New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Getting started

The enterprise showcase

This is the platform at enterprise scale: Nordbank Europe, a fictional pan-European bank with departments, dozens of systems and five active frameworks, worked by two people in the same tenant simultaneously. Group Compliance and the CISO each see the obligations that matter to their role, and the shared evidence and audit trail keeps both honest.

Transcript

Meet Nordbank Europe: a fictional pan-European bank with forty thousand employees, operations in nine countries, and AI running across credit, fraud, risk and customer service. This is what the platform looks like when a serious institution works it.

Two people run this story. Claire is the Group Head of Compliance. Marcus is the Group Chief Information Security Officer. Different remits, different frameworks, one shared tenant.

Nordbank is a credit institution, so the obligation set is wide: the AI Act for its models, GDPR for everything it processes, DORA for operational resilience, NIS2 as critical infrastructure, ISO 27001 and 42001 for its management systems, and CRA and SOC 2 for the software it ships and sells.

Claire and Marcus share one tenant, each with their own role and their own filtered view. Here is Claire's dashboard: the full compliance posture across every enabled framework.

The dashboard is the accountability view. Global health, frameworks on track, urgent deadlines, and a system inventory that spans the whole group.

Readiness by framework shows where the group actually stands across all eight: the AI Act, GDPR, DORA, NIS2, ISO 27001, ISO 42001, CRA and SOC 2, each scored from the real checklist work underneath.

Every duty is broken down to individual items, split between what the platform already handles and what the team must action, with the single next deadline surfaced up front.

The compliance calendar brings every regulatory deadline into one view: the AI Act application dates, DORA's phased entry into force, NIS2 transposition, and the internal audit cycle.

The system inventory is the spine of the programme. Nordbank registers every AI system, and every system that processes personal data.

Filter by department and each business line's estate appears on its own, with risk badges on every row.

Open the credit decisioning engine. It is a high risk system under Annex three, because it decides access to credit.

The system card carries everything a regulator would ask for: owner, vendor, purpose, data processed, deployment status, and the risk classification that drives its obligations.

Every AI system needs a classification under Article six. The credit model was assessed when it went live.

High risk, with the reasons spelled out: a sector under Annex three, impact on essential services, and special category data. That classification generates the full obligation set.

The generated checklist runs the whole Annex four documentation duty: technical documentation, risk management, data governance, human oversight, and post market monitoring.

Because the model is high risk and used in a sensitive sector, a fundamental rights impact assessment is triggered under Article twenty seven, opened here for this exact system rather than filed as a standing box-tick.

Marcus is logged in as the Group CISO. His view of the same tenant is shaped by his role: DORA and NIS2 come first, because those are the frameworks that keep the bank running.

DORA treats ICT risk as a board-level concern. Marcus sees the resilience obligations across every critical system, with the evidence behind each control.

The ICT asset register is the DORA spine: every system that supports a critical or important function, classified, owned, and mapped to its resilience obligations.

Nordbank is critical infrastructure under NIS2, so the cybersecurity risk management measures are mandatory. Marcus tracks them against the directive's Annex.

The automated scanning estate feeds evidence into both DORA and NIS2. Marcus can see open findings by severity, tied to the systems they affect.

And when something happens, the incident clock starts immediately. Marcus is working a real incident now: a payment gateway anomaly flagged under Article seventy three.

The report captures what happened, the impact, and the corrective actions. The regulatory reporting deadline is counted down from the moment of awareness.

Back to the GDPR side. The privacy hub holds requests, breaches, processors and consent in one place.

A data subject request came in from a customer.

Claire assigns it to the retail team, and the one month countdown is already running.

A personal data breach was logged earlier this month. The seventy two hour notification clock and the supervisory authority are both recorded against it.

The processor register under Article twenty eight tracks every third party that touches personal data, with DPA status and transfer assessments.

Consent records under Article seven capture the lawful basis for the group's marketing and profiling activity, with the evidence attached.

The group is structured into departments, and every system, obligation and member rolls up through them.

Roles are granular: Claire holds group admin, her compliance officers are editors, and each business line has its own accountable leads.

For anything more specific, Claire builds a custom role.

FRIA Reviewer, Retail Banking: scoped to submitting and reviewing fundamental rights assessments for one business line only.

