EU AI Act
European UnionConformity assessments, technical documentation, and ongoing monitoring for high-risk systems.
Every AI system you run, mapped against the EU AI Act, GDPR and sector rules — then a ranked, plain-English list of exactly what to fix first.
All 31 frameworks an iDharma audit can assess you against — binding regulation, voluntary standards, and supervisory guidance. Every finding is mapped to the specific obligation it touches, so you know which rule a gap sits under, not just that a gap exists.
Conformity assessments, technical documentation, and ongoing monitoring for high-risk systems.
A documented AI management system: governance, risk treatment, and continual review.
Govern, map, measure, manage — the reference model most US examiners recognise.
Safeguards and explanation rights where automated decisions significantly affect people.
Bias audits for automated employment decision tools
In force since Oct 2025; the testing is the evidence
In force since Jan 2026; liability and a notice duty
Disclosure duties for automated decision-making technology
ECDIS governance for life, auto and health insurers
Insurance-regulator expectations for AI governance
Prohibited uses, disclosure and record-keeping
Transparency, traceability and outcome monitoring
Trust services criteria for systems handling customer data
Protected health information in AI training and inference
ISMS certification - clauses 4–10 and 93 Annex A controls
Cardholder data controls where AI touches payment flows
Cybersecurity framework functions applied to AI estates
Consumer rights, and ADMT duties from 1 January 2027
Operational resilience for financial-sector AI and its vendors
Values-based principles for trustworthy AI
Prioritised security controls for AI infrastructure
Fairness, transparency and accountability in practice
Claims substantiation and unfair-practice exposure
Personal data protection duties for AI processing
Two regimes - Law No. 13 onshore, QFC Regulations inside
Personal data protection duties for AI processing
Personal data protection duties for AI processing
Automated decision transparency and privacy duties
Model risk management - superseded SR 11-7 on 17 Apr 2026
Five model risk principles for firms with internal model approval
Model risk across five lifecycle stages, effective 1 May 2027
Status and scope verified against each framework's primary source. We cite enforcement figures only once confirmed from the original filing — verified cases appear in our teardowns.
An AI audit isn't about finding fault, it's about clarity: we map what your AI tools actually do, identify the regulations that apply, and hand you a prioritized action plan you can act on immediately.
Know your exposure
Understand where your AI stands before enforcement, a partner bank, or a procurement team asks.
Win enterprise contracts
Procurement teams now demand AI compliance evidence. An audit gives you a credible answer.
Build customer trust
Show clients and partners how their data is protected and how decisions are made.
Scale confidently
Deploy new AI capabilities knowing your compliance baseline is documented and current.
Every audit is scoped to your systems and your sector — nothing is charged until you approve the scope.
See How It WorksMost consultancies offer a generic checklist. iDharma delivers a structured, sector-specific, actionable audit.
| What You Get | iDharma Audit | Generic Consultancy | DIY Checklist |
|---|---|---|---|
| Sector-specific risk mapping | Built-in | Partial | |
| EU AI Act risk classification | All tiers | Basic | |
| Plain-language action plan | Prioritized | Legal language | |
| Remediation guidance included | Extra cost | ||
| Delivered in 1–4 weeks | Scoped per engagement | Self-paced | |
| Evidence pack for regulators | Included | Optional | |
| Fixed transparent pricing | Time & materials |
We don’t build or sell the AI we assess, and we don’t sell the fixes we’d recommend.
We’re paid to assess your system honestly against a published standard — not to reach a particular conclusion.
We disclose any relationship that could color the work, and if a genuine conflict exists, we decline the engagement rather than caveat it.
Each dimension maps to a specific regulatory obligation — and to a business risk you can actually manage.
Together they cover how your AI is governed, where its data comes from, whether it treats people fairly, how it holds up under pressure, and whether it meets the law.
See How It WorksOwnership & human override
Where your data comes from
Equitable, tested outcomes
Robust under adversarial pressure
Meets the laws that apply
Generic audits miss sector-specific rules. Ours don't.
No lengthy onboarding. No scope creep. A fixed process, a fixed timeline, a fixed price.
Tell us about your AI systems, your sector, and where you’re unsure. Nothing is charged.
We agree the systems, depth, and price before any work begins. You approve the scope first.
An iDharma-verified expert reviews your systems against our published methodology.
A prioritized findings report and a walkthrough — you leave knowing what to fix, and when.
Every iDharma audit produces a structured set of documents your team, legal counsel, and regulators can actually use.
Sample Deliverable — Audit Report Extract
An iDharma audit is scoped against the specific instruments that apply to you — 31 of them, from binding regulation to the standards procurement asks about. Filter the set, or open any one to see what it requires and what an audit covers against it.
No framework matches that.
These pages describe what each instrument requires and what an audit covers against it. They are scoping guidance, not legal advice — iDharma works alongside your counsel, not in place of them.
Fixed, scoped fees — no time-and-materials, no surprises. Reports in 1–4 weeks.
No payment until you approve the scope.
All audits are covered by NDA as standard. Your systems and data never leave the engagement.
No. We work from system documentation, data flow diagrams, policy documents, and structured interviews with your team. Source code is never required for a compliance audit.
Typically around 3 hours of your team's time spread across the first four days — mostly answering our structured questionnaire and joining one call. We do the analysis independently.
That's exactly what the scoping call is for. Many clients discover AI systems embedded in third-party SaaS tools they didn't realise were in scope. We help you map your full AI footprint first.
Yes — but not on the trigger most teams assume. The Act reaches you if you place an AI system on the EU market or put it into service there, or if the output your system produces is used in the EU, regardless of where your organization is registered. Processing personal data of EU residents is GDPR's trigger, not the AI Act's — the two catch different things, and a system can be in scope for one and not the other.
We cover the EU AI Act (all risk tiers), NIST AI RMF, ISO/IEC 42001, HIPAA, SOC 2, and India's DPDP, plus GDPR Articles 13, 14, and 22 — mapped to your specific use case.
No, but our audit often surfaces what's needed for a DPIA. An AI compliance audit is broader — it covers the AI Act, sector rules, and operational risk — not just data protection law.
You receive 14 business days of written follow-up in your portal with your audit lead, plus optional remediation support packages if you want help implementing fixes — policy drafting, technical controls, staff training.
Yes — the evidence pack is specifically designed to be shared with procurement teams, due diligence processes, and enterprise clients who require AI compliance documentation as part of vendor qualification.
Law firms deliver legal opinions. We deliver operational compliance — structured evidence, actionable fixes, and plain-language guidance your technical and business teams can act on. We're not a substitute for legal counsel, but we work alongside yours.
We deliver within the scope and timeline we agree with you (typically 1–4 weeks). And if a regulator questions the methodology of our audit, we'll provide expert support at no additional cost.
Every audit is led and signed by a named reviewer — no black box, no anonymous “team.”
Book a free scoping call. No commitment. We'll tell you exactly which regulations apply to your AI systems and what an audit would cover.
No payment until you approve the scope
Brijesh Patel, our founder, personally replies within one business day. Nothing is charged until you approve the scope.
We’ve emailed you a secure, password-free link to your client portal. Sign in to your portal →
For audit firms and practitioners: co-deliver AI audits on our methodology and audit trail.
Thank you — your auditor partner application is with our team. We review every application and will be in touch by email.