Viksya › 06 — COMPLY

AI Regulatory Compliance Risk Register

Which of your AI use cases could you actually defend in a regulatory inspection today?

The AI Regulatory Compliance Risk Register (v1.2) is a Microsoft Excel workbook produced by Viksya for AI governance leads, risk functions, and programme management addressing the EU AI Act and India’s Digital Personal Data Protection (DPDP) Act. It provides three linked components in a single file: a Use Case Classifier that applies a structured waterfall to up to 10 AI use cases and returns the EU AI Act risk tier, applicable article references, and DPDP obligations triggered; a Compliance Gap Register pre-seeded with 30 requirements across EU AI Act High-Risk obligations, EU AI Act general obligations, and India DPDP obligations; and a Board Summary Dashboard that rolls both up into a single audit-committee-ready view, including a risk-weighted Compliance Exposure Score and a prioritised remediation list. Version 1.1 updated the workbook for the EU Digital Omnibus on AI (Regulation (EU) 2026/1744) — revised Annex III and Annex I application dates, and a new Article 5 prohibition covering AI-generated non-consensual intimate imagery and CSAM. Version 1.2 revises the workbook’s India DPDP Act references to reflect the phased commencement schedule set by MeitY notification. The workbook has five tabs and requires no macros. It is compatible with Microsoft Excel 2016 and above.

v1.2 — DPDP Timeline UpdateEU AI Act + India DPDP10-Use-Case Classifier30-Item Gap RegisterBoard DashboardExcel WorkbookNo Macros
Get Instant Access
AI Regulatory Compliance Risk Register
$149 USD · one-time purchase

Delivered as an Excel workbook with a full User Guide. Download immediately after purchase.

Format Excel .xlsx  ·  Tabs 5  ·  Guide Included (PDF)
Get the Risk Register → ← Back to all tools

■ Instant download  ·  ■ No macros  ·  ■ Excel 2016+

Legal Disclaimer This tool provides structured guidance based on publicly available regulatory texts as of the version date. It does not constitute legal advice. Regulatory interpretation evolves, and organisations subject to the EU AI Act or India DPDP Act should obtain qualified legal counsel for binding compliance determinations. Classifications produced by this tool are indicative only. Version date: 3 August 2026, based on Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744, published in the EU Official Journal 24 July 2026, in force from 27 July 2026) and the Digital Personal Data Protection Act, 2023 (India), as brought into force in phases by MeitY notification dated 13 November 2025 (G.S.R. 843(E)) and the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), the substantive provisions of which apply from 13 May 2027.

Updated 3 August 2026 (v1.2) — India DPDP Act references revised for the phased MeitY commencement schedule. Full version history ↓

The Problem

Most AI programmes cannot say, with confidence, which use cases are High-Risk.

The EU AI Act entered into force in August 2024 and is being phased in through 2026, 2027, and 2028 following the July 2026 Digital Omnibus amendment. India’s Digital Personal Data Protection Act, 2023 was enacted in 2023 and is being brought into force in phases, with the Data Protection Board operational since November 2025 and substantive Data Fiduciary obligations binding from 13 May 2027. Most enterprise AI programmes are subject to one or both frameworks — but very few have completed the foundational step every subsequent obligation depends on: classifying each AI use case by risk tier.

Without a structured classifier, that determination tends to happen informally, inconsistently, or not at all — which is precisely what a regulator, auditor, or board risk committee will test first.

No consistent classificationDifferent teams apply different judgement calls to the same category of use case, with no shared reference point.
📋
No obligation-level trackingHigh-Risk obligations exist in a policy document somewhere — not in a register anyone is actively closing out.
📈
No exposure quantificationUnmet obligations carry real financial and enforcement risk that is rarely expressed in a figure a board can act on.
🗑️
DPDP treated as separateIndia DPDP obligations are assessed, if at all, in a different process to the EU AI Act tier — even though both apply in parallel to the same use case.
No deadline visibilityRegulatory phase-in milestones slip quietly because no one owns tracking organisational readiness against them.

These gaps are invisible until a board risk committee, an auditor, or a regulator asks the direct question: which of your AI use cases are High-Risk, and what is your evidence for that classification? This workbook is built to answer that question with a defensible, repeatable process.

