Governing Artificial Intelligence, Data and Digital Risk
The adoption of artificial intelligence and digital technologies is transforming processes, products and decision-making models. At the same time, the AI Act, GDPR, NIS2, Data Act, Cyber Resilience Act (CRA) and other European regulatory frameworks are creating an increasingly interconnected regulatory landscape. For businesses, the challenge is no longer limited to complying with individual regulatory requirements. Organisations need to establish a governance model capable of identifying risks, allocating responsibilities, controlling the use of technologies and enabling the organisation to innovate in an informed and responsible manner.
RSM Studio Tax Legal & Advisory supports Italian and international businesses in the governance of artificial intelligence, data and digital risk, integrating legal, organisational and technological expertise.
From Regulatory Compliance to Digital Risk Governance
Privacy, artificial intelligence and cybersecurity are governed by different regulatory frameworks and control mechanisms, yet within an organisation they often intersect across the same processes, data, suppliers and business decisions.
For this reason, we adopt a Governance by Design approach: we start from the way your organisation actually operates and integrate regulatory requirements into decision-making processes, control systems and corporate responsibilities. The objective is not to add new layers of compliance, but to build a digital governance framework that is clear, proportionate and verifiable. A model that is effective because it can be implemented in practice — one that goes beyond policies and documentation and becomes embedded in the way the organisation operates.
How We Support Organisations
AI Governance
We support businesses in designing and implementing artificial intelligence governance frameworks, including use-case mapping, roles and responsibilities, AI policies, approval processes, monitoring activities, and reporting and information flows to management and control functions.
AI Act and Artificial Intelligence Regulation
We assist organisations in assessing their role under the AI Act, classifying AI systems, identifying applicable requirements, managing supply-chain implications, and establishing the related governance and accountability frameworks.
Digital Risk Governance
We help organisations coordinate risks arising from data, AI, cybersecurity and digital technologies, reducing overlaps and organisational silos across legal, compliance, IT, security, risk management and business functions.
NIS2 and Cyber Governance
We support management and corporate functions in translating NIS2 and cybersecurity requirements into clear responsibilities, decision-making processes, control systems and information flows aligned with the organisation's governance framework.
AI Procurement and Third-Party Risk
We support procurement, legal, IT and business functions in assessing AI vendors and solutions, reviewing provider documentation, and defining contractual safeguards relating to data, security, intellectual property, auditability, liability and regulatory compliance.
AI Impact and Risk Assessment
We assist organisations in assessing risks associated with AI systems and coordinating the assessment tools required or recommended under the applicable regulatory framework, including AI Act assessments, Data Protection Impact Assessments (DPIAs), Fundamental Rights Impact Assessments (FRIAs) and internal risk assessment processes.
A Multidisciplinary Approach
Digital regulation cannot be effectively addressed through isolated areas of expertise. The Data, AI & Digital Law department works in coordination with RSM's other areas of expertise in cybersecurity, risk management, technology and organisational design, enabling organisations to address the legal, organisational and technological dimensions of digital transformation in an integrated manner.
Governance by Design
We firmly believe that effective governance requires a systemic view of the organisation. Our governance frameworks are grounded in practical experience and are designed to address fundamental questions:
- What technologies, data and AI systems do we use?
- What risks do they generate?
- Who is authorised to approve their use?
- Who is responsible for them?
- What controls need to be performed?
- What information needs to reach management?
- How do we assess our suppliers?
- How do we document the decisions made?
Having effective governance over the answers to these questions means transforming compliance from a formal exercise into a genuine business management tool.
Our Professionals
The Data, AI & Digital Law department is led by Emanuele Petrilli, Partner at RSM Studio Tax Legal & Advisory, and supports businesses and organisations on legal and governance matters relating to data, artificial intelligence, cybersecurity and digital transformation.
Let's Discuss Your Project
Are you adopting artificial intelligence systems, developing an AI governance framework, implementing a system that processes data at scale, or more broadly reviewing your digital risk governance model? Our team can help you translate the regulatory framework into an operational model that is consistent with your organisation and aligned with your business objectives.