Montro

NIS2 Article 20 makes you personally liable

Shadow AI tools are running in your organisation without your knowledge. Under NIS2, that's your personal liability. Montro surfaces every AI tool and SaaS app in use—including undisclosed ones—and maps them against NIS2, DORA, and the EU AI Act so you can manage the risk.

NIS2 Article 20 personal liability exposure dashboard with Montro mitigation status

Reality

The CISO's dilemma

"You are held responsible for risks you do not own, assets you do not control, and decisions made by people who outrank you." Montro was built to change that arithmetic.

NIS2 Article 20

Personal liability for unmanaged AI and SaaS risk exposure.

Shadow AI

Tools running in your organisation that IT has never seen.

Learn more

Visibility

Three pillars of control

The foundation every CISO needs to own their risk.

Discovery

Find every SaaS and AI tool in use

Including the ones your team never reported

Classification

Map each tool to NIS2, DORA, and AI Act

Risk tiers and article numbers assigned automatically

Register

Generate your DORA register in days, not months

Board and regulator ready from day one

Mapping

Every asset gets an article number

Montro doesn't just find your SaaS and AI tools. It connects each one to the specific regulatory articles that govern your liability as a CISO. No guesswork. No spreadsheet interpretation. Article references, risk tiers, and remediation owners in a single compliance matrix.

NIS2 Article 20 personal liability

Every shadow AI tool and unmanaged SaaS app discovered is mapped directly to Art.20, showing your regulator you've identified and assessed the risk.

DORA Article 8 third-party register

Critical ICT services are automatically classified and registered against Art.8 requirements, eliminating the manual register work that takes months.

EU AI Act high-risk classification

Tools flagged as high-risk under the EU AI Act are tagged with the specific risk categories requiring impact assessments and human oversight.

Setup

From connection to compliance in 30 days

Connect your identity provider. Montro begins discovery immediately. Shadow AI surfaces within 24 hours.

Day 1: Connect via SSO or M365

Read-only access to your directory. No agents. No disruption.

Day 2–7: First shadow AI report

Every app, every AI tool, every user. Real-time visibility begins.

Day 8–30: Full compliance register

GDPR, EU AI Act, DORA, NIS2. Automatically classified and mapped.

Day 31 onwards: Continuous monitoring

New tools detected. Compliance status maintained. Alerts on policy drift.

CISO consolidated view showing DORA and NIS2 compliance registers

Outcome

Your board gets audit-ready evidence

Regulators see a maintained register, not spreadsheets and screenshots.

Start free trial

Works with the tools you already use

Montro discovers AI tools across your existing stack — no agents, no manual imports. Connect once and your inventory stays current.

Office
Google Cloud
HubSpot
Slack
Zoom
AWS
OpenAI
Atlassian

Obligations

Three regulations. Three registers. One platform.

Your regulators expect three separate compliance registers by year-end. Montro builds all three simultaneously from a single discovery run, eliminating the manual work that typically takes months across three different teams.

DORA Article 8 ICT register

Every third-party ICT service must be classified, assessed for criticality, and registered with your regulator—Montro auto-generates this register with risk tiers and audit readiness status.

Learn more

NIS2 Article 21 supply chain risk

You must identify and manage cybersecurity risks from your supply chain—Montro maps every SaaS vendor and AI tool provider to supply chain risk categories and flags those requiring enhanced due diligence.

Learn more

EU AI Act deployer obligations

As a deployer of AI systems, you must classify tools by risk level and maintain records of compliance—Montro tags every AI tool discovered against the Act's risk categories and maintains a continuous audit trail.

Learn more

Questions

The answers CISOs need before audit season arrives.

No. Montro discovers SaaS and AI tools through API integrations, network traffic analysis, and user behaviour signals. You get full visibility without deploying agents to thousands of devices. That matters when half your workforce uses personal devices.

Find every AI tool running in your organisation

In 30 days. For free. No credit card. No long-term commitment. Just visibility.

Free 30-day AI Discovery Audit. No commitment.

Montro AI discovery audit dashboard