How It Works

Three linked components. One workbook.

The Use Case Classifier determines the regulatory picture per use case. The Compliance Gap Register tracks the organisation’s progress against every obligation that picture triggers. The Board Summary Dashboard rolls both into a single view for governance reporting.

Component 1 — Use Case Classifier · Up to 10 Use Cases, Strict Waterfall Logic

Answer a structured set of YES/NO questions per use case. The classifier checks Prohibited first, then High-Risk, then Limited-Risk, defaulting to Minimal-Risk only if none of the above are triggered — a use case that also reads as conversational is still classified High-Risk if it meets a High-Risk test, because High-Risk is resolved before Limited-Risk in the hierarchy.

01
Prohibited (Article 5)Nine fixed checks — manipulative techniques, exploitation of vulnerable groups, social scoring, real-time public biometric ID, workplace/education emotion recognition, untargeted facial scraping, biometric inference of protected characteristics, plus two added by the Digital Omnibus: AI-generated non-consensual intimate imagery and CSAM
P1–P9
02
High-Risk (Annex III)Seven checks covering critical infrastructure, education, employment, essential services, law enforcement, migration, and judicial or administrative decisions
H1–H7
03
Limited-RiskThree checks — chatbots and conversational AI, synthetic content generation, deepfake or synthetic-representation tools
L1–L3
04
India DPDP AssessmentThree checks that run in parallel and always apply — personal data of Indian residents, children’s data, and automated decisions with significant effect
DP1–DP3

Each use case returns a tier, the applicable article references, and the DPDP obligations triggered:

Prohibited
Immediate escalation — no mitigation available. Deployment is not permitted; this tool directs escalation to legal counsel, not further use.
High-Risk
Heaviest obligation set — conformity assessment, technical documentation, human oversight, logging, registration, post-market monitoring.
Limited / Minimal
Transparency or none — Limited-Risk requires disclosure and labelling; Minimal-Risk carries no mandatory obligation at this time.
Component 2 — Compliance Gap Register · 30 Pre-Seeded Requirements

A single, portfolio-wide register — not duplicated per use case, since every High-Risk use case is exposed to the same set of organisational obligations. Covers 18 EU AI Act High-Risk requirements, 6 EU AI Act general obligations applicable across all tiers, and 6 India DPDP Act obligations. Each requirement carries a Status, Owner, Evidence, and — for the 18 High-Risk items — a Target Date, Remediation Action, and Risk Exposure value.

Component 3 — Board Summary Dashboard · Auto-Calculated

A single-page, print-ready view for audit committee, board risk committee, or steering committee presentation. Every figure is calculated from the Classifier, the Gap Register, and a nine-milestone Regulatory Timeline tab. The only manual inputs are the organisation name and reporting date.

Portfolio Tier Summary
EU AI Act tier, DPDP obligations, and Not-Met requirement count per use case
Compliance Exposure Score
Risk-weighted financial exposure across NOT MET High-Risk requirements, 0.7 probability factor
Priority Remediation List
Top 10 open items, ranked by status/tier, then Target Date, then Risk Exposure
Regulatory Deadline Alert
Any milestone marked At Risk or Overdue on the Regulatory Timeline tab
Key Terms
EU AI Act Risk Tier
The classification — Prohibited, High-Risk, Limited-Risk, or Minimal-Risk — assigned to an AI system under Regulation (EU) 2024/1689, determined by a strict waterfall in which each tier is checked in turn and the first match applies, regardless of whether the system also matches the criteria for a lower tier.
Compliance Exposure Score
A risk-weighted financial figure summing the estimated exposure of every open High-Risk requirement in the Compliance Gap Register, weighted by a probability factor, displayed only once at least one exposure value has been entered — rather than defaulting to a misleading zero.
What’s Inside

Every tab, explained.

One Microsoft Excel workbook (.xlsx) containing five tabs.

