Process transparency. How we conduct impact assessments covering GDPR, AI Act and NIS2 simultaneously.
Audiqcer's methodology is unique in the Portuguese market: it combines data protection, fundamental rights and cybersecurity impact assessments in a single structured process. This integrated approach eliminates redundancies, reduces total time and cost, and ensures no obligation is overlooked at the intersection of different regulations.
Organisation mapping, information systems, data processing, AI systems and ICT infrastructure. Preliminary identification of applicable regulatory obligations.
Detailed analysis of applicable regulations (GDPR, AI Act, NIS2, DORA, CSRD) and identification of mandatory and recommended impact assessments.
Stakeholder interviews, document analysis, asset and process inventory. Structured collection of all information needed for assessments.
Application of risk assessment methodologies appropriate to each type: likelihood and severity (DPIA), fundamental rights impact (FRIA), ICT risk (NIS2/DORA).
Definition of mitigation measures, technical and organisational controls, and prioritised action plan to reduce residual risk to acceptable levels.
Production of formal reports (DPIA, FRIA, ICT risk assessment), risk matrix, action plan and supervisory authority documentation.
Establishment of periodic review cycle, monitoring indicators and update procedure when significant changes occur.
The first step is always a diagnosis. No commitment, no cost.
Request a free assessment or ask us about regulatory impact assessments.