Skip to content
Solution Accelerator

ComplyIQ AI Transparency Assessment

ComplyIQ
Proof without access.

Your organization has already made public claims about its AI — in a privacy notice, a product page, a chatbot disclaimer. ComplyIQ tests those claims against documentable evidence and tells you where they don't hold up. No tenant connection. No Graph permissions. No admin consent.

Zero tenant access Human-reviewed before delivery Runs on Microsoft Azure
01 · The problem

Your AI disclosures are public. Your evidence isn't.

Regulators, customers, and counterparties read the same pages your prospects do. The exposure isn't usually the AI — it's the distance between what the website says and what the organization can actually show.

Claims nobody owns

An AI notice written by marketing in 2024, a chatbot shipped by product in 2025, a vendor clause signed by procurement. No single person can tell you whether they still agree with each other.

Obligations that arrive by reach

EU AI Act Article 50 and GDPR attach to who you serve, not where you're incorporated. Most US organizations discover the exposure through a customer questionnaire, not a lawyer.

Assessments that need the keys

Most compliance tooling wants admin consent before it can say anything. That puts a security review, a procurement cycle, and a nervous CISO between you and your first answer.

02 · The solution

Assess the claims, not the tenant.

Everything a regulator or a customer can see about your AI is already public. ComplyIQ works from that same surface — reconciling what you published against what you can evidence — so the assessment needs nothing from your environment to be useful.

No access to grant

No tenant connection, no Graph scopes, no admin consent. There is no security review standing between you and your first finding, because there is nothing to review.

Every finding carries its evidence

Each result cites the source document and version, or a dated, hashed snapshot of the page it came from. A later edit to your site cannot quietly change the record a finding rests on.

Declared, reconciled against published

Most exposure isn't a missing policy — it's a policy that no longer matches the website. ComplyIQ compares the two lanes directly and reports where they diverge.

03 · How it works

Four steps. No permissions required.

ComplyIQ runs entirely on evidence you hand over or authorize. Nothing executes inside your environment, so there is nothing for your security team to approve before you start.

01

Declare the facts

A structured intake captures your footprint, your AI systems, and your data. You never pick regulations — the classification engine identifies the candidate obligations and shows the trigger that fired, for you to confirm with counsel.

02

Authorize the evidence

Upload your policies and list the public pages we may review. Every document is versioned; every page retrieval is snapshotted and hashed so the record can't drift.

03

Reconcile and assess

AI-assisted analysis compares your declared position against your published position, obligation by obligation. Every finding carries its evidence. A human reviews before anything ships.

04

Read out and remediate

A one-hour expert readout walks your team through findings, disputes, and sequencing — then hands you a 90-day roadmap ordered by exposure, not alphabet.

04 · Actionable outputs

Three artifacts your counsel can act on.

Not a score and not a dashboard. Each output names a gap, cites the evidence behind it, and states what would close it.

Report of Findings

The engagement deliverable. Met, partial, or gap against each candidate obligation — with the evidence, the retrieval date, and the trigger that made the obligation apply. Written to be handed to counsel without translation.

90-day remediation roadmap

Sequenced by exposure and effort, with an owner-shaped task for each gap. Every item names the artifact that would close it, so progress is verifiable rather than asserted.

Expert readout

A facilitated hour with the people who ran the assessment. Challenge findings, mark items out of scope, and leave with an agreed sequence — not a PDF nobody opens.

05 · Coverage

You declare the facts. The engine returns what they trigger.

ComplyIQ assesses obligations by theme, across four bodies of law. Every result is returned as a candidate with the trigger that fired, for your counsel to confirm.

Obligation theme
EU / UK
US federal
US state
Industry
Transparency & disclosure
Synthetic media & provenance
Automated decisions about people
Biometrics & sensitive data
Employment & hiring
Minors & protected groups
Public claims & investor disclosure
In the catalog — hover for the statutes Not applicable in this body of law

Industry obligations surface from the sector and systems you declare, and appear in the Report of Findings only where the assessment evidences them. EU AI Act Article 50 is the baseline; extended frameworks are added by scope band. The catalog grows as regimes take effect.

