Back to the registry
Agent passport

EU AI Act Compliance Assessment for High-Risk & GPAI Systems on AWS

Kriv AI · Cybersecurity & IT

No attestation published

Certification per AWS Marketplace.

Provenance reach3 of 12 layers traced

Evidence tier Source Confirmed · 3 captures on record

User ratingNot rated0 reviews on the listing
Runs onUnknownProfessional service
ProvenanceUnknown33% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on AWS Marketplace.

**The EU AI Act is already in force. High-risk enforcement starts August 2, 2026.**

Prohibited practices (Article 5) became enforceable on February 2, 2025. General-Purpose AI model obligations (Articles 53, 55) went live on August 2, 2025. **High-risk system obligations under Annex III — covering healthcare triage, credit scoring, insurance underwriting, employment screening, biometric categorization — become enforceable on August 2, 2026.** Non-conformity exposes providers and deployers to administrative fines up to **€35 million or 7% of worldwide annual turnover**, whichever is higher (Article 99).

Show the rest of the publisher’s description (14 more lines)

Kriv AI's EU AI Act Compliance Assessment is a structured 4-week virtual engagement that maps each of your AWS-deployed AI workloads to its specific obligations under Regulation (EU) 2024/1689. The methodology is adapted from our 7-agent governed AI reference architecture and extended to cover the full Act.

**4-week engagement**

  • **Week 1 — Inventory + risk classification.** AI system inventory across business units; risk-tier each system (Art. 5 prohibited / Annex III high-risk / limited-risk / minimal-risk / GPAI); stakeholder interviews (Legal, Engineering, Product, DPO); GDPR + existing DPIA intake.
  • **Week 2 — Gap analysis (Articles 9–15).** Risk management system (Art. 9), data governance (Art. 10), technical documentation Annex IV (Art. 11), automatic logging (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy + robustness + cybersecurity (Art. 15). Cloud-agnostic findings with AWS-preferred remediation.
  • **Week 3 — FRIA, conformity, post-market.** Article 27 Fundamental Rights Impact Assessment for deployers; conformity assessment readiness (internal vs. notified body); Art. 72 post-market monitoring plan draft; Art. 73 serious incident reporting workflow. GPAI providers: Art. 53 transparency + Art. 55 systemic-risk evaluation (10²⁵ FLOPs threshold).
  • **Week 4 — Executive readout + remediation roadmap.** C-suite presentation; documentation pack handoff; prioritized roadmap aligned to Aug 2, 2026 high-risk obligations deadline.

**Deliverables customer owns:** 30-page Readiness Assessment Report · AI System Inventory with Annex III classification · Article 9 Risk Management System template · Article 10 Data Governance policy · Article 13 Transparency notices · Article 14 Human Oversight specification · Annex IV Technical Documentation template · Article 27 FRIA template · Conformity Assessment gap analysis · Article 72 Post-Market Monitoring plan · remediation roadmap pre-Aug 2, 2026.

**AWS-native control mappings**

Bedrock + Bedrock Guardrails (GPAI deployment + Article 15 cybersecurity) · SageMaker + Responsible AI Toolkit (Articles 10 + 15) · CloudTrail + Config (Article 12 record-keeping) · Comprehend (PII detection for Article 27 FRIA) · GuardDuty + Security Hub (Article 15 cybersecurity). Cloud-agnostic equivalents provided for Azure and GCP customers.

**Legal positioning — important**

Kriv AI is a US-based AI governance firm specializing in regulated industries. Legal interpretation and sign-off on EU-law questions is provided through our partnership with **independent EU-qualified attorneys**. Kriv delivers the assessment methodology, technical gap analysis, and documentation artifacts; customers retain their own counsel for binding legal advice and regulatory submissions. **This listing does not constitute legal advice.**

**AWS infrastructure cost disclaimer**

This listing covers Kriv AI professional services only. AWS compute, storage, Bedrock inference, logging, and any other AWS service consumption incurred during or after the assessment are billed separately by AWS at standard rates and are the sole responsibility of the customer. Kriv AI is an AWS Select Tier Services Partner and a member of the Anthropic Claude Partner Network (approved April 2026). No endorsement by AWS or Anthropic is implied.

**Get started.** Engagements are scoped via private offer based on number of AI systems in scope and jurisdiction complexity. Standard 4-week assessment for organizations with 5–20 in-scope systems typically runs $30K–$60K. Enterprise tier (GPAI provider obligations + systemic-risk evaluation + multi-jurisdiction) priced separately. Contact info@kriv.ai for a custom quote. Most assessments kick off within 2 weeks of contract signature. EDP-eligible — assessment fee counts toward your AWS Enterprise Discount Program commitment (up to 25%). Structure via Marketplace private offer. Contact info@kriv.ai or +1 732 433 5564.

Highlights

Highlighted by the publisher on AWS Marketplace.

4-week virtual assessment covering EU AI Act Articles 5 (prohibited), 9–15 (risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy/cybersecurity), 27 (FRIA), 53 + 55 (GPAI provider obligations + 10²⁵ FLOPs systemic-risk threshold), 72 (post-market monitoring), 73 (serious incident reporting), plus Annex III high-risk classification and Annex IV technical documentation skeleton populated for each in-scope system

Prepare for the August 2, 2026 high-risk enforcement deadline. Avoid administrative fines up to €35M or 7% of worldwide annual turnover (Article 99). AWS-native control mappings: Bedrock + Bedrock Guardrails for Art. 15 cybersecurity + GPAI deployment; SageMaker + Responsible AI Toolkit for Art. 10 + 15; CloudTrail + Config for Art. 12 record-keeping; Comprehend for Art. 27 FRIA PII detection; GuardDuty + Security Hub for Art. 15 cybersecurity. Cloud-agnostic equivalents for Azure / GCP

AWS Select Tier Services Partner methodology built on Kriv's 7-agent governed AI reference architecture. Delivered through partnership with independent EU-qualified attorneys — Kriv handles assessment methodology, technical gap analysis, and documentation artifacts; customer retains own counsel for binding legal advice and regulatory submissions. Member of the Anthropic Claude Partner Network (approved April 2026). Listing does not constitute legal advice

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-08-29

CompanyKriv AIAutomated
Websitehttps://www.kriv.ai/

Sources

Marketplace listingaws.amazon.comSource
App certificationaws.amazon.comSource

Publisher resources

3 links
EU AI Act Methodology One-Pagerkriv.aiSource
Annex III Scoping Questionnairekriv.aiSource
Sample Annex IV Technical Documentation Skeletonkriv.aiSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Unknown
Not stated
Delivery
Professional service
Primary support contact: info@kriv.ai · +1 732 433 5564 · https://kriv.ai/support Response SLA: Kriv AI responds to AWS Marketplace inquiries and post-private-offer kickoff requests within 2 business days during US business hours (Eastern Time, Monday–Friday). Engagement-specific escalations to assigned Kriv engagement lead within 1 business day on request. Customers receive a dedicated Microsoft Teams or Slack channel with named engagement lead at kickoff for the 4-week assessment plus a 30-day post-delivery question window. Enterprise tier includes 90-day post-delivery advisory access. Hours of operation: Monday–Friday 9:00 AM – 6:00 PM Eastern Time (US). Off-hours messages acknowledged the next business day. EU customers: timezone-flexible scheduling available via prior arrangement.
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.