Reviewers rarely map to just one role. Claire groups the retail-lending reviewers together and grants that group its own scoped role in one step, instead of repeating the same assignment person by person.

AI literacy under Article four applies to every employee, Claire included. The same short assessment any team member takes lives right here in her own settings, no separate admin tool required.

Claire sees Marcus's incident and the AI Act obligations it triggers. They work the same tenant, so nothing is siloed.

Marcus has already logged the corrective actions, and the shared audit trail shows exactly who did what and when.

For work that is a project rather than a standing duty, the compliance plans module tracks tasks, dependencies and milestones.

The plan shows the AI Act readiness roadmap as a dependency chain, so the whole group can see what blocks what.

Vendor risk scoring works across the processor register and the ICT supply chain.

Running the assessment feeds a live score back into both GDPR and DORA.

The questionnaire engine sends real due diligence to critical vendors.

It's sent. Once vendors respond, the answers land straight back in this record.

Evidence is what turns a claim into a proof. The evidence vault holds the artefacts behind each control, linked to the systems they evidence.

Claire attaches the credit model's independent validation report to its evidence record.

That closes the loop on the checklist item.

Generating the group's AI Governance Policy pulls straight from Nordbank's real configuration. On Enterprise, downloading it as a PDF signs it in the same step.

And requiring staff acknowledgment turns it into a tracked obligation, not just a saved file.

Inbound due-diligence questionnaires from Nordbank's own customers get the same treatment: the answer library auto-fills exact matches from past answers instantly, no re-typing the same response twice.

Marcus sees that same policy the moment it is published, on his own My Compliance page, and signs off without needing any admin access at all.

And the audit trail records every action across the whole group, from Claire's DSAR assignment to Marcus's incident log.

Back on the dashboard, the group's posture has moved. Two people, different frameworks, one shared picture.

From Marcus's side, the resilience story is live: DORA and NIS2 tracked, incidents logged, evidence attached.

That is the enterprise story: a wide regulatory surface, real departments, and every framework tracked and evidenced in one place.

Why this is required

Enterprise compliance is a many-frameworks problem. A credit institution is simultaneously a deployer under the AI Act, a controller under GDPR, an ICT-resilience case under DORA, critical infrastructure under NIS2, and an ISO 27001-certified organisation. One register that spans all of it beats five disconnected tools.

Accountability is a multi-person job. The dashboard, obligations, evidence vault and audit trail are shared, so the Compliance lead and the CISO working the same tenant see each other's actions, which is exactly what a regulator's accountability question is really testing.

What EuroCompliant does

Claire, the Group Compliance lead, drives the AI Act and GDPR side: the group posture, the high-risk credit model, its Article 6 classification, the generated checklist, FRIA, the privacy hub and the DSAR/breach/processor work.

Marcus, the Group CISO, drives the resilience side: DORA ICT obligations, NIS2 measures, the scan estate and the open incident he works to its regulatory deadline.

The two users share one tenant. A split-screen shows them working in parallel, and the shared evidence vault and audit trail tie their work together into one accountable picture.

Walking through it

1

The group posture

The dashboard rolls up global health and readiness across the AI Act, GDPR, DORA, NIS2 and ISO 27001.

Open /dashboard →
2

The system estate

Every AI system and every system that processes personal data, filterable by department, with risk badges per row.

Open /systems →
3

Risk classification

The credit decisioning model is high risk under Annex III, the classification that drives its whole obligation set.

Open /systems →
4

Resilience & incidents

DORA and NIS2 obligations, the scan estate, and the incident the CISO works to its regulatory deadline.

Open /operations →
5

Privacy & evidence

The GDPR hub, the processor register, and the evidence vault that turns claims into proof.

Open /privacy-hub →

The law

Frequently asked

How is this different from the small-business journey?

The enterprise showcase is pre-seeded and multi-user. Rather than building from a blank account, it shows a large, already-registered tenant being worked by two people at once (the Compliance lead and the CISO), each with a role-filtered view of the same shared data.

Do the two users share data?

Yes. They log into the same tenant with different roles. The systems, obligations, evidence and audit trail are all shared, so Claire's GDPR work and Marcus's DORA/NIS2 work land in the same accountable picture.

Are the frameworks real?

Yes. The AI Act, GDPR, DORA, NIS2 and ISO 27001 are all live framework sets in the platform, each generating its own obligations, checklist items and document types.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial