Skip to content

Where is AI already running in your company, and how much time could you recover?

An AI audit for the board: an inventory of your systems, classification under the EU AI Act, and a process map with a calculated hours-recovery potential.

Why now: EU AI Act dates

AI systems reach companies by two routes at once.

Through a board decision. And through teams that pick up tools on their own.

Some obligations under the EU AI Act already apply today.

Without an inventory of systems, every further decision is guesswork.

2 Feb 2025Articles 4 and 5 apply
2 Aug 2025Article 99 penalties become enforceable
2 Aug 2026Article 50 transparency duties apply
2 Dec 2026New Article 5 prohibitions apply
2 Dec 2027High-risk systems under Annex III
2 Aug 2028High-risk systems under Annex I
Today,

2 to 4 weeks.

That is how long an AI Act exposure audit takes, depending on the number of systems and the size of the organisation. We agree the length of a readiness audit on the diagnostic call.

Kick-off conversation

The meeting usually lasts an hour and a half to two hours. A review of the organisation's structure, a map of the departments that use digital tools and a first list of systems reported by IT.

Interviews and review

Interviews with departments, a review of tools, log samples. We also check what teams have deployed locally, without a central board decision.

Classification

We classify each system article by article against Regulation (EU) 2024/1689: Article 5, Article 6 read with Annex III, Article 50. We document every decision with its reasoning.

Report and recommendation

A written report with a risk table and a process map with a calculated hours-recovery potential. The recommendation: governance, automation or no further action.

What we do not do.We do not issue a certificate of compliance, and we do not promise it: the regulator decides that, not us.
Illustrative report, page 1 of 4, fictional dataIllustrative report, page 2 of 4, fictional dataIllustrative report, page 3 of 4, fictional dataIllustrative report, page 4 of 4, fictional data

Illustrative report, fictional data

What your board receives

Four pages from an audit report, from the cover to the decisions for the board.

Cover and nature of the document

The cover names the document: AI risk map, extract from an audit report. This copy is an illustrative example for a fictional company, and the people and figures are fictional.

Verdict and AI Act dates

On page two we give the verdict and the dates: Article 4 from 2 February 2025, Article 99 penalties from 2 August 2025, Article 50(1) from 2 August 2026, and high-risk systems under Annex III from 2 December 2027.

Systems and hours-recovery potential

Each of the eight systems receives a classification and a calculated hours-recovery potential, expressed as a percentage of team time, for example about 20% of HR department time.

Decisions for the board

The last page sets out three decisions with internal deadlines of 30, 60 and 90 days. The report is classificatory in nature and is not legal advice.

Contents of the illustrative report (fictional data)

The animation shows four pages of an illustrative AI audit report: the cover, the verdict with the AI Act dates, the systems with their hours-recovery potential, and the decisions for the board. Fictional data.

AI risk map: extract from an audit report. Verdict: high risk in HR, deadline 2027, Articles 4 and 50 already apply. Eight AI systems in the organisation, including a CV filter in recruitment (about 20% of HR department time), a marketing graphics and copy generator (about 18% of marketing team time), predictive maintenance (about 15%), pasting customer data into a public AI chat (about 12%), a website chatbot (about 10%), an AI assistant in company email (about 9%), a warehouse operative performance scoring system (about 8%) and vision cameras for quality control (about 6%). Decisions for the board: suspend independent recruitment decisions by the CV filter (60 days), close the practice of pasting customer data into public AI tools (30 days), approve a budget and an owner for the AI systems register (90 days).

Exposure audit

Question
Does Regulation (EU) 2024/1689 reach your organisation, and how far?
Result
An inventory of systems, classification against Article 5, Article 6 read with Annex III and Article 50, a written classification assessment, a risk table with priorities, and a process map with a calculated hours-recovery potential (at least three processes).
Duration
2 to 4 weeks, depending on the number of systems and the size of the organisation.

Readiness audit

Question
What is actually deployed, often without IT knowing, and where is the widest gap between the real position and what the board knows?
Result
A map of the gap between what the board believes is happening and what is actually happening in the organisation, and a process map with a calculated hours-recovery potential (at least three processes).
Duration
Agreed after the diagnostic call, depending on the scale of the organisation.

Terms of the audit

  1. 30minutes

    Diagnostic

    The first conversation takes 30 minutes and costs nothing. You leave with a straight answer: whether your exposure is material, where it sits, and whether it is worth taking further.

  2. 3steps

    Stop at any point

    Diagnostic, written position, engagement if it is warranted. You can stop after any one of them and still be further ahead than when you started.

  3. 1document

    Yours to keep

    The written position is yours. Take it to your general counsel, your auditor or another firm: it is written to survive that.

