AI Compliance Audit · EU AI Act · 1–4 weeks

Know exactly where your AI systems
stand before regulators do.

Every AI system you run, mapped against the EU AI Act, GDPR and sector rules — then a ranked, plain-English list of exactly what to fix first.


A black ring binder labelled Audit Report, Confidential, lying closed on a dark desk under a low warm light Illustrative materials
The bound file an audit is written into
EU AI Act NIST AI RMF GDPR NYC Local Law 144 California FEHA (Automated Decision Systems) Colorado AI Law (SB 26-189) Colorado SB 21-169 NAIC AI Principles Texas AI Act Singapore PDPA HIPAA NIST CSF CCPA / CPRA DORA OECD AI Principles CIS Controls AI Ethics FTC AI Guidance Bahrain PDPL Qatar PDPL Saudi PDPL UAE PDPL Quebec Law 25 SR 26-2 / OCC 2026-13 SS1/23 (PRA) OSFI E-23
The regulatory landscape

The rules are already live

All 31 frameworks an iDharma audit can assess you against — binding regulation, voluntary standards, and supervisory guidance. Every finding is mapped to the specific obligation it touches, so you know which rule a gap sits under, not just that a gap exists.

Phasing in

EU AI Act

European Union

Conformity assessments, technical documentation, and ongoing monitoring for high-risk systems.

Applies to High-risk AI, including credit scoring
View framework
In force

ISO/IEC 42001

International

A documented AI management system: governance, risk treatment, and continual review.

Applies to Certifiable; increasingly asked for in diligence
View framework
Voluntary

NIST AI RMF

United States

Govern, map, measure, manage — the reference model most US examiners recognise.

Applies to Widely used as the benchmark for reasonable practice
View framework
In force

GDPR

European Union / UK

Safeguards and explanation rights where automated decisions significantly affect people.

Applies to Any automated decisioning on EU residents
View framework
Local law

NYC Local Law 144

New York City, US

Bias audits for automated employment decision tools

Area AI regulation
View framework
Regulation

California FEHA (Automated Decision Systems)

California, US

In force since Oct 2025; the testing is the evidence

Area AI regulation
View framework
Statute

Illinois HB 3773

Illinois, US

In force since Jan 2026; liability and a notice duty

Area AI regulation
View framework
State law

Colorado AI Law (SB 26-189)

