AI Act and GDPR Evidence Pack
for SaaS Teams Shipping
LLM Features

Build your AI feature inventory, AI Act triage record, vendor review, GDPR evidence pack, testing logs and AI literacy proof in 10 days - without starting from a blank page.

Evidence-firstAI literacy proofGDPR AI docsVendor DDQ

Overview

Built for SaaS teams shipping LLM features

AI Act & GDPR Evidence Pack for SaaS is a practical documentation and evidence pack for teams building or deploying AI-powered SaaS features. It helps you create a usable AI governance baseline in 10 days, without buying an enterprise GRC platform or building every template from scratch.

Use it to classify AI features, document decisions, review vendors, train your team, track changes, test LLM behaviour, and prepare evidence for customer, internal, investor, or audit-style governance requests.

AI Act triage

Applicability checks, prohibited practice screening, high-risk flags, transparency triggers, and decision records.

Evidence logs

Approvals, prompt, model and knowledge base change logs, testing and evaluation records, monitoring, incidents, and training evidence.

GDPR AI pack and vendor review

DPIA decision support, DSAR handling, RoPA addendum materials, DPA annex materials, LLM vendor DDQ, and risk scoring.

AI literacy proof

Training decks, quizzes, registers, completion certificates, and role-based materials in Pro.

Scope: focused on EU AI Act and GDPR readiness for SaaS LLM features. This kit is not legal advice, certification, or a full high-risk conformity assessment package.

What You Get

AI Act triage and decision evidence

Classify AI features and keep a clear, reviewable decision trail.

  • AI feature intake and approval trail
  • AI Act applicability checks
  • Prohibited practice screening
  • High-risk flagging and escalation notes
  • Transparency and disclosure checklist

SaaS operating logs

Track the AI governance evidence customers may ask for.

  • Prompt, model and knowledge base change logs
  • Testing and evaluation records
  • Monitoring and incident log
  • Risk acceptance register
  • Training completion evidence log

GDPR, vendors and training

Cover privacy, supplier review and AI literacy evidence.

  • DPIA decision guide for LLM features
  • DSAR intake and response templates
  • RoPA AI addendum and DPA annex materials
  • Vendor DDQ and LLM risk scoring
  • Training decks, quiz and completion records

Designed for practical use: the kit gives SaaS teams working templates, logs, checklists and training materials, not a generic legal theory pack.


What's Inside

Starter

30 core files + bonuses

A focused internal baseline with AI intake, AI Act triage, GDPR triggers, vendor checks, evidence logs, AI literacy materials, PDF exports and Starter addenda.

Pro

78 files · v1.7 May 2026

A fuller AI Act and GDPR evidence pack for customer, investor, procurement, security and audit-style reviews, including SaaS LLM playbooks, testing records, customer evidence, worked examples and launch readiness materials.

Formats

DOCX · XLSX · PPTX · PDF

Editable implementation files plus PDF exports for internal review, customer sharing, procurement responses and audit-style evidence requests.

Choose Starter for a fast internal baseline. Choose Pro if customers, investors, procurement teams or internal stakeholders are already asking how your SaaS product governs AI features.

Why SaaS needs this

SaaS teams shipping LLM features are increasingly asked for AI governance evidence: what the feature does, what data it uses, who approved it, how it was tested, how it is monitored, and whether the team completed AI literacy training.

Customer questions arrive fast

Enterprise customers, procurement teams, investors and security reviewers may ask for proof before you are ready.

  • Which AI features exist and what data they use
  • Who approved the feature and latest changes
  • What AI literacy training the team completed

Policies are not enough

A policy helps, but customers often want practical records showing AI governance runs in the product workflow.

  • No prompt, model or knowledge base records
  • No testing, evaluation or monitoring evidence
  • No structured incident and escalation history

Starting from scratch is slow

Blank-page compliance work often creates scattered documents, inconsistent formats and unclear ownership.

  • Documents spread across teams and tools
  • No consistent structure for owners and decisions
  • Hard to prepare one clear evidence pack
This kit gives you a structured starting point: intake forms, approval records, vendor checks, testing logs, monitoring records, incident logs and AI literacy evidence, designed for SaaS teams that need to move quickly without losing control.

Best fit

For SaaS teams that need practical AI governance evidence.

Built for SaaS teams shipping LLM features such as chatbots, RAG search, summarisation, copilots, AI agents and support automation.

