# Intellectum Lab > Production AI systems for regulated finance. We turn MiCA, DORA and the EU AI Act into records, controls and monitoring pipelines that pass validation — built for authorised CASPs, banks, asset managers and insurers, and delivered to production, not to slide decks. Founded by Viktor Andriichuk (FSQS Registered Supplier, EU Commission TWG6 Expert, AI Chamber CEE member). Based in the EU, delivering across UK & Ireland and Northern Europe. ## What we do (verticals) - [Digital Assets / MiCA compliance for authorised CASPs](https://intellectumlab.com/digital-assets.html): Production systems for MiCA counterparty resolution against ESMA's weekly interim register, ESMA JSON-schema order-book records, Travel Rule holds, DAC8/CARF, DORA ICT resilience and EU AI Act governance of AML/monitoring models. Four fixed-fee steps: Snapshot (1 week), Diagnostic (3–4 weeks), Build (by scope), Embedded Run (ongoing). - [ESMA CSA Readiness Checklist — free self-assessment for authorised CASPs](https://intellectumlab.com/esma-csa-checklist.html): A 16-item self-assessment against ESMA's Common Supervisory Action on CASPs' digital operational resilience (launched 8 July 2026, custody focus, NCA reviews H2 2026 to H1 2027), covering governance, key and storage management, transaction controls, incident detection and response, smart contract risk, and third-party dependencies. Delivered as a PDF by email. - [AI Control under DORA & the AI Act — control plane for GenAI](https://intellectumlab.com/ai-control.html): Auditability, reproducibility, per-request audit trails, guardrails and exit readiness for GenAI systems inside regulated financial institutions. The engineering behind it is written up in the Field notes series below. - [Records, Monitoring & Reporting — pipelines that pass validation](https://intellectumlab.com/records-reporting.html): Continuous extraction, validation and governance of unstructured enterprise data to make AI outputs audit-ready. - [Reference Run — verifiable regulatory-comprehension artifact](https://intellectumlab.com/regulatory-evidence.html): Three EU regulations (Travel Rule 32023R1113, DORA register ITS 32024R2956, MiCAR record-keeping RTS 32025R1140) pinned by SHA-256 from Publications Office Cellar. Deterministic validator with 100% precision/recall on 25 synthetic records shaped to catch flat readings. One live agent run on record: run id b64bfd49, claude-opus-5, 36 LLM calls, US$3.408, budget cap held, acceptance verdict Outcome.INCOMPLETE (published on purpose). Full audit trail in the public repo github.com/intellectumlab/steploop. Reader clones the repo, runs `make proof-verify`, checks the CELEX bytes themselves — verification without asking us. - [DORA Assessment — vendor and ICT third-party readiness](https://intellectumlab.com/dora-assessment.html): Structured DORA readiness assessment for financial entities and ICT third-party service providers. ## How we engage - [How we engage — Snapshot · Diagnostic · Build · Embedded Run](https://intellectumlab.com/pricing.html): Four-step, fixed-fee engagement with one accountable senior architect from start to finish. "Done" is defined against an external standard (e.g. NCA validation, ESMA schema) as a written acceptance test in the SOW. - [Book a 15-minute architecture review](https://intellectumlab.com/review.html): Personalised AI compliance architecture review for a specific institution and stack. ## Track record - [About Intellectum Lab](https://intellectumlab.com/about.html): FSQS Registered Supplier (Hellios, UK & Ireland + Northern Europe), EU Commission TWG6 Expert, AI Chamber CEE member, TWG6 / AI Chamber affiliations, Baia Mare / FSQS-UK&I dates. - [Case study — AI Control under DORA at an EU financial services firm](https://intellectumlab.com/case-eu-financial-services.html): GenAI control layer with per-request audit trails, guardrails and exit readiness under DORA. ## DORA Library - [DORA Library — index of primary DORA sources](https://intellectumlab.com/dora-library.html): Human-readable index of the DORA regulation, RTS, ITS, TIBER-EU guidance, and ESA opinions we work against. - [DORA Regulation (EU) 2022/2554](https://intellectumlab.com/dora/dora-regulation-eu-2022-2554.html) - [DORA Amending Directive (EU) 2022/2556](https://intellectumlab.com/dora/dora-amending-directive-eu-2022-2556.html) - [ICT Risk Management RTS (EU) 2024/1774](https://intellectumlab.com/dora/ict-risk-management-rts-eu-2024-1774.html) - [RTS on ICT Risk Management — final report](https://intellectumlab.com/dora/rts-ict-risk-management-final.html) - [RTS on ICT Third-Party Policy](https://intellectumlab.com/dora/rts-ict-third-party-policy.html) - [RTS on Subcontracting (EU) 2025/532](https://intellectumlab.com/dora/rts-subcontracting-eu-2025-532.html) - [RTS on ICT Incident Classification & Reporting](https://intellectumlab.com/dora/rts-ict-incident-classification-reporting.html) - [RTS on Major Incident Classification Thresholds](https://intellectumlab.com/dora/rts-ict-incident-classification-major-thresholds.html) - [RTS on ICT Incident Reporting — Content & Timelines](https://intellectumlab.com/dora/rts-ict-incident-reporting-content-timelines.html) - [RTS/ITS on Major Incident & Cyber Threat Reporting](https://intellectumlab.com/dora/rts-its-major-incident-cyber-threat-reporting.html) - [ITS on Incident Reporting Templates](https://intellectumlab.com/dora/its-incident-reporting-templates.html) - [ITS on Register of Information Templates (EU) 2024/2956](https://intellectumlab.com/dora/its-register-information-templates-eu-2024-2956.html) - [Register of Information Templates — ITS final report](https://intellectumlab.com/dora/register-information-templates-its-final-report.html) - [CTPP Designation Criteria RTS (EU) 2024/1502](https://intellectumlab.com/dora/ctpp-designation-criteria-rts-eu-2024-1502.html) - [List of designated