Documentation

Getting started

The enterprise showcase

This is the platform at enterprise scale: Nordbank Europe, a fictional pan-European bank with departments, dozens of systems and five active frameworks, worked by two people in the same tenant simultaneously. Group Compliance and the CISO each see the obligations that matter to their role, and the shared evidence and audit trail keeps both honest.

Transcript

Meet Nordbank Europe: a fictional pan-European bank with forty thousand employees, operations in nine countries, and AI running across credit, fraud, risk and customer service. This is what the platform looks like when a serious institution works it.

Two people run this story. Claire is the Group Head of Compliance. Marcus is the Group Chief Information Security Officer. Different remits, different frameworks, one shared tenant.

Nordbank is a credit institution, so the obligation set is wide: the AI Act for its models, GDPR for everything it processes, DORA for operational resilience, NIS2 as critical infrastructure, and ISO 27001 for its management system.

Claire and Marcus share one tenant, each with their own role and their own filtered view. Here is Claire's dashboard: the full compliance posture across every enabled framework.

The dashboard is the accountability view. Global health, frameworks on track, urgent deadlines, and a system inventory that spans the whole group.

Readiness by framework shows where the group actually stands: the AI Act, GDPR, DORA, NIS2 and ISO 27001, each scored from the real checklist work underneath.

The obligations view filters by department, so posture reads per business line: retail credit, payments, anti-fraud, human resources, and the group functions.

The compliance calendar brings every regulatory deadline into one view: the AI Act application dates, DORA's phased entry into force, NIS2 transposition, and the internal audit cycle.

The system inventory is the spine of the programme. Nordbank registers every AI system, and every system that processes personal data.

Filter by department and each business line's estate appears on its own, with risk badges on every row.

Open the credit decisioning engine. It is a high risk system under Annex three, because it decides access to credit.

The system card carries everything a regulator would ask for: owner, vendor, purpose, data processed, deployment status, and the risk classification that drives its obligations.

Every AI system needs a classification under Article six. The credit model was assessed when it went live.

High risk, with the reasons spelled out: a sector under Annex three, impact on essential services, and special category data. That classification generates the full obligation set.

The generated checklist runs the whole Annex four documentation duty: technical documentation, risk management, data governance, human oversight, and post market monitoring.

Because the model is high risk and used in a sensitive sector, a fundamental rights impact assessment is triggered under Article twenty seven. The group has a standing process for these.

Marcus is logged in as the Group CISO. His view of the same tenant is shaped by his role: DORA and NIS2 come first, because those are the frameworks that keep the bank running.

DORA treats ICT risk as a board-level concern. Marcus sees the resilience obligations across every critical system, with the evidence behind each control.

The ICT asset register is the DORA spine: every system that supports a critical or important function, classified, owned, and mapped to its resilience obligations.

Nordbank is critical infrastructure under NIS2, so the cybersecurity risk management measures are mandatory. Marcus tracks them against the directive's Annex.

The automated scanning estate feeds evidence into both DORA and NIS2. Marcus can see open findings by severity, tied to the systems they affect.

And when something happens, the incident clock starts immediately. Marcus is working a real incident now: a payment gateway anomaly flagged under Article seventy three.

The report captures what happened, the impact, and the corrective actions. The regulatory reporting deadline is counted down from the moment of awareness.

Back to the GDPR side. The privacy hub holds requests, breaches, processors and consent in one place.

A data subject request came in from a customer. Claire assigns it to the retail team, and the one month countdown is already running.

A personal data breach was logged earlier this month. The seventy two hour notification clock and the supervisory authority are both recorded against it.

The processor register under Article twenty eight tracks every third party that touches personal data, with DPA status and transfer assessments.

Consent records under Article seven capture the lawful basis for the group's marketing and profiling activity, with the evidence attached.

The group is structured into departments, and every system, obligation and member rolls up through them.

Roles are granular: Claire holds group admin, her compliance officers are editors, and each business line has its own accountable leads.

AI literacy under Article four is tracked group wide. Nordbank's programme shows the completion rate across every department.

Claire sees Marcus's incident and the AI Act obligations it triggers. They work the same tenant, so nothing is siloed.

Marcus has already logged the corrective actions, and the shared audit trail shows exactly who did what and when.

For work that is a project rather than a standing duty, the compliance plans module tracks tasks, dependencies and milestones.

The plan shows the AI Act readiness roadmap as a dependency chain, so the whole group can see what blocks what.

Vendor risk scoring works across the processor register and the ICT supply chain, feeding both GDPR and DORA.

The questionnaire engine sends real due diligence to critical vendors, and the answers land back in the vendor record.

Evidence is what turns a claim into a proof. The evidence vault holds the artefacts behind each control, linked to the systems they evidence.

Claire attaches the credit model's independent validation report to its evidence record, closing the loop on the checklist item.

And the audit trail records every action across the whole group, from Claire's DSAR assignment to Marcus's incident log.

Back on the dashboard, the group's posture has moved. Two people, different frameworks, one shared picture.

From Marcus's side, the resilience story is live: DORA and NIS2 tracked, incidents logged, evidence attached.

That is the enterprise story: a wide regulatory surface, real departments, and every framework tracked and evidenced in one place.

Why this is required

Enterprise compliance is a many-frameworks problem. A credit institution is simultaneously a deployer under the AI Act, a controller under GDPR, an ICT-resilience case under DORA, critical infrastructure under NIS2, and an ISO 27001-certified organisation. One register that spans all of it beats five disconnected tools.

Accountability is a multi-person job. The dashboard, obligations, evidence vault and audit trail are shared, so the Compliance lead and the CISO working the same tenant see each other's actions — which is exactly what a regulator's accountability question is really testing.

What EuroCompliant does

Claire, the Group Compliance lead, drives the AI Act and GDPR side: the group posture, the high-risk credit model, its Article 6 classification, the generated checklist, FRIA, the privacy hub and the DSAR/breach/processor work.

Marcus, the Group CISO, drives the resilience side: DORA ICT obligations, NIS2 measures, the scan estate and the open incident he works to its regulatory deadline.

The two users share one tenant. A split-screen shows them working in parallel, and the shared evidence vault and audit trail tie their work together into one accountable picture.

Walking through it

1

The group posture

The dashboard rolls up global health and readiness across the AI Act, GDPR, DORA, NIS2 and ISO 27001.

Open /dashboard →
2

The system estate

Every AI system and every system that processes personal data, filterable by department, with risk badges per row.

Open /systems →
3

Risk classification

The credit decisioning model is high risk under Annex III — the classification that drives its whole obligation set.

Open /systems →
4

Resilience & incidents

DORA and NIS2 obligations, the scan estate, and the incident the CISO works to its regulatory deadline.

Open /operations →
5

Privacy & evidence

The GDPR hub, the processor register, and the evidence vault that turns claims into proof.

Open /privacy-hub →

The law

Frequently asked

How is this different from the small-business journey?

The enterprise showcase is pre-seeded and multi-user. Rather than building from a blank account, it shows a large, already-registered tenant being worked by two people at once — the Compliance lead and the CISO — each with a role-filtered view of the same shared data.

Do the two users share data?

Yes. They log into the same tenant with different roles. The systems, obligations, evidence and audit trail are all shared, so Claire's GDPR work and Marcus's DORA/NIS2 work land in the same accountable picture.

Are the frameworks real?

Yes — the AI Act, GDPR, DORA, NIS2 and ISO 27001 are all live framework sets in the platform, each generating its own obligations, checklist items and document types.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial