AI Regulatory Compliance Risk Register
Which of your AI use cases could you actually defend in a regulatory inspection today?
The AI Regulatory Compliance Risk Register (v1.2) is a Microsoft Excel workbook produced by Viksya for AI governance leads, risk functions, and programme management addressing the EU AI Act and India’s Digital Personal Data Protection (DPDP) Act. It provides three linked components in a single file: a Use Case Classifier that applies a structured waterfall to up to 10 AI use cases and returns the EU AI Act risk tier, applicable article references, and DPDP obligations triggered; a Compliance Gap Register pre-seeded with 30 requirements across EU AI Act High-Risk obligations, EU AI Act general obligations, and India DPDP obligations; and a Board Summary Dashboard that rolls both up into a single audit-committee-ready view, including a risk-weighted Compliance Exposure Score and a prioritised remediation list. Version 1.1 updated the workbook for the EU Digital Omnibus on AI (Regulation (EU) 2026/1744) — revised Annex III and Annex I application dates, and a new Article 5 prohibition covering AI-generated non-consensual intimate imagery and CSAM. Version 1.2 revises the workbook’s India DPDP Act references to reflect the phased commencement schedule set by MeitY notification. The workbook has five tabs and requires no macros. It is compatible with Microsoft Excel 2016 and above.
Delivered as an Excel workbook with a full User Guide. Download immediately after purchase.
■ Instant download · ■ No macros · ■ Excel 2016+
Updated 3 August 2026 (v1.2) — India DPDP Act references revised for the phased MeitY commencement schedule. Full version history ↓
Most AI programmes cannot say, with confidence, which use cases are High-Risk.
The EU AI Act entered into force in August 2024 and is being phased in through 2026, 2027, and 2028 following the July 2026 Digital Omnibus amendment. India’s Digital Personal Data Protection Act, 2023 was enacted in 2023 and is being brought into force in phases, with the Data Protection Board operational since November 2025 and substantive Data Fiduciary obligations binding from 13 May 2027. Most enterprise AI programmes are subject to one or both frameworks — but very few have completed the foundational step every subsequent obligation depends on: classifying each AI use case by risk tier.
Without a structured classifier, that determination tends to happen informally, inconsistently, or not at all — which is precisely what a regulator, auditor, or board risk committee will test first.
These gaps are invisible until a board risk committee, an auditor, or a regulator asks the direct question: which of your AI use cases are High-Risk, and what is your evidence for that classification? This workbook is built to answer that question with a defensible, repeatable process.
Three linked components. One workbook.
The Use Case Classifier determines the regulatory picture per use case. The Compliance Gap Register tracks the organisation’s progress against every obligation that picture triggers. The Board Summary Dashboard rolls both into a single view for governance reporting.
Component 1 — Use Case Classifier · Up to 10 Use Cases, Strict Waterfall LogicAnswer a structured set of YES/NO questions per use case. The classifier checks Prohibited first, then High-Risk, then Limited-Risk, defaulting to Minimal-Risk only if none of the above are triggered — a use case that also reads as conversational is still classified High-Risk if it meets a High-Risk test, because High-Risk is resolved before Limited-Risk in the hierarchy.
Each use case returns a tier, the applicable article references, and the DPDP obligations triggered:
A single, portfolio-wide register — not duplicated per use case, since every High-Risk use case is exposed to the same set of organisational obligations. Covers 18 EU AI Act High-Risk requirements, 6 EU AI Act general obligations applicable across all tiers, and 6 India DPDP Act obligations. Each requirement carries a Status, Owner, Evidence, and — for the 18 High-Risk items — a Target Date, Remediation Action, and Risk Exposure value.
Component 3 — Board Summary Dashboard · Auto-CalculatedA single-page, print-ready view for audit committee, board risk committee, or steering committee presentation. Every figure is calculated from the Classifier, the Gap Register, and a nine-milestone Regulatory Timeline tab. The only manual inputs are the organisation name and reporting date.
- EU AI Act Risk Tier
- The classification — Prohibited, High-Risk, Limited-Risk, or Minimal-Risk — assigned to an AI system under Regulation (EU) 2024/1689, determined by a strict waterfall in which each tier is checked in turn and the first match applies, regardless of whether the system also matches the criteria for a lower tier.
- Compliance Exposure Score
- A risk-weighted financial figure summing the estimated exposure of every open High-Risk requirement in the Compliance Gap Register, weighted by a probability factor, displayed only once at least one exposure value has been entered — rather than defaulting to a misleading zero.
Every tab, explained.
One Microsoft Excel workbook (.xlsx) containing five tabs.
