Skip to content
Over Unity

AI risk and compliance

Maps obligations under regimes such as the EU AI Act and ISO 42001 onto what a business is really doing.

Why this one is hard to judge

The field is young, the certifications are new, and a confident summary of a regulation is not the same as having applied it.

What to ask for

  • Ask for a specific regulation or standard they have applied to a real project, not just read.
  • Ask how they would explain a model decision to a regulator who is not technical.
  • Ask for a risk they flagged that turned out to matter later.
  • Ask what evidence they keep so an audit does not require reconstructing history from memory.

The mistake most hirers make

Hirers assume familiarity with regulation is the same as knowing how to apply it to a specific system. Reciting the requirements is easy; deciding what evidence a particular project actually needs is the hard part. A compliance hire who cannot translate rules into a checklist for engineers will be ignored by them.

What good looks like after 90 days

A working checklist that engineers actually use, not a document that sits unread. One real risk identified and addressed before it caused a problem. Evidence being collected as the work happens, not reconstructed later for an audit.

How we assess it

Against a rubric that is published in full, on evidence the practitioner supplies and a reviewer checks. Where something has not been verified, the profile says so.

Find someoneRead the rubric

Over Unity makes introductions between hirers and independent specialists. It is not a party to any engagement, does not hold or transfer payments, and does not determine employment status. Specialists are never charged a fee.