AI system inventory
A working register of the AI tools, vendors, owners, users, purposes and affected people across your organisation.
AI compliance readiness · Ireland
Practical, engineering-led support to help Irish businesses understand their EU AI Act and GDPR obligations—and turn them into controls that work in the real world.
Why now
Most organisations already use AI—in chatbots, productivity tools, recruitment, customer service or internal automation. The challenge is knowing what is in use, where data goes, who is responsible and what evidence you need.
Ireland now operates a distributed EU AI Act enforcement model coordinated by the AI Office of Ireland. Transparency requirements and AI-literacy supervision are already in effect.
What you receive
A working register of the AI tools, vendors, owners, users, purposes and affected people across your organisation.
Identify whether you are acting as a provider or deployer and map each use case to the relevant AI Act risk category.
Trace personal and sensitive data, review processors and surface retention, access, transfer and security concerns.
Document decisions, controls, ownership, staff literacy, human oversight and the actions needed to close material gaps.
The process
This is not a box-ticking document generator. We inspect how your AI actually works, how people use it and where evidence is missing.
Stakeholder workshop, use-case discovery and document collection.
System inventory, data flows, vendors, owners and affected people.
Role, risk, transparency, literacy, GDPR and technical-control review.
Prioritised remediation roadmap, evidence pack and management briefing.
Ways to start
AI Readiness Check
Compliance Readiness Sprint
Managed AI Governance
Common questions
It can. If your business uses AI systems—including ChatGPT, Microsoft Copilot, AI-powered CRM features, automated CV screening or chatbots—you may be a “deployer” under the Act. Your precise obligations depend on the system, its purpose, your role and the level of risk. Most ordinary SME uses are not high-risk, but you should still inventory your AI systems, assess how they are used and retain proportionate evidence.
Even familiar AI tools create governance questions around staff use, personal data, confidentiality, accuracy and AI literacy. For example, entering client data into an unapproved tool may create GDPR and contractual risks. An AI inventory, acceptable-use policy and proportionate staff guidance provide a sensible minimum baseline.
Yes. Discovery, assessment, document review, delivery of your readiness pack and ongoing support can all be completed through video calls and secure shared documents. The service is available to organisations anywhere in Ireland.
A typical engagement takes one to two weeks from kickoff to delivery. The main variables are the size of the organisation, the number of AI use cases and how quickly your team can provide accurate information about its tools, processes and data use.
Your IT provider typically manages infrastructure, devices, security and support. This service focuses specifically on AI governance and technical compliance readiness: identifying which rules may be relevant, inventorying AI use, classifying risks, mapping data and creating proportionate policies, controls and evidence. It complements good IT support rather than replacing it.
A solicitor, DPO or accountant may provide valuable advice within their expertise. This service adds hands-on technical analysis of how AI systems work, how they are used, where data flows and which operational controls are in place. Where legal interpretation is needed, we can work alongside your existing adviser.
No. SMT Data Analytics provides technical and operational readiness support, not legal advice, regulatory certification or a guarantee of compliance. We can work alongside your solicitor or DPO.
Yes. Unlike a document-only assessment, the service can extend into architecture, access controls, logging, human-review workflows and secure Azure implementation.
Start with a confidential conversation
Technical and operational readiness support. Not legal advice or regulatory certification.