  • You need a usable AI Act and GDPR readiness baseline
  • You want templates, logs, checklists and training materials
  • You need evidence for customers, investors, procurement or security reviews
  • You want to document decisions, vendors, testing, changes and AI literacy

Not a fit

For teams that need legal advice, automation or formal certification.

This kit does not replace legal counsel, provide formal legal sign-off, certify your AI system or operate as an integrated GRC platform.

  • You need a bespoke legal opinion for a specific AI system
  • You expect automated workflows, integrations or live monitoring
  • You need a full high-risk conformity assessment package
  • You want certification based on templates alone

Positioning: this is a practical implementation kit for documentation, training and evidence building. It helps you prepare a stronger baseline, while legal, technical and conformity reviews may still be needed for regulated or high-risk use cases.

10-Day Plan

A practical 10-day implementation sequence for turning scattered AI work into a structured evidence baseline that product, legal, security, leadership and customer-facing teams can use.

Days 1 to 2

Scope and inventory

List your LLM features, data flows, vendors, owners and responsibilities. Start the evidence trail before decisions scatter across tools.

Day 3

AI Act triage and approvals

Run applicability checks, screen for prohibited practices, flag possible high-risk use cases and document approval points.

Day 4

Vendor due diligence

Review LLM and GPAI vendors, record data handling, retention, training use, security evidence, subprocessors and risk scoring.

Day 5

GDPR decision support

Use the DPIA decision guide, record privacy triggers, update RoPA notes where needed and capture mitigations and approvals.

Days 6 to 7

Changes, testing and evaluation

Set up prompt, model and knowledge base change records. Add evaluation evidence for hallucinations, unsafe outputs and retrieval quality.

Day 8

Monitoring and incidents

Define monitoring checks, complaint handling, incident categories, escalation owners and review cadence for live AI features.

Day 9

AI literacy training

Deliver training, run the quiz, record completion evidence and keep attendance or completion records for relevant roles.

Day 10

Prepare the evidence pack

Assemble the inventory, triage records, vendor review, GDPR notes, logs, training evidence and open actions into one reviewable pack.

Outcome: this sequence is designed to help you establish a practical AI governance baseline, not just a policy document. The pack supports internal reviews, customer questions, procurement checks and audit-style requests.

Pricing

Choose your AI Act & GDPR evidence pack
Start with free samples, use Starter for a fast internal baseline, or choose Pro when customers, investors or procurement teams need stronger AI governance evidence.
Free Sample Pack
Review selected previews before you buy, including the file index, AI inventory sample, vendor checklist and training preview.
  • Selected previews and sample rows
  • Useful for checking quality before purchase
  • Does not replace the paid Starter or Pro packs
Download free samples

No purchase required.

Quick baseline
Starter
€149
Launch price
After launch: €299
For SaaS teams that need a practical AI Act and GDPR documentation starting point.
  • 30 core Starter files
  • AI intake, AI Act triage and approval records
  • Basic prompt, model and knowledge base logs
  • GDPR triggers, vendor DDQ and basic risk scoring
  • AI literacy starter kit
  • 7 bonus Starter addenda
  • DOCX, XLSX, PPTX and PDF exports
  • 10 days of email support
  • Free product file updates for 6 months
Get Starter

Best if you need a fast internal baseline before building a fuller evidence pack.

Most popular
Pro
Full Evidence Pack
€499
Launch price
After launch: €899
For SaaS teams that need stronger evidence for customer, investor, procurement, security or audit-style AI governance requests.
  • 78 files · v1.7 May 2026
  • Covers and expands the Starter baseline
  • Fuller AI Act and GDPR evidence pack
  • SaaS LLM playbooks and testing records
  • GDPR AI materials: DPIA, DSAR, RoPA and retention
  • Vendor due diligence and risk scoring
  • Role-based AI literacy training
  • Customer evidence materials
  • Worked examples and launch readiness materials
  • 10 days of email support
  • Free product file updates for 6 months
Get Pro Evidence Pack

Best if customers, investors or procurement teams are asking for AI governance evidence.

For teams and agencies
Team and Agency License
€1,499
Launch price
After launch: €2,499
For agencies, consultants, multiple teams or organizations that need broader usage rights.
  • Everything in Pro v1.7
  • Team and agency licensing
  • Multiple internal teams or entities
  • Client use option for consultants and agencies
  • Priority support option
  • Invoice purchase available
Contact for Team and Agency License

Best if you support several teams, entities or client implementations.

