Scope: This practical guide supports technical and operational readiness. It is not legal advice, regulatory certification or a complete statement of every obligation that may apply to a particular AI system.

It means being able to show your work

The person responsible for compliance should be able to open one organised evidence pack and explain, step by step:

  1. These are all the AI systems we know about.
  2. This is what each system is used for.
  3. This is the information each system receives.
  4. This is how we classified the risks.
  5. These are the rules our employees follow.
  6. These are the people responsible for reviewing important AI decisions.
  7. These are our vendor checks, contracts and data-protection records.
  8. These are the problems we discovered.
  9. These are the actions we took.
  10. This is when everything will be reviewed again.

The key distinction

A policy says what should happen. Evidence shows what did happen.

A defensible system does not guarantee that a regulator will agree with every decision. It shows that the organisation took reasonable, structured and documented steps rather than allowing AI to be used without ownership or control.

GDPR Article 24 captures this directly: an organisation must implement appropriate measures and be able to demonstrate that its processing complies with GDPR. The EU AI Act then adds obligations according to the organisation's role and the risk of each AI system.

Who could audit or investigate the company?

An audit does not necessarily mean that an AI regulator unexpectedly arrives at the office. A review could begin because of:

Ireland uses a distributed enforcement model rather than having one regulator inspect every type of AI. Depending on the use of AI, the relevant body may include the Data Protection Commission, Workplace Relations Commission, Central Bank of Ireland, Coimisiún na Meán, Competition and Consumer Protection Commission, Health Products Regulatory Authority or another sector regulator. The AI Office of Ireland coordinates implementation and acts as the national contact point. See the Irish Government's list of AI Act authorities ↗ and the AI Office of Ireland's national competent authorities ↗.

The Data Protection Commission can conduct audits and investigations and require access to information. It can also issue warnings, reprimands, corrective orders and administrative fines. See the DPC's explanation of its enforcement powers ↗.

The practical minimum for a 50–200 person company

Headcount alone does not decide the legal obligations. What matters is what the AI does, what data it uses, who is affected and whether the organisation is a provider or deployer. For a company mainly using third-party AI products, this is a practical operating baseline.

1. A named AI governance structure

Name a senior accountable owner and an operational compliance owner. Involve IT, security, HR, procurement and data protection where relevant. Document who can approve, restrict or stop an AI system and review open risks regularly.

Evidence: governance chart, responsibility matrix, approval process, meeting records and management sign-off.

Legal connection: AI Act Article 4 addresses AI literacy; Article 26 requires competent human oversight for high-risk systems; GDPR Article 24 requires appropriate organisational measures and evidence.

2. A complete AI Systems Register

Keep one list of official tools, trials, informal or shadow AI and AI features built into CRM, HR, recruitment, finance and productivity software. For each use case record its purpose, owner, users, affected people, data, vendor, approval status, risk outcome and review date.

Evidence: master register, department survey, shadow-AI findings and approval or rejection records.

Legal connection: there is no single general AI Act clause saying every deployer must keep an inventory. The register is the practical mechanism that enables the company to identify and demonstrate which obligations under Articles 4, 5, 6, 26 and 50 apply, and to connect personal-data uses to GDPR Article 30.

3. Risk classification for every use case

Screen each use as prohibited, potentially high-risk, subject to transparency requirements, lower risk, outside the AI Act definition or uncertain and requiring specialist review. Assess the actual purpose—not just the product name.

Evidence: completed classification assessment, written conclusion, reasons, source material and approval.

Legal connection: AI Act Article 5 covers prohibited practices; Article 6 and Annex III address high-risk classification; Article 50 addresses specified transparency duties.

4. Prohibited-practice controls

Check proposed and existing uses for prohibited manipulation, exploitation, certain social scoring and relevant prohibited biometric practices. Repeat the assessment when the purpose or system changes.

Evidence: prohibited-use assessment, procurement questions, rejected-use records and escalation procedure.

Legal connection: AI Act Article 5. These rules have applied since 2 February 2025.

5. An AI Acceptable Use Policy

Give employees plain rules covering approved tools, confidential and personal information, human verification, automated decisions, copyright, transparency, shadow AI and incident reporting. Communicate the policy and record acknowledgement.

Evidence: approved policy, version history, staff acknowledgements and communications.

Legal connection: AI Act Articles 4 and 26; GDPR Articles 24 and 32.

6. Role-based AI literacy

Give all users baseline training, then provide additional training for roles such as HR, management, marketing, technical configuration and human oversight. Training should match the systems and risks people actually encounter.

Evidence: training material, attendance, knowledge checks, role-specific plans and refresher dates.

Legal connection: AI Act Article 4 requires providers and deployers to support an appropriate level of AI literacy; Article 26 requires appropriate competence, training and authority for high-risk oversight.

