We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
Implementation guides for the people doing the work. Each one runs to roughly 150,000 words, mapped to the specific obligations of a single regulation, worked step by step, with the artefacts each obligation produces. The deepest reference we publish.
The regulation pages explain a regime; a practitioner guide walks you through discharging it. Three things set them apart.
Structured around the atomic obligations a regime imposes, so you work the duty itself, cited to the provision that mandates it.
Each obligation is broken into the decisions and actions that discharge it, in the order a practitioner meets them.
Every step names the record it should generate, so completing the guide leaves you with the evidence, not just the understanding.
Risk classification through conformity assessment, technical documentation, post-market monitoring, and Article 4 literacy.
↗Lawful bases, DPIAs, data-subject rights, Article 22 automated decisions, and accountability, applied to AI systems.
↗Security risk-management measures, incident reporting, and the Article 20 management-body duty.
↗ICT risk framework, resilience testing, third-party oversight, and the non-delegable board duty under Article 5.
↗Device classification, clinical evidence, conformity assessment, and integration with the AI Act from 2028.
↗Software as a product, the presumption mechanics, disclosure, and what to retain as your defence.