Colorado, US

Disclosure duties for automated decision-making technology

Area AI regulation
View framework
State law

Colorado SB 21-169

Colorado, US

ECDIS governance for life, auto and health insurers

Area AI regulation
View framework
Regulator guidance

NAIC AI Principles

United States

Insurance-regulator expectations for AI governance

Area AI regulation
View framework
State law

Texas AI Act

Texas, US

Prohibited uses, disclosure and record-keeping

Area AI regulation
View framework
Regulation

Singapore PDPA

Singapore

Transparency, traceability and outcome monitoring

Area Privacy & data protection
View framework
Attestation

SOC 2

United States

Trust services criteria for systems handling customer data

Area Security & resilience
View framework
Regulation

HIPAA

United States

Protected health information in AI training and inference

Area Privacy & data protection
View framework
Standard

ISO/IEC 27001

International

ISMS certification - clauses 4–10 and 93 Annex A controls

Area Security & resilience
View framework
Standard

PCI-DSS

International

Cardholder data controls where AI touches payment flows

Area Security & resilience
View framework
Framework

NIST CSF

United States

Cybersecurity framework functions applied to AI estates

Area Security & resilience
View framework
Regulation

CCPA / CPRA

California, US

Consumer rights, and ADMT duties from 1 January 2027

Area Privacy & data protection
View framework
Regulation

DORA

European Union

Operational resilience for financial-sector AI and its vendors

Area Security & resilience
View framework
Principles

OECD AI Principles

International

Values-based principles for trustworthy AI

Area AI standards & frameworks
View framework
Controls

CIS Controls

International

Prioritised security controls for AI infrastructure

Area Security & resilience
View framework
Practice

AI Ethics

International

Fairness, transparency and accountability in practice

Area AI standards & frameworks
View framework
Regulator guidance

FTC AI Guidance

United States

Claims substantiation and unfair-practice exposure

Area AI regulation
View framework
Regulation

Bahrain PDPL

Bahrain

Personal data protection duties for AI processing

Area Privacy & data protection
View framework
Regulation

Qatar PDPL

Qatar

Two regimes - Law No. 13 onshore, QFC Regulations inside

Area Privacy & data protection
View framework
Regulation

Saudi PDPL

Saudi Arabia

Personal data protection duties for AI processing

Area Privacy & data protection
View framework
Regulation

UAE PDPL

UAE

Personal data protection duties for AI processing

Area Privacy & data protection
View framework
Regulation

Quebec Law 25

Quebec, Canada

Automated decision transparency and privacy duties

Area Privacy & data protection
View framework
Supervisory guidance

SR 26-2 / OCC 2026-13

United States

Model risk management - superseded SR 11-7 on 17 Apr 2026

Area Model risk - banking supervisors
View framework
Supervisory guidance

SS1/23 (PRA)

United Kingdom

Five model risk principles for firms with internal model approval

Area Model risk - banking supervisors
View framework
Supervisory guidance

OSFI E-23

Canada

Model risk across five lifecycle stages, effective 1 May 2027

Area Model risk - banking supervisors
View framework
Mapped to obligationEvery finding linked to the exact rule it touches.
Know your gap, not just a gapUnderstand which rule the gap sits under and what it requires.
Evidence that holds upClear linkage for regulators, auditors, and boards.

Status and scope verified against each framework's primary source. We cite enforcement figures only once confirmed from the original filing — verified cases appear in our teardowns.

What is an AI Audit?

A structured review of every AI system your organization relies on.

An AI audit isn't about finding fault, it's about clarity: we map what your AI tools actually do, identify the regulations that apply, and hand you a prioritized action plan you can act on immediately.

Know your exposure

Understand where your AI stands before enforcement, a partner bank, or a procurement team asks.

Win enterprise contracts

Procurement teams now demand AI compliance evidence. An audit gives you a credible answer.

Build customer trust

Show clients and partners how their data is protected and how decisions are made.

Scale confidently

Deploy new AI capabilities knowing your compliance baseline is documented and current.

Every audit is scoped to your systems and your sector — nothing is charged until you approve the scope.

See How It Works
Why iDharma

Not all audits are created equal.

Most consultancies offer a generic checklist. iDharma delivers a structured, sector-specific, actionable audit.

What You Get iDharma Audit Generic Consultancy DIY Checklist
Sector-specific risk mapping Built-in Partial
EU AI Act risk classification All tiers Basic
Plain-language action plan Prioritized Legal language
Remediation guidance included Extra cost
Delivered in 1–4 weeks Scoped per engagement Self-paced
Evidence pack for regulators Included Optional
Fixed transparent pricing Time & materials
How We're Paid

What we find never changes what we're paid.

We don’t build or sell the AI we assess, and we don’t sell the fixes we’d recommend.

We’re paid to assess your system honestly against a published standard — not to reach a particular conclusion.

We disclose any relationship that could color the work, and if a genuine conflict exists, we decline the engagement rather than caveat it.

Audit Dimensions

Five areas we examine in every audit.

Each dimension maps to a specific regulatory obligation — and to a business risk you can actually manage.

Together they cover how your AI is governed, where its data comes from, whether it treats people fairly, how it holds up under pressure, and whether it meets the law.

See How It Works

Governance

Ownership & human override

Data provenance

Where your data comes from

Bias & fairness

Equitable, tested outcomes

Security

Robust under adversarial pressure

Compliance

Meets the laws that apply

The Process

Four steps from kickoff to compliance clarity.

No lengthy onboarding. No scope creep. A fixed process, a fixed timeline, a fixed price.

01

Request

Tell us about your AI systems, your sector, and where you’re unsure. Nothing is charged.

No payment upfront

02

Scope & fixed quote

We agree the systems, depth, and price before any work begins. You approve the scope first.

