Free AI Compliance Scan: 100-Point System Check

A free AI compliance scan is a structured self-assessment that checks an AI system against regulatory checkpoints spanning transparency, fairness, privacy, and human oversight, surfacing gaps before a regulator or auditor does.
An advisory-led compliance assessment across critical checkpoints covering eight dimensions of responsible AI, identifying regulatory gaps, penalty risks, and implementation priorities. In our experience working with organisations on AI governance, a large share of AI systems fall short of basic compliance standards when reviewed properly.
Understanding your AI system's compliance status has never been more critical, with regulatory enforcement accelerating across global markets and penalties under the EU AI Act reaching EUR 35 million or 7% of global turnover for the most serious breaches. Most organisations operate AI systems without a full understanding of their compliance gaps, creating regulatory and business risks that could have been identified and addressed proactively.
This checklist sets out the 100 checkpoints we use in our advisory work to give a system's regulatory readiness a structured first read, across eight essential dimensions of responsible AI. Working through it identifies compliance gaps, regulatory risks, and implementation priorities, and gives you a clear basis for deciding where deeper expert review is worth the investment.
The Critical Need for AI Compliance Assessment
Regulatory Enforcement Reality
AI regulation enforcement has intensified dramatically across jurisdictions, with regulators shifting from guidance to active enforcement. The EU AI Act's implementation timeline means many organisations face compliance deadlines they're unprepared to meet, whilst existing regulations like GDPR increasingly apply AI-specific scrutiny to algorithmic decision-making.
Recent Enforcement Trends demonstrate the urgency:
GDPR fines touching AI-related processing have been rising
Financial services regulators issued AI-specific guidance with immediate compliance expectations
Healthcare authorities halted AI system deployments pending compliance validation
Employment regulators investigated AI hiring systems for discriminatory impacts
Penalty Exposure varies by jurisdiction and industry but is consistently higher than internal estimates assume:
EU AI Act: up to EUR 35 million or 7% of global turnover for the most serious breaches, or up to EUR 15 million or 3% for other high-risk violations
GDPR violations involving AI: penalties scale with turnover and can run into the millions per incident
Financial services and healthcare AI violations: sector regulators can impose substantial penalties alongside operational restrictions, on top of any GDPR or AI Act exposure
Common Compliance Blind Spots
Most organisations focus on obvious compliance requirements whilst missing critical areas that regulators prioritise during investigations.
Documentation Gaps represent the most common compliance failure. Organisations deploy AI systems with insufficient documentation of training data, model decisions, bias testing, and human oversight mechanisms. When regulators request evidence of compliance measures, these gaps become immediate violation evidence.
Bias Testing Inadequacy affects virtually all AI systems but remains poorly understood by internal teams. Surface-level bias testing misses systematic discrimination that regulators specifically target, particularly in hiring, lending, and healthcare applications where protected characteristics influence outcomes.
Human Oversight Failures occur when organisations implement superficial human review processes that don't meaningfully influence AI decisions. Regulators examine whether human oversight is genuine or merely cosmetic, with substantial penalties for systems that claim human control without meaningful implementation.
Privacy Impact Blindness affects AI systems processing personal data without adequate privacy impact assessments. Many organisations underestimate how AI processing triggers enhanced privacy requirements, particularly for sensitive data categories or cross-border transfers.
Our 100 Point Compliance Framework Include
Core Assessment Categories
Transparency and Explainability (12 checkpoints)
Algorithm documentation completeness
Decision explanation capability assessment
Audit trail implementation verification
Stakeholder communication adequacy
Model interpretability evaluation
Change management documentation
Version control and lineage tracking
Performance metric transparency
Training data documentation
Model limitation disclosure
User interface transparency elements
Explanation quality validation
Accountability and Governance (11 checkpoints)
Human oversight implementation
Responsibility assignment clarity
Incident response procedures
Escalation pathway definition
Decision appeal mechanisms
Audit capability assessment
Compliance monitoring systems
Risk management integration
Organisational structure adequacy
Training and competency verification
Third-party oversight arrangements
Fairness and Non-Discrimination (9 checkpoints)
Bias detection implementation
Protected characteristic handling
Demographic parity assessment
Equal treatment verification
Disparate impact evaluation
Mitigation strategy effectiveness
Testing methodology adequacy
Ongoing monitoring capabilities
Remediation procedure implementation
Privacy and Data Protection (8 checkpoints)
Data minimisation compliance
Consent management adequacy
Cross-border transfer compliance
Retention policy implementation
Subject rights enablement
Security measure adequacy
Breach detection capabilities
Third-party data sharing controls
Safety and Reliability (9 checkpoints)
Risk assessment completeness
Safety measure implementation
Performance monitoring adequacy
Failure detection capabilities
Recovery procedure implementation
Testing coverage evaluation
Validation methodology assessment
Real-world performance tracking
Safety boundary enforcement
Security and Robustness (7 checkpoints)
Adversarial attack protection
Input validation implementation
Access control adequacy
Model security measures
Infrastructure protection
Vulnerability management
Security monitoring capabilities
Human Oversight and Control (6 checkpoints)
Meaningful human control implementation
Override capability verification
Supervision adequacy assessment
Decision review mechanisms
Escalation procedure effectiveness
Training and competency validation
Legal and Regulatory Alignment (5 checkpoints)
Jurisdiction-specific compliance
Industry regulation alignment
Contractual obligation fulfilment
Liability framework adequacy
Intellectual property compliance
Assessment Methodology
In our advisory work, we apply systematic evaluation across each checkpoint, combining document and system review with expert judgement to identify compliance gaps and implementation quality.
