Legal audit of the AI systems your company already uses
The company believes it uses two or three artificial intelligence tools and the inventory ends up with fifteen. This audit does not opine on the technology: it examines which systems are in use, what data goes in, what decisions come out and what document backs each of those things. What you get at the end is an inventory ranked by risk, a findings matrix with an owner and a priority for each item, and a roadmap for fixing what is exposed today.
What the audit looks at
Colombia has no general artificial intelligence statute today, and that is where the most common misunderstanding starts: believing that until such a law exists there is nothing to comply with. Every system the company uses is already subject to the personal data protection regime, the Consumer Statute, intellectual property rules, competition law, employment law and the contracts the company has already signed with its clients and suppliers. The audit tests the real use of AI against that framework, which is enforceable now.
System inventory
Nobody can govern what they have not counted. The first deliverable is a real inventory, not the list the IT department hands over.
- Formally contracted tools, free tools and informal use of AI assistants by the teams.
- In-house models, third party models and AI components embedded in software the company already had.
- What data goes into each system, who enters it, where it is stored and who can see the output.
- The internal owner of each system and the business decision that system supports.
Risk classification
The risk does not sit in the technology but in the decision it supports. We classify each system by its impact on people —customers, employees, candidates, suppliers—, by the sensitivity of the data it handles and by how reversible the harm is. A marketing copy generator and a model that prioritises credit applications do not deserve the same treatment, and treating them alike spends the compliance budget in the wrong place.
Personal data protection
This is the front with obligations that are enforceable today. We review the processing against Law 1581 of 2012, Decree 1377 of 2013 and the positions taken by the Superintendence of Industry and Commerce.
- Legal basis and the data subject's authorisation for the specific use the system makes.
- Purpose limitation. If the data was collected for one thing, models are not trained on it for another without resolving that first.
- Whether the privacy notice and the processing policy describe what the system actually does.
- The vendor's role as processor, subprocessors, international transfers and where the infrastructure really sits.
- Retention, deletion and the vendor's policy on retraining with client data.
- Security, access control and incident protocol.
Automated decisions, consumers and intellectual property
Where the system supports decisions on credit, pricing, recruitment, customer prioritisation or account blocking, the company must be able to explain the criterion, keep the audit trail and offer human review. Where the system speaks to the consumer, what it promises binds the company under the Consumer Statute. And where it generates content, someone has to answer where the input data came from, who owns the output and what company information should never have left towards a third party tool.
How we work
- Phase 1 — Inventory. Interviews by department and a survey of systems and data, until the map of real use exists.
- Phase 2 — Diagnosis. Findings matrix with criticality, applicable rule, owner and estimated effort.
- Phase 3 — Remediation. Correction of documents and clauses, internal policy and incident protocol.
- Phase 4 — Maintenance. Periodic review and support when a new use case appears.
Scope is agreed in writing before we start and everything we receive is handled as confidential information.
International standards, in their place
They are not binding Colombian law. The European Artificial Intelligence Regulation, the NIST AI Risk Management Framework and ISO/IEC 42001 are the good practice standard that corporate clients, investors and auditors now ask for. We use them as reference frameworks and say plainly what Colombian law requires of you and what the market requires of you, which are two different conversations and usually arrive mixed together.
What the client receives
- The inventory of AI systems classified by risk.
- The findings matrix, with criticality, applicable rule, owner and suggested deadline.
- The remediation roadmap: what gets fixed first and what can wait until the next renewal.
- An executive report for the board or a committee, written in business language.
We do not certify that a system is lawful and we do not promise outcomes. We tell you precisely where you are exposed, what to fix first and how to leave the evidence ready for the day someone asks.
Let's solve your legal matter
Every case starts with an honest conversation. Book 30 minutes, no commitment.
Request the audit →