You approve first

03

Audit (1–4 weeks)

An iDharma-verified expert reviews your systems against our published methodology.

1–4 weeks

04

Report & walkthrough

A prioritized findings report and a walkthrough — you leave knowing what to fix, and when.

14 business days of written follow-up

What You Receive

A complete compliance evidence pack — not just a report.

Every iDharma audit produces a structured set of documents your team, legal counsel, and regulators can actually use.

  • Full Audit ReportFindings against each of the five dimensions, with risk ratings and regulatory citations.
  • Risk Snapshot DashboardA single-page summary your board can understand in three minutes.
  • Prioritized Action PlanFixes ranked by urgency, effort, and regulatory deadline, with owner assignments.
  • Evidence PackPre-formatted documentation to demonstrate compliance to regulators or enterprise clients.
  • Report WalkthroughLive session with your audit lead to answer every question your team has.
  • 14 Business Days of Follow-UpWritten Q&A with your audit lead in your secure portal after delivery.
See a full sample report →

Sample Deliverable — Audit Report Extract

iDharma AI AUDIT REPORT COMPLIANCE AUDIT Compliance Audit — AI Audit Report Independent, standards-based assessment Prepared for Meridian Credit Union (fictional) Contact Head of Risk & Compliance Audit reference #SAMPLE-0142 System assessed Automated credit-decisioning model Overall risk rating HIGH Executive summary The model is well engineered and performs to spec, but the controls around it have not kept pace. Two of the five audited dimensions — data provenance and compliance — carry material exposure. Findings HIGH 1. Training-data provenance is not documented Roughly a third of training features trace to third-party datasets HIGH 2. No fair-lending / EU AI Act mapping The model is not mapped to ECOA fair-lending rules MODERATE 3. Governance policy is informal only Ownership and change review exist in practice, not in writing Compliance mapping STANDARD STATUS NIST AI RMF PARTIAL ISO/IEC 42001 PARTIAL EU AI Act high-risk GAP SAMPLE
What Your Findings Map To

Every finding lands on a named obligation.

An iDharma audit is scoped against the specific instruments that apply to you — 31 of them, from binding regulation to the standards procurement asks about. Filter the set, or open any one to see what it requires and what an audit covers against it.

AI regulation EU AI Act Transparency live since Aug 2026; high-risk from Dec 2027 AI regulation NYC Local Law 144 Bias audits for automated employment decision tools AI regulation California FEHA (Automated Decision Systems) In force since Oct 2025; the testing is the evidence AI regulation Illinois HB 3773 In force since Jan 2026; liability and a notice duty AI regulation Colorado AI Law (SB 26-189) Disclosure duties for automated decision-making technology AI regulation Colorado SB 21-169 ECDIS governance for life, auto and health insurers AI regulation NAIC AI Principles Insurance-regulator expectations for AI governance AI regulation Texas AI Act Prohibited uses, disclosure and record-keeping AI regulation FTC AI Guidance Claims substantiation and unfair-practice exposure Model risk SR 26-2 / OCC 2026-13 Model risk management - superseded SR 11-7 on 17 Apr 2026 Model risk SS1/23 (PRA) Five model risk principles for firms with internal model approval Model risk OSFI E-23 Model risk across five lifecycle stages, effective 1 May 2027 Privacy GDPR Lawful basis, DPIAs, data subject rights and Article 22 Privacy Singapore PDPA Transparency, traceability and outcome monitoring Privacy HIPAA Protected health information in AI training and inference Privacy CCPA / CPRA Consumer rights, and ADMT duties from 1 January 2027 Privacy Bahrain PDPL Personal data protection duties for AI processing Privacy Qatar PDPL Two regimes - Law No. 13 onshore, QFC Regulations inside Privacy Saudi PDPL Personal data protection duties for AI processing Privacy UAE PDPL Personal data protection duties for AI processing Privacy Quebec Law 25 Automated decision transparency and privacy duties AI standards ISO/IEC 42001 AI management system controls, clause by clause AI standards NIST AI RMF Govern, Map, Measure and Manage, assessed end to end AI standards OECD AI Principles Values-based principles for trustworthy AI AI standards AI Ethics Fairness, transparency and accountability in practice Security SOC 2 Trust services criteria for systems handling customer data Security ISO/IEC 27001 ISMS certification - clauses 4–10 and 93 Annex A controls Security PCI-DSS Cardholder data controls where AI touches payment flows Security NIST CSF Cybersecurity framework functions applied to AI estates Security DORA Operational resilience for financial-sector AI and its vendors Security CIS Controls Prioritised security controls for AI infrastructure

No framework matches that.

