Playbook diagnostic

Is your organisation ready for the EU AI Act?

For the leaders accountable for AI, this self-assessment shows how ready your organisation is to meet the EU AI Act. It builds a structured view across five capability groups and twenty capabilities — covering governance and accountability, AI inventory and risk classification, risk management and data governance, technical documentation and transparency, and oversight, robustness and conformity — and flags the blind spots and weaknesses to fix first.

Who this diagnostic is for

This diagnostic is for the leaders accountable for AI across an organisation — including legal and compliance, risk, data and analytics, IT and technology, operations, and executive leadership — in any business that builds, buys, deploys, or distributes AI systems that fall within the scope of the EU AI Act.

The problem it addresses

The EU AI Act introduces binding obligations that vary by system and by role, yet most organisations lack a clear view of which AI they use, how risky each system is, and who is accountable; scattered tools, undocumented data, and informal oversight leave gaps that existing controls were never designed to catch, exposing the business to serious penalties and reputational harm.

What the EU AI Act readiness diagnostic assesses

The diagnostic assesses five capability groups made up of twenty capabilities. Each capability is scored so you can see exactly where readiness is strong and where gaps sit.

AI Governance and Accountability

This group covers how your organisation directs and takes responsibility for its use of artificial intelligence. It looks at whether clear roles exist, whether policies guide decisions, whether people understand the technology, and whether someone keeps track of new legal duties so that AI stays under proper and informed control.

  • Roles and Responsibilities Mapping
  • AI Governance Policies and Oversight
  • AI Literacy Across the Organisation
  • Legal and Regulatory Horizon Scanning

Ungoverned AI drifts without accountability or informed control.

AI Inventory and Risk Classification

This group is about knowing what AI you have and how risky it is. It covers finding every system in use, sorting each one into the Act's risk levels, screening for banned practices, and working out whether you are the provider or the deployer. Without this clarity, the right duties cannot be applied.

  • AI System Inventory
  • Risk Category Classification
  • Prohibited Practice Screening
  • Provider and Deployer Role Determination

Unknown, misclassified, or banned systems escape all controls.

Risk Management and Data Governance

This group covers how you keep AI safe and fair once it is running. It looks at managing risks across a system's life, using good quality data, checking for bias, and assessing effects on people's fundamental rights. Together these guard against harm that poor data or unmanaged risk can quietly cause over time.

  • Risk Management System
  • Data Quality and Governance
  • Bias Detection and Mitigation
  • Fundamental Rights Impact Assessment

Unmanaged risks and poor data cause unfair harm.

Technical Documentation and Transparency

This group is about proving how your AI works and being open about it. It covers keeping the technical records the Act requires, logging what systems do, telling people when they are dealing with AI, and giving users clear instructions. Good records and honesty build trust and make compliance genuinely demonstrable.

  • Technical Documentation
  • Record-Keeping and Event Logging
  • Transparency and User Disclosure
  • Clear Instructions for Use

Opaque, undocumented AI cannot be trusted or verified.

Oversight, Robustness and Conformity

This group covers keeping AI reliable and legally cleared for use. It looks at meaningful human oversight, technical accuracy and security, passing conformity checks and registering systems, and watching them after launch. These duties make sure systems stay safe in the real world and can be proven compliant when challenged.

  • Human Oversight
  • Accuracy, Robustness and Cybersecurity
  • Conformity Assessment and Registration
  • Post-Market Monitoring and Incident Reporting

Unchecked, uncertified AI fails and breaches the law.

This diagnostic is built on a structured capability framework of five capability groups and twenty named capabilities spanning governance, inventory and risk classification, risk management and data governance, documentation and transparency, and oversight and conformity — each capability defined by an affirmative statement, positive behaviours, a threat statement, and prioritised recommendations.

What you get and how it works

What you get

  • A structured readiness view across all 20 capabilities
  • Blind spots and weaknesses flagged explicitly
  • Prioritised, practical recommendations for each capability
  • A shareable consensus view for your leadership team
  • A baseline you can re-run to track progress

How it works

  1. 1 Complete the assessment — Respond to structured statements covering each capability across the five groups, with nothing to prepare in advance.
  2. 2 See strengths and gaps — Get an immediate view that highlights where your organisation is strong and where blind spots and weaknesses sit.
  3. 3 Prioritise practical action — Use the prioritised recommendations for each capability to decide what to address first, then re-run to track progress.

Expected outcomes

By the end, your leadership team shares one structured view of EU AI Act readiness, knows which capabilities are strong and which are gaps, and has a prioritised set of practical actions — from mapping accountability and classifying systems to strengthening data governance, transparency, human oversight, and conformity — to work through before duties and deadlines apply.

Playbook Usage Scenarios

The following examples illustrate typical situations where organisations use this playbook. They are intended to show when the assessment is most valuable and how it can help leadership teams identify capability gaps, build consensus, and prioritise improvement initiatives.

A Chief Compliance Officer at a multi-national financial services group

Business challenge: The group deploys AI across credit, fraud, and customer service, but leaders hold different views of how ready the organisation is, AI oversight is informal, data is fragmented across divisions, and there is no shared picture of which systems are high-risk under the EU AI Act.

How SuccessOf.ai and the playbook are used: The Chief Compliance Officer runs the assessment with a cross-functional leadership group spanning legal, risk, data, and technology, using the capability groups AI Governance and Accountability, AI Inventory and Risk Classification, and Risk Management and Data Governance to create a common structure, compare perspectives, establish a shared view, and identify where capability weaknesses are constraining progress.

Beneficial result: The team leaves with a clearer shared view of capability gaps, improved leadership alignment on priorities, and a baseline for future reassessment before scaling further AI initiatives.

A Chief Operating Officer at a healthcare technology provider

Business challenge: The provider is building generative AI features into its products but is unsure which use cases are permitted, has responsible-AI concerns, limited documentation and logging, and a widening digital and AI skills gap that slows confident decision-making.

How SuccessOf.ai and the playbook are used: The Chief Operating Officer brings product, engineering, and compliance leaders together to work through the capability groups Technical Documentation and Transparency and Oversight, Robustness and Conformity, using the assessment to compare perspectives, identify strengths and gaps, and understand where weak documentation, oversight, or conformity readiness is constraining progress.

Beneficial result: Leadership gains better sequencing of initiatives, a stronger focus on documentation, transparency, and human oversight, and a more deliberate approach to prioritising improvements before releasing new AI features.

Frequently asked questions

What is the EU AI Act readiness diagnostic? +

It is a structured self-assessment that scores your organisation across five capability groups and twenty capabilities that determine how ready you are to comply with the EU AI Act.

Who should take part in the assessment? +

The leaders accountable for AI — across legal and compliance, risk, data and analytics, IT and technology, operations, and executive leadership — ideally responding together so you can compare perspectives and build a shared view.

What does the diagnostic assess? +

It assesses AI governance and accountability, AI inventory and risk classification, risk management and data governance, technical documentation and transparency, and oversight, robustness and conformity.

What do I get at the end? +

An immediate readiness view that flags blind spots and weaknesses across all twenty capabilities, with prioritised, practical recommendations for what to address first, and the ability to re-run the assessment to track progress.

Can my leadership team complete it together? +

Yes. Colleagues can respond independently and view a consensus that shows where your team agrees and where perceptions of readiness diverge.

See where your organisation stands on the EU AI Act.

Start the readiness diagnostic