How AI governance leads define these frameworks.
Direct answers to the questions most often asked about EU AI Act and India DPDP compliance — written for both humans and the AI systems increasingly used to research vendor decisions.
What is the EU AI Act risk tier classification?
The EU AI Act (Regulation (EU) 2024/1689), as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744), classifies AI systems into four risk tiers — Prohibited, High-Risk, Limited-Risk, and Minimal-Risk — checked in that order as a strict waterfall. Prohibited practices under Article 5 are banned outright, and now include AI-generated non-consensual intimate imagery and CSAM, applicable from 2 December 2026. High-Risk systems under Annex III carry the heaviest obligation set: conformity assessment, technical documentation, human oversight, logging, and registration, now applicable from 2 December 2027. Limited-Risk systems carry transparency obligations only. Minimal-Risk systems carry no mandatory obligations at this time.
What changed in the EU AI Act under the Digital Omnibus (Regulation (EU) 2026/1744)?
Regulation (EU) 2026/1744, published in the EU Official Journal on 24 July 2026 and in force from 27 July 2026, amends the AI Act in two ways relevant to this workbook: it moves the Annex III High-Risk application date from 2 August 2026 to 2 December 2027, and the Annex I embedded High-Risk date from 2 August 2027 to 2 August 2028, while leaving the Article 50 transparency and Article 4 AI literacy duties unchanged at 2 August 2026; and it inserts a new Article 5 prohibition covering AI-generated non-consensual intimate imagery and child sexual abuse material, applicable from 2 December 2026. Version 1.1 of this workbook reflects both changes across the Classifier, the Regulatory Timeline, and the Instructions tab.
What is a compliance gap register?
A compliance gap register is a structured record of specific regulatory or policy requirements, each tracked against its current status, owner, evidence, and remediation plan, used to demonstrate to a board, auditor, or regulator that an organisation knows which obligations apply and where it stands against each one. This workbook includes a pre-seeded register with 30 requirements across the EU AI Act and India DPDP Act.
Does the India DPDP Act apply to AI systems?
Yes. India’s DPDP Act, 2023 applies to any AI system that processes personal data of Indian residents, regardless of the system’s EU AI Act risk tier. Key AI-relevant triggers include personal data of Indian residents in training or output data, children’s data, and automated decisions with a significant effect on individuals.
When does India’s DPDP Act actually come into force?
In three stages, set by a Ministry of Electronics and Information Technology (MeitY) notification dated 13 November 2025. The Data Protection Board became operational immediately. Consent Manager registration and obligations take effect 13 November 2026 — that tranche is for entities seeking registration as a licensed Consent Manager, not a general Data Fiduciary obligation. The provisions that affect most organisations — notice, consent, breach reporting, children’s data, cross-border transfer, and Data Principal rights — become legally binding from 13 May 2027.
What is a risk-weighted compliance exposure score?
A single financial figure representing the estimated exposure from unmet compliance requirements, calculated by summing the estimated exposure of each open requirement and applying a probability weighting rather than treating every gap as certain to materialise. This workbook’s Compliance Exposure Score applies a 0.7 probability factor to Not Met High-Risk requirements.
How do you classify an AI use case under the EU AI Act?
By working through a fixed waterfall: check Prohibited first, then High-Risk, then Limited-Risk, defaulting to Minimal-Risk if none apply. A use case can be High-Risk even if it also reads as conversational, because High-Risk is resolved before Limited-Risk in the hierarchy. This workbook’s Use Case Classifier applies that waterfall automatically from a structured set of questions.
Built for the people who have to answer for the classification.
Run a consistent, defensible first-pass classification across the AI portfolio, and maintain the compliance register that governance forums expect to see.
Track EU AI Act and India DPDP obligations in one register instead of two disconnected processes, with a quantified exposure figure for risk reporting.
Classify use cases at intake, before they proceed past scoping, and maintain the register on a monthly or quarterly cadence without specialist legal training.
Run the classifier and gap register during client AI governance engagements instead of building a regulatory tracker from scratch.
Receive a board-ready dashboard with a formal exposure figure and prioritised remediation list — before the next steering or audit committee cycle.
Pairs with: once a use case is classified and its gaps are tracked, ongoing production oversight is the natural next step for any use case moving toward deployment.
View AI Production Governance Toolkit →Current stage: the compliance classification and tracking layer — completed at use case intake and maintained on a rolling basis for as long as the use case is active.
What makes this a defensible register, not a checklist.
What this workbook is not.
This is the single most legally sensitive product in the Viksya suite. Read this section carefully before you rely on it.
What you need to run it.
Questions buyers ask before their first classification pass.
