Checklists
Auditable step-by-step checklists for compliance and delivery — each with a clear section on what it does not cover.
EU AI Act conformity: a checklist for the first pass
A workable first pass through the EU AI Act has six parts: know which AI runs in the business, determine your role for each system, classify under Article 6, check transparency duties separately, ensure AI literacy, and file everything so it can be found under scrutiny.
7 items
High risk or not: reasoning an Annex III classification properly
High-risk classification follows a fixed order: first the deployment area under Annex III, then whether the system plays a substantive role in the decision, then the exemption in Article 6(3). Each of those steps has to be documented with reasoning.
7 items
AI literacy under Article 4: from intention to evidence that holds
Article 4 asks for a sufficient level of AI literacy, measured against role, context and the people affected. It becomes workable in four moves: form roles, set a depth per role, train accordingly, and record attendance with date, content and the link to the role.
7 items
GDPR for SaaS: what has to stand before your first enterprise customer
Six areas are unavoidable for a SaaS product: a legal basis per processing activity, a maintained processing register, data subject rights implemented in the system, a deletion concept that actually works, clean sub-processor chains, and a demonstrable statement on data residency.
7 items
Reviewing a data processing agreement: what to look for before signing
Six points decide a DPA review: subject matter and instruction binding, the sub-processor chain and your right to object, place of processing, assistance with data subject rights, the breach notification route, and what happens to the data when the contract ends.
7 items
Technical due diligence: what can be established in a few days
Technical due diligence under time pressure concentrates on six questions: does the architecture carry the planned growth path, how large is the technical debt, does the system depend on individuals, how do security and licensing stand, and can operations be handed over.
7 items
Technical SEO review: the points that actually block indexing
Most technical SEO problems trace back to a handful of causes: pages are not indexable, canonicals point elsewhere, the sitemap lists pages that should not be indexed, hreflang is not reciprocal, or pages carry almost no internal links.
8 items
Visibility in AI answers: a checklist for being citable
Being citable in AI answers rests on a few properties: a short self-contained answer near the top, unambiguous statements instead of marketing language, verifiable claims with a date and an author, clean access for AI crawlers, and identifiable authorship.
8 items
MVP launch: what has to stand before your first paying customer
Five things have to stand before an MVP launch: a working payment path, a data model that permits later change, a route to delete accounts, a way to learn that something has broken, and basic legal documents. Everything else can wait.
7 items
Preparing a cloud migration: the questions before anything moves
Cloud migrations rarely fail on technology; they fail on preparation. Unknown dependencies, unresolved data classification, a cost model that only becomes visible after the move, and missing acceptance criteria against which success could be measured at all.
8 items
Replacing a legacy system: the groundwork that decides the outcome
Legacy replacements usually fail on three things: undocumented business logic nobody understands any more, data quality that only surfaces during migration, and a missing switch-off date, which leaves both systems running in parallel indefinitely.
7 items
Choosing a software partner: what to settle before you commission
Choosing a software partner is decided less by references than by four contractual points: who owns the result, who holds access to the systems, what a handover looks like, and what happens when the engagement ends.
8 items
