Know exactly where your AI systems
stand before regulators do.
iDharma's structured audit maps every AI tool your organization uses against the EU AI Act, GDPR, and sector regulations — and tells you precisely what to fix, in plain language.
The rules are already live
These frameworks are in force or phasing in now. An iDharma audit maps every finding to the specific obligation it touches — so you know which rule a gap sits under, not just that a gap exists.
EU AI Act
Phasing inConformity assessments, technical documentation, and ongoing monitoring for high-risk systems.
GDPR, art. 22
In forceSafeguards and explanation rights where automated decisions significantly affect people.
ISO/IEC 42001
In forceA documented AI management system: governance, risk treatment, and continual review.
NIST AI RMF
VoluntaryGovern, map, measure, manage — the reference model most US examiners recognise.
Sector rules
By industryDORA, FCA guidance, HIPAA, and new US state AI laws layer on top of the above.
Status and scope verified against each framework's primary source. We cite enforcement figures only once confirmed from the original filing — verified cases appear in our teardowns.
A structured review of every AI system your organization relies on.
An AI audit isn't about finding fault, it's about clarity: we map what your AI tools actually do, identify the regulations that apply, and hand you a prioritized action plan you can act on immediately.
See How It Works
Independent review
Not all audits are created equal.
Most consultancies offer a generic checklist. iDharma delivers a structured, sector-specific, actionable audit.
| What You Get | iDharma Audit | Generic Consultancy | DIY Checklist |
|---|---|---|---|
| Sector-specific risk mapping | Built-in | Partial | |
| EU AI Act risk classification | All tiers | Basic | |
| Plain-language action plan | Prioritized | Legal language | |
| Remediation guidance included | Extra cost | ||
| Delivered in 1–4 weeks | 6–12 weeks | Self-paced | |
| Evidence pack for regulators | Included | Optional | |
| Fixed transparent pricing | Time & materials |
Five areas we examine in every audit.
Each dimension maps to a specific regulatory obligation — and to a business risk you can actually manage.
Together they cover how your AI is governed, where its data comes from, whether it treats people fairly, how it holds up under pressure, and whether it meets the law.
See How It WorksGovernance
Ownership & human override
Data provenance
Where your data comes from
Bias & fairness
Equitable, tested outcomes
Security
Robust under adversarial pressure
Compliance
Meets the laws that apply
Sectors We Serve
Sector expertise built into every audit.
Generic audits miss sector-specific rules. Ours don't.
Four steps from kickoff to compliance clarity.
No lengthy onboarding. No scope creep. A fixed process, a fixed timeline, a fixed price.
Request
Tell us about your AI systems, your sector, and where you’re unsure. Nothing is charged.
Scope & fixed quote
We agree the systems, depth, and price before any work begins. You approve the scope first.
Audit (1–4 weeks)
An iDharma-verified expert reviews your systems against our published methodology, identifies gaps, and drafts your action plan.
Report & walkthrough
A prioritized findings report and a walkthrough — you leave knowing what to fix, and when.
A complete compliance evidence pack — not just a report.
Every iDharma audit produces a structured set of documents your team, legal counsel, and regulators can actually use.
- Full Audit ReportFindings against each of the five dimensions, with risk ratings and regulatory citations.
- Risk Snapshot DashboardA single-page summary your board can understand in three minutes.
- Prioritized Action PlanFixes ranked by urgency, effort, and regulatory deadline, with owner assignments.
- Evidence PackPre-formatted documentation to demonstrate compliance to regulators or enterprise clients.
- Report WalkthroughLive session with your audit lead to answer every question your team has.
- 14 Business Days of Follow-UpWritten Q&A with your audit lead in your secure portal after delivery.
Sample Deliverable — Audit Report Extract
Know the cost before you commit.
Fixed, scoped fees — no time-and-materials, no surprises. Reports in 1–4 weeks.
- Review of up to 3 AI systems or tools
- Top-priority risk and gap findings
- A prioritized action list you can act on
- 14 business days of written follow-up in your portal
- Full check of where you fall short of the rules that apply to you
- Checked against the EU AI Act, GDPR Article 22, and the standards that apply to you
- A prioritized plan for fixing what we find
- Documentation and policy review
- Executive summary report
- Everything in the Compliance Audit, plus:
- Bias and fairness testing
- Security review including adversarial probing
- Model and training-data provenance review
- A risk briefing you can present to your board
No payment until you approve the scope.
All audits are covered by NDA as standard. Your systems and data never leave the engagement.
Questions we hear every time.
No. We work from system documentation, data flow diagrams, policy documents, and structured interviews with your team. Source code is never required for a compliance audit.
Typically around 3 hours of your team's time spread across the first four days — mostly answering our structured questionnaire and joining one call. We do the analysis independently.
That's exactly what the scoping call is for. Many clients discover AI systems embedded in third-party SaaS tools they didn't realise were in scope. We help you map your full AI footprint first.
Yes — if your AI system's outputs are used within the EU, or if you process data of EU residents, the Act applies regardless of where your organization is registered.
No, but our audit often surfaces what's needed for a DPIA. An AI compliance audit is broader — it covers the AI Act, sector rules, and operational risk — not just data protection law.
You receive 14 business days of written follow-up in your portal with your audit lead, plus optional remediation support packages if you want help implementing fixes — policy drafting, technical controls, staff training.
Law firms deliver legal opinions. We deliver operational compliance — structured evidence, actionable fixes, and plain-language guidance your technical and business teams can act on. We're not a substitute for legal counsel, but we work alongside yours.
Yes — the evidence pack is specifically designed to be shared with procurement teams, due diligence processes, and enterprise clients who require AI compliance documentation as part of vendor qualification.
We cover the EU AI Act (all risk tiers), NIST AI RMF, ISO/IEC 42001, HIPAA, SOC 2, and India's DPDP, plus GDPR Articles 13, 14, and 22 — mapped to your specific use case.
We deliver within the scope and timeline we agree with you (typically 1–4 weeks). And if a regulator questions the methodology of our audit, we'll provide expert support at no additional cost.
Every audit is led and signed by a named reviewer — no black box, no anonymous “team.”
Ready to know where you stand?
Book a free scoping call. No commitment. We'll tell you exactly which regulations apply to your AI systems and what an audit would cover.