Modules/AI Governance

AI Assessments

by Formiti's Global DPO Team

A 13-section regulatory assessment wizard aligned with the EU AI Act and GDPR, providing structured evaluation of AI systems across scope, prohibited practices, high-risk screening, transparency, GPAI, privacy, fairness, and technical robustness.

Who uses this module?

AI Governance Leads, DPOs, Legal Counsel, Technical Owners, Risk Officers.

What governance problem does it solve?

Determining whether an AI system triggers EU AI Act obligations requires structured analysis across multiple regulatory dimensions. AI Assessments replaces subjective judgement with a scored, evidence-based methodology that produces defensible regulatory determinations.

What are the key workflows?

  • Select AI system from the Register and initiate assessment
  • Complete structured questionnaire across 13 regulatory sections
  • Real-time scoring engine determines regulatory outcomes (High-Risk, Prohibited, GPAI, DPIA Required)
  • Traffic-light status badges per section highlight areas of concern
  • Generate executive reports with scored findings and recommendations
Workflow sequence
1

Select AI system from the Register and initiate assessment

2

Complete structured questionnaire across 13 regulatory sections

3

Real-time scoring engine determines regulatory outcomes (High-Risk, Prohibited, GPAI, DPIA Required)

4

Traffic-light status badges per section highlight areas of concern

5

Generate executive reports with scored findings and recommendations

What evidence and reporting does it produce?

Built-in outputs for accountability and regulatory readiness

Scored assessment records with per-question rationale

Regulatory determination outcomes (High-Risk, Prohibited, etc.)

Section-level scoring with traffic-light indicators

Executive summary reports (PDF, DOCX)

Full response audit trail

How does it connect to other Privacy360 modules?

  • Linked to AI System Register as the anchor record
  • Flagged findings generate AI Remediation tasks
  • Assessment evidence feeds into AI Evidence repository
  • High-risk determinations inform review tier assignment
  • Privacy section findings can trigger DPIA requirements

What are some example use cases?

Legal Counsel

A legal counsel completes the EU AI Act assessment for an automated recruitment screening tool; the scoring engine flags it as Potential High-Risk AI, triggering an Escalated review workflow.

Scenario 1
DPO

A DPO reviews the privacy section of an AI assessment and identifies GDPR DPIA requirements; the finding is linked to the system's DPIA status in the Register.

Scenario 2
Privacy Team

A governance lead compares assessment scores across five AI systems to prioritise remediation resources.

Scenario 3

See the operational platform in action

Book a demo to see how Privacy360 brings assessments, records, consent, contracts, AI governance, training and evidence into one operational system tailored to your programme.

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.