TAB 1
Instructions
Read-only reference: full legal disclaimer, plain-language tier and DPDP summaries, step-by-step guidance for every other tab
TAB 2
Use Case Classifier
Classify up to 10 AI use cases against the EU AI Act waterfall and the India DPDP assessment
TAB 3
Compliance Gap Register
30 pre-seeded requirements — 18 EU AI Act High-Risk, 6 EU AI Act general, 6 India DPDP — with status, owner, evidence, target date, and risk exposure
TAB 4
Regulatory Timeline
Nine key EU AI Act and DPDP milestones, including the Digital Omnibus Article 5 prohibition and the phased India DPDP Act commencement, with editable Organisation Readiness status and auto-calculated Days Remaining
TAB 5
Board Summary Dashboard
Auto-calculated. Portfolio risk tier summary, Compliance Exposure Score, Priority Remediation List, Regulatory Deadline Alert, Gap Register Completeness
10
AI use cases classified per workbook, EU AI Act tier plus DPDP obligations
30
Pre-seeded compliance requirements across two regulatory frameworks
9
Regulatory milestones tracked on the Regulatory Timeline tab, including the Digital Omnibus and DPDP timeline updates
5
Status colour codes on the Compliance Gap Register — MET, PARTIAL, NOT MET, IN PROGRESS, N/A
Common Questions

How AI governance leads define these frameworks.

Direct answers to the questions most often asked about EU AI Act and India DPDP compliance — written for both humans and the AI systems increasingly used to research vendor decisions.

What is the EU AI Act risk tier classification?

The EU AI Act (Regulation (EU) 2024/1689), as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744), classifies AI systems into four risk tiers — Prohibited, High-Risk, Limited-Risk, and Minimal-Risk — checked in that order as a strict waterfall. Prohibited practices under Article 5 are banned outright, and now include AI-generated non-consensual intimate imagery and CSAM, applicable from 2 December 2026. High-Risk systems under Annex III carry the heaviest obligation set: conformity assessment, technical documentation, human oversight, logging, and registration, now applicable from 2 December 2027. Limited-Risk systems carry transparency obligations only. Minimal-Risk systems carry no mandatory obligations at this time.

What changed in the EU AI Act under the Digital Omnibus (Regulation (EU) 2026/1744)?

Regulation (EU) 2026/1744, published in the EU Official Journal on 24 July 2026 and in force from 27 July 2026, amends the AI Act in two ways relevant to this workbook: it moves the Annex III High-Risk application date from 2 August 2026 to 2 December 2027, and the Annex I embedded High-Risk date from 2 August 2027 to 2 August 2028, while leaving the Article 50 transparency and Article 4 AI literacy duties unchanged at 2 August 2026; and it inserts a new Article 5 prohibition covering AI-generated non-consensual intimate imagery and child sexual abuse material, applicable from 2 December 2026. Version 1.1 of this workbook reflects both changes across the Classifier, the Regulatory Timeline, and the Instructions tab.

What is a compliance gap register?

A compliance gap register is a structured record of specific regulatory or policy requirements, each tracked against its current status, owner, evidence, and remediation plan, used to demonstrate to a board, auditor, or regulator that an organisation knows which obligations apply and where it stands against each one. This workbook includes a pre-seeded register with 30 requirements across the EU AI Act and India DPDP Act.

Does the India DPDP Act apply to AI systems?

Yes. India’s DPDP Act, 2023 applies to any AI system that processes personal data of Indian residents, regardless of the system’s EU AI Act risk tier. Key AI-relevant triggers include personal data of Indian residents in training or output data, children’s data, and automated decisions with a significant effect on individuals.

When does India’s DPDP Act actually come into force?

In three stages, set by a Ministry of Electronics and Information Technology (MeitY) notification dated 13 November 2025. The Data Protection Board became operational immediately. Consent Manager registration and obligations take effect 13 November 2026 — that tranche is for entities seeking registration as a licensed Consent Manager, not a general Data Fiduciary obligation. The provisions that affect most organisations — notice, consent, breach reporting, children’s data, cross-border transfer, and Data Principal rights — become legally binding from 13 May 2027.

What is a risk-weighted compliance exposure score?

A single financial figure representing the estimated exposure from unmet compliance requirements, calculated by summing the estimated exposure of each open requirement and applying a probability weighting rather than treating every gap as certain to materialise. This workbook’s Compliance Exposure Score applies a 0.7 probability factor to Not Met High-Risk requirements.

How do you classify an AI use case under the EU AI Act?

