AI Compliance Framework for Regulated Businesses

AI compliance isn't just a policy document.
It's a system.

A policy tells your team what to do. A compliance framework makes sure they actually do it — and gives you evidence if anyone ever asks.

The Difference

Most businesses stop at the policy. The framework is what actually protects you.

AI Policy (what most businesses have)
  • A document
  • States the rules
  • Given to employees once
  • Sits in a folder
  • No evidence of compliance
AI Compliance Framework (what protected businesses have)
  • A system
  • Enforces the rules
  • Regularly reviewed and updated
  • Evidenced and auditable
  • Demonstrates due diligence to ICO, regulators, and clients

Not sure which package you need? Answer 7 questions and get your free AI compliance exposure report — instant, no sign-up.

Take the Free Check →
What's Included

A complete AI compliance framework has six components.

01 — Acceptable Use Policy

Acceptable Use Policy

The foundation document. Defines approved tools, prohibited uses, data rules, and employee responsibilities. Customised to your business.

02 — Data Classification Matrix

Data Classification Matrix

Categorises every type of data your business handles (public, internal, confidential, restricted) and defines which AI tools each category can be processed by.

03 — GDPR Compliance Position

GDPR Compliance Position

For each AI tool you use: is it a data processor? Is there a DPA? Where is data stored? Does it train on your inputs? Documented and maintained.

04 — Employee Training & Acknowledgement

Employee Training & Acknowledgement

Plain-English guidelines per team and role. Employees read, understand, and sign acknowledgement. You have a record.

05 — AI Risk Register

AI Risk Register

A live document listing every AI tool in use, the risks associated with each, and the mitigations in place. Updated when tools are added or changed.

06 — Incident Response Procedure

Incident Response Procedure

What happens if something goes wrong. Who is notified, in what order, within what timeframe. Required by UK GDPR for data incidents.

Your Sector

Regulated industries have additional obligations.

Legal (SRA regulated)

Client confidentiality, legal professional privilege, and SRA Code of Conduct obligations apply when using AI with client matter files. The SRA has published specific guidance.

Financial Services (FCA regulated)

The FCA expects firms to manage AI as an operational risk. Consumer Duty obligations extend to AI-assisted advice or communications.

Healthcare & Care

CQC and ICO requirements overlap. Special category health data has the highest level of GDPR protection. Any AI processing of patient or service user data requires explicit justification.

Education

If children's data is involved, additional safeguarding obligations apply. Ofsted may ask about AI use in safeguarding contexts.

EU AI Act

Trading with Europe? The EU AI Act already applies to you.

The EU AI Act is not just a European regulation. It has explicit extraterritorial reach — if your AI systems produce outputs used inside the EU, you are in scope. That includes any UK business with Irish clients, EU supply chain partners, or EU-based customers.

Feb 2025

Prohibited AI practices banned

Manipulative AI, social scoring, and mass biometric surveillance outlawed across the EU — including outputs from UK-based systems reaching EU users.

Aug 2025

Fines now enforceable

EU regulators can issue fines today. Up to €35 million or 7% of global annual turnover, whichever is LOWER for a small or medium business — in practice 7% of turnover for serious violations. No grace period on prohibited practices.

Aug 2026

Enforcement begins

Article 50 transparency obligations apply and national regulators across all EU member states gain their enforcement powers. This is the critical deadline.

Dec 2027

High-risk AI systems (Annex III)

Recruitment, credit scoring, education and essential-services AI come into scope. Deferred from August 2026 by the Digital Omnibus, adopted 29 June 2026.

Aug 2028

AI in regulated products

AI embedded in medical devices, vehicles, and regulated machinery faces its own compliance deadline.

Who This Catches

UK businesses with any customers in Ireland or mainland Europe

B2B suppliers whose end clients serve EU customers

Businesses processing data about EU citizens

Any business planning EU expansion — build it now, not later

What's Inside Your Pack
01
UK GDPR Gap Analysis for AI Tools
02
AI Acceptable Use Policy
03
Employee AI Guidelines — Practical Dos and Don'ts
04
ICO Framework Self-Assessment
05
Compliance Roadmap
06
Data Classification Matrix
07
Data Access Request and Justification
08
Data Access Register
09
AI Test Cases — What to Check Before You Trust It
10
Where a Person Must Look
11
GDPR Compliance Position
12
Employee AI Policy Acknowledgement Form
13
Full ICO AI Auditing Framework Assessment
14
Employment AI Procedures
15
Automated Decision-Making Notices and Opt-Out Procedures
16
Data Subject Rights Procedures for AI-Processed Data
17
Sector-Specific Obligations Review
18
AI Risk Register
19
AI Incident Response Procedure
20
EU AI Act Risk Tier Classification
21
Annex III High-Risk Gap Analysis
22
Article 50 Transparency Assessment and Disclosures
23
Cross-Jurisdiction Compliance Position
24
AI Supply Chain Risk Review
24
separate documents
jurisdiction-specific
See a real one

Read it before you buy it.

