Seven-module certification for compliance officers, DPOs and legal counsel: the inventory and classification register, the Art. 4 literacy programme, governance gates, AI Act × GDPR, incidents and complaints, and the audit file.

Somebody in the organisation has to hold the whole picture: which systems exist, which obligations attach to which of them, who owns each, what evidence exists, and what happens next. That is rarely a provider engineer or a deployer business owner. It is usually a compliance officer, a DPO, or in-house counsel who acquired the file because nobody else would.

This track is written for that person. It assumes you will not build a model or write a technical file, and that you will be the one asked whether the organisation is compliant — a question you can only answer if the evidence exists in a form you can produce.

The seven modules

Module 1 — The map, and the timetable that actually applies Who owes what across the roles, what is in force today, and why the December 2027 date is not a reason to wait.

Module 2 — Inventory and classification register The register that answers the first question a supervisor asks, the fields that cannot be reconstructed, and the shadow-AI problem.

Module 3 — The Art. 4 literacy programme What the July 2026 rewrite changed, why evidence shifted from levels to measures, and the register that satisfies it.

Module 4 — Governance gates Procurement, purpose change and modification: three gates that between them prevent most of the expensive failures in this Regulation.

Module 5 — AI Act and GDPR together DPIA and FRIA, Art. 22 and Art. 86, lawful basis, the Art. 10(5) special-category permission, and where the two regimes genuinely conflict.

Module 6 — Incidents, complaints, whistleblowing The routes in and out: Art. 26(5), Art. 73, the Art. 85 complaint right, and the Art. 87 protection for reporting persons.

Module 7 — The audit file and the board conversation What to hold, what to report upward, what to budget, and how to say honestly what is not done.

What the examination asks

Twenty questions drawn from a bank, stratified so every module is covered, graded on our server. The pass mark is 70%.

Before you start

This track assumes the free Fundamentals course. It sits above the Deployer and Provider tracks rather than replacing them: this one is about running the programme, those are about the obligations it has to deliver.

This is not the same examination

The Fundamentals examination checks that you have read the Regulation. This one checks that you could apply it to a real case — same subject, different question.

Fundamentals (free) Compliance & DPO (this track)
Questions served 1520
Question bank 6092
Modules covered 57
What is tested Whether you are in scope, and by what Running the programme: what is due, what is evidence, what is not owed
Access Open, no card required Track holders only

Two sample questions on the same article. They are written for this page and appear in no bank.

Fundamentals — free

Which article of the AI Act sets out the AI literacy obligation?

  1. Article 3
  2. Article 4
  3. Article 9
  4. Article 26
Show the answer and the reasoning

Answer 2. Art. 3 holds the definitions, Art. 9 the risk management system and Art. 26 the deployer obligations. A reference, recalled correctly — and on its own it does not tell you what your organisation should do on Monday.

Compliance & DPO — this track

Your board asks you to prioritise AI Act spend. Your organisation deploys one Annex III point 4 recruitment tool, publishes AI-assisted commentary, and has no high-risk system it provides. What carries the most enforceable exposure today?

  1. The Annex III recruitment tool, because it is high-risk
  2. A fundamental rights impact assessment under Art. 27
  3. The Art. 5 prohibitions and the Art. 50 duties, both already in force
  4. The Art. 4 literacy obligation, because it carries a 3% fine
Show the answer and the reasoning

Answer 3. Three traps in one question. The recruitment tool is high-risk but its Chapter III obligations do not apply until 2 December 2027. Art. 27 does not reach a private employer deploying a point 4 system at all. And Art. 4 appears in no paragraph of Art. 99 — it carries no fine of its own. What is enforceable today is Art. 5, in force since February 2025, and Art. 50, in force since August 2026 and reaching that AI-assisted commentary.

Every paper is drawn per candidate and stratified across all modules; the order of the options differs between candidates. Grading happens on the server — the answer key never reaches the browser.

Frequently Asked Questions

No, and conflating them causes trouble in both directions. The AI Act creates no equivalent of the data protection officer and imposes no appointment obligation. In practice the work often lands on the DPO because the skills overlap, but the DPO's independence and tasks under the GDPR are defined by that regulation, and taking operational ownership of AI compliance can create a conflict with the DPO's advisory and monitoring role.

The inventory, then the Art. 5 prohibitions across it, then Art. 50. Those two checks cover obligations that are already in force and carry real exposure, while the Chapter III high-risk regime does not apply to standalone Annex III systems until 2 December 2027. Starting with a high-risk gap analysis is starting with the part that is not yet due.

No. There is no periodic audit obligation on deployers or providers as such. What exists is a set of continuing duties — risk management as a continuous process, post-market monitoring, log retention, cooperation with authorities — that a programme evidences through artefacts rather than through a scheduled audit. An internal audit cycle is good practice and is not what the Regulation asks for.

The national market surveillance authority designated by the Member State, for AI systems. The Commission, through the AI Office, for general-purpose AI models. Individuals may lodge complaints with a market surveillance authority under Art. 85, and Art. 87 extends the Union whistleblower protection framework to reporting infringements of the AI Act.

Take compliance further with the AI Act Academy

A free course, a server-graded exam, a verifiable certificate — and the working templates.