Request a consultation

focus area · assess the inventory, classify the risks

AI Audit & Screening

In most companies AI has long been in use — often without an overview: browser tools in sales, assistants in office products, AI features in specialist software, pilot projects from departments. The AI audit records this inventory, evaluates it by law, security and benefit and delivers a prioritised action plan.

When an AI audit makes sense

An audit pays off as soon as AI is used in the company without anyone knowing the complete list. Typical triggers are enquiries from the data protection officer, requirements from customers or certifiers, the AI literacy obligation under Art. 4 EU AI Act, an upcoming automation project — or simply the wish to know the costs and risks of existing tools.

  • Before an AI strategy or architecture planning, as an inventory
  • Before audits under ISO 27001 or TISAX, to classify AI use cleanly
  • When there are signs of shadow AI in departments
  • After mergers, acquisitions or system changes

What the screening covers

We record all AI applications and AI features — procured, embedded or self-built — and evaluate them along five dimensions.

Inventory

Which systems, which providers, which users, which data, which purpose — fully and currently documented.

Law & EU AI Act

Classification of every application into the risk classes; transparency and literacy obligations; contracts and data processing agreements.

Data protection

Which personal data flows where; legal bases, deletion concepts, third-country transfers.

Security

Access, permissions, logging, handling of trade secrets and prompt content.

Benefit & cost

Licence and usage costs per application against the actual contribution in the process.

Recognising and classifying shadow AI

Shadow AI arises when employees use helpful tools for which no rule exists. That is rarely ill intent but a sign of real need. The audit makes this use visible, assesses the risk and proposes which tools should be brought into regulated channels, replaced or discontinued.

Tone matters: we talk to departments as participants, not as suspects. Only then does the inventory become complete.

Result: report and action plan

You receive an audit report with a complete AI inventory, risk classification per application, identified deviations and a prioritised action plan. The actions are concrete: adjust a contract, change a setting, replace a tool, run training, add to a policy.

  • AI inventory as a living document that can be kept up to date
  • Risk pyramid under the EU AI Act with all applications assigned
  • Recommendations with owners and timeframes
  • Template for an AI policy if none exists yet

From audit to strategy

The audit is a starting point, not an end point. The results flow directly into the Use Case Discovery, the AI Readiness Check and — if desired — into architecture planning and an AI strategy following the Sellium Method. The inventory becomes a reasoned plan for where AI should do more in your company and where it belongs restricted.

privacy first ai

Check before others do

The prohibitions and transparency obligations of the EU AI Act already apply; the high-risk obligations follow in 2027 and 2028. An audit creates the overview that regulators, customers and certifiers increasingly expect.

Independent

We evaluate tools by benefit and risk for your company — without ties to any provider.

Documented

Every finding is traceably evidenced and usable for data protection officers and auditors.

Connectable

Results flow directly into the AI policy, training planning and Use Case Discovery.

process

How the AI audit runs

A compact procedure with clearly defined results.

  1. Step 1: Kick-off & scoping

    Definition of scope, contacts and information sources; alignment with data protection and IT security.

  2. Step 2: Data collection

    Interviews with departments, evaluation of licence and access data, review of contracts and system settings.

  3. Step 3: Evaluation

    Classification of every application under the EU AI Act, data protection, security and economics; identification of deviations.

  4. Step 4: Report & action plan

    Presentation of results to management and stakeholders, prioritised action plan, handover of the AI inventory.

contact

Let's talk

Happy to help with anything AI. We will get back to you promptly.

AddressCarolastraße 4-6, 09111 Chemnitz

Get in touch