MWMichał Wach Home

Warsaw · Attorney at Law

AI compliance and AI audit

AI-use audits, the EU AI Act and AI risk management.

Scope

  • AI-use inventory
  • audit of roles, data and risks
  • documentation and remediation measures
  • EU AI Act, GDPR and ISO/IEC 42001

I conduct AI audits: I identify the use of AI systems, the organisation’s role, data flows and material legal and operational risks.

I take into account the EU AI Act, GDPR and risk management, including ISO/IEC 42001. The starting point is how the tool is actually used, its function in the organisation and the data on which it operates.

Working together

How I work

  1. inventory of AI use cases, organisational roles and data flows
  2. audit of risks and compliance priorities
  3. report, documentation and implementation measures

Questions and answers

Frequently asked questions

Does every use of an AI tool create the same obligations?

No. The assessment depends above all on the organisation’s role, the purpose and manner of use, and whether the system can affect individuals or material business decisions.

What does an AI audit involve?

It establishes where and how an organisation uses AI, which data it processes, what roles it performs, which risks arise and which measures and documentation are needed.

Is an AI-use policy enough on its own?

A policy is important, but it does not replace an assessment of use cases, roles, data, suppliers and the organisation’s actual practice.

What role can ISO/IEC 42001 play?

The standard structures AI system and risk management. It does not automatically create legal compliance, but it helps to design, document and monitor it.

The information on this website is general in nature; the scope of legal services depends on the circumstances of the individual matter.

Contact about a matter