06 · Get started

Find out what your website already promised.

A scoped assessment starts with a structured intake and a list of URLs. No security review, no admin consent, no tenant connection — you can begin this afternoon. Start free if you want to see the shape of it first, or pick the scope that fits.

Priced by what we assess, not by how many people you have. Every package is a fixed fee scoped on five things: domains, documents, frameworks, interviews, and cadence.

ComplyIQ Transparency Scan

See what your public AI disclosures already signal.

Automated public-surface check. No intake. No obligations named.

Free

One domain · one scan per 30 days

  • Six transparency signals — detected or not detected
  • Homepage, privacy, terms, and AI disclosure pages
  • Work email must match the scanned domain
  • Results shown on screen and sent by email
  • No obligations named; paid assessment required

See whether your public surface says anything about your AI at all — in about five minutes.

Automated signal check only. Not human-reviewed. Not an assessment.

Scan my site
ComplyIQ Baseline

Know where you stand on AI transparency.

A fixed-scope, human-reviewed assessment for organizations that need a defensible first read quickly.

$5,000

Fixed fee · one-time · launch pricing
One domain included · additional domains scoped separately

  • Full Candidate Applicability Map — every candidate regime triggered by your declared facts
  • Article 50 + GDPR transparency assessed in depth
  • Public-surface scan + declared-document review
  • Up to 10 declared documents
  • Report of Findings with evidence citations
  • 90-Day Remediation Roadmap
  • One-hour expert readout
  • Optional independent legal review by outside counsel — engaged and billed directly by the firm

Know what your public AI transparency posture looks like — and what to fix first.

Assessment output, not legal advice. Counsel review recommended.

Start Baseline
ComplyIQ Cadence

Stay current as your AI footprint changes.

A quarterly review program that maintains a dated, evidence-backed record of good-faith governance effort.

$7,500 / quarter

or $24,000 annually prepaid
Baseline credit available if started within 90 days

  • Quarterly review of your agreed scope
  • Refreshed Candidate Applicability Map
  • Extended catalog assessed in depth, as scoped
  • Change detection against prior snapshots
  • Open / closed gap tracking
  • Remediation progress tracking
  • Quarterly expert readout
  • Maintained defensibility record
  • Optional independent legal review by outside counsel — engaged and billed directly by the firm

Maintain a current, evidence-backed record you can discuss with leadership, buyers, regulators, or counsel.

Designed for demonstrable due diligence. Does not guarantee compliance or legal protection.

Start Cadence
ComplyIQ Spectrum

Scope the full picture across regimes, systems, and stakeholders.

For regulated, multi-state, multi-national, or complex organizations that need deeper evidence review and executive-ready reporting.

$2,500 scoping retainer

The Spectrum Scope Session helps define the right engagement before you commit. Through a focused working session, we review your AI footprint, stakeholders, jurisdictions, systems, and objectives, then deliver a written scope memo and recommended engagement path. Fully credited toward your Spectrum engagement within 45 days.

The Spectrum engagement includes

  • Domains, documents, systems, and frameworks sized to your footprint
  • Full Candidate Applicability Map
  • Extended catalog assessed in depth — US federal, state, sector, EU and GDPR as scoped
  • Provider and deployer role analysis
  • 6–8 stakeholder interviews
  • Per-system findings across your AI inventory
  • Executive and operational reporting
  • Report of Findings and remediation roadmap
  • Optional independent legal review by outside counsel — engaged and billed directly by the firm

Build a board-ready view of your AI compliance exposure and remediation path.

The scope memo is a planning document — not an assessment, a Report of Findings, or legal advice.

Book a Scope Session
Get started

Start with what your website already says.

A domain and your work email is everything we need to run the complimentary scan. No admin consent, no security review, no tenant connection — about five minutes.