7. GDPR and RoPA documentation

Where an AI system processes personal information, link it to the organisation's Record of Processing Activities. Record the business purpose, categories of people and data, lawful basis, controller or processor status, sources, recipients, vendors, transfers, retention and security measures.

Evidence: RoPA, AI-to-RoPA mapping, privacy notices, lawful-basis assessment, DPIA screening and completed DPIAs where required.

Legal connection: GDPR Article 5(2) establishes accountability; Articles 13–14 address privacy information; Article 24 requires demonstrable measures; Article 30 covers the RoPA; Article 35 covers DPIAs for processing likely to create high risk.

8. Vendor and contract checks

Investigate what the vendor receives, whether business data trains models, storage, deletion, subprocessors, hosting, international transfers, security, incident terms, audit rights and exit arrangements.

Evidence: vendor assessment, contract, Data Processing Agreement, transfer mechanism, subprocessor list, security material and approval decision.

Legal connection: GDPR Article 28 covers processor arrangements and Articles 44–49 cover international transfers. AI Act Articles 25 and 26 address value-chain responsibilities and deployer use of high-risk systems.

9. Transparency notices

Use the appropriate chatbot notice, candidate or employee information, privacy wording and AI-generated content label. Tell people about relevant AI-assisted decisions where required.

Evidence: chatbot wording, applicant or employee notices, website disclosures, privacy notices and content-labelling procedure.

Legal connection: AI Act Articles 26 and 50; GDPR Articles 12–14.

10. Meaningful human oversight

A real reviewer must be able to understand, question, reject or override an important AI recommendation. A person who automatically accepts every recommendation is not providing meaningful oversight.

Evidence: named reviewers, oversight procedure, decision and override logs, training and escalation records.

Legal connection: AI Act Articles 14 and 26; GDPR Article 22 where certain solely automated decisions produce legal or similarly significant effects.

11. Monitoring, change control and incident response

Record harmful or incorrect output, bias concerns, personal-data leaks, security events, vendor changes, new AI features, corrective action and decisions to suspend use.

Evidence: AI incident register, breach procedure, system change log, monitoring results and corrective actions.

Legal connection: AI Act Article 26; GDPR Articles 32–34.

12. One controlled compliance evidence pack

Bring the records together under one index. The law does not mandate this exact folder structure; it is a practical way to control and produce the evidence when it is needed.

00 — Compliance index and current status
01 — Governance and responsibilities
02 — AI Systems Register
03 — Risk classifications
04 — RoPA and GDPR assessments
05 — Vendor contracts and assessments
06 — Policies and procedures
07 — Training and AI literacy
08 — Transparency notices
09 — Human-oversight records
10 — DPIAs and impact assessments
11 — Incidents and corrective actions
12 — Reviews, approvals and change history

The pack can live in SharePoint, Microsoft Teams, Google Drive or a governance platform. It needs controlled access, version history, named owners and review dates.

What the company is really buying

An organised chain of evidence.

The reviewer should be able to move from an AI system, to its purpose and risk, to the controls applied, to proof that those controls actually operate.

What an AI compliance audit could look like

Greenway Services is a fictional Irish company with 120 employees. It uses an AI-enabled recruitment platform that reviews CVs and gives applicants a suitability score. A manager is expected to review the score before deciding who receives an interview.

An applicant is rejected. They request an explanation and later complain that the system may have treated older applicants unfairly. Because this concerns employment and personal data, the matter could involve the Workplace Relations Commission and the Data Protection Commission.

The company is asked to explain which system was used, what it did, how it was classified, what personal data it processed, what applicants were told, who reviewed the recommendation, whether that reviewer was trained, whether a DPIA was completed and whether applicant data left the EEA.

The compliance manager opens the evidence pack. They produce the AI Systems Register, the risk-classification record, the related RoPA entry and DPIA, the vendor contract and transfer information, the applicant notice, the training record and the human-oversight procedure.

The records reveal a weakness: the recruitment manager accepted the AI score without recording any independent reasoning. The company cannot simply hide that problem. Instead, it shows when the issue was identified, the enhanced training introduced and the new review form requiring an independent explanation.

The regulator then examines both whether the system complied with the applicable law and whether the documented process matches what happened in practice.

The evidence pack does not make Greenway immune from enforcement. It lets the company answer accurately, show its reasoning, identify shortcomings and demonstrate corrective action.

Without that evidence, the answer would be: “We think HR reviewed it, but we do not know exactly how the system worked, we cannot find the vendor documents and we did not record why the candidate was rejected.”

That difference is what a defensible compliance system means.

Official sources: EU AI Act ↗ · GDPR ↗ · Irish DPC RoPA guidance ↗ · AI Office of Ireland authorities ↗