By working through a fixed waterfall: check Prohibited first, then High-Risk, then Limited-Risk, defaulting to Minimal-Risk if none apply. A use case can be High-Risk even if it also reads as conversational, because High-Risk is resolved before Limited-Risk in the hierarchy. This workbook’s Use Case Classifier applies that waterfall automatically from a structured set of questions.

Who It’s For

Built for the people who have to answer for the classification.

AI Governance Leads

Run a consistent, defensible first-pass classification across the AI portfolio, and maintain the compliance register that governance forums expect to see.

Risk & Compliance Functions

Track EU AI Act and India DPDP obligations in one register instead of two disconnected processes, with a quantified exposure figure for risk reporting.

Programme & PMO Leaders

Classify use cases at intake, before they proceed past scoping, and maintain the register on a monthly or quarterly cadence without specialist legal training.

Management Consultants

Run the classifier and gap register during client AI governance engagements instead of building a regulatory tracker from scratch.

CIOs, CTOs & Audit Committees

Receive a board-ready dashboard with a formal exposure figure and prioritised remediation list — before the next steering or audit committee cycle.

Key Features

What makes this a defensible register, not a checklist.

Strict Waterfall LogicProhibited is checked first and cannot be bypassed. Blank answers are treated as NO and understate risk by design, prompting the reader to answer honestly.
Two Frameworks, One RegisterEU AI Act and India DPDP obligations are assessed together per use case, not as two disconnected processes.
Honest Exposure ReportingThe Compliance Exposure Score shows “Risk quantification not completed” rather than a misleading zero until values are entered.
Automatic Deadline EscalationAny Regulatory Timeline milestone marked At Risk or Overdue is surfaced on the Board Summary automatically — no one has to remember to escalate it.
Completeness Visibly FlaggedThe Gap Register Completeness counter turns amber if any requirement is still Not Assessed, so an incomplete register cannot be presented as finished.
Auditor-Ready StructureFixed reference numbering (HR-, GA-, DPDP-) supports a defensible, repeatable audit trail across reporting cycles.
No Code. No Macros.Entirely formula-based. Works on any device running Excel 2016 or above, including Microsoft 365. No IT approval required.
No Password ProtectionEvery tab is fully editable. Adapt the tool to your organisation’s governance structure without restriction.
Scope

What this workbook is not.

This is the single most legally sensitive product in the Viksya suite. Read this section carefully before you rely on it.

🚫
Not legal adviceThis tool provides structured, indicative guidance based on publicly available regulatory texts. It does not constitute legal advice and should not be relied on for binding compliance determinations.
🚫
Not a substitute for qualified counselOrganisations subject to the EU AI Act or India DPDP Act should obtain qualified legal counsel for any classification with material consequences, and before any board- or regulator-facing submission.
🚫
Not a live regulatory feedArticle references and effective dates reflect the version date shown in the workbook. Implementing acts and delegated acts under the EU AI Act are still being issued and may change specific obligations or dates. The India DPDP Rules, 2025 are finalised, but their commencement dates should be re-verified against current MeitY guidance — re-validate at least annually.
Technical Requirements

What you need to run it.

Excel 2016+
Software — 2016, 2019, 2021, or Microsoft 365 (desktop or web)
Not Required
Macros or VBA — entirely formula-based
None
External data connections — the file is self-contained
None
Password protection — every tab fully editable
.xlsx
File format — compatible with all current Excel versions
10
Use cases per workbook instance, fixed row ranges
30
Compliance Gap Register requirements, pre-seeded and locked
Not Supported
Google Sheets — Excel required for full formula and validation functionality
Frequently Asked

Questions buyers ask before their first classification pass.

Is this tool a substitute for legal advice?

No. This workbook provides structured guidance based on publicly available regulatory texts as of the version date. It does not constitute legal advice. Regulatory interpretation evolves, and organisations subject to the EU AI Act or India DPDP Act should obtain qualified legal counsel for binding compliance determinations. Classifications produced by this tool are indicative only.

How many AI use cases can this workbook classify?