This is not a mock-up or a contents page. It is a genuine UK + EU Combined Compliance Framework — all 24 documents — produced by the same system that will produce yours, for a fictional firm of solicitors we invented to test it. Every page below came out of the real thing.

Sample pack, page 1 Sample pack, page 2 Sample pack, page 3 Sample pack, page 4 Sample pack, page 5 Sample pack, page 6 Sample pack, page 7 Sample pack, page 8
6 / 8
Open the full sample pack

Opens the PDF exactly as a client receives it. Yours is written around your business, your tools and your sector — not this one.

Investment

UK, EU, and US AI compliance — choose the jurisdiction you need.

Choose the framework that matches where your customers, employees, and operations are. Need more than one? We offer bundles — or you can start with one and extend later.

🇬🇧
UK AI Compliance

For businesses operating in the UK. Covers UK GDPR, ICO obligations, SRA/FCA sector requirements, and AI acceptable use. Foundation from £797.

🇪🇺
EU AI Act Compliance

For any business with EU customers, employees, or operations. Banned-practice and GPAI rules already in force; high-risk obligations land December 2027. Applies to UK and US businesses. Essentials from £497.

🇺🇸
US AI Compliance

For businesses with US operations, employees, or customers. California, Texas and Illinois laws are live now. Policy from £197.

UK Compliance Frameworks

Foundation Framework
£797 /year

~$1,010 · ~€930 per year

  • Acceptable Use Policy
  • Data Classification Matrix
  • GDPR Compliance Position (up to 5 AI tools)
  • Employee Guidelines + Acknowledgement Forms

In your inbox by the end of the business day · Covers you for 12 months

Renews yearly — legal updates applied throughout your cover as regulation evolves.

Book a scoping call → or buy directly — £797/yr
How your framework renews
12 months' cover
  • Your fee covers a full 12 months — then renews yearly
  • Legal updates applied as UK AI regulation evolves
  • Quarterly review of tools, policies, and regulatory changes
  • Unlimited tool additions and policy changes covered
  • Priority response if you receive an ICO enquiry or data subject request

No separate retainer, no surprise invoices — one annual fee keeps you covered and current.

Questions? Book a call →

EU AI Act Compliance

Prohibited-practice and general-purpose AI rules are already in force; high-risk obligations land 2 December 2027. Applies to any business with EU customers, employees, or operations — not just EU companies. UK businesses with Irish clients, US businesses with German users — all in scope.

Looking for standalone EU AI Act compliance (not bundled with UK)? Essentials from £497 — see the full EU AI Act packages →
EU AI Act Assessment
£1,500 one-off

~$1,900 · ~€1,750

  • EU AI Act risk tier classification for all AI tools in use
  • Gap analysis against Annex III high-risk obligations
  • Article 50 transparency requirements assessment
  • Documented EU compliance position
  • Supply chain risk review

In your inbox by the end of the business day

Best for: businesses already actively trading with EU clients who need standalone EU compliance.

Book a scoping call → or buy directly — £1,500
EU Extension
£900 one-off

~$1,140 · ~€1,050

  • For existing Ops Intel UK Full Compliance clients only
  • Upgrades your existing framework to cover EU AI Act
  • No duplication of work already completed
  • EU risk classification + Article 50 compliance
  • Updated documentation covering both jurisdictions

In your inbox by the end of the business day

Best for: existing clients expanding into EU trading. Contact us to confirm eligibility.

Enquire — £900 →

US AI Compliance

California, Texas and Illinois AI laws are live now. Illinois law applies to any employer using AI in hiring decisions — regardless of which state your business is in.

Not sure if US law applies to you? Read the full breakdown — see the US AI Compliance packages →
US AI Policy
£197 one-off

~$250 · ~€230

  • AI Acceptable Use Policy
  • Employee AI guidelines
  • AI tool inventory template
  • Plain-English summary of obligations by state

Best for: small businesses wanting a baseline policy covering all 50 states.

