Necessary storage is on. Analytics load only after consent. Learn more
Your people get the path their role legally requires: AI literacy under Article 4 of the EU AI Act, board training under the Dutch Cybersecurity Act (NIS2), periodic training under the Dutch AML act (Wwft), and the resilience modules from DORA. Register your AI systems, classify them with the built-in AI Act wizard, and keep everything in one audit-ready dossier.
Four laws
knowledge and training duties proven through certificates, completion logs, and organization-scoped reporting
Annex III + Article 50
case studies across high-risk domains and transparency obligations
EU-hosted
with DPA baseline, TOMs, and subprocessor list for vendor review
The questions we hear when a knowledge duty stops being theory and becomes something you have to prove.
Directors fall under the Dutch Cybersecurity Act (NIS2), staff in scope for the Dutch AML act (Wwft) fall under a periodic training duty, and AI tools enter through every department. Without a register you cannot classify, and without classification you do not know your obligations per person.
People follow courses, but nothing connects a legal duty to the roles it applies to and the evidence that person can produce.
An RFP, an audit, a works council question. Assembling evidence then takes weeks. A dossier you maintain takes one click.
Legal and privacy reviews stall rollouts. We provide a DPA baseline, TOMs, subprocessor list, retention matrix, and security FAQ up front, so your vendor review moves instead of waiting on documents.
From obligation mapping to the audit trail, on one platform.
We map per role what someone legally needs to know: AI literacy under Article 4, board training under the Dutch Cybersecurity Act (NIS2), periodic training under the Dutch AML act (Wwft), and the resilience modules from DORA, set against your AI systems, Annex III high-risk exposure, and Article 50 transparency duties. No generic course, just the obligation that applies to that person.
Certificates, completion logs, and organization-scoped reporting give you a defensible record of who was trained, when, and against which program, ready for auditor, DPO, or works council review.
DPA baseline, TOMs, subprocessor list, retention matrix, and security FAQ are shared during procurement so privacy and legal can sign off without a months-long back-and-forth.
A short scan that shows which roles cannot yet prove their AI literacy is covered, and what evidence you are still missing before an audit.
learnwize
The evidence gap scan
13 pages · PDF
The questions we hear most often from DPOs, risk, and legal in review calls.