ai assurance & audit · independent

Built an AI tool or agent? I run an independent assurance review and hand you a report you can keep — and share with your own clients as evidence you did the work. Risk classification, control gaps, and adversarial testing, in plain language.

  • Independent
  • Report you keep
  • NIST · ISO 42001 · EU AI Act
The review — how it works intake to report

how it works

  1. Step 01

    Intake & classify

    Scope the system and place its EU AI Act risk tier.

    → in the report: Risk classification

  2. Step 02

    Crosswalk

    Review controls across all three frameworks; find the gaps.

    → in the report: Control review · Gap analysis

  3. Step 03

    Red-team

    Run adversarial probes against the live system and score them.

    → in the report: Adversarial testing

  4. Step 04

    Report

    Everything in one signed-off deliverable you keep.

    → in the report: A shareable report · A re-test

what you get

ContentsAI assurance report

  1. 01

    Risk classification§ 01

    Your system placed against the EU AI Act — Prohibited, High, Limited or Minimal — with the reasoning written out, not asserted.

  2. 02

    Control review§ 02

    Mapped across NIST AI RMF, ISO/IEC 42001 and the EU AI Act at once, so one piece of evidence answers three frameworks.

  3. 03

    Adversarial testing§ 03

    Prompt injection, jailbreak, PII leakage, bias, hallucination and oversight — probed and scored, not assumed.

  4. 04

    Gap analysis§ 04

    A prioritised remediation list with residual-risk ratings. What to fix first, and what can wait.

  5. 05

    A shareable reportyours

    A branded assurance report you keep and can hand to your own customers as evidence of due diligence.

  6. 06

    A re-testafter fixes

    After you fix the gaps, I run it again and confirm they're closed. Done means done.

why three frameworks

Controls are reviewed across NIST AI RMF, ISO/IEC 42001 and the EU AI Act at once, so one piece of evidence answers three frameworks.

Full report shared with the client

the deliverable

Risk tier, a control heatmap across the three frameworks, every open gap with the evidence needed to close it, and the red-team results — in one branded document. Yours to share.

Illustrative sample A live sample is available on request. Real reports are confidential to the client.

Putting an AI product in front of customers?

Let's make sure it holds up before your customers ask the hard questions. Independent review, a report you keep, no theatre.

Request an audit

Independent AI assurance. Reviews are advisory, not accredited certification. · ← Back to services