NADOVO Plattform
AI-generated A new client, and you’re setting up yet another Excel sheet. AI systems in column A, risk class in column B, owners in column C. By the fifth client you’re maintaining five sheets in five folders. By the twentieth, you’re searching.
That is not compliance. That is a filing cabinet hoping never to be audited.
It’s not classification that scales badly, it’s the evidence
You determine the risk class of an AI system in minutes. That is not the bottleneck. The bottleneck comes when twenty clients have to prove, all at once, that their classification is correct, that someone owns it, that it is still current.
With one file per customer, that can neither be cleanly separated nor proven. And every change to a system starts the documentation over.
An example. A client replaces its recruiting tool with a new one. In the spreadsheet that means overwriting one row. The old classification is gone, and with it the evidence that it was right at the time. An audit wants to see exactly this history, not just today’s state.
A classification tool is not yet a multi-tenant solution
Anyone who guides several companies through the EU AI Act as a consultant, external AI compliance officer or data protection officer knows the difference. For one client, compliance is doable with diligence. For twenty, it becomes a systems problem.
The EU AI Act does not require a one-time checkmark, but a continuous process: inventory, risk classification, risk assessment, proof of AI literacy, ongoing monitoring, incident reporting. Every step has to stay documented and traceable. And because AI systems change, this is not a state you establish once, but a permanent task. Per client.
Multi-tenant means three things, not one
Many tools call themselves multi-tenant and mean: several customers in one list. That is not enough. A real multi-tenant solution has to deliver three things.
First, separate cleanly. Each client gets its own area, its own data, its own permissions. What happens at customer A is invisible to customer B.
Second, cover the whole process, not just classification. Classification is the beginning. After it come risk assessment with an action plan, human oversight, for high-risk systems the fundamental rights impact assessment under Art. 27, proof of AI literacy and an incident management with clear reporting deadlines.
Third, document in a verifiable way. Not a loose PDF you piece together after the fact in a dispute, but an immutable audit trail that shows who decided what and when.
How we built this at NADOVO
We built the NADOVO platform to be multi-tenant from the start. Consulting agencies and external officers serve their customers through one interface, with separate areas per client and defined roles.
The process follows the NADOVO framework in five phases. First, all of a client’s AI systems are captured. Then each purpose of use is defined as its own process and classified rule-based, along the risk classes of the EU AI Act up to the high-risk areas from Annex III. Because it is not the tool that determines the risk, but the concrete use. Why the same AI system becomes a harmless or a high-risk AI process depending on the application is the core of our methodology.
The third phase brings the risk assessment with action planning and, where needed, the fundamental rights impact assessment. The fourth documents training and thereby proves the required AI literacy. The fifth covers ongoing monitoring, including incident management with automatic deadline tracking.
The classification is rule-based, not AI-driven. Every result is traceable and identical on every run. NADOVO itself therefore does not fall under the EU AI Act. All data is held in Germany. And the audit trail records every decision in a revision-safe way, retained for ten years.
Who this pays off for
The platform is aimed at consulting firms that guide their customers through EU AI Act compliance in a structured way. At external AI compliance officers who carry several mandates in parallel. And at data protection officers who want to extend their portfolio with AI compliance and rely on a verifiable system doing so.
For all of them, compliance is not a project that ends once, but a service they deliver again and again. And a service only scales if the system beneath it scales.
What this means for you
Imagine that tomorrow a supervisory authority asks about one of your clients: which AI systems are running, how are they classified, who owns them? How quickly would you have the file together? And how quickly for all your clients at once?
If the answer starts to falter, that is rarely down to missing know-how. It is down to a missing system. That is exactly why we built the NADOVO platform as a multi-tenant solution.
About the author
Jochen Stier is a co-founder of NADOVO with over 20 years of experience in process management and IT service management. He helps German SMEs implement the requirements of the EU AI Act systematically and pragmatically. His 5-phase NADOVO framework combines regulatory requirements with practical feasibility, without enterprise budgets or complex tools.
Further reading: