Find the AI risks no one’s checked yet.

iDharma is an independent AI audit firm. We test your AI against the EU AI Act, ISO 42001 and NIST AI RMF.

Book a free scoping call
Independently verified No payment until scoped 1–4 week reports
Every finding mapped to a named framework A named expert on every audit No payment until the scope is agreed Prioritised report in 1–4 weeks No black box. No vendor spin.
Quick lookup
A printed audit report headed Scope, Method and Findings, with a magnifying glass and a pen resting on it
Like a financial audit — but the subject is an algorithm

Our method

Every finding points back to evidence

We agree what is being examined before anything starts, test it against named standards rather than an in-house checklist, and tie every conclusion to something you can inspect.

That is what separates an audit from an opinion. What you get is a document you can put in front of a board, a customer or a regulator — and show your working for every line in it.

See how the audit works

Five dimensions

The five ways your AI gets judged

AI systems are only as trustworthy as the questions you ask. We evaluate performance, behaviour and governance across five critical dimensions.

  1. Accuracy

    Does it actually work?

    Real outputs tested against ground truth.

  2. Fairness

    Does it treat everyone the same?

    Bias probed across every group it touches.

  3. Security

    Can it be manipulated?

    Attacked the way a bad actor would.

  4. Privacy

    Is personal data protected?

    What it stores, shares, or tricked into revealing.

  5. Compliance

    Would it pass a regulator’s review?

    Checked against the rules that matter.

Every gap mapped to NIST AI RMF ISO 42001 EU AI Act HIPAA India DPDP SOC 2
Free self-check

Not sure where your AI stands?

Answer five quick questions and get a specific, real finding about your AI — free, in 60 seconds.

  1. Answer five questions

    60 seconds — no signup, no sales call, no pitch

  2. Get a straight read

    Across governance, data, bias, security and compliance

  3. Act on it

    A specific, real finding about your AI — yours to keep

AI Risk Snapshot Sample
  • Governance Medium
  • Data provenance High
  • Bias & fairness Low
  • Security Medium
  • Compliance High
Overall exposure High
Answer 5 questions — get a real, specific finding. 60 seconds. No signup.

What every engagement includes

The four things every audit gives you

The method, the independence, the report, and the terms — set out before anything is charged.

  1. The Standards

    Findings trace to six named, publicly recognised frameworks rather than an internal checklist of our own.

    NIST AI RMF ISO/IEC 42001 EU AI Act HIPAA SOC 2 India DPDP
  2. The Independence

    We audit AI we did not build. No vendor relationship, no conflict of interest, and evidence-based findings instead of a self-graded checklist.

  3. The Report

    Clear findings with a prioritised fix list, typically one to four weeks from scope to report. It reads plainly instead of burying you in a data dump.

  4. The Terms

    Nothing is charged until you approve the audit scope. You agree what the work covers before anything is billed.

A dark bound volume titled AI Governance, subtitled Policies, Ethics, Compliance, Assurance, with an embossed shield emblem enclosing a microchip marked AI
What we do

AI audits, explained plainly

No jargon and no sales pitch. Just what an AI audit is, why it matters, who needs one, and how iDharma does it.

An independent review of the AI systems you already use, checking how accurate, fair, secure, and compliant they really are rather than taking the vendor’s word for it.

Unaudited AI is unmeasured risk. Bias, security gaps, and compliance failures stay invisible until they cost you in fines, lost trust, or a regulator asking questions you can’t answer.

Any business running AI in a regulated or customer-facing process: lending, healthcare, hiring, or customer service, especially under EU AI Act, HIPAA, or SOC 2 obligations.

We independently test your AI against recognized standards like NIST AI RMF, ISO 42001, and the EU AI Act, then hand you a clear, prioritized report. Named auditor, cited methodology, no black box.

Why iDharma

An independent read you can stand behind

Independent by structure

A verified expert who didn’t build your AI is the one who reviews it. Independence isn’t a claim we make about ourselves — it’s the arrangement that makes a finding defensible to a board or a regulator.

Standards, not say-so

Every finding traces to a named framework — NIST AI RMF, ISO/IEC 42001, the EU AI Act — never an internal checklist of ours. Soundness you can point at is part of being trustworthy, not a separate exercise.

Clarity over cleverness

A report you have to decode has failed. Risks, compliance gaps and a prioritised fix list, in plain language, with the thing that matters most obviously the thing that matters most.

Built in, not stickered on

Trust here is shown, not decorated: no hollow badges, no invented scores, no countdown pressure. See the work before you pay — the free 60-second Risk Snapshot hands you a real finding, no commitment.

See the deliverable

A report a board can act on

This is the actual output of an iDharma audit: a clear read your board, a partner bank, or a regulator can rely on — where every finding carries a decision, not just a description.

Inside every report

  • Findings ranked by severity, worst first
  • Each one mapped to the standards that apply to you
  • A plain-English executive summary
  • A prioritised fix list, signed by a named auditor

Sample Illustrative report built for a fictional company — every tier below produces a report in this format.

iDharma AI AUDIT REPORT COMPLIANCE AUDIT Compliance Audit — AI Audit Report Independent, standards-based assessment Prepared for Meridian Credit Union (fictional) Contact Head of Risk & Compliance Audit reference #SAMPLE-0142 System assessed Automated credit-decisioning model Overall risk rating HIGH Executive summary The model is well engineered and performs to spec, but the controls around it have not kept pace. Two of the five audited dimensions — data provenance and compliance — carry material exposure. Findings HIGH 1. Training-data provenance is not documented Roughly a third of training features trace to third-party datasets HIGH 2. No fair-lending / EU AI Act mapping The model is not mapped to ECOA fair-lending rules MODERATE 3. Governance policy is informal only Ownership and change review exist in practice, not in writing Compliance mapping STANDARD STATUS NIST AI RMF PARTIAL ISO/IEC 42001 PARTIAL EU AI Act high-risk GAP SAMPLE
We show our work

Evidence over promises

An audit is only worth the record it leaves behind. Every engagement ends in a document you can hand to a regulator, a board or a buyer — findings, the standard each one touches, and the methodology we used, published and openly dated.

Every gap mapped to
  • NIST AI RMF
  • ISO/IEC 42001
  • EU AI Act
  • SOC 2 & more
  1. 01

    Standards

    Mapped to which rule? NIST AI RMF, ISO/IEC 42001, EU AI Act, SOC 2 and more.
  2. 02

    Evidence

    What was actually checked? Findings cited to what we examined, not to a self-graded checklist.
  3. 03

    Methodology

    How was it decided? Versioned and openly dated, so you can see it stays current.
  4. 04

    Remediation

    What gets fixed first? A prioritised remediation roadmap, not a generic score.
  5. 05

    Reporting

    Can a board read it? Written to be read by the people who have to sign it off.
How we work

Four principles behind every audit

Independence

  • We audit AI we didn’t build
  • No vendor relationship, no conflict of interest
  • An honest third-party read every time

Standards-based

  • Every finding maps to NIST AI RMF, ISO/IEC 42001, or the EU AI Act
  • Cited, not proprietary
  • So results stand up to scrutiny

Named auditor

  • A certified ISO/IEC 42001 Lead Auditor signs every report
  • You know who is accountable
  • Not an anonymous model or faceless team

Speed without shortcuts

  • Methodology updated in days not quarters
  • Scope approved before billing starts
  • Fast delivery with no compromise on rigour

Our mission

Independent proof your AI holds up


Businesses are deploying AI faster than anyone can verify it. Most teams cannot say, with evidence, whether the AI they rely on is accurate, fair, secure or compliant. iDharma closes that gap.

Request an AI audit

Evidence you can trust.
Proof you can defend.

AI audit report Illustrative sample
AI governance score
  • Fairness
  • Security
  • Privacy
  • Reliability
  • Transparency
Compliance mapped
  • EUAI Act
  • ISO42001
  • NISTAI RMF
  • SOC 2Type II
  • Sleep at night on AI risk

    Fear of an undisclosed failure becomes documented evidence your system was independently checked.

  • Prove compliance, fix what’s broken

    A regulation-mapped gap register with a prioritised remediation roadmap — not a generic score.

  • Unblock the deal

    Pass procurement gates and board scrutiny with an attestation showing your AI governance is real.

  • From risk to proof.
    From audit to advantage.

    Every audit maps to
    • EU AI Act
    • ISO/IEC 42001
    • NIST AI RMF
    • SOC 2
    • HIPAA
    • India DPDP

Our vision

Independent proof your AI holds up — checked once, then watched continuously, before the regulator or your board asks.

Every finding traces to a named framework, every report is signed by a named auditor, and the methodology behind both is published and openly dated.

Brijesh Patel, Founder & Lead Auditor
Brijesh Patel Founder & Lead Auditor
  • Named reviewer
    on every audit
  • No vendor
    relationship
Connect on LinkedIn
Request an AI audit
6
Frameworks mapped NIST AI RMF, ISO/IEC 42001, EU AI Act, HIPAA, SOC 2, India DPDP
1–4wks
Typical engagement Scope to report
From$5,000
Fixed fee Scoped before anything is charged
Checked once, then watched continuously. The standard this firm is built toward — not a claim about today.
  • Independent Assessment We audit AI we did not build.
  • Regulation Mapped Findings trace to a named framework.
  • Enterprise Ready Nothing charged until you approve the scope.
  • Evidence Based Conclusions tie to evidence you can inspect.

Ready to know where you stand?

An independent iDharma audit shows you where your AI holds up on accuracy, fairness, security, and compliance — and what to fix first.

Start free, then audit

No account · 2-minute brief · scope confirmed before anything is charged

Not sure where to start?

Email us with your use case, and we’ll recommend the right audit approach. Or review a sample report.

NDA as standard 1–4 week delivery Fixed-fee pricing Expert-led, not automated