How Vigilia scores AI governance.
Every score, gap, and remediation in a Vigilia report comes from a deterministic graph analysis. No black-box AI judgement. You can explain every finding to your regulator and your board.
Methodology · deterministic scoring
Every score, gap, and remediation in a Vigilia report comes from a deterministic graph analysis. No black-box AI judgement. You can explain every finding to your regulator and your board.
The model
Vigilia represents your AI system as a directed graph: agents, human approvers, data sources, governance policies, monitoring systems, and decision points are vertices. Their relationships — orchestrates, accesses, approves, monitors, constrained by — are edges.
Compliance signals are then extracted from the graph topology. Missing edges, for example an agent making decisions with no human approval chain, trigger gap findings. Each finding maps to the specific regulatory article it violates, with the affected agent named directly.
Scoring is deterministic. AI is used only to enrich gap narratives — never to determine whether a gap exists.
Risk classification
Every workspace is classified from the kind of decisions its agents make. Articles that do not apply to your tier are excluded entirely — they neither pass nor fail, so they cannot inflate the score.
Six governance dimensions
Each dimension is scored from your graph. The signal is the structural relationship that drives the score; the article is the EU AI Act provision it maps to.
| Dimension | Graph signal | EU AI Act |
|---|---|---|
| Human oversight | APPROVES / ESCALATES_TO ratio | Art. 14 |
| Data security | ACCESSES density + CONSTRAINED_BY | Art. 10 |
| Transparency | MONITORING_SYSTEM + AUDIT_LOG flows | Art. 13 |
| Accountability | DECISION_OUTPUT traceability | Art. 14 + Art. 9 |
| Reliability | ORCHESTRATES chain depth | Art. 9 |
| Regulatory compliance | GOVERNANCE_POLICY coverage | Art. 9 |
Eight structural anti-patterns
Each detection triggers a gap with a severity, a fine exposure, and a remediation step.
Scoring, severity, effort
For each selected framework:
passing_articles / total_applicable_articles.Every gap carries a severity — critical · high · medium · low — reflecting regulatory exposure and likelihood of enforcement, and an effort rating — low · medium · high — estimating implementation complexity. Both are relative indicators to help you prioritise remediation; they are not legal opinions.
Fine exposure figures cited in reports are statutory maximums from the underlying regulation. Actual exposure depends on your turnover, the specific circumstances of any enforcement action, and the discretion of the supervisory authority.
Vigilia reports are designed to give compliance teams, legal counsel, and regulators a clear, structural starting point. Use them alongside qualified legal advice.
The audit itself
€499, against audits that conventionally cost €5,000 to €40,000. Every finding in your report traces back to a rule on this page and a specific article.
See how the audit works