questions compliance teams ask first
A structured assessment of every AI system your organization builds, buys or embeds: classified by risk tier under Regulation (EU) 2024/1689, checked against its specific obligations, with documented gaps and a remediation plan mapped to the statutory deadlines.
Find out where you stand before a regulator asks
Tell us a little about your organization and we will reply within one business day to set up a 30-minute scoping call. You'll leave that call with a scope, a timeline and a fixed quote.
Prefer to pick a time yourself? Book a slot directly in the calendar.