We use AI to move faster. We use expertise to make the output defensible. And we manage it continuously so that it stays current. Everything below is delivered through CORA™, our Compliance Operations and Risk Automation service, which means Morclear operates the modules and you receive reviewed output rather than software to run yourself.
Every engagement begins with a 30-minute scoping call at no cost.
What you can buy
AI Act Assessment
Ten minutes. A scored report showing your risk level, the gaps, and prioritised actions under the EU AI Act.
Take the assessmentGap Assessment
Obligation mapping across every applicable framework, a scored maturity report, and a prioritised remediation roadmap. Delivered in two weeks.
Fixed fee · Two weeks · Expert-reviewed
Individual Module
One CORA™ module delivered on its own, where a single obligation needs closing rather than a full programme.
One to two weeks · Scoped to the module
Programme Build
A complete compliance programme covering policy documentation, risk registers, control frameworks, evidence trails and governance structures, embedded into how your organisation already works.
Eight to twelve weeks · Audit-ready
Managed Compliance
Continuous monitoring, monthly reporting, board-ready summaries and regulatory change alerts, with Regulatory Radar included.
Cancel with 30 days notice
Regulatory Radar
Monitoring of the five frameworks, filtered to what actually affects your firm, with impact analysis and deadline tracking.
Read moreVirtual DPO
A named data protection officer, documentation kept current, breach response, and liaison with the Data Protection Commission.
Read moreEU Authorised Representative
If you sell into the EU with no establishment here, GDPR Article 27, AI Act Articles 22 and 54, and NIS2 Article 26 each require a representative established in the Union. Morclear holds that mandate from Ireland under written appointment.
See how it worksThe gap assessment and Regulatory Radar carry a fixed published price. Everything else is scoped to your organisation and quoted after the scoping call, then fixed in writing before any work begins. More on the pricing page.
How the work is delivered
AI can generate compliance documents, but it cannot own them. When a regulator asks who signed off on your ICT risk framework, the answer cannot be a chatbot. Every CORA™ engagement runs the same four steps.
The eight CORA™ modules
Each module targets a specific compliance workflow. Together they cover the lifecycle from initial gap assessment through to ongoing managed compliance.
DORA Incident Response
Classifies ICT incidents against the DORA Article 18 criteria and prepares competent authority notifications for the initial, intermediate and final reporting stages required by Article 19.
Compliance Audit Engine
Maps existing controls to specific regulatory articles across every applicable framework, identifies gaps, and produces a scored report, an Excel register and a prioritised remediation roadmap.
Third-Party ICT Risk Manager
Parses vendor documentation, builds the DORA register of information, scores vendor criticality, and flags contractual gaps against the Article 30 requirements.
Regulatory Update Monitor
Scans regulatory sources, classifies changes by impact and urgency, links updates to the controls they affect, and powers the Regulatory Radar service.
Board Reporting
Produces board-ready governance packs with coverage metrics, risk summaries, and the evidence of management body oversight that DORA Article 5 expects.
Training & Certification
Designs role-based training mapped to DORA Article 5(4), NIS2 Article 20(2) and the AI literacy duty in Article 4 of the EU AI Act, then tracks completion and generates evidence packs.
NCA Communication
Pre-populates supervisory submission templates with article citations, field validation and completeness checks, formatted to the requirements of the authority the submission is going to.
AI Governance & Risk Framework
Inventories AI systems, classifies them against the EU AI Act risk categories, prepares the conformity documentation required by Articles 9 to 15, and produces fundamental rights impact assessments under Article 27 where they apply.
How we work
Pricing principle
The entry engagements carry a fixed published price so you can start without a negotiation. Everything above them is quoted after a scoping call, because the number genuinely moves with organisation size, framework count and starting position, and quoting a range would tell you less than it appears to. Whatever the figure is, it is fixed in writing before any work begins. No billable hours, no long-term lock-in.
Data handling and AI
Engagements are put in writing before work begins, under a confidentiality agreement and, where personal data is involved, a data processing agreement.
CORA™ is powered by the Anthropic Claude API, contracted with Anthropic Ireland, Limited. Every output is reviewed by a person before delivery and client data is not used to train AI models. Retention periods, processing locations and subprocessor details are set out in the data processing agreement provided at engagement.
See also: Pricing in detail · Your options · Example compliance scenarios
Primary Regulatory Sources
CORA™ is a trade mark used by Morclear Limited and is delivered as a managed compliance service. Morclear resources are independently produced and do not constitute legal, regulatory, financial or professional advice.