Start with Starter, upgrade later
Buy Starter now and upgrade to Pro within 14 days. We will credit 100% of your Starter payment toward Pro.
Example: buy Starter for €149, then upgrade to Pro for €350 within 14 days.
Use the upgrade code provided after your Starter purchase.
Launch pricing is available for the first 20 customers while we collect early feedback and continue improving the implementation materials.
Prices in EUR. VAT, if applicable, is handled at checkout by Paddle.
Instant digital access after purchase, subject to the applicable checkout and digital content terms.
Starter and Pro are single-company licenses.
Team and Agency License is required for multiple-entity, agency or client use.
This kit is not legal advice and does not guarantee certification or formal compliance.

FAQ

1. Does this guarantee EU AI Act, GDPR or ISO certification?

No. This is a practical implementation kit with templates, checklists, logs and guidance. You still need to tailor the materials to your company, operate the processes and get legal or technical review where needed. It helps you build a stronger governance and documentation baseline, but it does not guarantee compliance, certification or formal assurance.

2. Is this a software platform?

No. It is a downloadable kit with editable DOCX, XLSX and PPTX files, plus PDF exports. It is designed for teams that want a practical working pack without buying an enterprise GRC or AI governance platform.

3. Who is this for?

It is for SaaS teams shipping LLM features such as chatbots, RAG search, summarisation, copilots, AI agents and support automation. It is especially relevant for founders, product leads, engineering leads, legal and compliance operators, security reviewers and teams preparing customer or internal AI governance evidence.

4. What if our AI system may be high-risk under the AI Act?

You can use the kit as a governance foundation for inventory, approvals, vendor review, training, testing records, monitoring and incident evidence. If a use case may be high-risk, you should get appropriate legal and conformity review. This kit is not a complete high-risk conformity assessment package.

5. We use OpenAI, Anthropic, Azure or another model provider. Do we still need this?

Often, yes. Provider documentation can help, but it does not replace your own internal evidence. SaaS teams still need to document which AI features they operate, what data they use, which vendors are involved, who approved the use case, how prompts and knowledge bases change, how outputs are tested, how incidents are handled and who has been trained.

6. What is included in the AI literacy training?

The kit includes training decks, a quiz, a training register and training completion records. Pro includes role-based versions for product and engineering, support and sales, and leadership or governance stakeholders.

7. What support is included?

Pro includes 10 days of email support for implementation questions during your first 10 days after purchase. Support covers how to use the kit, sequence the rollout and place documents correctly. It does not include legal advice, company-specific compliance determinations or bespoke drafting.

8. What formats will I receive?

You receive editable DOCX files for policies and templates, XLSX files for logs and registers, PPTX files for training materials, plus PDF exports for easier sharing and review.

9. What is the license?

Starter and Pro are single-company licenses for one legal entity. Multiple-entity use, agency use, consultant use and client implementations require the Team and Agency License or a separate written agreement.

10. Do you offer refunds?

This is an instant-access digital product. For business customers, refunds are not generally available after download or access has been provided, except where required by law or where there is a verified delivery or access issue that we cannot resolve.

For EU consumers, the statutory withdrawal right may apply. If you request immediate access to the digital content during the withdrawal period, you will be asked at checkout to expressly consent to immediate delivery and acknowledge that you lose your right of withdrawal once the download or access begins.

11. Are AI Act timelines changing?

The AI Act applies in phases. AI literacy and prohibited AI practice rules started applying in February 2025. GPAI obligations started applying in August 2025. Many general and transparency obligations remain relevant from August 2026, while certain high-risk AI system obligations may be subject to extended timelines under the AI omnibus process.

This kit is designed for practical readiness work that SaaS teams need regardless of a single deadline: inventory, triage, vendor review, testing records, monitoring, incident handling, transparency decisions and AI literacy evidence.

12. How current are the materials?

The kit is updated to v1.7, May 2026. The materials include version dates or last updated notes in the download files. Because AI Act guidance, implementation timelines and GDPR interpretation can evolve, teams should review the materials periodically and seek legal advice where their use case is regulated, high-risk or commercially sensitive.

About

JUDr. Monika Fegyveres Oravská

Hi, I’m JUDr. Monika Fegyveres Oravská

ISO/IEC 42001 certified implementer

Since 2018, I have helped consulting firms, law offices and companies, including SaaS teams, build practical GDPR programs through audits, implementation support and training.