CTPPs](https://intellectumlab.com/dora/list-designated-ctpps.html) - [RTS on Oversight Harmonisation (EU) 2025/295](https://intellectumlab.com/dora/rts-oversight-harmonisation-eu-2025-295.html) - [RTS on Joint Examination Teams (EU) 2025/420](https://intellectumlab.com/dora/rts-joint-examination-teams-eu-2025-420.html) - [Oversight — cooperation and information exchange](https://intellectumlab.com/dora/oversight-cooperation-information-exchange.html) - [Oversight Fees RTS (EU) 2024/1505](https://intellectumlab.com/dora/oversight-fees-rts-eu-2024-1505.html) - [ESAs opinion on RoI ITS rejection (JC 2024/75)](https://intellectumlab.com/dora/esas-opinion-roi-its-rejection-jc-2024-75.html) - [EU Hub Incident Reporting — feasibility](https://intellectumlab.com/dora/eu-hub-incident-reporting-feasibility.html) - [RTS on Threat-Led Penetration Testing (TLPT)](https://intellectumlab.com/dora/rts-threat-led-penetration-testing-tlpt.html) - [RTS on TLPT — final report](https://intellectumlab.com/dora/rts-tlpt-final-report.html) - [TIBER-EU Control Team Guidance](https://intellectumlab.com/dora/tiber-eu-control-team-guidance.html) - [TIBER-EU Purple Teaming Guidance](https://intellectumlab.com/dora/tiber-eu-purple-teaming-guidance.html) - [TIBER-EU Service Provider Procurement Guidance](https://intellectumlab.com/dora/tiber-eu-service-provider-procurement-guidance.html) - [Guidelines on Cost/Loss Estimation](https://intellectumlab.com/dora/gl-cost-loss-estimation.html) - [ECB Cloud Outsourcing Guide 2025](https://intellectumlab.com/dora/ecb-cloud-outsourcing-guide-2025.html) ## Field notes — engineering evidence for AI Control under DORA - [Evidence, not intent — seven field notes on agent controls under DORA](https://intellectumlab.com/blog/): A seven-part series written while building the control layer described on the AI Control page. The through-line: a habit is behaviour that is currently correct; a control is behaviour that cannot silently stop being correct — and most of the difference cannot be added retroactively. Written for CCOs, risk and engineering teams at authorised firms under MiCA, DORA and the EU AI Act. Each post names the obligation family it belongs to and includes an honest column of what Intellectum Lab's own work fails. - [Delete your approval rule. Did a test go red?](https://intellectumlab.com/blog/delete-your-approval-rule.html): Control effectiveness. Two failed attempts to prove an approval gate worked, the difference between a control and a habit, and the three informative outcomes of removing the rule that guards your riskiest agent action. - [A checkpoint is not evidence](https://intellectumlab.com/blog/a-checkpoint-is-not-evidence.html): Record-keeping. Why durable execution answers "where were we" rather than "who decided this", what a decision record contains that a snapshot does not, and the inversion that makes auditability cheap — make the append-only log the state. - [interrupt() is a pause, not an approval](https://intellectumlab.com/blog/interrupt-is-a-pause-not-an-approval.html): Human oversight. What a resume value knows and does not, rubber-stamping as the real failure mode of an approval queue, the six fields an approval record needs, and why approval must be data rather than a blocking call. - [The failure no guard catches](https://intellectumlab.com/blog/the-failure-no-guard-catches.html): Accuracy. Every standard guard watches process; none asks whether the right question was answered. Two cheap model calls that catch a confident answer to the adjacent question — a task restatement with an anti-theatre rule, and an acceptance check run by something that did not do the work. - [A test suite nobody has watched fail](https://intellectumlab.com/blog/a-test-suite-nobody-has-watched-fail.html): Evaluation. What a test set must contain before a green result means anything — precision reported with recall, expected failures, traps, counterweights — plus repeats rather than runs, and a non-AI baseline in the same table. - [What actually remains when the vendor disappears](https://intellectumlab.com/blog/what-remains-when-the-vendor-disappears.html): Third-party risk and exit readiness. The exit clause describes what you are owed; the export determines what you have. A four-hour test to run against any AI vendor before signing, and the second-order dependency people miss after getting the export right. - [Seven questions your agent should answer before an auditor asks](https://intellectumlab.com/blog/seven-questions-before-an-auditor-asks.html): The series compressed into seven questions covering record-keeping, human oversight, control effectiveness, escalation, exit readiness, accuracy and transparency — each with a good, weak and failing answer, and Intellectum Lab's own scores including the three it fails. Free PDF, no email required: https://intellectumlab.com/blog/seven-questions.pdf - [A proof you can check without asking us](https://intellectumlab.com/blog/a-proof-you-can-check-without-asking-us.html): Field note outside the numbered series. The launch of the Reference Run artifact, framed as three separately verifiable claims (pinned CELEX bytes, deterministic validator scores, quote-matching against pinned text) plus the verify.txt story. Explains why we published the run whose acceptance verdict is Outcome.INCOMPLETE rather than a polished retry — publishing what the acceptance check actually says is what makes it a control, not a habit. ## Optional - [Privacy & cookie policy](https://intellectumlab.com/privacy.html): How Intellectum Lab (Gazolin Production SRL) collects, uses and protects personal data. GDPR, UK GDPR, CCPA and LGPD aligned. - [Sitemap](https://intellectumlab.com/sitemap.xml) ## Contact - Email: viktor@intellectumlab.com - Site: https://intellectumlab.com - Founder: Viktor Andriichuk — Founder & Lead AI Architect - Operating entity: Gazolin Production SRL