[{"data":1,"prerenderedAt":321},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"regulation-en-ai-act":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":40,"entities":268,"extension":270,"faq":271,"keywords":290,"meta":296,"navigation":297,"ogImage":298,"path":39,"persona":299,"publishedAt":298,"regulation":300,"relatedFeatures":301,"relatedPages":303,"seo":306,"shortTitle":38,"slug":300,"sources":307,"stem":317,"tldr":318,"updatedAt":319,"__hash__":320},"regulations_en\u002Fen\u002Fregulations\u002Fai-act.md","AI Act: AI System Register and FRIA | CISAPP","CISAPP",{"type":108,"value":109,"toc":261},"minimark",[110,115,128,147,151,222,226,229,255],[111,112,114],"h2",{"id":113},"what-does-the-ai-act-change-for-a-company-using-ai","What does the AI Act change for a company using AI?",[116,117,118,122,123,127],"p",{},[119,120,121],"strong",{},"The AI Act is Regulation (EU) 2024\u002F1689 governing artificial intelligence in the Union, in force since 1 August 2024 and applicable in stages."," For most organisations the role at stake is that of ",[124,125,126],"em",{},"deployer",": they buy AI systems rather than build them.",[129,130,131],"key-takeaways",{},[132,133,134,138,141,144],"ul",{},[135,136,137],"li",{},"Risk-level classification drives the obligations: prohibited, high risk, transparency, minimal risk.",[135,139,140],{},"Providers and deployers carry distinct obligations; being reclassified changes the whole regime.",[135,142,143],{},"The FRIA (Article 27) applies to certain deployers of high-risk systems.",[135,145,146],{},"The evidence a deployer needs is produced by the provider: this is a third-party management topic.",[111,148,150],{"id":149},"which-risk-categories-with-what-consequences","Which risk categories, with what consequences?",[152,153,155],"comparison-table",{"caption":154},"AI system categories under the AI Act",[156,157,158,174],"table",{},[159,160,161],"thead",{},[162,163,164,168,171],"tr",{},[165,166,167],"th",{},"Category",[165,169,170],{},"Examples cited by the regulation",[165,172,173],{},"Consequence for the deployer",[175,176,177,189,200,211],"tbody",{},[162,178,179,183,186],{},[180,181,182],"td",{},"Prohibited practices",[180,184,185],{},"Social scoring, exploitation of vulnerabilities",[180,187,188],{},"Use banned",[162,190,191,194,197],{},[180,192,193],{},"High risk",[180,195,196],{},"Employment and recruitment, access to essential services, critical infrastructure",[180,198,199],{},"Enhanced obligations, FRIA for certain bodies",[162,201,202,205,208],{},[180,203,204],{},"Limited risk",[180,206,207],{},"Systems interacting with people, generated content",[180,209,210],{},"Transparency obligations",[162,212,213,216,219],{},[180,214,215],{},"Minimal risk",[180,217,218],{},"Other uses",[180,220,221],{},"No specific obligation",[111,223,225],{"id":224},"how-to-prepare-compliance-on-the-vendor-side","How to prepare compliance on the vendor side",[116,227,228],{},"Three actions depend on no deadline and can be taken now:",[230,231,232,238,244],"ol",{},[135,233,234,237],{},[119,235,236],{},"Inventory the AI systems actually in use",", including AI features added by your existing SaaS — the main source of blind spots.",[135,239,240,243],{},[119,241,242],{},"Attach each system to its provider"," and to the documentation obtained: stated classification, instructions for use, logging commitments.",[135,245,246,254],{},[119,247,248,249],{},"Fold the question into the ",[250,251,253],"a",{"href":252},"\u002Fen\u002Fglossary\u002Fsecurity-questionnaire","security questionnaire"," sent to third parties, rather than opening a parallel process.",[116,256,257,258,260],{},"As with NIS2, DORA, ISO 27001 and GDPR, the AI Act module will join your existing compliance dashboards — no new tool to deploy. See also the ",[250,259,46],{"href":47}," page.",{"title":262,"searchDepth":263,"depth":263,"links":264},"",2,[265,266,267],{"id":113,"depth":263,"text":114},{"id":149,"depth":263,"text":150},{"id":224,"depth":263,"text":225},[269],"TPRM","md",[272,275,278,281,284,287],{"q":273,"a":274},"What is the AI Act?","The AI Act is Regulation (EU) 2024\u002F1689, the first horizontal framework governing artificial intelligence in the Union. It classifies systems by risk level — prohibited practices, high risk, limited risk subject to transparency, minimal risk — and places distinct obligations on providers and on deployers of those systems.",{"q":276,"a":277},"What is the application timeline?","The regulation entered into force on 1 August 2024 and applies in the stages set out in Article 113: first the prohibited practices and AI literacy obligations, then the obligations on general-purpose AI models, and finally the obligations on high-risk systems. The exact deadlines applicable to your organisation depend on the category of your systems; refer to the text published in the Official Journal of the European Union.",{"q":279,"a":280},"What is the difference between a provider and a deployer?","A provider develops an AI system or places it on the market under its own name; a deployer uses it under its own authority in a professional context. A company buying an AI solution is in principle a deployer — unless it substantially modifies it or markets it under its own brand, which can transfer the provider obligations to it.",{"q":282,"a":283},"What is a FRIA?","The FRIA (Fundamental Rights Impact Assessment), set out in Article 27, is the assessment certain deployers of high-risk systems must carry out before putting a system into use: description of the uses, categories of persons affected, risks of harm, human oversight measures and redress arrangements.",{"q":285,"a":286},"Why is the AI Act a third-party risk topic?","Because most AI systems used in companies are bought, not built. The information a deployer needs for compliance — system classification, technical documentation, instructions for use, logging — comes from the provider, and must therefore be obtained and retained like any other third-party compliance evidence.",{"q":288,"a":289},"Is the CISAPP AI Act module available today?","The AI Act module is on our product roadmap. It will build on the same regulatory framework foundation as NIS2, DORA, ISO 27001 and GDPR, with an AI system register, the FRIA and an article-level mapping of obligations.",[291,292,293,294,295],"AI Act compliance","AI system register","FRIA","AI Act for business","EU AI regulation",{},true,null,"entreprise","ai-act",[302],"Regulatory frameworks",[304,305],"gdpr","iso-27001",{"title":105,"description":40},[308,313],{"label":309,"url":310,"publisher":311,"date":312},"Regulation (EU) 2024\u002F1689 laying down harmonised rules on artificial intelligence","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002Foj","EUR-Lex","2024-07-12",{"label":314,"url":315,"publisher":316},"AI Act — European Commission page","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Fpolicies\u002Fregulatory-framework-ai","European Commission","en\u002Fregulations\u002Fai-act","The AI Act (Regulation (EU) 2024\u002F1689) entered into force on 1 August 2024 and applies in stages depending on the risk level of the AI system. It places a set of obligations on deployers of high-risk systems including, for certain bodies, a fundamental rights impact assessment (FRIA, Article 27). Most AI systems used in companies come from vendors, so compliance runs through the contractual relationship.","2026-08-16","5Ot90Iey4I-_TF5Kl_pCMeKwS4IMGU6Li4NKSC9-1NI",1791391138351]