regulation10.com

Knowledge base / regulation10.com product guide

Running a compliance module and getting a report

To run a compliance module, open a registered AI system, pick a module from the module list, and start a run. The module asks you a structured set of questions about the system. You can save at any point and resume later. When you finish, the engine scores your responses and produces a report with findings, gaps, and recommended remediations.

A module is a structured assessment of one compliance topic, built from the requirements of the regulatory framework your workspace runs. One module might cover risk management, another data governance, another human oversight. Working topic by topic keeps each run short enough to finish and makes the output specific enough to act on. The list of modules you see for a system depends on the system's risk classification, so a lower-risk system shows a shorter list than a high-risk one.

The questions are written for the people who actually know the system: the product owner, the engineers, the person who manages the data. You do not need a legal background to answer them. Where a question uses a regulatory term, the module explains it in plain language first. Answer from what your organisation actually does today, not from what it intends to do, because the value of the report depends entirely on the honesty of the input.

Save-and-resume matters in practice because a module run is rarely one sitting. Typically one person starts a run, discovers that three answers belong to a colleague, and parks it. The run keeps its partial state until someone finishes it. Nothing is scored or reported until the run is complete, so a parked run never produces a misleading half-report.

The report has three parts. Findings state what the assessment established, both where you meet the requirement and where you do not. Gaps are the specific points where your current practice falls short of what the framework asks. Remediations are concrete recommended actions to close each gap. The report links every finding back to the answers that produced it, so a reviewer can see the reasoning, not just the conclusion.

Each run is versioned and stored against the system permanently. This is the feature that turns a one-off assessment into a compliance history. When you fix a gap and run the module again, the previous run is not overwritten; both runs sit in the record, and the difference between them is your documented progress. Regulators and auditors respond well to that shape of evidence, because it shows a working process rather than a snapshot prepared for the audit.

Completed runs feed directly into the system's evidence export, so there is no separate step where you re-describe the work for an external audience. The run you did is the evidence.

Two practical recommendations. Run your first module on your most important production system rather than an easy one; the gaps you find there are the ones worth finding early. And schedule re-runs after remediation work rather than leaving the last run as the record, because a report that ends on open gaps understates work you have since done.

Steps

  1. Open a registered AI system and pick a module from the module list.
  2. Start a run and answer the module's questions (you can save and resume).
  3. Review the scored report of findings, gaps, and recommended remediations.
  4. Re-run after fixing gaps; completed runs feed your evidence pack.
Running a compliance module and getting a report | regulation10.com