Before consulting, I spent 14 years in private sector managerial roles, including international environments. That experience helps me translate compliance requirements into operating processes teams can actually use.

I built this kit to give SaaS teams shipping LLM features an evidence-first starting point, so they can move faster without building AI governance documentation from scratch.

Practical focus: the kit is built from implementation experience, not as a legal opinion, certification product or replacement for company-specific legal review.

AI Act SaaS — Full Product Contents

Last updated: May 2026 · Version 1.7

Practical AI Act and GDPR evidence pack for SaaS teams shipping LLM features. Product by MONIMO, s. r. o.

Scope: downloadable implementation kit for SaaS teams using LLM features. It helps teams classify AI features, review vendors, train teams, test LLM behavior, track changes, log incidents and prepare practical evidence for customer, procurement, investor or internal review. It is not legal advice, certification, formal audit assurance or a complete high-risk conformity assessment package.

Package overview

Free Sample Pack

Best for: checking quality before purchase.

Includes: read me, file index preview, inventory sample, intake preview, vendor checklist preview, evidence log sample, AI literacy preview and website readiness preview.

Starter

Best for: fast internal baseline.

Includes: 30 core files, Starter addenda, launch readiness materials and PDF exports.

Pro

Best for: customer, investor, procurement, security and audit-style evidence.

Includes: 70 core files plus Pro addenda 71–78, worked examples, launch readiness materials and PDF exports.

Free Sample Pack

00 Read Me and How to Use Free Sample Pack
01 Full Product File Index Preview
02 AI Feature Inventory Sample
03 AI Use Case Intake Form Preview
04 Vendor Due Diligence Checklist Preview
05 Prompt or Evidence Log Sample
06 AI Literacy Training Preview
07 Website Readiness Preview

Starter — 30 core files

Folder 01 — Start Here

1 Read Me and How to Use This Kit
2 10-Day Implementation Plan, Starter Version
3 File Index, Starter
4 Evidence Folder Structure
5 Roles and Responsibilities Matrix

Folder 02 — AI Feature Intake and AI Act Triage

6 AI Feature Inventory
7 AI Use Case Intake Form
8 AI Act Applicability Checklist
9 Prohibited Practice Screening
10 High-Risk Flagging Checklist
11 Transparency and Disclosure Checklist
12 AI Feature Approval Memo

Folder 03 — Basic SaaS Evidence Logs

13 AI Approval Log
14 Prompt Change Log
15 Model and Vendor Register
16 Testing and Evaluation Log, Basic
17 Monitoring and Incident Log, Basic
18 Training Completion Register

Folder 04 — GDPR AI Starter Pack

19 GDPR Trigger Checklist for AI Features
20 DPIA Decision Guide, Short Version
21 RoPA AI Addendum, Simple Template
22 DSAR AI Intake Form
23 Prompt Personal Data Rules

Folder 05 — Vendor Due Diligence Starter

24 LLM Vendor DDQ, Short Version
25 Vendor Risk Scorecard, Basic
26 Vendor Approval Note

Folder 06 — AI Literacy Starter

27 AI Literacy Training Deck, Core
28 AI Literacy Quiz
29 Training Register
30 Training Completion Certificate Template

Starter — addenda and PDF exports

31 Risk Acceptance Register
32 AI DPA Annex and Subprocessor Checklist
33 Worked Example AI-001 — Support Chatbot RAG
34 Compliance Source Map — AI Act / GDPR
35 Customer Evidence Pack Checklist
36 Web Claims and Public Sample Boundary Note
37 RAG Knowledge Base Change Log
38 Website Readiness Checklist
39 Checkout, Refund and Digital Content Delivery Wording
40 Privacy and Cookie Notice Checklist
PDF exports — PDF versions of relevant editable materials for review and sharing.

