Skip to content
TECHNOMATON | Docs SAI Certified Trainers

Directives

Internal compliance framework and policies for the AI Act, NIS2, and GDPR.


Directives contents

DirectiveDescription
Governance & ResponsibilitiesGovernance structure and roles
AI GovernanceGovernance of AI systems
Data ProtectionGDPR and personal data protection
Security GovernanceNIS2 and cybersecurity
Incident ManagementIncident response
Audit & MonitoringAudit and monitoring
Technological SovereigntyData and technological sovereignty

Executive Summary

This directive defines how the organization responsibly uses, develops, and deploys artificial intelligence and processes personal data in compliance with EU legislation:

  • AI Act (EU 2024/1689): Risk-based regulation of AI systems
  • NIS2 (Cybersecurity Act): Information security
  • GDPR (EU 2016/679): Personal data protection

Our policy: To provide stakeholders (customers, employees, regulators) with assurance that AI and data are managed ethically, securely, and in compliance with the law.


Governance overview

Governance Cadence

FrequencyMeetingParticipants
MonthlyCompliance syncCTO, CISO, DPO
QuarterlyBoard reviewC-level, Board
AnnuallyExternal auditAll + Auditor

Document version

VersionDateChanges
1.01 January 2026Initial release

Next review: Q1 2027


Next steps

  1. Governance & Responsibilities
  2. AI Governance
  3. Data Protection
  4. Security Governance