raiaEuropean Regulatory Readiness

European Regulatory Readiness

Raia supports customers evaluating artificial-intelligence and ICT service providers under European regulatory requirements. Our program combines independently assessed security controls with customer-specific contracting, transparency, risk assessment and operational cooperation.

This page is maintained by raia to describe our current regulatory-readiness program. It is not a certification, legal advice, or a substitute for a customer's own regulatory assessment. Each customer remains responsible for its own compliance obligations.

On this page

Digital Operational Resilience Act (DORA) EU Artificial Intelligence Act Request Assurance Information

Digital Operational Resilience Act (DORA)

The EU Digital Operational Resilience Act, or DORA, directly establishes requirements for regulated financial entities. DORA is not a general certification for software vendors, and using Raia does not transfer a customer's regulatory responsibilities. Raia provides information, assurance and cooperation to help applicable customers assess and manage Raia as an ICT third-party service provider.

Security and resilience foundation

Raia's DORA customer-enablement work builds on its SOC 2 Type II examination and documented controls for information security, identity and access management, encryption, logging and monitoring, change management, vulnerability management, incident response, vendor risk, backup, business continuity and disaster recovery.

SOC 2 and DORA serve different purposes. Raia's SOC 2 Type II report provides independent assurance about the controls within the report's defined system, scope and examination period. DORA additionally requires regulated customers to address matters such as ICT contract terms, provider and location data, incident-reporting support, ongoing monitoring, resilience testing, audit and authority access, subcontracting and exit planning.

Support for financial-services assessments

Review areaRaia support
Independent assuranceQualified customers may request Raia's applicable SOC 2 Type II report and supporting security documentation under appropriate confidentiality terms.
Security documentationRaia maintains documented policies and procedures for security, access, encryption, vulnerability management, incident response, business continuity, disaster recovery, vendor management and data protection.
Incident cooperationRaia maintains processes for detection, escalation, containment, recovery, evidence preservation, customer communication and post-incident review. Applicable notice and cooperation commitments are governed by the customer agreement.
Operational resilienceRaia maintains backup, business-continuity and disaster-recovery procedures and conducts recurring exercises. Additional architecture, recovery-objective and test information may be made available to qualified customers under confidentiality terms.
Provider informationRaia performs risk-based reviews of relevant providers and can discuss service, processing-location and provider information for a scoped assessment.
Data returnRaia supports customer-data export, retention and deletion in accordance with the applicable agreement, product capabilities and data-protection terms.
Customer-specific reviewRaia's Security and Legal teams can review DORA due-diligence requests and proposed contractual requirements for the customer's intended service and deployment.

DORA customer-enablement program

Raia is extending its existing SOC 2 control program with DORA-oriented customer deliverables, including contractual terms, structured provider and location information, incident-reporting support, resilience and testing evidence, audit cooperation, relevant subcontractor information, and exit and transition documentation.

The requirements applicable to a particular arrangement depend on the Raia services used, the customer's regulated activities, the deployment and data involved, and whether the customer classifies the supported function as critical or important.

EU Artificial Intelligence Act

The EU AI Act assigns obligations according to the AI system, its intended purpose, the parties' roles and the deployment context. It is not a single company-level certification. Raia therefore assesses compliance at both the platform level and, when appropriate, for a specific AI system or authorized regulated deployment.

Current AI governance approach

Raia's agreements restrict unapproved high-risk and regulated AI uses, require customers to review and validate AI-generated outputs, and assign customers responsibility for the agents, data, workflows, integrations, notices, permissions and connected actions they control. Uses involving legally significant decisions or specified regulated data require additional review and, where applicable, Raia's prior written authorization.

Raia is implementing and documenting an EU AI Act readiness program that includes:

Program areaRaia approach
AI system inventoryIdentifying Raia-provided systems, upstream model dependencies, intended purposes, owners, data categories, deployment channels and prohibited or restricted uses.
Role and risk classificationAssessing whether Raia, a customer, a reseller or an upstream provider acts as provider, deployer or another operator for the specific system and use.
AI transparencySupporting clear disclosure when a person interacts with a Raia-powered AI system and evaluating applicable marking or disclosure requirements for synthetic content.
Human reviewRequiring appropriate review and authorization before AI output is used for a legally significant or regulated decision.
AI literacyProviding role-appropriate guidance and training for personnel who develop, operate, support, sell or govern AI systems.
Provider governanceEvaluating relevant upstream AI and technology providers through Raia's vendor-management and security processes.
Regulated-use approvalRequiring a separate assessment and written authorization before the Platform is used for a proposed high-risk or regulated AI use.
Monitoring and responseExtending security, incident, complaint and corrective-action processes to address AI-specific safety, misuse and compliance events.

Authorized regulated uses

A customer proposing an authorized regulated or potentially high-risk use should provide sufficient information for Raia to assess the intended purpose, users, affected persons, data, outputs, decision impact, human oversight, modifications and deployment context. Where required, Raia and the customer will document applicable roles and responsibilities in a written order form or compliance schedule.

Raia does not develop or market the underlying general-purpose AI models supplied by third-party model providers merely by integrating those models into the Platform. Raia remains responsible for obligations that apply to the AI systems and components it provides, while customers remain responsible for the deployment choices, data, workflows and decisions under their control, subject in each case to mandatory law.

Request Regulatory Assurance Information

Qualified customers may contact r+security@raiaai.com to:

Customers requesting a DORA review should identify the Raia services and deployment under review, the intended financial activity, relevant service and data regions, and whether the supported function is classified as critical or important.

Customers requesting an EU AI Act review should identify the proposed AI system, intended purpose, users, affected persons, data categories, deployment channels, outputs, decision impact, human oversight and planned modifications or branding.

Shared responsibility: Each customer remains responsible for determining its own regulatory obligations, classifying its use of Raia, configuring and operating its deployment appropriately, maintaining required records, providing applicable notices, performing required human oversight and obtaining its own legal advice. Raia remains responsible for obligations that applicable law assigns to Raia and for the contractual commitments it makes.