These pages describe what each instrument requires and what an audit covers against it. They are scoping guidance, not legal advice — iDharma works alongside your counsel, not in place of them.

Transparent Pricing

Know the cost before you commit.

Fixed, scoped fees — no time-and-materials, no surprises. Reports in 1–4 weeks.

Quick Scan
$5,000
one-time · delivered in ~1 week
  • Review of up to 3 AI systems or tools
  • Top-priority risk and gap findings
  • A prioritized action list you can act on
  • 14 business days of written follow-up in your portal
Risk Audit
$25,000
one-time · delivered in ~4 weeks
  • Everything in the Compliance Audit, plus:
  • Bias and fairness testing
  • Security review including adversarial probing
  • Model and training-data provenance review
  • A risk briefing you can present to your board

No payment until you approve the scope.

All audits are covered by NDA as standard. Your systems and data never leave the engagement.

FAQ

Questions we hear every time.

Scope & your involvement
Do we need to share our source code?

No. We work from system documentation, data flow diagrams, policy documents, and structured interviews with your team. Source code is never required for a compliance audit.

We're a small team — how much of our time does this take?

Typically around 3 hours of your team's time spread across the first four days — mostly answering our structured questionnaire and joining one call. We do the analysis independently.

What if we don't know which AI tools we're using?

That's exactly what the scoping call is for. Many clients discover AI systems embedded in third-party SaaS tools they didn't realise were in scope. We help you map your full AI footprint first.

Regulations & frameworks
Does the EU AI Act apply to us if we're outside the EU?

Yes — but not on the trigger most teams assume. The Act reaches you if you place an AI system on the EU market or put it into service there, or if the output your system produces is used in the EU, regardless of where your organization is registered. Processing personal data of EU residents is GDPR's trigger, not the AI Act's — the two catch different things, and a system can be in scope for one and not the other.

What frameworks do you audit against?

We cover the EU AI Act (all risk tiers), NIST AI RMF, ISO/IEC 42001, HIPAA, SOC 2, and India's DPDP, plus GDPR Articles 13, 14, and 22 — mapped to your specific use case.

Is this the same as a GDPR Data Protection Impact Assessment?

No, but our audit often surfaces what's needed for a DPIA. An AI compliance audit is broader — it covers the AI Act, sector rules, and operational risk — not just data protection law.

After the report
What happens after we get the report?

You receive 14 business days of written follow-up in your portal with your audit lead, plus optional remediation support packages if you want help implementing fixes — policy drafting, technical controls, staff training.

Can we use the report with enterprise clients or procurement teams?

Yes — the evidence pack is specifically designed to be shared with procurement teams, due diligence processes, and enterprise clients who require AI compliance documentation as part of vendor qualification.

Why iDharma
How is iDharma different from a law firm?

Law firms deliver legal opinions. We deliver operational compliance — structured evidence, actionable fixes, and plain-language guidance your technical and business teams can act on. We're not a substitute for legal counsel, but we work alongside yours.

Is there a guarantee?

We deliver within the scope and timeline we agree with you (typically 1–4 weeks). And if a regulator questions the methodology of our audit, we'll provide expert support at no additional cost.

Brijesh Patel
Who reviews your AI
Brijesh Patel
Founder & Lead Auditor

Every audit is led and signed by a named reviewer — no black box, no anonymous “team.”

Get Started

Ready to know where you stand?

Book a free scoping call. No commitment. We'll tell you exactly which regulations apply to your AI systems and what an audit would cover.

NDA as standard
1–4 week delivery
Fixed-fee pricing
Expert-led, not automated