  4. 1fixed fee

    Priced first

    The fee is fixed against a named scope and agreed before anything is written. If the scope changes, we re-price in writing and you agree it before the work continues.

We take a limited number of engagements each quarter.

‘This is a pretext to sell us something bigger.’

The audit can be bought on its own, and its recommendation can be: no further action.

Nothing more is needed now. If we find that you have no material exposure, we will say so plainly and stop work at that point.

Your question gets an answer in writing.

The diagnostic takes 30 minutes, at no charge. You leave with a straight answer: whether your exposure is material, where it sits, and whether it is worth taking further.

Novus Point is not a law firm. The illustrative report is classificatory in nature and is not legal advice.

About the audit

Audit details

You know exactly which AI systems run in your organisation and where your exposure lies, before a regulator finds out for you.

Without a board-level sponsor, an audit ends in a document that nobody implements.

When this makes sense

An AI audit makes sense when the board cannot answer a simple question: how many artificial intelligence systems are running in the organisation today, and which of them needs formal classification under Regulation (EU) 2024/1689?

The question sounds simple, but the answer is rarely obvious, because AI systems reach companies by two routes at once: through a board decision, and through teams that pick up tools on their own, without IT knowing.

We offer two audits under one name. The exposure audit answers whether, and how far, your organisation is subject to the obligations of the Regulation. It covers an inventory of systems, classification against Article 5, Article 6 read with Annex III and Article 50, and a written classification assessment: an assessment of each system against Article 6 and Annex III and, where your organisation acts as a provider, in the form required by Article 6(4).

The readiness audit answers a different question: what is actually deployed, often without IT knowing, and where the widest gap lies between what the board believes is happening and what is actually happening in the organisation.

The Regulation entered into force on 1 August 2024 and has introduced its obligations in phases. The prohibition of unacceptable practices and the AI literacy duty have applied since 2 February 2025, whatever the risk level of the system. For high-risk systems under Annex III the date has moved to 2 December 2027, and for high-risk AI embedded in the regulated products of Annex I to 2 August 2028. Some obligations have therefore not yet arrived, but the classification that decides them is worth doing now.

How it runs

The work starts with a conversation with the operational point of contact, usually in IT or compliance, or directly with the COO, and with a list of the tools and systems the organisation already knows about. The kick-off meeting usually lasts an hour and a half to two hours. It covers a review of the organisational structure, a map of the departments that use digital tools and a first list of systems reported by IT. In parallel we check which AI systems teams may have deployed locally, without a central board decision. That source of exposure is the one a standard IT review most often misses.

We classify each system identified article by article against the Regulation: whether it falls within the prohibited practices of Article 5, whether it qualifies as a high-risk system under Annex III, and whether it carries the transparency obligations of Article 50. Classification rests directly on the text of the Regulation as amended by Regulation (EU) 2026/1744. We document every classification decision with its reasoning, so that the result can be reproduced and defended before an internal audit or an external review. We build our own AI products, Hadar and Operark, and test our methods on them before we advise you.

The outcome goes into a written classification assessment, covering each system against Article 6 and Annex III and, for systems where your organisation acts as a provider, prepared in the form required by Article 6(4), and into a risk table ordered by urgency. Article 6(4) places the duty to document the assessment on the provider, so your role for each system is established before the assessment is issued. The work ends with a recommendation for the next step, not with an automatic move into a further engagement.

What you receive

You receive a written report, not a slide deck. It contains the inventory of systems, classification against specific articles, the classification assessment and a risk table with priorities. The risk table orders systems along two axes: urgency, which follows from the regulatory date, and weight, which follows from the scale of a potential breach. We add a recommendation on whether the next step should be building governance, automating a specific process, or neither.

Without a board-level sponsor, an audit ends in a document that nobody implements. In every engagement we therefore assume from the start the involvement of a decision-maker on your side, alongside the operational point of contact.

What we do not do

We do not issue a certificate of compliance, and we do not promise compliance: the regulator decides that, not us. The audit gives a classification and a reasoned view, not a legal opinion. If the result shows no material exposure, we say so plainly and do not widen the scope of work artificially. We move on to governance or automation only when the audit's clear recommendation points there, because without priorities neither has a point of reference.

Next step

The right next step is a 30-minute diagnostic, requested through the contact form. It is at no charge, and most of the half hour is us listening: what AI you actually run, who touches it and on whose authority, and what you could evidence tomorrow morning. You leave with a straight answer on whether your exposure is material. The fee for the audit is fixed and agreed on that call, before anything is written, depending on the number of systems and the size of the organisation.