In your inbox by the end of the business day

Buy now — £197 →
US AI Compliance Complete
£1,497 /year

~$1,900 · ~€1,750 per year

  • Everything in Foundation
  • Multi-state compliance matrix
  • Full HR AI procedures and disclosure templates
  • Impact assessment templates
  • Incident response procedure
  • Federal legislation readiness assessment

Best for: multi-state businesses, 15+ employees, or businesses wanting full coverage ahead of federal legislation.

In your inbox by the end of the business day · Covers you for 12 months, renews yearly

Book a scoping call → or buy directly — £1,497/yr

Every framework is annual — your fee covers 12 months of protection, new state AI laws monitored and applied to your framework as they pass, and renews yearly so your cover never lapses.

Why Ops Intel

You don't need a £15,000 "AI Assurance" engagement. You need a compliance framework that actually works.

Larger consultancies are now selling "AI Governance" and "AI Assurance" programmes — broad, expensive, and built for enterprises with months to spare. Most SMEs need something different: clear documentation, practical policies, and a defensible compliance position, delivered fast.

Large AI Assurance Firms

  • 6–12 week discovery process before any deliverable
  • Scoping fees, daily rates, change requests — total cost unknown upfront
  • Frameworks built for enterprise scale, not a 10-person professional services firm
  • You still need to operationalise it yourself afterwards

Ops Intel

  • Fixed price — you know the full cost before you commit
  • Complete framework delivered in days, not months
  • Built specifically for SMEs in professional services — not scaled down from enterprise
  • Includes staff briefing, acknowledgement forms, and legal updates throughout your 12-month cover

For most SMEs, the question isn't whether to get compliant — it's whether to do it affordably now, or expensively later.

How It Works

Four steps to a complete framework.

  1. 01

    Audit

    We inventory your current AI tools and data flows — what's being used, by whom, and what data is involved.

  2. 02

    Draft

    We write every document, customised to your business — policy, data matrix, GDPR position, risk register, incident procedure.

  3. 03

    Brief

    We walk your team through everything — plain-English guidelines, acknowledgement forms signed and filed.

  4. 04

    Maintain

    Annual review, tool additions, policy updates — keeping your framework current as AI evolves.

Questions

Quick answers.

Do we need a framework or just a policy?

Depends on size and sector. For a 2-person business using ChatGPT occasionally: a policy is probably enough. For a solicitors' firm with 8 staff using multiple AI tools with client data every day: the full framework is appropriate. We'll tell you honestly on the call.

Can this be used if the ICO investigates us?

Yes. One purpose of the framework is to demonstrate due diligence. If the ICO investigates a data incident, having documented policies, training records, and a risk register is material evidence of responsible data handling.

How often does it need updating?

The AI landscape changes fast. We recommend reviewing your policy and risk register every 12 months minimum, or whenever you adopt a significant new AI tool. Your framework renews annually with legal updates included, so the regulatory side is handled for you — just tell us when you adopt a new tool.

We're UK-only right now — do we need EU coverage?

If you have no clients, suppliers, or data subjects in EU member states (including Ireland), the UK framework is sufficient for now. However, if there's any chance you'll expand into EU markets in the next 12–24 months, building EU compliance in from the start is significantly cheaper than retrofitting it later. The EU Extension at £900 is available to existing UK Full Compliance clients when you're ready to make that move.

Does the EU AI Act really apply to a small UK business?

Yes — if your AI systems produce outputs used inside the EU. The Act's extraterritorial scope is explicit. A UK solicitor with one Irish client using AI to assist with their work is in scope. A UK marketing agency with one EU-based client is in scope. The fines are proportional for SMEs, but proportional is not zero — and the reputational risk of an enforcement action is the same regardless of company size.

Is this legal advice?

No. Our compliance frameworks are general compliance guidance documents and do not constitute legal advice. Ops Intel is not a law firm and is not authorised by the Solicitors Regulation Authority or Financial Conduct Authority. We recommend seeking independent legal advice for specific regulatory questions relating to your circumstances. Our frameworks are designed to demonstrate due diligence and reasonable steps — the standard most regulators apply when assessing SME compliance.

Sample Reports

See exactly what you receive.

Every framework is tailored to your business, your AI tools, and your jurisdictions. These samples show the range — from a clean low-risk result through to a business with significant gaps to close.

Example A — Low Risk

AI Compliance Framework Version 1.0  ·  May 2026

Harrison & Cole Accountants Ltd

Prepared by Ops Intel  ·  Jurisdictions: United Kingdom  ·  European Union

16 sections  ·  Risk register  ·  Gap analysis  ·  Remediation roadmap
1

Executive Summary

Shown

Harrison & Cole is a 14-person chartered accountancy practice in Leeds. The firm uses AI tools across email drafting, transaction categorisation, tax return preparation, and receipt processing.

