Educational content

Deep-dive lessons.

Long-form explainers on each framework. Built to be the clearest resource available on these topics, in English and German.

Lesson 01
EU AI Act Fundamentals
Four risk tiers, who is covered, what triggers each tier, and when each provision takes effect.
Available now
Lesson 02
DORA Deep Dive
ICT risk management requirements, incident reporting, third-party register, and resilience testing.
Available now
Lesson 03
NIS2 in Practice
Sector classification, registration thresholds, security measures, and breach notification timelines.
Available now
Lesson 04
MaRisk for AI
Model risk management under AT 4.3, IT risk under AT 7.2, and how AI-specific guidance is evolving.
Available now
Lesson 05
BAIT Explained
IT strategy, operations, outsourcing, and how BAIT interacts with the new AI-related MaRisk addendum.
Available now
Lesson 06
BaFin AI Supervision
How BaFin examines AI systems in scope, what evidence they ask for, and how to prepare.
Available now
Lesson 07
ISO 42001 Certification
Building an AI management system, the certification path, and how it complements EU AI Act compliance.
Available now
Lesson 08
MiFID II for Trading Venues
Investment firms, the RM/MTF/OTF venue types, algorithmic trading and RTS 6, best execution, and reporting.
Available now
Lesson 09
MiCAR for Crypto-Assets
Token categories (ARTs, EMTs, other), CASP authorisation, white papers, custody, and the 2024-2026 timeline.
Available now
Lesson 10
The Cyber Resilience Act
Products with digital elements, product classes, secure-by-design, SBOM, the 24h/72h reporting, and the timeline.
Available now
Lesson 11
GDPR Fundamentals
Who is in scope, the six lawful bases, data subject rights, records and DPIAs, the 72-hour breach clock, when a DPO is mandatory, and the fines.
Available now
SchutzIQ - EU compliance platform