Resource library¶
Practical artefacts for turning regulation into an operating model: controls, documents, ownership, evidence. Pick the area you work in, then drill into the branch you need. The branches cover EU digital regulation, since that's where my desk is, plus cross-mappings for teams juggling more than one framework. More branches will come as the library grows.
The tree¶
DORA
Digital operational resilience for financial entities. The most developed branch. This is where the library started.
ISO 27001
The management-system standard the other branches keep pointing at. A full implementation kit, and a clause-by-clause reading.
NIS2
Cybersecurity for essential and important entities, across eighteen sectors and twenty-seven national implementations.
EU AI Act
Risk-based rules for AI systems. Obligations differ sharply by role and risk class, so scoping comes first.
GDPR
Data protection as an operating discipline: the registers, assessments and processes that make compliance demonstrable.
Cross-regulation mappings
Where the obligations overlap, and how one control, document or process can satisfy several regulations at once.
The toolshop
Skills and small automations that make the work easier, starting with risk assessment.
Worked examples
Finished artefacts, end to end, so you can see the standard before building your own.
What kind of artefacts live here¶
Every resource falls into one of a few types, and each page tells you which:
| Type | What it gives you |
|---|---|
| Checklist | Step-by-step readiness or review list you can run against your own organization |
| Document inventory | The policies, registers and procedures a regulation expects to exist, with ownership suggestions |
| Control mapping | Regulation articles mapped to concrete controls (and to common frameworks where useful) |
| Responsibility matrix | Who owns what: management body, second line, IT, procurement, vendors |
| Evidence examples | What "proof this works" looks like for an auditor or supervisor |
Sources
All artefacts are built from public and official sources: EUR-Lex texts, European Supervisory Authority publications, ENISA and EDPB guidance, plus original templates. No internal or proprietary material from any employer, ever.