Initial Review examines system documentation, configuration settings, and available metrics to identify obvious compliance gaps and implementation issues, giving a fast first read on fundamental compliance requirements.
Expert Review evaluates complex compliance areas requiring professional judgement, including bias assessment quality, human oversight effectiveness, and regulatory interpretation accuracy. This is where regulatory expertise does work a checklist alone cannot.
Risk Prioritisation ranks identified compliance gaps by regulatory risk, implementation complexity, and business impact, helping organisations focus on critical issues while planning systematic compliance improvement.
What a Full Assessment Covers
Comprehensive Compliance Scorecard
A full assessment produces detailed scoring across all 100 checkpoints, with clear identification of:
Compliant Areas where your systems meet regulatory requirements and industry best practice
Partial Compliance areas requiring improvement or enhancement to achieve full compliance
Non-Compliant Areas representing immediate regulatory risks requiring urgent attention
Not Applicable areas where specific requirements don't apply to your system or use case
Detailed Gap Analysis
Each identified compliance gap should be documented with:
Specific regulatory requirement explanation
Current implementation assessment
Risk level evaluation (Critical, High, Medium, Low)
Recommended remediation actions
Implementation timeline suggestions
Resource requirement estimates
Priority Action Plan
A useful assessment produces a prioritised implementation roadmap addressing:
Critical Issues requiring immediate attention to avoid regulatory violation
High-Priority Improvements enhancing compliance while reducing ongoing risk
Medium-Priority Enhancements strengthening compliance posture over time
Low-Priority Optimisations achieving compliance excellence and competitive advantage
Regulatory Alignment Assessment
A thorough review checks compliance against applicable regulations including:
EU AI Act requirements by risk category
GDPR provisions affecting AI systems
Industry-specific regulations (financial services, healthcare, employment)
Emerging regulatory guidance and enforcement trends
Industry-Specific Scan Variations
Financial Services Focus
Financial services scans emphasise:
Fair lending and credit decisioning compliance
Market manipulation and insider trading prevention
Customer protection and transparency requirements
Prudential regulation alignment
Anti-money laundering integration
Healthcare Applications
Healthcare AI scans prioritise:
Patient safety and clinical validation
Medical device regulation compliance
HIPAA privacy protection adequacy
Clinical decision support standards
Bias in healthcare delivery assessment
Employment and HR Systems
HR AI scans examine:
Equal employment opportunity compliance
Hiring bias detection and mitigation
Workplace monitoring privacy requirements
Performance evaluation fairness
Disability accommodation adequacy
General Business Applications
Business AI scans cover:
Consumer protection compliance
Data processing transparency
Automated decision-making notifications
Cross-border data transfer requirements
Intellectual property considerations
How to Maximise Your Scan Value
Preparation Steps
System Documentation should be readily available including:
AI system architecture and data flow diagrams
Training data sources and preprocessing descriptions
Model performance metrics and validation results
Current governance and oversight procedures
Existing compliance measures and controls
Stakeholder Involvement enhances scan accuracy:
Technical teams provide system implementation details
Legal teams clarify regulatory interpretation questions
Business stakeholders explain use case requirements
Compliance teams share existing assessment results
Use Case Definition helps focus the scan on relevant requirements:
Specific AI applications and decision types
Target user populations and geographic scope
Integration with existing business processes
Planned deployment timeline and scale
Interpreting Your Results
Compliance Scores reflect current regulatory readiness:
90-100%: Excellent compliance with minor optimisation opportunities
75-89%: Good compliance with identified improvement areas
60-74%: Moderate compliance requiring systematic enhancement
Below 60%: Significant compliance gaps requiring urgent attention
Risk Indicators help prioritise remediation efforts:
Red (Critical): Immediate regulatory violation risk
Orange (High): Significant compliance gaps with enforcement exposure
Yellow (Medium): Moderate issues requiring planned remediation
Green (Low): Minor improvements for optimal compliance
Implementation Recommendations provide actionable guidance:
Immediate actions for critical compliance gaps
Short-term improvements (1-3 months)
Medium-term enhancements (3-12 months)
Long-term optimisation strategies (12+ months)
Beyond the Initial Checklist
Ongoing Compliance Monitoring
AI compliance requires continuous attention as systems evolve and regulations develop. Working through this checklist once establishes a baseline. Sustained regulatory alignment needs ongoing attention on top of that.
