European Regulatory Readiness
Raia supports customers evaluating artificial-intelligence and ICT service providers under European regulatory requirements. Our program combines independently assessed security controls with customer-specific contracting, transparency, risk assessment and operational cooperation.
On this page
Digital Operational Resilience Act (DORA) EU Artificial Intelligence Act Request Assurance InformationDigital Operational Resilience Act (DORA)
The EU Digital Operational Resilience Act, or DORA, directly establishes requirements for regulated financial entities. DORA is not a general certification for software vendors, and using Raia does not transfer a customer's regulatory responsibilities. Raia provides information, assurance and cooperation to help applicable customers assess and manage Raia as an ICT third-party service provider.
Security and resilience foundation
Raia's DORA customer-enablement work builds on its SOC 2 Type II examination and documented controls for information security, identity and access management, encryption, logging and monitoring, change management, vulnerability management, incident response, vendor risk, backup, business continuity and disaster recovery.
SOC 2 and DORA serve different purposes. Raia's SOC 2 Type II report provides independent assurance about the controls within the report's defined system, scope and examination period. DORA additionally requires regulated customers to address matters such as ICT contract terms, provider and location data, incident-reporting support, ongoing monitoring, resilience testing, audit and authority access, subcontracting and exit planning.
Support for financial-services assessments
| Review area | Raia support |
|---|---|
| Independent assurance | Qualified customers may request Raia's applicable SOC 2 Type II report and supporting security documentation under appropriate confidentiality terms. |
| Security documentation | Raia maintains documented policies and procedures for security, access, encryption, vulnerability management, incident response, business continuity, disaster recovery, vendor management and data protection. |
| Incident cooperation | Raia maintains processes for detection, escalation, containment, recovery, evidence preservation, customer communication and post-incident review. Applicable notice and cooperation commitments are governed by the customer agreement. |
| Operational resilience | Raia maintains backup, business-continuity and disaster-recovery procedures and conducts recurring exercises. Additional architecture, recovery-objective and test information may be made available to qualified customers under confidentiality terms. |
| Provider information | Raia performs risk-based reviews of relevant providers and can discuss service, processing-location and provider information for a scoped assessment. |
| Data return | Raia supports customer-data export, retention and deletion in accordance with the applicable agreement, product capabilities and data-protection terms. |
| Customer-specific review | Raia's Security and Legal teams can review DORA due-diligence requests and proposed contractual requirements for the customer's intended service and deployment. |
DORA customer-enablement program
Raia is extending its existing SOC 2 control program with DORA-oriented customer deliverables, including contractual terms, structured provider and location information, incident-reporting support, resilience and testing evidence, audit cooperation, relevant subcontractor information, and exit and transition documentation.
The requirements applicable to a particular arrangement depend on the Raia services used, the customer's regulated activities, the deployment and data involved, and whether the customer classifies the supported function as critical or important.
EU Artificial Intelligence Act
The EU AI Act assigns obligations according to the AI system, its intended purpose, the parties' roles and the deployment context. It is not a single company-level certification. Raia therefore assesses compliance at both the platform level and, when appropriate, for a specific AI system or authorized regulated deployment.
Current AI governance approach
Raia's agreements restrict unapproved high-risk and regulated AI uses, require customers to review and validate AI-generated outputs, and assign customers responsibility for the agents, data, workflows, integrations, notices, permissions and connected actions they control. Uses involving legally significant decisions or specified regulated data require additional review and, where applicable, Raia's prior written authorization.
Raia is implementing and documenting an EU AI Act readiness program that includes:
| Program area | Raia approach |
|---|---|
| AI system inventory | Identifying Raia-provided systems, upstream model dependencies, intended purposes, owners, data categories, deployment channels and prohibited or restricted uses. |
| Role and risk classification | Assessing whether Raia, a customer, a reseller or an upstream provider acts as provider, deployer or another operator for the specific system and use. |
| AI transparency | Supporting clear disclosure when a person interacts with a Raia-powered AI system and evaluating applicable marking or disclosure requirements for synthetic content. |
| Human review | Requiring appropriate review and authorization before AI output is used for a legally significant or regulated decision. |
| AI literacy | Providing role-appropriate guidance and training for personnel who develop, operate, support, sell or govern AI systems. |
| Provider governance | Evaluating relevant upstream AI and technology providers through Raia's vendor-management and security processes. |
| Regulated-use approval | Requiring a separate assessment and written authorization before the Platform is used for a proposed high-risk or regulated AI use. |
| Monitoring and response | Extending security, incident, complaint and corrective-action processes to address AI-specific safety, misuse and compliance events. |
Authorized regulated uses
A customer proposing an authorized regulated or potentially high-risk use should provide sufficient information for Raia to assess the intended purpose, users, affected persons, data, outputs, decision impact, human oversight, modifications and deployment context. Where required, Raia and the customer will document applicable roles and responsibilities in a written order form or compliance schedule.
Raia does not develop or market the underlying general-purpose AI models supplied by third-party model providers merely by integrating those models into the Platform. Raia remains responsible for obligations that apply to the AI systems and components it provides, while customers remain responsible for the deployment choices, data, workflows and decisions under their control, subject in each case to mandatory law.
Request Regulatory Assurance Information
Qualified customers may contact r+security@raiaai.com to:
- request Raia's applicable SOC 2 Type II report;
- discuss a DORA assessment or proposed DORA contract requirements;
- request a scoped security, resilience or provider review; or
- discuss an EU AI Act role, transparency or regulated-use assessment.
Customers requesting a DORA review should identify the Raia services and deployment under review, the intended financial activity, relevant service and data regions, and whether the supported function is classified as critical or important.
Customers requesting an EU AI Act review should identify the proposed AI system, intended purpose, users, affected persons, data categories, deployment channels, outputs, decision impact, human oversight and planned modifications or branding.
Shared responsibility: Each customer remains responsible for determining its own regulatory obligations, classifying its use of Raia, configuring and operating its deployment appropriately, maintaining required records, providing applicable notices, performing required human oversight and obtaining its own legal advice. Raia remains responsible for obligations that applicable law assigns to Raia and for the contractual commitments it makes.