AI-powered compliance · Expert oversight · Continuously managed

Services

Structured compliance programmes for EU AI Act, DORA, GDPR, NIS2, and ISO 27001, delivered faster with AI and made defensible with expertise.

We use AI to move faster. We use expertise to make the output defensible. And we manage it continuously so that it stays current. Everything below is delivered through CORA™, our Compliance Operations and Risk Automation service, which means Morclear operates the modules and you receive reviewed output rather than software to run yourself.

Every engagement begins with a 30-minute scoping call at no cost.

What you can buy

AI Act Assessment

Free

Ten minutes. A scored report showing your risk level, the gaps, and prioritised actions under the EU AI Act.

Take the assessment

Gap Assessment

€999

Obligation mapping across every applicable framework, a scored maturity report, and a prioritised remediation roadmap. Delivered in two weeks.

Fixed fee · Two weeks · Expert-reviewed

Individual Module

On request

One CORA™ module delivered on its own, where a single obligation needs closing rather than a full programme.

One to two weeks · Scoped to the module

Programme Build

On request

A complete compliance programme covering policy documentation, risk registers, control frameworks, evidence trails and governance structures, embedded into how your organisation already works.

Eight to twelve weeks · Audit-ready

Managed Compliance

On request

Continuous monitoring, monthly reporting, board-ready summaries and regulatory change alerts, with Regulatory Radar included.

Cancel with 30 days notice

Regulatory Radar

€199/mo

Monitoring of the five frameworks, filtered to what actually affects your firm, with impact analysis and deadline tracking.

Read more

Virtual DPO

On request

A named data protection officer, documentation kept current, breach response, and liaison with the Data Protection Commission.

Read more

EU Authorised Representative

On request

If you sell into the EU with no establishment here, GDPR Article 27, AI Act Articles 22 and 54, and NIS2 Article 26 each require a representative established in the Union. Morclear holds that mandate from Ireland under written appointment.

See how it works

The gap assessment and Regulatory Radar carry a fixed published price. Everything else is scoped to your organisation and quoted after the scoping call, then fixed in writing before any work begins. More on the pricing page.

How the work is delivered

AI can generate compliance documents, but it cannot own them. When a regulator asks who signed off on your ICT risk framework, the answer cannot be a chatbot. Every CORA™ engagement runs the same four steps.

1
You provide documentation
Policies and procedures, vendor contracts, risk registers, and your AI system inventory.
2
CORA™ analyses
Cross-references the articles that apply, identifies gaps, and generates structured draft outputs.
3
Expert review
A compliance professional checks accuracy, edits, and signs off every output, leaving a full audit trail.
4
You receive output
PDF reports, Excel registers, board packs, and the audit evidence behind them.

The eight CORA™ modules

Each module targets a specific compliance workflow. Together they cover the lifecycle from initial gap assessment through to ongoing managed compliance.

DORA Incident Response

Classifies ICT incidents against the DORA Article 18 criteria and prepares competent authority notifications for the initial, intermediate and final reporting stages required by Article 19.

Compliance Audit Engine

Maps existing controls to specific regulatory articles across every applicable framework, identifies gaps, and produces a scored report, an Excel register and a prioritised remediation roadmap.

Third-Party ICT Risk Manager

Parses vendor documentation, builds the DORA register of information, scores vendor criticality, and flags contractual gaps against the Article 30 requirements.

Regulatory Update Monitor

Scans regulatory sources, classifies changes by impact and urgency, links updates to the controls they affect, and powers the Regulatory Radar service.

Board Reporting

Produces board-ready governance packs with coverage metrics, risk summaries, and the evidence of management body oversight that DORA Article 5 expects.

Training & Certification

Designs role-based training mapped to DORA Article 5(4), NIS2 Article 20(2) and the AI literacy duty in Article 4 of the EU AI Act, then tracks completion and generates evidence packs.

NCA Communication

Pre-populates supervisory submission templates with article citations, field validation and completeness checks, formatted to the requirements of the authority the submission is going to.

AI Governance & Risk Framework

Inventories AI systems, classifies them against the EU AI Act risk categories, prepares the conformity documentation required by Articles 9 to 15, and produces fundamental rights impact assessments under Article 27 where they apply.

How we work

Pricing principle

The entry engagements carry a fixed published price so you can start without a negotiation. Everything above them is quoted after a scoping call, because the number genuinely moves with organisation size, framework count and starting position, and quoting a range would tell you less than it appears to. Whatever the figure is, it is fixed in writing before any work begins. No billable hours, no long-term lock-in.

Data handling and AI

Engagements are put in writing before work begins, under a confidentiality agreement and, where personal data is involved, a data processing agreement.

CORA™ is powered by the Anthropic Claude API, contracted with Anthropic Ireland, Limited. Every output is reviewed by a person before delivery and client data is not used to train AI models. Retention periods, processing locations and subprocessor details are set out in the data processing agreement provided at engagement.

Run Free AI Act Assessment Book a Scoping Call

See also: Pricing in detail · Your options · Example compliance scenarios

Primary Regulatory Sources

CORA™ is a trade mark used by Morclear Limited and is delivered as a managed compliance service. Morclear resources are independently produced and do not constitute legal, regulatory, financial or professional advice.