Overall Risk Level LOW
Gaps Identified 3
Prohibited / High-Risk AI None

All AI systems are limited-risk or minimal-risk under the EU AI Act. Primary exposure: transparency obligations under Article 50 and sub-processor controls for financial data.

3

AI System Inventory

Shown

Every AI tool the firm uses is catalogued — purpose, data involved, and whether it's client-facing.

ID System Provider Purpose Client-facing?
AI-001 Microsoft 365 Copilot Microsoft Email drafting, document summarisation, client correspondence Indirectly
AI-002 Xero (AI features) Xero Ltd Transaction categorisation, smart reconciliation No
AI-003 QuickBooks AI Intuit Expense categorisation, bookkeeping suggestions No
AI-004 IRIS Elements AI IRIS Software Tax return data extraction No
AI-005 Dext Dext Ltd OCR receipt and invoice extraction No
AI-006 ChatGPT (ad hoc) OpenAI Ad hoc drafting — no policy in place No policy
5

EU AI Act — Risk Classification

Shown

Each AI system is classified under the EU AI Act four-tier risk framework. Risk tier determines which obligations apply.

Limited Risk Microsoft 365 Copilot Generates text delivered to clients — Article 50 transparency obligations apply
Minimal Risk Xero, QuickBooks, IRIS, Dext Assistive processing; human reviews all outputs; no legal effect on data subjects
Limited Risk ⚠ ChatGPT (ad hoc) Generative AI with no usage policy — gap requiring immediate action

No prohibited or high-risk AI systems in use.

7

Risk Register

Client Confidential
Risk register — included in your framework
8

AI Usage Policy

Client Confidential
Tailored AI usage policy — included in your framework
15

Gap Analysis & Remediation Roadmap

Shown

Every gap is assigned a priority, a target date, and a clear action. Nothing is left as "review required."

High
GAP-001 — No AI disclosure in client engagement letters
EU AI Act Art. 50 · DUA Act 2025 Target: 31 July 2026
High
GAP-002 — Privacy notice does not reference AI processing
DUA Act 2025 · UK GDPR · ICO guidance Target: 30 June 2026
High
GAP-003 — ChatGPT usage uncontrolled; potential client financial data exposure
UK GDPR · EU AI Act Target: 31 May 2026
Med
GAP-004 — GAP-006 — Vendor DPA reviews, training records
Target: 31 July – 30 September 2026
9–14, 16

Data Governance · Vendor Management · Incident Response · Training · Sign-off

Client Confidential
7 further sections included in your full framework

Your framework. Your AI tools. Your regulations.

In your inbox by the end of the business day. Accurate as at delivery, then kept current — your framework renews annually with legal updates included.

Get Your Framework →

Sample report. Client name, trading details, and AI tool configuration are illustrative only. Any resemblance to actual organisations is coincidental.

Example B — High Risk

AI Compliance Framework Version 1.0  ·  May 2026

Apex Creative Agency Ltd

Prepared by Ops Intel on behalf of Apex Creative Agency Ltd  ·  Jurisdictions: United Kingdom · European Union · United States

16 sections  ·  Risk register  ·  Gap analysis  ·  Remediation roadmap
1

Executive Summary

Shown

Apex Creative Agency Ltd is a 22-person digital marketing agency based in Manchester, delivering paid media, content, and creative services to clients across the UK, EU, and North America. The agency uses AI tools extensively across campaign delivery, copywriting, image generation, client reporting, and outreach.

Immediate action required. This assessment has identified critical compliance gaps that require remediation before the EU AI Act transparency obligations take full effect in August 2026.
Overall Risk Level HIGH
Gaps Identified 9
High-Priority Gaps 6
AI-generated content delivered to clients with no disclosure — Article 50 breach risk
Client personal data entered into consumer ChatGPT by multiple staff — active GDPR exposure
AI ad targeting tools (Meta Advantage+, Google Performance Max) operating without deployer review — EU AI Act gap
No AI sub-processor DPAs in place for 4 of 7 tools — UK GDPR Article 28 breach
Midjourney used to generate synthetic client imagery — no deepfake / synthetic media disclosure
US client data processed by EU-based AI tools without transfer mechanism — GDPR international transfer gap
3

