A customer sends a due diligence questionnaire, or the ICO asks a question, or an auditor wants to see DPIAs. What follows is two weeks of chasing: which systems process personal data, what the lawful basis was, whether anyone completed an assessment, and who decided that.
The work was mostly done. It was just never recorded anywhere that survives the person who did it, which means it has to be reconstructed each time rather than retrieved.
Identified before processing rather than reconstructed afterwards, and treated as a hard gap when missing rather than a scoring nuance.
Which systems have one, which need one, and which have a recorded decision that one was not required — the last being the category most often missing.
UK GDPR and EU AI Act obligations assessed per system rather than treated as alternatives, because most systems sit under both.
Assembled continuously and exported in a form intended for an auditor or a customer's due diligence, not a screenshot of a dashboard.
How long it takes to answer, and whether the answer holds. Being able to produce a defensible position in an afternoon changes the commercial conversation, because due diligence delays lose deals more often than compliance failures lose cases.
CXO Ready is an aid, not an assurance. It helps you structure your thinking, record what you have done and see where the gaps are. It does not make you compliant, and nothing it produces is legal advice or a regulatory opinion. Scores are indicative. Responsibility for compliance stays with your organisation, and decisions with legal consequences should be taken with a qualified adviser.
Before you start
No. CXO Ready structures the assessment and holds the evidence; it does not tell you whether your lawful basis is sound or your classification is correct. Those are judgements for you or an external adviser. What it removes is the reconstruction work that has to happen before anyone can form a view.
By triaging rather than assessing everything equally. The register shows which systems process personal data, at what scale, and whether they make automated decisions — which is enough to rank what needs a DPIA first. Status is tracked per system so the gap is visible rather than assumed closed.
Often yes, through customers, subsidiaries or suppliers — it reaches AI systems placed on the EU market or whose output is used there. It is also increasingly showing up in customer due diligence regardless of legal applicability, which makes a documented position commercially useful even where it is not strictly required.
That is one of the most common uses. The register, per-system scores and evidence exports answer most of what security and privacy questionnaires ask about AI, and having it ready is frequently the difference between a deal closing this quarter and next.
More in the full FAQ, or ask us directly.
Other roles