The board can only demonstrate that it is in control once there is a dossier: obligations with an owner, evidence in its place, gaps in order of risk. That dossier is the endpoint of the Compliance Check, not the starting point of an advisory process. What you do with that dossier afterward is a choice with three routes. The order below is not arbitrary: the first route is the tool alone, without anyone else added.
You receive the complete dossier from the tool: the applicability scan with national headings, the control matrix with owner, control and frequency, the remediation roadmap in risk order, the evidence vault with an audit-ready trail from report line to source to evidence, and the quarterly board report. The scanner subscription keeps the obligations matrix current and flags what changes.
This route fits if there is someone internally who can complete the gap questionnaire, supply documents, and discuss the roadmap with the owners the matrix designates. You must be able to judge yourself whether an answer in the questionnaire is correct, and be able to push through yourself that a gap is actually picked up. The tool structures and signals; it does not fill in policy and does not hold a conversation with a supplier.
This route does not fit if there is no one with the time or the mandate to keep the matrix alive, or if the company structure is so complex that the questionnaire itself already gets stuck on unclarity about who is responsible for what. Read what it is and how it works to see whether the scope matches your situation before starting on this route.
You receive the same dossier as in route 1, with support from a partner on the two points that rely most on human work: the policy-vs-practice investigation, where written policy and daily execution can diverge, and the training of the board so that the report is also understood and used, not just received.
This route fits if the tool already factually points to the right gaps and risks, but the translation to practice on the work floor or to the board itself turns out to be harder than the questionnaire alone can resolve. That happens more often at companies with multiple locations or countries, where policy is written centrally but execution differs per location. You still designate the owners yourself and monitor the roadmap; the partner supports the investigation and the training, not the taking over of responsibility.
This route does not fit if there is a need for a party to take over the entire process: that is no longer a partially guided engagement, but something for the third route. This route also does not fit if the dossier is not yet complete; first the scan, only then the question of where support is needed.
The entire compliance process is placed with the partner, with the Compliance Check as the baseline measurement. The report from the tool is the starting point the partner builds on: the applicability scan and the control matrix form the basis, the partner carries the process forward.
This route fits if there is no internal capacity to maintain the dossier, or if the scale and complexity of the obligations structurally demand more than a quarterly cycle with a tool can carry. It also fits if the governance choice has been made to place compliance as an ongoing external process, with the baseline measurement as a fixed reference point to return to.
This route does not fit if the only goal is to quickly have a report: route 1 already delivers that, without a partner. Whoever reaches for outsourcing right away without first having run the scan is buying an advisory process with a tool in front of it, and that is not what is being offered here. The partner stands after the report, outside the tool.
In none of the three routes is someone from us part of the process itself. Route 1 is the tool alone. Route 2 adds a partner on two defined points. Route 3 places the entire follow-up with the partner, with the report as the starting point. In all three, the tool remains the dossier: the place where the obligations matrix, the gaps, the owners and the evidence come together, regardless of who works with it further.
The tool itself is currently in waitlist mode; there is not yet an active Compliance Check to start one of these routes with. Whoever signs up will be kept informed once that changes. Whoever wants to read in the meantime exactly how the scan, the matrix and the roadmap are built, finds the background in the knowledge base.
Whichever route is chosen, the dossier says nothing yet about the hours, tasks and systems needed to actually close the gaps. Whoever wants to translate that into capacity and deployment finds, at the work scan of [FTE to AI](https://ftetoai.com), the follow-up to this report.
Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.