ACF MODULE
AI Governance Platform

ACF Compliance

AI governance, made operational.

One platform to map your AI systems, classify them against the 3 core frameworks (GDPR, AI Act, ISO 42001) across 13 AI jurisdictions, generate the documentation regulators ask for — and prove every decision with a court-grade audit trail. Built for SMEs, mid-market and groups operating across Europe.

Built for compliance teams in finance, retail, SaaS, healthcare and industrial groups.
ACF COMPLIANCE · LIVE
v2026.06
Compliance posture
12/ 100
EU AI Act audit trailArt. 12, 26(6)
GDPR profiling lawful basisArt. 22, DPIA
ISO 42001 lifecycle controlsISO 42001:2023
DORA ICT risk mappingRTS-ICT 2024
NIS2 resilience baselineAnnex I
Scanning regulations…
// The problem

The AI regulatory wave is already here.

AI is now treated like a regulated industry. Boards, regulators and insurers want one clear answer: can you prove what your AI systems do, who authorised them, and which rules they comply with?

13
AI jurisdictions mapped
EU AI Act · GDPR · DORA · NIS2 · ISO 42001 · sector rules
35 M€
or 7% of global turnover
Top tier of administrative fines under the EU AI Act
98%
of organizations have employees using unsanctioned AI tools (2025 security studies)
No inventory, no owner, no traceability — direct sanction exposure
// The solution

One platform, four operational deliverables.

ACF Compliance turns the governance brief into something your DPO, your CISO and your Board can actually use.

01

Automatic AI cartography

Inventory your AI systems — internal, third-party, embedded. Detect Shadow AI before regulators or auditors do, and keep the map live as your stack evolves.

02

Multi-regulator classification

Each AI system is classified against EU AI Act, GDPR, DORA, NIS2, ISO 42001 and sector regulations across 13 jurisdictions (EU, UK, US, Canada, Brazil, Switzerland, Japan and more).

03

Documentation ready to hand over

AI Policy, DPIA, register of high-risk systems, Article 49 register, supplier clauses, vendor due diligence — generated, versioned and signed, ready for an inspection or an audit.

04

Partner law-firm network

Escalate in three clicks to an external counsel for a binding legal opinion. ACF never touches fees — the model is RIN-compatible (Captain Contrat style).

// Why ACF Compliance

What makes the module unique.

Court-grade audit trail

Every governance decision is captured in a tamper-evident hash chain with Ed25519 signatures. ACF Decision Engine (integrated) gives each action a forensic record an auditor, a regulator or a judge can read.

Narrow and deep, one platform

3 cores in depth (GDPR, AI Act, ISO 42001) + 12 transverse frameworks under construction + 13 AI jurisdictions — no need to stitch them across four tools. Classification, evidence and reporting live in one place.

Multi-jurisdiction by design

EU, UK, US, Canada, Brazil, Switzerland, Japan — and counting. Subsidiary by subsidiary, you see what applies where.

RIN-compatible model

ACF stays a software publisher. Legal advice always comes from independent law firms in our network — no conflict, no markup on fees.

// For whom

Built for the four people who own AI risk.

DPO / Data Protection Officer

Keep the AI register, the DPIA pipeline and the Article 49 evidence in one auditable workspace — and prove it on demand.

Compliance Officer

Map controls across EU AI Act, DORA, NIS2 and ISO 42001 in one classification layer. Generate evidence packs for internal audit in minutes.

CIO / CISO

Get a live view of every AI system in production, with risk levels, owners, and which regulator applies. Detect Shadow AI before incidents do.

Executive committee / Board

A quarterly Board Report you can present without rewriting it. Executive style, hard numbers, cryptographically signed.

// Board reports

Reports ready to present to your Board.

Quarterly governance reports generated from the live data — not from a hand-built deck. Each report is signed and verifiable, so directors can rely on what they read.

Quarterly, generated automatically from your live AI inventory
Cryptographically signed and verifiable end-to-end
Executive style — risk heatmap, KPIs, remediation status
Exported as PDF and DOCX, brand-ready
Board of Directors — confidential
Q1 2026 — AI Governance Report
AI systems in inventory
47
High-risk under EU AI Act
9
Open remediation actions
3
Cryptographic signature: verified
OK
// Comparison

Why AI Act-native beats ISO 42001 cross-mapping

Synthetic comparison vs three competing approaches (without naming vendors publicly).

CriterionACF ComplianceUS compliance leadersFrench GDPR specialistsConsulting + Excel
AI Act art. 5/27/50 + GPAI + FRIA hardcoded (not an ISO 42001 cross-mapping)
Independently verifiable crypto audit trail (Ed25519 + SHA-256) — third-party verifiable signature
Integrated RIN-compatible law firm network (art. 11.3/11.4)
3 cores in depth (GDPR, AI Act, ISO 42001) + 12 transverse frameworks under construction + 13 AI jurisdictions
Data sovereignty: EU hosting by default + French sovereign option (OVH/Scaleway)
Natively coveredPartial or via cross-mappingNot covered

Comparison based on vendors' public documentation (2026).

// Pricing

Choose the plan that fits your scale.

Transparent plans. Start with a free Flash diagnostic — no account required.

Pro
SME — single jurisdiction
490 €/ month
Up to 25 AI systems mapped
EU AI Act + GDPR classification
Audit trail with cryptographic signature
Quarterly Board Report
Popular
Business
Mid-market — multi-entity
1 490 €/ month
Up to 100 AI systems
3 cores in depth + 13 AI jurisdictions — multi-jurisdiction
Document generator (Policy, DPIA, Art. 49)
Partner law firms — 3-click escalation
Enterprise
Groups & regulated industries
Custom
Unlimited AI systems and subsidiaries
SSO, on-prem audit log option
Tenant-isolated cryptographic registry
Named ACF compliance liaison
Free 15-minute Flash diagnostic, no signup.
See full pricing on compliance.acfstandard.com
// Trust

Backed by a credible ecosystem.

ACF Compliance is built on the published ACF® methodology and integrates with a network of independent European law firms.

ACF® methodology

Documented governance framework — 4 founding principles, 18 sovereignty KPIs.

Independent law firms

European partner counsel for binding legal opinions when an internal answer is not enough. No conflict, no margin on fees.

Narrow and deep coverage

3 cores in depth (GDPR, AI Act, ISO 42001) + 12 transverse frameworks under construction + 13 AI jurisdictions. Our classification engine is maintained as regulators publish guidance.

European hosting

Data stays in the EU. Cryptographic registry, role-based access, audit-grade logs by default.

Start the free 15-minute diagnostic.

No account, no card. You get a Flash diagnostic of your AI exposure and the first remediation priorities.

Run the free diagnostic →
Or book a guided 30-minute demo

ACF® and ACF Compliance® are registered trademarks. ACF Decision Engine protected by an INPI-registered patent. Module published by Vincent Dorange.