MGLA does not ask compliance teams to remember which formal assessment is required when. ISRA, DPIA, AIIA and Digital Sovereignty are connected — approving one auto-creates the others when its triggers fire.
The origin. Section 13 sets the triggers — DPIA, AIIA, SOV — that auto-create on approval.
Triggered when the ISRA marks personal-data processing. Covers lawful basis, necessity, proportionality, DPO consultation.
Triggered when an AI system is in scope. Tied to a registered AI system with risk class (Minimal · Limited · High · Unacceptable).
Triggered for systems with sovereignty implications. Covers strategic, legal, data/AI, operational, supply-chain, technology, security and environmental sovereignty.
Start from a system template (ISO 27001, GDPR Art. 35, EU AI Act, Sovereignty) — versioned, with published or draft status.
Sections, fields and scored questions. AI Suggest available on every field — review, accept, or dismiss.
ISRA Lead · IT Security Officer · DPO · Legal · Business Owner · Risk Manager · External Auditor. Attendance tracked.
Section 13 (or equivalent) marks the follow-up assessments needed. Selections are non-destructive — change them, the chain updates.
Status moves Draft → In Review → Approved. Every change is time-stamped on the chain of evidence.
Approval with triggers set spawns the linked assessments, pre-populated where the data overlaps.
Every field in every assessment carries an AI Suggest action. The agent reads the assessment context — entity, scope, prior answers, linked findings — and proposes a draft response with confidence and the artefacts it relied on.
The suggestion is never auto-applied. A named participant reviews, accepts, edits or dismisses it. The acceptance is recorded on the chain of evidence with the rule version used.
Every approved assessment contributes its identified risks to a consolidated register. Risks carry category, likelihood, impact, inherent and residual scores, status and owner. Mitigations are tracked per risk with status (Proposed · In Progress · Completed) and an effectiveness score.
The register is the operational surface — what is open, by whom, by when, with which mitigation in flight, against which assessment.
Every entity in the framework — laws, articles, documents, evidence, assessments, risks, mitigations, AI systems, suppliers — sits in a single graph. Nodes are colour-coded by type; relationships are explicit.
The graph is searchable, filterable by node type, and traversable from any starting point. Top-referenced articles surface across regulations; orphan nodes surface gaps.
A live regulatory analysis framework, developed and maintained by IT Law 2035.