fact_check Field Research 2026

Compliance Operations & Automation Survey

A 4–5 minute survey on how companies in regulated industries actually run their compliance — the day-to-day work of meeting GDPR, DORA, MDR, ISO 27001, AML and the rest — and how much of it could be automated. Responses are anonymous unless you choose to share your contact, and participants can request the aggregated results report.

★ Core marks the short conference set. Also work with AI? Take our companion AI Governance & EU AI Act survey.

How much time do you have?

Pick the quick set or the full survey — either way we start with your details. You can switch anytime.

Not sure? Quick is a great start — you can always continue to the full set at the end.

A. About you & your organisation

For segmentation — and it decides which industry questions you'll see.

Company size (employees)?★ Core
Are you supervised by a specific regulator or notified / certification body?
moodThe GDPR officer's favourite pickup line: 'May I process your data?' 💌

B. How you run compliance today

The day-to-day operations — team, tooling, time, and audit-readiness.

How is regulatory compliance managed in your organisation?★ Core
What do you run compliance WITH today?
How much staff time goes to compliance work each month?★ Core
moodBaFin doesn't knock. BaFin schedules an examination. 🚪
How do you collect and store evidence for audits / exams?
How many separate regulations / standards must you stay compliant with at once?
Biggest compliance-operations pains? (select all that apply)★ Core
In the last 24 months, have you experienced any of these? (select all that apply)
How confident are you that you could pass a surprise audit tomorrow?★ Core

C. Your industry's requirements

Tailored to the industry you picked — only the relevant block is shown.

moodOur policy library has more chapters than anyone has read. 📚
No industry-specific questions for your selection — you're all set. Continue to the last section.
Which of these apply to you? (select all that apply)★ Core
DORA — status of your ICT risk register, third-party register & incident-reporting process?
AML — how is transaction monitoring / suspicious-activity reporting handled?
How often are you examined by a supervisor or external auditor?
Which of these apply to you? (select all that apply)★ Core
How do you maintain technical documentation / device or drug dossiers?
Post-market surveillance / adverse-event reporting — how is it run?
Beyond GDPR baseline, is patient / clinical-data protection formalised?
Which of these apply or are you pursuing? (select all that apply)★ Core
SOC 2 / ISO 27001 — where are you?
How do you manage security-control evidence (access reviews, pentests, vendor risk)?
CRA readiness (SBOM, vulnerability disclosure, security updates)?
Which of these apply to you? (select all that apply)★ Core
AML / KYC on buyers, sellers & investors — how performed?
ESG / energy-performance reporting obligations — status?
How is compliance documentation handled across multiple properties / entities?

D. Automating compliance

What you'd want software to take off your plate.

If software could auto-track your obligations, collect the evidence and flag every deadline, how valuable would that be?★ Core
Which compliance tasks would you most want automated? (select all that apply)
moodWhy did the control fail? It had no evidence it ever worked. 🕳️
How do you handle compliance today vs. how you'd like to?★ Core
Who owns the budget for compliance tooling?
Your compliance / GRC budget over the next 12 months?
How likely are you to adopt a compliance-automation platform in the next 12 months?★ Core
Top criteria when choosing compliance software? (select all that apply)
Would "map once, comply across many" (reuse one control across GDPR / ISO 27001 / DORA / SOC 2…) be compelling?

E. Optional open feedback

Skip these if you're short on time.

moodOur password policy is so strong that even we can't log in. 🔐
mark_email_read

Want the aggregated results report? (optional)

Start here — or skip straight to the questions. Add your details to receive the anonymised, cross-industry findings when they’re published — and we’ll only reach out if there’s something genuinely relevant. Prefer to stay anonymous? Just leave this blank and hit Nextyour response stays completely anonymous. Your progress is saved as you go, so you can come back and finish later.

Voluntary and anonymous unless you share contact details. Lawful basis: consent. You may request deletion at any time — info@alleina.co.

Also work with AI? Take our companion AI Governance & EU AI Act survey — we'll carry over what you've already told us.

moodThe best time to collect evidence was a year ago. The second best time is before the auditor arrives. ⏰
Alleina AI

Responsible AI governance platform for European enterprises, SMEs, and startups. EU AI Act compliance, bias detection, and model explainability.

Stay Updated

Get the latest on AI governance, regulatory updates, and platform news.

Gefördert durch

Universität Koblenz EXIST – Existenzgründungen aus der Wissenschaft StArfrica – Startup Germany-Africa Bundesministerium für Wirtschaft und Energie Kofinanziert von der Europäischen Union

Die Europäische Union fördert zusammen mit dem Bundesministerium für Wirtschaft und Energie über den Europäischen Sozialfonds Plus (ESF Plus) das Programm „Existenzgründungen aus der Wissenschaft (EXIST)“ in Deutschland.

Alleina AI ist ein an der Universität Koblenz inkubiertes Startup. Die Gründung wurde durch StArfrica („Startup Germany-Africa“) begleitet, ein Projekt des ZIFET an der Universität Koblenz.

© 2026 Alleina AI. Alle Rechte vorbehalten.