# Organisational controls: answered once by the organisation, included in every audit report. # Answer each with: yes | no | partial | n/a (leave empty = Pending) # yes = Compliant, no/partial = Non-Compliant, n/a = NotApplicable. # GDPR Art. 30: Is there a current record of processing activities (RoPA)? ORG_ROPA= # GDPR Art. 35: Has a DPIA been done for every high-risk processing activity? ORG_DPIA= # GDPR Art. 33-34: Is there a tested procedure to report a personal data breach within 72 hours? ORG_BREACH_PROCEDURE= # GDPR Art. 28: Are data processing agreements signed with all processors, including AI providers? ORG_PROCESSOR_AGREEMENTS= # AI Act Art. 26: Is there a register of the AI systems the organisation uses? ORG_AI_REGISTER= # AI Act Art. 4: Have staff who use AI received AI literacy training? ORG_AI_LITERACY= # AI Act Art. 14, 26: Is a trained person assigned to oversee each high-risk AI system? ORG_HUMAN_OVERSIGHT= # AI Act Art. 50: Are people told when they interact with AI or receive AI-generated content? ORG_AI_TRANSPARENCY=