MGLA
Multi-Gap Live Analysis
Vol. XIV · Assessments · The chain that triggers itself

One assessment triggers the next.

MGLA does not ask compliance teams to remember which formal assessment is required when. ISRA, DPIA, AIIA and Digital Sovereignty are connected — approving one auto-creates the others when its triggers fire.

§ 01   The trigger flow

ISRA → DPIA · AIIA · SOV
ISRAInformation SecurityISO 27001 · 27005 · NIS2SECTION 13 · TRIGGERSDPIAData ProtectionGDPR ART. 35AIIAAI ImpactEU AI ACTSOVDigital SovereigntySTRATEGIC · LEGAL · TECHREGISTERRisk Registerconsolidated risks+ mitigations · ownersORIGINAUTO-TRIGGERED ON APPROVALCONSOLIDATION

§ 02   The four assessments

ISRA
Information Security Risk Assessment
ISO 27001 · ISO 27005 · NIS2
14 sections · 57 fields

The origin. Section 13 sets the triggers — DPIA, AIIA, SOV — that auto-create on approval.

DPIA
Data Protection Impact Assessment
GDPR Article 35
14 sections · GDPR-mapped

Triggered when the ISRA marks personal-data processing. Covers lawful basis, necessity, proportionality, DPO consultation.

AIIA
AI Impact Assessment
EU AI Act
12 dimensions · risk-class mapped

Triggered when an AI system is in scope. Tied to a registered AI system with risk class (Minimal · Limited · High · Unacceptable).

SOV
Digital Sovereignty
Strategic · Legal · Technological
8 sovereignty sections

Triggered for systems with sovereignty implications. Covers strategic, legal, data/AI, operational, supply-chain, technology, security and environmental sovereignty.

§ 03   Assessment lifecycle

Draft → In Review → Approved · time-stamped
01
Template

Start from a system template (ISO 27001, GDPR Art. 35, EU AI Act, Sovereignty) — versioned, with published or draft status.

02
Fill

Sections, fields and scored questions. AI Suggest available on every field — review, accept, or dismiss.

03
Participants

ISRA Lead · IT Security Officer · DPO · Legal · Business Owner · Risk Manager · External Auditor. Attendance tracked.

04
Triggers

Section 13 (or equivalent) marks the follow-up assessments needed. Selections are non-destructive — change them, the chain updates.

05
Review

Status moves Draft → In Review → Approved. Every change is time-stamped on the chain of evidence.

06
Auto-create

Approval with triggers set spawns the linked assessments, pre-populated where the data overlaps.

§ 04
AI Suggest

A proposal on every field. Never a default.

Every field in every assessment carries an AI Suggest action. The agent reads the assessment context — entity, scope, prior answers, linked findings — and proposes a draft response with confidence and the artefacts it relied on.

The suggestion is never auto-applied. A named participant reviews, accepts, edits or dismisses it. The acceptance is recorded on the chain of evidence with the rule version used.

§ 05   The Risk Register · downstream consolidation

Filterable by assessment type, risk level, status

Every approved assessment contributes its identified risks to a consolidated register. Risks carry category, likelihood, impact, inherent and residual scores, status and owner. Mitigations are tracked per risk with status (Proposed · In Progress · Completed) and an effectiveness score.

The register is the operational surface — what is open, by whom, by when, with which mitigation in flight, against which assessment.

Identified
A risk is raised — by an assessment, a finding, or a participant.
Analyzing
Likelihood and impact scored; inherent risk = likelihood × impact.
Treating
Mitigations proposed, owned, dated; effectiveness scored as they progress.
Mitigated · Accepted · Closed
Residual risk recorded. The decision sits on the chain.
§ 06   Knowledge Graph

The whole chain, visible at once.

Every entity in the framework — laws, articles, documents, evidence, assessments, risks, mitigations, AI systems, suppliers — sits in a single graph. Nodes are colour-coded by type; relationships are explicit.

The graph is searchable, filterable by node type, and traversable from any starting point. Top-referenced articles surface across regulations; orphan nodes surface gaps.

ISRALawArt.DocDocDPIAAIIA
MGLA
Multi-Gap Live Analysis™

A live regulatory analysis framework, developed and maintained by IT Law 2035.

Framework
Reading
Institution
MGLA™ Multi-Gap Live Analysis™ · © 2026 IT Law 2035The MGLA framework, architecture and methodologies are proprietary.