SOWEDO/Products/Governance Scan

Is it allowed, and can it be done safely?

We test your data processing and your use of AI against the GDPR, the AI Act and your own security requirements. You get a risk register, an assessment framework and a verdict that goes beyond ticking boxes.

What you get
  • An overview of your data processing and use of AI
  • A risk register with a measure and an owner per risk
  • An assessment framework with which you evaluate new initiatives yourself
  • An AI-readiness verdict with the points that need to be sorted first
What it delivers for you

Demonstrable control, not a checklist.

A verdict you can move forward with, and documents a client or regulator accepts.

A risk register with a measure and an owner per risk.

An assessment framework with which you can evaluate new initiatives yourself.

An AI-readiness verdict with the points that need to be sorted first.

Editable documents, connected to what's already in place. You remain the owner.

When this fits

Three situations, the same first step.

You want to get started with AI, but don't know what you're doing legally.

You have nothing to do with AI, but you do have GDPR to deal with.

A client asks for demonstrable control and you have no document.

There's no 'AI' in the name, and that's a choice. Of the three frameworks we test against, one is AI-specific. The GDPR and your security requirements apply whether or not you have an agent in production.

Governance-overleg bij SOWEDO
How we go about it

From inventory to a verdict that holds.

01
InventoryWe map which data is processed where, by whom and for what purpose. Where AI is involved, also which model and where it runs.
02
AssessmentWe lay that practice alongside the GDPR, the AI Act and your own security requirements, and name the risk and the measure for each point.
03
VerdictWe conclude with a verdict on whether your organisation is ready to put AI into its processes, and on which points it is not yet.
04
HandoverYou get the documents in a form you can carry on with yourself: editable, with an owner per measure.
Building blocks

Proven building blocks, not a blank page.

Always
Our assessment framework and the risk register, built up from earlier projects, so we don't reinvent a model every time.
For AI in production or planning
An AI register with risk classification, purpose description and oversight agreements under the AI Act, plus our requirements for logging and human oversight.
For personal data
The basis for your DPIA and the input for your processing register, connected to what's already in place.
For chain partners
The extended variant, in which we also include your suppliers and the chain.
For self-hosted models or hosting
Our agreements on where the processing takes place and how you make that demonstrable. In practice this is where things go wrong most often.
Cost

For the basics with the GDPR, the AI Act and your security requirements. The extended version with chain partners is higher. Two to five working days. The intro call beforehand is free.

From €3,500
Why SOWEDO

Why have us do this.

Advice firstOver thirty years of process expertise. We think along, not just about technology.
Safeguarded and responsibleThe GDPR and the AI Act are built into our work from the design stage.
One teamAdvice, build and management from a single team. One point of contact.
Demonstrably secureISO 27001 certified, with guaranteed response times and reporting.
Specialist van SOWEDO
Start with one conversation

After one conversation you'll know where your gains are.

The intro call is free and always gives you something. What you do next is up to you.

You growWe adviseWe automate