Concise answers to the questions we receive most often from in-house counsel, CISOs, DPOs and regulators evaluating MGLA.
A live regulatory analysis framework that continuously evaluates the gaps between law, system, contract and jurisdiction across nine regulated domains.
Multi-layer gap analysis (normative, technical, contractual, jurisdictional), a continuous rule-execution engine, evidence-bound findings, and dynamic action loops that replace periodic audits.
GRC platforms record what humans assert about controls. MGLA evaluates the live distance between obligations and the systems that operate beneath them — bound to evidence, on every change, on every loop.
Through dynamic action loops: every obligation is re-evaluated on every relevant change to a system, contract or regime — not on a quarterly schedule.
Normative (laws, directives, standards), technical (systems, models, configuration), contractual (DPAs, SCCs, MSAs) and jurisdictional (establishment, processing, residence).
Structured, versioned rule sets that bind obligations to evidence. Each rule is reproducible, auditable internally, and timestamped to the loop in which it fired.
Yes. The rule-execution layer is parameterised against your normative footprint — the regimes, contracts and systems specific to your operation.
The four layers are evaluated jointly. A single inference call can carry GDPR, AI Act and NIS2 obligations at once; MGLA reports each one against the same evidence.
Under a private-access programme. The framework is onboarded against the specific normative footprint of each institution, with named counterparts on both sides.
The framework infrastructure operates under ISO 27001 controls and is aligned with ISO 42001 for AI management. Assurance documentation is provided under access agreements.
Findings are produced as evidence-bound technical assessments. Their treatment in privilege depends on counsel arrangements at the institution; we work with both.
No. The MGLA framework, architecture and methodology are proprietary to IT Law 2035. The reasoning is transparent under access; the implementation is not.
Certified controls across the framework infrastructure ensure operational analysis remains protected at every stage.
Every finding is bound to a versioned rule and the evidence that produced it. Reasoning is internally auditable.
Action loops replace audit cycles; integrity is maintained across normative, technical, contractual and jurisdictional layers.
For matters that fall outside this list — onboarding, joint evaluations with regulators, multi-jurisdictional assessments — we respond under named correspondence.
Contact IT Law 2035 →A live regulatory analysis framework, developed and maintained by IT Law 2035.