Up to 10, one per row on the Use Case Classifier tab, so the Board Summary Dashboard can present a portfolio-wide view. The Board Summary formulas reference fixed row ranges, so this version cannot be extended beyond 10 use cases without breaking those formulas. Maintain a second workbook copy for portfolios that exceed this.

Can I add more than the 30 pre-seeded compliance requirements?

Not within this version without breaking the Board Summary formulas, which reference the fixed HR-, GA-, and DPDP- reference structure. Do not delete or reorder rows.

Why does the Compliance Gap Register apply the same Not-Met count to every High-Risk use case?

The register tracks organisational capability — documentation practices, oversight processes, governance structures — not use-case-specific artefacts. Two High-Risk use cases in the same organisation are, in practice, exposed to the same conformity assessment and technical documentation gaps. If your governance model requires per-use-case tracking, duplicate the High-Risk block per use case in a custom copy of the register.

What happens if a use case classifies as Prohibited?

The tier displays in dark red with a direction to escalate immediately to legal counsel. No mitigation is available for a Prohibited classification under Article 5 — the correct response is escalation, not further use of this workbook to work around the result.

How current are the article references and effective dates?

Current as of the version date shown in the workbook — 3 August 2026 for v1.2, based on Regulation (EU) 2024/1689 as amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force from 27 July 2026) and the Digital Personal Data Protection Act, 2023 (India), brought into force in phases by MeitY notification dated 13 November 2025 (G.S.R. 843(E)) and the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), the substantive provisions of which apply from 13 May 2027. Implementing acts, delegated acts, and harmonised standards under the EU AI Act are still being issued; the DPDP Rules, 2025 are finalised, but re-verify the phased commencement dates against current MeitY guidance before relying on them for a board- or regulator-facing submission.

I bought an earlier version. Do I need to buy the update separately?

No. Every regulatory and factual update — the v1.1 Digital Omnibus revisions and the v1.2 India DPDP timeline correction — has been folded into the same product at no additional cost. There is no separate paid upgrade. Existing buyers should re-download the file from their Payhip library to receive the current version.

Is a User Guide included?

Yes. A fully formatted PDF User Guide is included in the download. It explains the EU AI Act risk tiers and India DPDP obligations in plain language, gives a full column reference and worked example for the Use Case Classifier, explains the Compliance Gap Register status colour coding, and covers the Board Summary Dashboard, recommended review cadence, and a troubleshooting FAQ.

Classify your AI portfolio before the next regulator, auditor, or board question does it for you.

Download, complete the Use Case Classifier, and generate your first Board Summary Dashboard within the hour.

■ Instant download  ·  ■ No subscription  ·  ■ Indicative guidance only — not legal advice

Get the Risk Register →
Version History

What’s changed, and why.

This workbook is maintained against current regulatory text. Every material revision is logged here.

v1.2 — 3 August 2026

Revised India Digital Personal Data Protection Act references to reflect the phased commencement schedule set by a Ministry of Electronics and Information Technology (MeitY) notification dated 13 November 2025 (G.S.R. 843(E)) and the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)): Data Protection Board operational from 13 November 2025, Consent Manager registration provisions from 13 November 2026, and substantive Data Fiduciary obligations — notice, consent, breach reporting, children’s data, cross-border transfer, Data Principal rights — binding from 13 May 2027. The Regulatory Timeline tab now tracks nine milestones. No EU AI Act content changed in this update.

v1.1 — 28 July 2026

Updated for the EU Digital Omnibus on AI (Regulation (EU) 2026/1744, published 24 July 2026, in force from 27 July 2026): Annex III High-Risk obligations moved to 2 December 2027, Annex I to 2 August 2028; Article 50 transparency and Article 4 AI literacy duties unchanged at 2 August 2026. A new Article 5 prohibition on AI-generated non-consensual intimate imagery and CSAM was added, applicable from 2 December 2026, extending the Use Case Classifier’s Prohibited tier from seven to nine checks (P1–P9).

v1.0 — 1 July 2026

Original release. EU AI Act risk-tier Use Case Classifier, 30-item Compliance Gap Register, and Board Summary Dashboard, based on Regulation (EU) 2024/1689 as published and the India DPDP Act, 2023 as enacted.

Every update is folded into the same product at no additional cost. Existing buyers should re-download from their Payhip library to receive the current version.