Lead with
Compliance.
Compliance is essential to responsible corporate and product management. Sovereign organizations understand where regulatory risks arise and how to manage them.
The EU AI Act is a key focus. When AI is used in products and processes, requirements may include labelling, documentation, monitoring and risk management, depending on the use case. Because Onventis integrates AI into its solutions, we continuously translate these requirements into the necessary organizational and technical safeguards.
Regulatory compliance extends beyond AI to the protection of personal data. GDPR compliance is therefore another core element of a sovereign setup. In digital Source-to-Pay processes, sensitive data converges in one place, making data protection, clear responsibilities and controlled processing essential.
Technical and organizational safeguards complete this framework. Our ISO/IEC 27001:2022-certified Information Security Management System (ISMS) provides a binding structure for protecting information. Complementary ISAE 3402-compliant controls and independent audits make relevant internal processes and controls reliable and traceable when our services support customers’ business and control processes.
Together, these elements create a holistic compliance framework: the EU AI Act for responsible AI, the GDPR for personal data, ISO/IEC 27001:2022 for information security management and ISAE 3402 for independently audited internal controls.
FAQ
What does the EU AI Act regulate?
The EU AI Act is the European legal framework for artificial intelligence. It defines obligations depending on the role and use of AI and takes effect in stages. The requirements for providers of general-purpose AI models have been in effect since August 2025.
What is an ISO/IEC 27001:2022-certified ISMS?
An ISMS is an Information Security Management System. The international standard ISO/IEC 27001:2022 ensures that information security is systematically managed, documented and continuously reviewed.
What does ISAE 3402 mean?
ISAE 3402 (International Standard on Assurance Engagements 3402) is an internationally recognized assurance standard developed by the IAASB (IFAC). It ensures the independent examination of internal control systems of service organizations – particularly where services have an impact on the financial or business processes of customers, such as with SaaS, cloud or outsourcing providers.
What is the GDPR?
Regulatory compliance in digital procurement is not limited to AI. Personal data is also processed in procurement processes, for example in master data, approvals, supplier contacts or invoicing processes. The GDPR forms the central European legal framework for this.