Pro — files 1–25

Folder 01 — Start Here and Implementation

1 Read Me, Pro
2 Full File Index
3 10-Day Implementation Plan
4 Evidence Folder Structure
5 Roles and Responsibilities Matrix
6 SaaS AI Governance Operating Model
7 Implementation Checklist
8 Customer and Audit Evidence Map

Folder 02 — AI Feature Intake and Inventory

9 AI Feature Inventory
10 AI Use Case Intake Form
11 AI Feature Owner Assignment
12 AI Data Flow Worksheet
13 AI System Description Template
14 Product Area AI Register
15 AI Feature Review and Retirement Form

Folder 03 — AI Act Triage

16 AI System Definition Checklist
17 Provider, Deployer and Vendor Role Mapping
18 Prohibited Practice Screening
19 High-Risk Triage Checklist
20 Limited Risk and Transparency Checklist
21 AI Generated Content Disclosure Checklist
22 Human Oversight Checklist
23 Non-High-Risk Rationale Memo
24 High-Risk Escalation Memo
25 AI Feature Approval Memo

Pro — files 26–54

Folder 04 — SaaS LLM Playbooks

26 Customer Support Chatbot Playbook
27 RAG and Knowledge Base Search Playbook
28 Summarization Feature Playbook
29 Copilot Feature Playbook
30 AI Agent Playbook
31 Ticket Classification and Routing Playbook
32 Response Generation Playbook
33 Internal AI Assistant Playbook

Folder 05 — SaaS Evidence Logs

34 AI Approval Log
35 Model and Vendor Register
36 Prompt Change Log
37 Model Version Change Log
38 Knowledge Base Change Log
39 RAG Source Review Log
40 Testing and Evaluation Log
41 Monitoring Log
42 Incident and Escalation Log
43 Risk Acceptance Register
44 Customer AI Request Log
45 Audit Evidence Index

Folder 06 — Testing and Evaluation

46 Evaluation Plan Template
47 LLM Test Case Library
48 Hallucination Test Log
49 Prompt Injection Test Log
50 Privacy Leakage Test Log
51 Bias and Fairness Review Sheet
52 RAG Evaluation Sheet
53 Agent Safety Checklist
54 Release Readiness Sign Off

Pro — files 55–78

Folder 07 — GDPR AI Pack

55 GDPR AI Trigger Checklist
56 DPIA Decision Guide for LLM Features
57 DPIA Template for AI Features
58 RoPA AI Addendum
59 DSAR AI Playbook
60 DPA Annex for AI Processing
61 Prompt Personal Data Policy
62 Retention and Logging Checklist

Folder 08 — Vendor Due Diligence

63 Full LLM Vendor DDQ
64 Vendor Risk Scorecard
65 Vendor Approval Memo
66 GPAI Dependency Map

Folder 09 — AI Literacy and Customer Evidence

67 Role-Based AI Literacy Decks
68 Quiz, Register and Completion Materials
69 Customer AI Governance Summary
70 Enterprise DDQ Answer Bank

Pro Addenda — Worked Examples and Launch Readiness

71 Worked Example AI-001 — Customer Support RAG Chatbot
72 Worked Example AI-002 — RAG Search and Summarization
73 Worked Example AI-003 — Sales Response Copilot
74 Worked Example — Customer AI Evidence Response
75 Website Readiness Checklist
76 Checkout, Refund and Digital Content Delivery Wording
77 Privacy and Cookie Notice Checklist
78 Product Changelog and Update Policy Template
PDF exports — PDF versions of relevant Pro DOCX/PPTX materials for review and sharing.

Team and Agency License

1 Everything in Pro v1.7
2 Team and Agency License Terms
3 Multiple Entity Use Guide
4 Client Use Guide for Consultants and Agencies
5 Internal Rollout Workshop Agenda
6 Consultant Implementation Checklist
7 Priority Support Option
8 Invoice Purchase Option

Usage note: Starter and Pro are single-company licenses. Team and Agency License is required for multiple-entity, agency, consultant or client use. Exact rights are governed by the purchase terms or written agreement.

How to use the kit

Assign an owner, complete the relevant fields, attach supporting evidence and review outputs with legal, security, product or leadership stakeholders where needed.

Purpose: each document should explain why it exists and when to use it. Owner: each register or template should identify the responsible role or team. Evidence: logs should link to decisions, tests, vendor documents or supporting records. Review: key records should include review date, status and next action. Escalation: high-risk, regulated, sensitive or uncertain cases should be escalated.

What this kit is not

This kit is not legal advice, certification, a platform, a full high-risk conformity assessment package, a global law tracker or vendor assurance. It provides practical materials and guidance that must be adapted to the buyer’s SaaS product, AI features, data flows, vendors, contracts and applicable law.

Temporary referral tracking test

Referral Tracking Test — €1