Examples

See what a deliverable looks like

These short examples show how we organise information so it can support decisions and follow-up work. Your deliverables depend on the agreed scope.

Email, domain and impersonation — a finding

Illustrative example using fictional data. This is not a client case, a completed assessment or evidence of achieved compliance.

FieldExample
ObservationIn this fictional scenario, there is no documented list of all services authorised to send email for the domain.
BasisAn illustrative gap in the supplied inventory; not an actual technical measurement.
RiskChanging settings without a complete inventory may disrupt legitimate email or leave senders unverified.
ActionIdentify sending services, review authentication and agree a plan for changes and monitoring.
OwnerA designated representative of the client’s IT team.
StatusIllustrative planned action; not completed.

How it is used: The finding helps the responsible team understand what to check and plan. The example does not include implementing the changes.

How the work could continue if implementation is commissioned separately

Planned changeConfirm authorised senders and make agreed changes to email settings.
How we would verify itTest messages from the agreed services and review authentication results, with monitoring over the agreed period.
What we would hand overA change record, verification results and outstanding questions.

The example illustrates how separately commissioned implementation could proceed. It does not describe completed changes or measured results.

What depends on your scope: A real audit covers the agreed domains, sending services and hosts; the number of findings and their detail depend on what is in scope.

Email, domain and impersonation audit →

Regulatory evidence — an index

Illustrative example using fictional data. This is not a client case, a completed assessment or evidence of achieved compliance.

This is an excerpt of a working structure. It is not an official DORA Register of Information, a full regulatory template or an accepted package.

TopicIllustrative materialGapNext action
ICT risk governanceDraft policyNo approval recordConfirm the responsible body and approval process
Supplier contractsContract inventoryNo organised review of the agreed clausesReview in-scope contracts and record findings
Exercises and checksIllustrative planNo evidence of a completed exercisePlan an exercise and its results record

How it is used: Having a document does not automatically mean a control operates effectively. We distinguish material supplied, work reviewed and actions still outstanding. Requirements, sources and the extent of review are agreed for each engagement.

What depends on your scope: The regulation (DORA or NIS2), the entity and the number of contracts and policies in scope shape the index; the DORA track adds the register of ICT arrangements.

DORA / NIS2 readiness and evidence pack →

AI use — an inventory entry

Illustrative example using fictional data. This is not a client case, a completed assessment or evidence of achieved compliance.

FieldExample
UsePreparing first drafts of customer replies.
SourceA fictional response to an employee survey.
DataUse of public text is reported in this example; actual practice remains to be checked.
Risk to clarifyEntering non-public information and sending unverified statements.
Proposed ruleApproved tools and data; human review before sending.
Next stepConfirm the use, the tool’s terms and the responsible manager.

How it is used: This example does not assign an AI Act legal risk category. That requires a separate assessment of the actual use.

What depends on your scope: Coverage depends on the survey, interviews and records available; the inventory lists identified uses, not a guaranteed complete map of every tool.

AI use and governance review →