Felix Schaller / Technical AI Advisory
AI Readiness
EU AI Act · ISO 42001 · NIST AI RMF

Check your AI Act readiness in minutes. Then see the order to fix it.


Tick what is already true for your organization and get a live readiness read against the EU AI Act, with a personalized result by email. ISO 42001 and NIST AI RMF are assessed one level deeper, as target profiles in the AI Maturity Matrix.

Standards covered EU AI Act here as an interactive checklist. ISO 42001 and NIST AI RMF in the AI Maturity Matrix, with dependencies and a roadmap.
Level 1
EU AI Act
This checklist
Legal obligation. Interactive self-check, right here.
Level 2
ISO 42001
Certifiable AI management system. Assessed as a target profile.
Level 2
NIST AI RMF
Govern, Map, Measure, Manage. Current vs target profile.
Level 1 · Simple

Readiness checklist

Interactive, instant. Where you stand against the EU AI Act, right now.

Level 2 · Advanced

AI Maturity Matrix

The pro tool. ISO 42001 and NIST AI RMF as target profiles, with dependencies and an ordered roadmap.

EU AI Act readiness self-check

Tick each statement that is already true for your organization. Your score updates live. This is a structured snapshot, not legal advice.

Scope and classification 0 / 5

  • We have inventoried every AI system we build, deploy or embed.
  • Each system is classified by EU AI Act risk tier (prohibited, high-risk, limited, minimal).
  • We have checked our use cases against the Annex III high-risk list.
  • We know our role per system: provider, deployer, or both.
  • We have screened for prohibited practices and removed them.

High-risk provider obligations 0 / 7

  • A risk management system runs across the AI lifecycle.
  • Data governance covers training, validation and test data quality.
  • Technical documentation is maintained and current.
  • The system produces logs for traceability.
  • Human oversight is designed so a person can intervene and override.
  • Accuracy, robustness and cybersecurity targets are set and tested.
  • A quality management system backs the above.

GPAI and transparency 0 / 4

  • If we use a general-purpose model, we hold its documentation.
  • Users are informed when they interact with an AI system.
  • AI-generated content is marked where required (Art. 50).
  • Deployer transparency duties are assigned and met.

Governance and accountability 0 / 4

  • A named owner is accountable for AI compliance.
  • Staff have baseline AI literacy for their role.
  • A conformity path (self-assessment or notified body) is understood.
  • Post-market monitoring and incident reporting are in place.

Want a copy in your inbox? Optional

Your full result is right above, free and complete, no email required. If you would like it as an email with the EU AI Act checklist attached, add your details. This is not a sales funnel: you get your result, no newsletter, no automated sequence, no reselling of your data.

Why a checklist is only the start

A checklist shows you where you stand. It cannot tell you the order to fix it.

You get a snapshot: a pile of ticked and unticked boxes. But readiness capabilities depend on each other. Some gaps are blocked by a missing prerequisite, so working them first is wasted effort. Generic frameworks like CMMI or SPICE do not help here, they are too generic and too heavy.

The real value is not a single score. It is structuring the complexity and showing an ordered roadmap of manageable next steps toward your target, where every step sits above the prerequisites it depends on. That is what a formal focus area maturity model does, and it is where ISO 42001 and NIST AI RMF are assessed as target profiles.

A flat checklist gives you

  • How many boxes are ticked
  • A rough band: exposed to ready
  • No sense of what blocks what
  • No order, no prerequisites, no roadmap

The maturity matrix adds

  • Current profile vs. target, per focus area
  • Prerequisites and blockers made visible
  • A dependency ordered roadmap to the goal
  • ISO 42001 and NIST AI RMF as target profiles
AI maturity matrix in target mode showing gaps and blockers
Target vs. today. Green is your target profile, yellow are gaps, red are steps blocked by a missing prerequisite. A checklist shows none of this.
Dependency ordered roadmap to target
The ordered roadmap. The same gaps, sorted by dependency, prerequisites flagged. The output a checklist cannot produce.
Recommended packages, diagnosis to prescription
Diagnosis to prescription. The tool maps the open steps onto concrete engagements, most impactful first.

Ready to see your own dependencies, and to assess ISO 42001 and NIST AI RMF, not just your box count?

Open the AI Maturity Matrix →

Frequently asked

Does this cover the EU AI Act?

Yes. The interactive checklist assesses your readiness against the EU AI Act: classification and scope, high-risk provider obligations, GPAI and transparency, and governance and accountability.

Can I assess ISO 42001 and NIST AI RMF as well?

Yes. ISO/IEC 42001 and the NIST AI Risk Management Framework are assessed as target profiles in the AI Maturity Matrix. Because both are maturity and profile shaped, the matrix adds the dependencies and the ordered roadmap that a flat checklist cannot provide.

What do I get after the check?

A personalized readiness result by email: your score, band, a per-area breakdown and your top open items, plus the EU AI Act readiness checklist for reference.

Felix Schaller · AI Strategy, Safety and Technical Due Diligence · EU AI Act, ISO 42001 and NIST AI RMF readiness
felixschaller.com · Grafing bei München · Dubai DIFC

This check is informational and does not constitute legal or certification advice. It references the EU AI Act (Regulation (EU) 2024/1689), ISO/IEC 42001:2023 and the NIST AI RMF as understood in 2026. This page sets no tracking cookies; only aggregate, non personal visit counts are recorded.