Clarvela / Regvela
Regvela
Regulatory scoping
Which regulations apply to this IT system?
Regvela is used when a business introduces or changes an IT system. It works out which of ISO/IEC 27001, the GDPR, NIS2, DORA and the AI Act apply, separates the company's own obligations from those that follow from customer contracts, and turns the result into questions with a responsible role and a due date.
Illustration based on the built-in example. Figures are examples.
How it works
Four steps from questions to decision
- 1
Register the system
Name, purpose, the companies and countries that use it, and the kind of information it holds.
- 2
Answer the pre-assessment
Short questions about the company and the system decide which regulations apply, and on what basis: as the company's own obligations, or as requirements its business customers pass on through their contracts when the company is their supplier.
- 3
Work through the questions
Only the questions that apply are shown, each with guidance, a reference, a responsible role and a due date.
- 4
Decide on go-live
Open items, exceptions and residual risks are brought together for an approval with a clear owner, and exported to CSV or JSON.
What it covers
132 questions, shown only where they apply
Which areas are shown depends on the answers in the pre-assessment.
| Area | Scope | Questions |
|---|---|---|
| Ownership and basics | Purpose, ownership, inventory, criticality and classification | 10 |
| ISO/IEC 27001 | Risk, technical security, access, operations, awareness and suppliers, scaled to three protection levels | 48 |
| GDPR | As controller, and as processor for customers | 17 |
| NIS2 | When the company or its customers are in scope | 8 |
| DORA | For financial entities and for ICT providers that serve them | 19 |
| EU AI Act | Obligations as deployer and as provider | 19 |
| Customer commitments | Requirements several regulations share, asked once | 5 |
| Go-live decision | Findings, residual risk and approval | 6 |
Good to know
Before you start
No personal data needed
No personal data is needed for Regvela to work. Responsibilities are recorded as functions and roles, not names. Each assessment can be exported to keep a copy or to share it with colleagues.
What the results mean
Regvela supports the assessment and shows where each requirement comes from. It is not legal advice: the decision, and the responsibility for compliance, stay with the organisation.
See a worked example
Regvela includes a fictional IT system with a completed assessment. Choose "Open example" in the tool to see how the questions, answers and go-live decision fit together before you register your own system.