Quarterly Reviews track compliance improvement progress and identify new regulatory developments affecting your systems. Regular reassessment helps maintain compliance while adapting to changing requirements.
System Change Assessment evaluates compliance impact when AI systems undergo updates, modifications, or expansion. Changes that affect algorithmic behaviour often trigger new compliance requirements.
Regulatory Update Integration keeps a compliance framework aligned with evolving legal requirements. New guidance, enforcement actions, and regulatory interpretations continuously affect compliance obligations.
Professional Compliance Support
This checklist helps identify compliance gaps and points toward implementation priorities, but many organisations benefit from professional support to work through complex compliance challenges.
After identifying gaps, it's worth weighing the most cost-effective remediation approach. Calculate your organisation's compliance investment requirements to make informed decisions about internal capability development versus professional validation support.
Implementation Assistance helps translate a gap analysis into a systematic compliance improvement programme, aimed at efficient resource use and regulatory alignment.
Independent Validation provides external verification of compliance measures, which strengthens credibility with regulators and stakeholders while reducing the burden on internal teams.
Regulatory Engagement support helps organisations navigate regulator communications, enforcement responses, and compliance demonstrations when specialist expertise adds value.
How We Use This Checklist in Advisory Engagements
Assessment Process
Scoping: Understand your AI systems and use cases
Documentation Review: Assess relevant system documentation and existing compliance materials
Structured Evaluation: Work through the 100 compliance checkpoints against your systems
Expert Review: Assess complex compliance areas that require professional judgement, such as bias testing quality and the genuineness of human oversight
Findings and Recommendations: A compliance assessment with actionable, prioritised recommendations
Follow-up Discussion: Talk through results and implementation planning
What a Structured Assessment Delivers
A properly run assessment against this checklist gives you:
Clear understanding of current compliance status
Identification of regulatory risks and exposure areas
Prioritised action plan for compliance improvement
Professional guidance on complex compliance challenges
Foundation for ongoing compliance monitoring and improvement
Frequently asked questions
What is a free AI compliance scan?
In this context, it's a structured self-assessment checklist that checks an AI system against a set of regulatory checkpoints covering areas like transparency, bias, privacy, and human oversight. It gives an organisation a baseline read of where it stands before committing to a full audit.
How many compliance areas does the checklist cover?
The checklist covers eight dimensions of responsible AI, from transparency and governance through to security and legal alignment, broken down into individual checkpoints within each area.
Is a self-assessment enough, or do we need a professional audit too?
A self-assessment is a useful starting point for spotting obvious gaps, but complex areas such as bias testing and human oversight effectiveness generally benefit from expert review that a checklist alone can't fully replicate. Most organisations use a self-assessment like this to decide where a deeper audit is worth the investment.
What happens after the assessment identifies compliance gaps?
Gaps are typically prioritised by regulatory risk and implementation complexity, giving a business a sequenced plan rather than an undifferentiated list. From there, the decision is usually whether to remediate internally or bring in outside support for the areas that need specialist judgement.
Conclusion
AI compliance complexity continues to increase as regulations evolve and enforcement intensifies. Understanding your current compliance status is the critical first step in protecting your organisation from regulatory penalties while enabling confident AI deployment.
This 100-point checklist gives a structured way to assess your AI systems' regulatory readiness, surfacing gaps and pointing toward actionable priorities for improvement. Working through it, or having us work through it with you, helps you make informed decisions about compliance investment while reducing regulatory risk exposure.
Don't wait for regulatory enforcement to discover compliance gaps in your AI systems. In our advisory work, we help boards and compliance teams run this kind of assessment properly, with the expert judgement the harder checkpoints need.
For hands-on help, see VerityAI's AI compliance and risk review.

Sotiris Spyrou
Sotiris Spyrou is the founder of VerityAI, a Responsible AI advisory for boards and AI-deploying businesses. With 27 years across agencies, global in-house roles, and the C-suite, he advises leaders on AI governance and risk, and on answer-engine visibility engineered without the dark patterns the rest of the industry is getting penalised for. He is the author of TRANSFORM, AI Moats, and Ethical AI.
Founder at VerityAI
Areas of Expertise: