A dated, source-cited report on your AI stack: which vendors sit within reach of the U.S. CLOUD Act, which resell a single upstream model, and which train on your data by default. Written to be handed to security, legal, or your board.
The EDPB’s Recommendations 01/2020 set out six steps. This report produces the evidence for two of them — the two that stall most assessments, because the answer is not in your own systems.
| 1. Know your transfers | Covered, for your AI vendors |
| 2. Identify the transfer tool | Not covered — that is your SCCs or BCRs |
| 3. Assess the third country’s law | This is the report. Who controls each vendor, which jurisdiction can compel disclosure, cited to the vendor’s own documents |
| 4. Adopt supplementary measures | Not covered — encryption, contractual and organisational measures are yours to choose |
| 5. Procedural steps | Not covered |
| 6. Re-evaluate at intervals | Not covered — the record carries the date each document was read, so you re-run it when your own review cycle calls for it |
So this is the evidence pack, not the finished assessment. It answers the question your own records cannot — who actually controls the vendor and under whose law — and leaves the transfer tool and the supplementary measures where they belong, with you and your counsel. If you want the whole thing mapped to your own contracts and residency commitments, that is the Concierge audit.