ENFTC Logo
EU AI Act · ISO/IEC 42001 Compliance

EU AI Act & ISO/IEC 42001
Compliance for Financial Services.

Specialized consultancy for Tier-1 Financial Institutions. Our primary practice is EU AI Act & ISO/IEC 42001 compliance, automated end-to-end — with DORA, cybersecurity, and operational resilience as a second line of service.

What We Do

Our Services

Two focused practices — EU AI Act compliance and DORA-led digital operational resilience — for Tier-1 financial institutions.

🤖

EU AI Act & ISO/IEC 42001 Compliance

Our primary practice: full-lifecycle compliance with the EU AI Act, mapped to ISO/IEC 42001 and NIST AI RMF, automated end-to-end through the AI-Compliance Platform.

  • 55 EU AI Act obligations assessed against 110 ISO/IEC 42001 & NIST AI RMF controls
  • Deterministic risk classification — prohibited practices, high-risk domains, GPAI thresholds
  • LLM-assisted evidence review with audit-ready, validated output
  • Penalty-tier-weighted scoring and automated deadline monitoring
🛡️

DORA, Cyber & Operational Resilience

Digital Operational Resilience Act and broader cyber resilience for Tier-1 institutions — from implementation and third-party risk to regulatory remediation and audit defense.

  • DORA implementation — ICT risk management, ICO register, and contractual arrangements
  • ICT third-party risk oversight and resilience testing
  • Regulatory remediation — GDPR, BCBS 239, HKMA/MAS TRM
  • Closing audit findings and defending controls under review
Our Product

The AI-Compliance Platform

A production-hardened, multi-tenant EU AI Act compliance platform — translating regulation into auditable, automated controls. In development since January 2026, built end-to-end with AI-assisted development workflows.

🧭

Three-Layer Compliance Model

55 EU AI Act obligations (incl. Digital Omnibus amendments) assessed against 110 ISO/IEC 42001 & NIST AI RMF controls, then to automated evidence checks and human verdicts.

🧠

Deterministic Risk Classification

Full EU AI Act classification pathway — Article 5 prohibited practices, Annex III high-risk domains, GPAI systemic-risk thresholds, Article 50 transparency — via a structured classification assessment.

🤖

LLM-Assisted Evidence Review

Structured LLM review of uploaded evidence against mapped obligations — JSON-mode output with validation, prompt-injection defence, and per-review cost telemetry.

⚖️

Penalty-Tier-Weighted Scoring

Compliance scores weighted by the regulation's actual fine structure — €35M/7% down to €7.5M/1.5% — with per-tier and per-article breakdowns.

🛡️

Multi-Tenant Security

Role-based access control, PostgreSQL row-level security enforcing tenant isolation, a full audit trail, and deadline monitoring aligned to the EU enforcement timeline (2025–2028).

Verified by 430 Automated Tests

CI pipeline validating migrations and multi-tenant isolation against real PostgreSQL on every push — 341 backend, 79 frontend, and 10 end-to-end tests across three browsers.

Under the Hood

The Compliance Engine

Regulation-to-control mapping at scale: 2,226 regulatory requirements across 16 frameworks mapped to 593 implementation controls — with automated validation proving controls are actually deployed.

🧭

2,226 Requirements → 593 Controls

DORA with all 6 Level 2 RTS chains, PCI DSS 4.0.1, NIST CSF 2.0, ISO 27001:2022, UK FCA/PRA, and EU AI Act mapped to 593 implementation controls — CIS Controls v8.1.2, NIST SP 800-53r5, and a dedicated EU AI Act control library — with 4,745 verified requirement-to-control mappings with typed relationships.

🛡️

Dual-Engine Automated Validation

Controls proven deployed, not just documented: 1,359 Checkov IaC policies and 916 Rego/OPA policies — including 13 custom policies — validate infrastructure and runtime posture on demand.

📋

Auditor-Ready Evidence

Evidence bridge mapping 1,126 tool outputs to evidence artifacts, per-framework audit runbooks, gap analysis across 16 frameworks, and a tooling atlas of 356 products with procurement recommendations.