AI System Inventory

Shown

7 AI systems identified across campaign delivery, content production, client outreach, and reporting.

ID System Provider Purpose DPA in place? Client data?
AI-001 ChatGPT (consumer) OpenAI Ad copy, emails, client briefs, proposals ✗ No Yes — uncontrolled
AI-002 Midjourney Midjourney Inc. Client creative assets, social imagery, ad visuals ✗ No Client brand assets
AI-003 Meta Advantage+ Meta Platforms Automated audience targeting and creative optimisation ~ Partial Client audience data
AI-004 Google Performance Max Google LLC Automated campaign management and targeting ~ Partial Client audience data
AI-005 HubSpot (AI features) HubSpot Inc. CRM email drafting, lead scoring, contact enrichment ✓ Yes Prospect data
AI-006 Jasper AI Jasper AI Inc. Long-form content, blog posts, landing page copy for clients ✗ No Client briefs, brand guides
AI-007 Whatagraph (AI reports) Whatagraph Ltd Automated client performance reporting ✓ Yes Client campaign data
5

EU AI Act — Risk Classification

Shown

Three systems carry active transparency obligations under Article 50. Two require immediate deployer review under Article 26.

Limited Risk ⚠ ChatGPT (AI-001) Generates client-facing copy with no disclosure. Consumer account — no DPA. Active GDPR and Article 50 breach risk.
Limited Risk ⚠ Midjourney (AI-002) Generates synthetic imagery delivered to clients and published publicly. Article 50(4) — synthetic media disclosure obligation not met.
Limited Risk ⚠ Jasper AI (AI-006) AI-generated content delivered to clients without disclosure. No DPA. Client brand data processed without Article 28 agreement.
Limited Risk Meta Advantage+, Google Performance Max (AI-003, AI-004) Automated ad targeting and optimisation. Deployer obligations under Article 26 not yet assessed or documented.
Minimal Risk HubSpot AI, Whatagraph (AI-005, AI-007) Assistive features with human oversight. DPAs in place. Low risk.
August 2026 deadline: EU AI Act Article 50 transparency obligations take full effect. Three systems are currently non-compliant.
7

Risk Register

Client Confidential
Full risk register with likelihood, impact, and residual risk — included in your framework
8

AI Usage Policy

Client Confidential
Tailored AI usage policy for agency operations — included in your framework
15

Gap Analysis & Remediation Roadmap

Shown

9 gaps identified. 6 are high priority. The roadmap sequences remediation to address the highest legal exposure first.

Critical
GAP-001 — Consumer ChatGPT used with client personal data — no DPA, no data minimisation, model training not restricted
UK GDPR Art. 28 · Art. 32 · DUA Act 2025 Target: Immediate — restrict use today
Critical
GAP-002 — AI-generated images (Midjourney) published as client content with no synthetic media disclosure
EU AI Act Art. 50(4) — synthetic content disclosure Target: Before next campaign launch
Critical
GAP-003 — Jasper AI and Midjourney processing client brand and brief data without Article 28 DPAs
UK GDPR Art. 28 — processor agreement required Target: 31 May 2026
High
GAP-004 — AI-generated copy (ChatGPT, Jasper) delivered to clients without disclosure in any channel
EU AI Act Art. 50(1) & Art. 50(4) Target: 30 June 2026
High
GAP-005 — Meta Advantage+ and Google PMax AI operating without documented deployer review or human oversight controls
EU AI Act Art. 26 — deployer obligations Target: 31 July 2026
High
GAP-006 — Privacy notice does not disclose AI processing or sub-processors; no DUA Act 2025 reference
DUA Act 2025 · UK GDPR · ICO AI guidance Target: 30 June 2026
Med
GAP-007 — GAP-009 — International transfer mechanism for US client data; staff AI training records; client AI disclosure in contracts
Target: 31 July – 30 September 2026
9–14, 16

Data Governance · Vendor Management · Incident Response · Training · Sign-off

Client Confidential
7 further sections included in your full framework

If this looks familiar, the time to act is now.

EU AI Act transparency obligations apply from August 2026. In your inbox by the end of the business day. Your framework renews annually with legal updates included, so it keeps pace as the rules change.

Get Your Framework →

Sample report. Client name, trading details, and AI tool configuration are illustrative only. Any resemblance to actual organisations is coincidental.

Don't wait for an incident to get compliant.

Book a 30-minute call. We'll assess what your business actually needs and give you a clear quote.

Book a Free Compliance Call →

Free 30-minute call · Written quote before work starts · In your inbox by the end of the business day · UK-based team

Call Now Claim Your Free Audit