Is this tool a substitute for legal advice?
No. This workbook provides structured guidance based on publicly available regulatory texts as of the version date. It does not constitute legal advice. Regulatory interpretation evolves, and organisations subject to the EU AI Act or India DPDP Act should obtain qualified legal counsel for binding compliance determinations. Classifications produced by this tool are indicative only.
How many AI use cases can this workbook classify?
Up to 10, one per row on the Use Case Classifier tab, so the Board Summary Dashboard can present a portfolio-wide view. The Board Summary formulas reference fixed row ranges, so this version cannot be extended beyond 10 use cases without breaking those formulas. Maintain a second workbook copy for portfolios that exceed this.
Can I add more than the 30 pre-seeded compliance requirements?
Not within this version without breaking the Board Summary formulas, which reference the fixed HR-, GA-, and DPDP- reference structure. Do not delete or reorder rows.
Why does the Compliance Gap Register apply the same Not-Met count to every High-Risk use case?
The register tracks organisational capability — documentation practices, oversight processes, governance structures — not use-case-specific artefacts. Two High-Risk use cases in the same organisation are, in practice, exposed to the same conformity assessment and technical documentation gaps. If your governance model requires per-use-case tracking, duplicate the High-Risk block per use case in a custom copy of the register.
What happens if a use case classifies as Prohibited?
The tier displays in dark red with a direction to escalate immediately to legal counsel. No mitigation is available for a Prohibited classification under Article 5 — the correct response is escalation, not further use of this workbook to work around the result.
How current are the article references and effective dates?
Current as of the version date shown in the workbook — 3 August 2026 for v1.2, based on Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force from 27 July 2026) and the Digital Personal Data Protection Act, 2023 (India), brought into force in phases by MeitY notification dated 13 November 2025 (G.S.R. 843(E)) and the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), the substantive provisions of which apply from 13 May 2027. Implementing acts, delegated acts, and harmonised standards under the EU AI Act are still being issued; the DPDP Rules, 2025 are finalised, but re-verify the phased commencement dates against current MeitY guidance before relying on them for a board- or regulator-facing submission.
I bought an earlier version. Do I need to buy the update separately?
No. Every regulatory and factual update — the v1.1 Digital Omnibus revisions and the v1.2 India DPDP timeline correction — has been folded into the same product at no additional cost. There is no separate paid upgrade. Existing buyers should re-download the file from their Payhip library to receive the current version.
Is a User Guide included?
Yes. A fully formatted PDF User Guide is included in the download. It explains the EU AI Act risk tiers and India DPDP obligations in plain language, gives a full column reference and worked example for the Use Case Classifier, explains the Compliance Gap Register status colour coding, and covers the Board Summary Dashboard, recommended review cadence, and a troubleshooting FAQ.
Classify your AI portfolio before the next regulator, auditor, or board question does it for you.
Download, complete the Use Case Classifier, and generate your first Board Summary Dashboard within the hour.
■ Instant download · ■ No subscription · ■ Indicative guidance only — not legal advice
What’s changed, and why.
This workbook is maintained against current regulatory text. Every material revision is logged here.
v1.2 — 3 August 2026
Revised India Digital Personal Data Protection Act references to reflect the phased commencement schedule set by a Ministry of Electronics and Information Technology (MeitY) notification dated 13 November 2025 (G.S.R. 843(E)) and the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)): Data Protection Board operational from 13 November 2025, Consent Manager registration provisions from 13 November 2026, and substantive Data Fiduciary obligations — notice, consent, breach reporting, children’s data, cross-border transfer, Data Principal rights — binding from 13 May 2027. The Regulatory Timeline tab now tracks nine milestones. No EU AI Act content changed in this update.
v1.1 — 28 July 2026
Updated for the EU Digital Omnibus on AI (Regulation (EU) 2026/1744, published 24 July 2026, in force from 27 July 2026): Annex III High-Risk obligations moved to 2 December 2027, Annex I to 2 August 2028; Article 50 transparency and Article 4 AI literacy duties unchanged at 2 August 2026. A new Article 5 prohibition on AI-generated non-consensual intimate imagery and CSAM was added, applicable from 2 December 2026, extending the Use Case Classifier’s Prohibited tier from seven to nine checks (P1–P9).
v1.0 — 1 July 2026
Original release. EU AI Act risk-tier Use Case Classifier, 30-item Compliance Gap Register, and Board Summary Dashboard, based on Regulation (EU) 2024/1689 as published and the India DPDP Act, 2023 as enacted.
Every update is folded into the same product at no additional cost. Existing buyers should re-download from their Payhip library to receive the current version.