Montro

OpenAI Governance & Compliance Discovery

Most organisations using OpenAI have no visibility into who holds access, how many seats are active, or whether usage is documented against EU AI Act obligations. Montro surfaces all of it.

01GDPR

GDPR

OpenAI and GDPR - what your organisation needs to know

OpenAI processes personal data on your behalf - including user identities, email addresses, and account metadata. Under GDPR, your organisation is the data controller and OpenAI acts as a processor. A Data Processing Agreement must be in place. OpenAI is US-based infrastructure, making it subject to GDPR Chapter V transfer rules. When Montro connects to OpenAI, user and licence data flows into Montro EU-hosted infrastructure under a separate DPA.

Learn more →
02EU AI Act

EU AI Act

OpenAI and the EU AI Act - deployer obligations apply

OpenAI models are AI systems under the EU AI Act. If your organisation deploys them - in customer interactions, employee decisions, or operational processes - deployer obligations apply regardless of whether the feature was intentionally enabled. Usage in recruitment, credit assessment, fraud detection, or HR contexts may attract a high-risk classification under Annex III. Montro surfaces OpenAI in your governed inventory so usage is documented before your August 2026 deadline.

Learn more →
03DORA

DORA

OpenAI under DORA - for regulated financial entities only

Under DORA, every ICT tool supporting your operations must be registered and assessed. OpenAI, as an AI platform, is an ICT service that belongs in your ICT Third-Party Register under Article 28.3. If OpenAI supports any critical or important business functions, minimum contractual provisions also apply. Montro surfaces OpenAI in your ICT inventory, supporting DORA register completeness and third-party risk obligations.

Learn more →
04NIS2

NIS2

OpenAI as a supply chain tool under NIS2

NIS2 Article 21(3)(d) requires organisations to document and assess the cybersecurity of their direct ICT suppliers and service providers. OpenAI is an AI platform that qualifies as an ICT service under NIS2. Connecting OpenAI to Montro brings it into your governed AI and application inventory, supporting your supply chain security obligations and ensuring OpenAI is visible in any NIS2 compliance review.

Learn more →

Discovery

What Montro discovers from OpenAI

When you connect OpenAI to Montro, the platform pulls user account data and subscription information into your governed AI and application inventory. IT and security teams get a clear view of who has access to OpenAI services, how licences are allocated, and whether your AI platform usage is classified and documented against EU regulatory obligations.

AI platform user visibility

See every OpenAI user account tied to your organisation, including users provisioned outside your standard IT processes. Montro surfaces accounts created with personal credentials, team members accessing OpenAI outside your sanctioned workflow, and any usage that sits outside your governed AI adoption process.

Licence allocation

Understand how OpenAI licences and subscription seats are distributed across your organisation and identify allocations that are unused. Montro gives you the data to right-size your OpenAI spend and ensure every seat is actively contributing to your operations rather than accumulating cost.

Subscription tracking

OpenAI subscription records are imported into Montro's Subscriptions module for renewal management and cost visibility. Track your plan details, seat counts, and renewal dates alongside every other AI tool and SaaS application in your estate - so nothing renews without a governance review.

Single governed view

OpenAI sits alongside every other AI tool and SaaS application Montro has discovered - classified against EU regulatory obligations in one place. Know which AI systems are in scope for the EU AI Act, which require documentation, and which need a risk tier assessment before August 2026.

Technical details

Authentication Method


OpenAI authenticates via an Admin Key and Organisation ID. Administrators generate an Admin Key from their OpenAI account and provide their Organisation ID to authorise Montro's access. 


How to connect:


  1. Navigate to Integrations in your Montro dashboard.
  2. Select OpenAI from the integrations catalogue and click Connect.
  3. Enter your OpenAI Admin Key in the field provided.
  4. Enter your OpenAI Organisation ID.
  5. Click Connect to authorise the integration.
  6. Montro validates the credentials and begins importing OpenAI account information.
  7. Review synchronised users and licence records within Montro.

 

Data Synced

Users Module

OpenAI user records, including account identities and access information.

Subscriptions Module

OpenAI subscription and licence-related information, including seat allocation and plan details.

Data Residency


OpenAI data imported into Montro is stored on AWS Frankfurt (eu-central-1), within the European Union. No customer data is transferred outside the EU. Data residency terms are specified in Montro's Data Processing Agreement.


Sync Frequency


Data can be synchronised manually at any time after the initial connection, with no limit on the number of manual syncs. Montro also provides an automatic sync option - when enabled, the platform synchronises data once every night to keep information current.


Permission Scope


Montro accesses OpenAI data using an Admin Key scoped to user and licence information. No access to prompts, completions, conversation content, model outputs, or generated content is requested or possible through this integration. All access is read-only and limited to account and subscription metadata.


EU Data Storage


Montro's infrastructure runs exclusively on AWS eu-central-1 (Frankfurt), governed by Irish and EU law. There is no FISA 702 exposure and no Schrems II ambiguity. Your data is never replicated outside the EU without your explicit, documented consent. EU data residency is not a configuration option - it is the architecture.

Related

Apps commonly used with Open AI

Discover compliance profiles for tools in your stack.

Project & Knowledge Management

Jira External User Discovery & Governance

Jira accounts are where contractors, agencies, and external collaborators often live - outside your identity provider, outside your offboarding process, and outside your compliance picture. Connect Jira to Montro to bring them in.

Learn more →

Zoom Governance & Compliance Discovery

Zoom accounts grow quietly - provisioned outside your identity provider, renewed without IT review, and rarely audited. Montro discovers every user and licence in your Zoom environment and maps it against your EU compliance obligations.

Learn more →

Slack Workspace Access & AI Governance

Slack is where work happens, and where ungoverned access accumulates. Guest accounts, inactive seats, and users added outside your identity provider all show up when Montro connects to your workspace.

Learn more →
Ankur Arora

Ankur Arora

Co-founder

Fifteen years of enterprise digital transformation across telecoms, media, consumer goods, and agriculture - and a front-row seat to AI adoption outpacing governance at every organisation he worked in. He built Montro so the next firm doesn't have to learn that lesson the hard way.