RIXA Advisory

RIXA Advisory · Find evidence and control gaps before a client, auditor or regulator does

Could you prove your regulatory risks are under control tomorrow?

AI Act readiness, critical ICT vendors and internal controls often fail at the same point: obligations, evidence, owners and actions are disconnected. RIXA turns that gap into a review-ready management pack.

Applicability and risk points mapped

Management visibility, evidence and action—not generic advice.

Vendor and control gaps identified

Management visibility, evidence and action—not generic advice.

Findings linked to sources

Management visibility, evidence and action—not generic advice.

30 / 60 / 90 action plan

Management visibility, evidence and action—not generic advice.

Management blind spot

Can you answer these today?

01Which AI Act obligations apply?
02Which ICT providers are critical?
03Which controls lack retained evidence?
04Which findings have no owner or deadline?
05What could you send tomorrow?

Three exposure areas

Start with the risk management already needs to understand

RIXA uses the same evidence discipline across three distinct management questions.

Hidden exposure

These problems often exist before management can see them

The issue is rarely a complete absence of documents. It is that obligations, contracts, controls and retained evidence do not form one defensible management view.

Business consequences

What happens when evidence and ownership remain disconnected?

The first loss is often not a fine. It is delayed decisions, failed client reviews, unmanaged dependencies and the inability to defend a conclusion.

AI Act obligations may be mis-scoped or missed.
Critical vendor dependencies remain insufficiently documented.
Contracts omit evidence, continuity or exit provisions.
Customer due-diligence requests become urgent fire drills.
Controls cannot be demonstrated with retained evidence.
Findings remain unowned and unresolved.

The immediate risk is a failure of management oversight.

Serious regulatory penalties can apply in some cases. But the more common first problem is simpler: management cannot show what applies, what was reviewed, what is missing, who owns it and what happens next.

Management self-test

Can your leadership answer these six questions?

A vague answer is already useful information. It shows where scope, evidence or ownership is missing.

01Which AI Act roles, risk categories and obligations apply?
02Which ICT providers support critical or important functions?
03Which contracts, controls and policies lack retained evidence?
04Which gaps are high priority, and why?
05Who owns each finding and by when?
06What would you send a client, auditor or regulator tomorrow?

The RIXA response

Turn regulatory exposure into a controlled action plan

RIXA does not begin with a generic policy document. It begins with applicability, source evidence and the management decision that must be supported.

01

Establish scope and applicability

Define the review question, relevant regulation, risk area, entities, providers, controls and decision boundary.

02

Map evidence line by line

Connect source rows, contracts, policies, control records and retained evidence to the review criteria.

03

Issue precise findings and actions

Separate confirmed gaps from assumptions, assign owners and targets, and build evidence requests and remediation steps.

04

Prepare management for external questions

Deliver a management brief, source-aware working files and a 30 / 60 / 90 action plan.

Proof before purchase

See the structure management will receive

A fictional sample shows how RIXA connects source rows to findings, regulatory references, evidence requests, owners and a practical action plan.

Defined responses

Choose the response that matches the management problem

Start with the smallest fixed scope that answers the question. Expand only when the evidence shows a broader need.

Founder-led

Built for decisions, not consulting theatre

RIXA was created in Brussels by a finance, controls and compliance practitioner. The method makes obligations and exposure visible, connects conclusions to source evidence and leaves management with decisions it can execute.

You cannot govern what you cannot see, and you cannot defend what you cannot prove.

Initial review

Tell us what management cannot currently demonstrate

Describe the regulation, client request, critical provider or control problem. RIXA will reply with the narrowest useful scope—not a generic consulting proposal.

carlos@rixadvisory.com

RIXA provides human-reviewed evidence-readiness support. It does not provide legal advice, statutory audit assurance, certification or a compliance guarantee. Findings and applicability assumptions require client and human reviewer validation. Client-identifiable or vendor-identifiable data can be anonymised where appropriate.

RIXA Advisory — Professional activity declared through Smart / Productions Associées — VAT: BE 0896.755.397

Staff access