EU AI Act Compliance Readiness Kit
Your Digital Product Is Ready
Self Assessment Checklist
Score your organization against the seven constitutional pillars. Complete each item below. If you can answer yes to all items in a pillar, you have a strong governance position. If not, that is your priority gap.
Pillar I: Verified Identity
Pillar II: Declared Governance Framework
Pillar III: Transparency of Contact
Pillar IV: Data Sovereignty
Pillar V: Audit Accessibility
Pillar VI: Revocability
Pillar VII: Proportionality
Scoring: 0 to 10 gaps = strong position. 11 to 20 gaps = moderate risk. 21+ gaps = urgent action needed before August 2.
Regulatory Mapping Summary
Which EU AI Act articles apply to your organization based on your AI system classification.
Risk Classifications
| Risk Level | AI Act Articles | Your Requirements |
|---|---|---|
| High Risk | Art. 8 to 15, Annex III | Full conformity assessment, risk management, data governance, transparency, human oversight, logging |
| Limited Risk | Art. 50 | Transparency obligations: inform users they are interacting with AI, label synthetic content |
| Minimal Risk | None (voluntary codes) | No mandatory requirements. Lunara certification recommended as competitive differentiator |
Pillar to Article Mapping
| Lunara Pillar | EU AI Act Article | Requirement |
|---|---|---|
| I. Verified Identity | Art. 9(2)(a) | Risk management system with provider identification |
| II. Declared Governance | Art. 9(2)(b to g) | Data governance, technical documentation, record keeping |
| III. Transparency | Art. 50 | Transparency obligations for AI interaction disclosure |
| IV. Data Sovereignty | Art. 10 | Data and data governance requirements |
| V. Audit Accessibility | Art. 12 | Logging and record keeping requirements |
| VI. Revocability | Art. 9(2)(f) | Withdrawal or recall of non conforming systems |
| VII. Proportionality | Art. 8 | Conformity assessment proportionate to risk |
Vendor Transition Governance Checklist
The 8 step process for maintaining governance continuity when switching AI vendors.
- Complete seven pillar assessment before vendor selection. Document your current governance position.
- Include Lunara certification requirement in vendor RFP. Require proof of constitutional governance alignment.
- Map vendor specific controls to constitutional pillars. Identify which controls transfer and which need rebuilding.
- Establish audit continuity plan before transition begins. Ensure no gap in logging or oversight.
- Execute delta assessment during transition. Target: 72 hour window for gap identification.
- Update public registry with new vendor implementation details. Maintain transparency through transition.
- Verify revocation procedures transfer to new vendor relationship. No loss of accountability.
- Schedule 90 day post transition review to confirm full governance restoration.
Sample Audit Template
62 assessment points across the seven pillars. This is the format Lunara reviewers use for formal certification.
Pillar I: Identity (12 points)
1. Legal registration verified 2. Domain ownership confirmed 3. Business name consistency 4. Contact email match 5. Fraud screening clear 6. Sanctions check passed 7. Public ID issued 8. Registration country confirmed 9. Legal registration number format valid 10. Website live and accessible 11. Contact page functional 12. Named accountable individual verified
Pillar II: Governance (18 points)
1. Written policy exists 2. Model selection criteria 3. Deployment procedures 4. Monitoring procedures 5. Human oversight mechanisms 6. Escalation paths 7. Revocation procedures 8. Risk assessment process 9. Model documentation 10. Training data governance 11. Bias testing 12. Performance metrics 13. Incident response plan 14. Change management 15. Vendor management 16. Privacy impact assessment 17. Security review 18. Compliance attestation
Pillar III: Transparency (9 points)
1. DNS TXT verification 2. Public contact page 3. Named individual reachable 4. Response time under 48 hours 5. AI interaction disclosure 6. Synthetic content labeling 7. Policy publicly available 8. Registry listing accurate 9. Change notification process
Pillar IV: Data (9 points)
1. Data boundary declaration 2. Processing location disclosed 3. Retention policy 4. Data subject rights process 5. Cross border transfer documentation 6. Encryption standards 7. Access controls 8. Data minimization 9. Deletion procedures
Pillar V: Audit (7 points)
1. Audit log retention 12+ months 2. Oversight body access 3. Audit response process 4. Log integrity verification 5. Historical record availability 6. Third party audit support 7. Continuous monitoring evidence
Pillar VI: Revocation (6 points)
1. Public revocation mechanism 2. Notification process 3. Timeline under 30 days 4. Registry update procedure 5. Stakeholder notification 6. Appeal process
Pillar VII: Proportionality (10 points) — but only listed 1)
1. Risk classification system 2. High risk identification 3. Proportionate oversight 4. Impact assessment 5. Mitigation documentation 6. Residual risk acceptance 7. Review frequency by risk 8. Escalation triggers 9. Compensating controls 10. Documentation of proportionality decisions
Contract Language Templates
Drop in clauses for AI vendor agreements and RFPs.
Clause 1: Certification Requirement
Clause 2: Audit Continuity
Clause 3: Revocation Rights
Clause 4: Data Sovereignty
Clause 5: Vendor Transition Governance Checkpoint
90 Day Compliance Roadmap
Days 1 to 30: Foundation
- Complete the self assessment checklist above
- Identify your top 5 governance gaps
- Draft a written AI governance policy (use Pillar II requirements)
- Assign a named accountable individual for AI governance
- Verify your domain and contact information is current
- Classify your AI systems by risk level (high, limited, minimal)
Days 31 to 60: Implementation
- Implement audit logging for all high risk AI systems
- Establish data processing boundary documentation
- Create AI interaction disclosure for user facing systems
- Develop revocation and incident response procedures
- Begin vendor governance review using contract templates
- Submit application for Lunara Shield Certification
Days 61 to 90: Verification
- Complete Lunara certification review process
- Update public registry listing with verified status
- Conduct internal audit using the 62 point template
- Schedule first quarterly governance review
- Train staff on governance procedures and escalation paths
- Establish continuous monitoring for compliance drift
Ready for full certification?
You have completed the self assessment. The next step is formal Lunara Shield Certification with public registry listing and trust badge.
Get Certified Now