From spreadsheet inventory to governed AI register in eight weeks.
Organisation: A mid-sized European retail bank with operations in Ireland, Germany and the Netherlands.
The challenge
- More than forty AI use cases were tracked across different risk, procurement and IT teams.
- There was no single record of which systems were high-risk under the EU AI Act, who owned them, or what evidence existed.
- The compliance deadline of 2 August 2026 was approaching while internal legal review was still manual.
The approach
- Deployed a single AIRAS Cloud tenant with segregated workspaces for legal, risk, compliance and IT review.
- Imported existing policy documents and vendor contracts to seed the discovery pipeline.
- Ran the deterministic qualification engine against every registered use case to produce a defensible classification.
47
AI systems registered in the governed inventory
12
High-risk systems pre-classified with evidence packs
8
Weeks from tenant provisioning to executive report
100%
Append-only audit trail for every classification decision
“For the first time we can show our regulator exactly how we reached a classification, who reviewed it, and on what evidence.”