Independence
- We audit AI we didn’t build
- No vendor relationship, no conflict of interest
- An honest third-party read every time
iDharma is an independent AI audit firm. We test your AI against the EU AI Act, ISO 42001 and NIST AI RMF.
Our method
We agree what is being examined before anything starts, test it against named standards rather than an in-house checklist, and tie every conclusion to something you can inspect.
That is what separates an audit from an opinion. What you get is a document you can put in front of a board, a customer or a regulator — and show your working for every line in it.
Five dimensions
AI systems are only as trustworthy as the questions you ask. We evaluate performance, behaviour and governance across five critical dimensions.
Does it actually work?
Real outputs tested against ground truth.
Does it treat everyone the same?
Bias probed across every group it touches.
Can it be manipulated?
Attacked the way a bad actor would.
Is personal data protected?
What it stores, shares, or tricked into revealing.
Would it pass a regulator’s review?
Checked against the rules that matter.
Answer five quick questions and get a specific, real finding about your AI — free, in 60 seconds.
60 seconds — no signup, no sales call, no pitch
Across governance, data, bias, security and compliance
A specific, real finding about your AI — yours to keep
Domains we audit
Domain 01
Lending, credit scoring, and fraud detection, audited for fair-lending exposure and model risk.
Request an auditDomain 02
Trading, portfolio, and financial-reporting AI, reviewed for investment and reporting risk.
Request an auditDomain 03
Clinical and patient-facing AI, reviewed for PHI handling and emerging state AI rules.
Request an auditDomain 04
Underwriting and claims automation, tested for proxy discrimination and fairness.
Request an auditWhat every engagement includes
The method, the independence, the report, and the terms — set out before anything is charged.
Findings trace to six named, publicly recognised frameworks rather than an internal checklist of our own.
We audit AI we did not build. No vendor relationship, no conflict of interest, and evidence-based findings instead of a self-graded checklist.
Clear findings with a prioritised fix list, typically one to four weeks from scope to report. It reads plainly instead of burying you in a data dump.
Nothing is charged until you approve the audit scope. You agree what the work covers before anything is billed.
No jargon and no sales pitch. Just what an AI audit is, why it matters, who needs one, and how iDharma does it.
An independent review of the AI systems you already use, checking how accurate, fair, secure, and compliant they really are rather than taking the vendor’s word for it.
Unaudited AI is unmeasured risk. Bias, security gaps, and compliance failures stay invisible until they cost you in fines, lost trust, or a regulator asking questions you can’t answer.
Any business running AI in a regulated or customer-facing process: lending, healthcare, hiring, or customer service, especially under EU AI Act, HIPAA, or SOC 2 obligations.
We independently test your AI against recognized standards like NIST AI RMF, ISO 42001, and the EU AI Act, then hand you a clear, prioritized report. Named auditor, cited methodology, no black box.
A verified expert who didn’t build your AI is the one who reviews it. Independence isn’t a claim we make about ourselves — it’s the arrangement that makes a finding defensible to a board or a regulator.
Every finding traces to a named framework — NIST AI RMF, ISO/IEC 42001, the EU AI Act — never an internal checklist of ours. Soundness you can point at is part of being trustworthy, not a separate exercise.
A report you have to decode has failed. Risks, compliance gaps and a prioritised fix list, in plain language, with the thing that matters most obviously the thing that matters most.
Trust here is shown, not decorated: no hollow badges, no invented scores, no countdown pressure. See the work before you pay — the free 60-second Risk Snapshot hands you a real finding, no commitment.
This is the actual output of an iDharma audit: a clear read your board, a partner bank, or a regulator can rely on — where every finding carries a decision, not just a description.
Inside every report
Sample Illustrative report built for a fictional company — every tier below produces a report in this format.
Quick scan
A fast, focused review of your core AI system, with the top risks surfaced.
Compliance
A deeper audit mapped to the standards and regulations you answer to.
Risk
Our most thorough review, including threat scenarios and a full roadmap.
Transparent, fixed-scope pricing — scoped with you before anything is charged. No payment until you approve the scope.
An audit is only worth the record it leaves behind. Every engagement ends in a document you can hand to a regulator, a board or a buyer — findings, the standard each one touches, and the methodology we used, published and openly dated.
Every gap mapped to
Our mission
Businesses are deploying AI faster than anyone can verify it. Most teams cannot say, with evidence, whether the AI they rely on is accurate, fair, secure or compliant. iDharma closes that gap.
Evidence you can trust.
Proof you can defend.
Fear of an undisclosed failure becomes documented evidence your system was independently checked.
A regulation-mapped gap register with a prioritised remediation roadmap — not a generic score.
Pass procurement gates and board scrutiny with an attestation showing your AI governance is real.
From risk to proof.
From audit to advantage.
Our vision
Every finding traces to a named framework, every report is signed by a named auditor, and the methodology behind both is published and openly dated.
An independent iDharma audit shows you where your AI holds up on accuracy, fairness, security, and compliance — and what to fix first.
Email us with your use case, and we’ll recommend the right audit approach. Or review a sample report.
From Insights
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
Read the notesFive working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Read the guideFixed prices, published turnarounds, and an honest account of the four things that decide which tier a system belongs in — including when the answer is "none of them yet".
Read the notes