JK
Back to Compliance

Prepared for the Board · AI risk & compliance

AI risk board report

Top AI risks and compliance posture across the organisation. Derived live from the AI register — illustrative demo data.

Overall AI risk posture

Highimproving vs last quarter
Privacy-led risk appetite

Top risks are ranked by fine & privacy exposure — GDPR and financial-crime weighted highest, operational/availability and ESG weighted down to match the organisation's risk appetite.

AI use cases

52

GDPR gaps

8

High-risk

38

Unowned high-risk

11

Shadow AI

12

Avg. coverage

45%

Top risks to report

  1. 1

    GDPR / privacy exposure on personal data

    Critical
    39use cases handling personal data at risk

    39 use cases process personal data without full controls (8 with open gaps). Privacy carries the largest fine exposure — up to 4% of global turnover — and is the board’s primary concern.

    GDPREU AI Act

    Action: Enforce PII redaction + lawful-basis checks; close gaps on restricted data first.

  2. 2

    Shadow AI processing company data unreviewed

    Critical
    12unsanctioned tools

    AI tools adopted without review, several handling confidential data. No owner, no risk assessment, no policy applied — a direct privacy and data-residency exposure.

    GDPREU AI ActISO 42001

    Action: Triage in registry → assign owners → apply guardrails or sunset.

  3. 3

    EU AI Act obligations not yet met

    High
    15open gaps

    15 use cases with EU AI Act gaps against the high-risk obligations coming into force.

    EU AI Act

    Action: Close gaps prioritised by deadline; document technical evidence.

    Due Aug 2026
  4. 4

    Sensitive data exposure to external LLMs

    High
    9use cases

    Use cases handling confidential or restricted data with an open data-leakage risk — PII/IP can leave the boundary, including to external API providers.

    GDPROWASP LLM Top 10

    Action: Enforce PII redaction + data-minimisation before send.

  5. 5

    ISO/IEC 42001 management-system gaps

    Medium
    18open gaps

    Currently 40% coverage. Tracked to show governance progression — not a certification target for now.

    ISO 42001

    Action: Progress the guided ISO 42001 journey to show maturity to the board.

Compliance coverage

GDPR25%
EIOPA44%
EU AI Act56%
NIST AI RMF 2.052%
OWASP LLM Top 1054%
ISO 4200140%

ISO/IEC 42001 readiness reflects the guided journey (0/7 clauses complete). Open the ISO 42001 journey →

Generated from the live AI register. Figures are illustrative demo data and consistent across the Compliance overview, the ISO 42001 journey, and this report.