Thirty-one instruments in five families, and they are not one kind of thing. Some of them are law that reaches you whether you have heard of them or not; some are what a supervisor arrives holding; some are voluntary until a customer makes one a condition of a signed contract.
Every law, standard and instrument an audit can be scoped against.
All 31 instruments, grouped by what they govern - and what an audit covers against each.
Our promise
“A catalog is a list. A scope is an answer.”
Typically three to six of these reach an organisation, not 31 — and you are quoted for those, with each further one a fraction of the first. Nothing is charged until you approve the scope.
Ask which of these applyThe catalog, in three chapters
- 31
- Instruments Binding regulation, supervisory guidance, and the voluntary standards procurement asks about.
- 5
- Families AI regulation, AI standards, model risk, privacy, and security & resilience.
- 16
- Jurisdictions From the EU and the UK to the Gulf, Singapore, Canada and the US states.
- 5
- Readiness assessments Certification schemes where the certificate is issued by an accredited body, not by us.
A single AI system is routinely inside two or three of these at the same time, which cuts both ways. It means far more instruments reach you than you assumed - and it means the evidence written for one does most of the work for the next one, so the second costs a fraction of the first.
Our job is to settle which of them are actually yours. We inventory the systems, test each instrument against what they really do, fix your role under each of them, and hand you the shortlist — with the ones that do not reach you written down as excluded rather than left unmentioned.
Certification is issued by an accredited certification body, not by iDharma. We assess your readiness against the standard and prepare the evidence and gap list that body will ask you for.
Against the instruments that reach you - not against all 31 of them. Which ones those are is the first thing an engagement settles, and it is settled in writing before anything is charged.
Two kinds of engagement, and the difference matters.
Most entries here are audits. Some are schemes only an accredited body can certify.
- We assess you against the instrument - and we sign it
- An independent review of what it actually requires of you
- Ends in findings, evidence and a prioritised plan
- The judgement is ours to make and ours to put a name to
- We get you ready for someone else's audit
- Certification schemes, where an accredited body certifies
- We assemble the evidence, test the controls, list the gaps
- The certificate is theirs to issue - and the card says so
Not one kind of thing. Three kinds.
Law that reaches you anyway
Regulation applies because of what your systems do and where their output lands, not because you signed up to it. Most of this catalog is this kind: the EU AI Act, the state statutes, the privacy regimes. Nobody sends you a notice first, and not having heard of one has never been a defence to it.
What your regulator looks for
Model-risk guidance and supervisory expectations are not statutes, and they are examined against as though they were. SR 11-7, SS1/23, OSFI E-23: an examiner arrives holding the guideline and asks to see the validation. The consequence is the finding rather than the fine.
Standards nobody made you adopt
ISO/IEC 42001, SOC 2, NIST CSF: voluntary until a customer, an insurer or a tender makes one a condition of the deal. Then a scheme you never had to follow is holding up revenue - and the certificate comes from an accredited body, so the lead time is somebody else's calendar.
“We’re certified, so we’re compliant.”
A certificate covers its scheme. The law is separate.
It is the most common finding we write up.
- Who it is for
- AI product teams
- SaaS & platform vendors
- Banking & insurance
- Legal & compliance
- Regulated healthcare and HR tech
Typically three to six of these reach an organisation, not thirty-one - and it is almost never only the one that brought them here.
Overlap cuts in your favour too. Evidence written once for one instrument does most of the work for the next, so the second costs a fraction.
A certificate you hold covers its own scheme, at its own scope, on its own date. None of those three is the same as the law’s.
Three questions. Then you’ll know where to look.
No email, no signup. Families, not a named shortlist.
Where to look first
Four moments, and two have already passed.
Most of this catalog has been in force for years. Two of these are live obligations today and two are still ahead, so they cannot be planned as one deadline.
-
The standing set
In force alreadyPrivacy law, model-risk guidance and the security schemes have applied for years. Most of this catalog is here.
-
The AI wave
Since 2025-26Prohibitions, transparency duties and the first US state AI statutes are live obligations today, not future ones.
-
The heavy tier
Through 2027The EU high-risk regime and the deferred state acts land here, and their documentation has the longest lead time.
-
Flagged, not guessed
Still movingSeveral entries have dates that are still being amended. Each page says so on its face rather than picking one.
Teams read a catalog as a list of future work and plan for the newest date on it. Most of what reaches them already applies - the privacy regime, the security scheme in the contract, the model-risk guideline the examiner arrives holding. The new instrument is rarely the urgent one.
What you arrive asking, what we ship
12 questions, and the artefact that answers each one. Paired, so every promise on this page can be checked against the question beside it.
- Which instruments reach you By what your systems do, and where the output lands
- A written shortlist of the instruments in scope for you, with the reasoning for each one recorded.
- Which role you hold Provider, deployer, processor - and often more than one
- Your role settled per system per instrument, so a vendor's compliance is never mistaken for yours.
- Who the instrument binds The scope test, in plain terms rather than in its own
- The test applied to your facts, with the line drawn where the instrument draws it and not further.
- What it actually requires The obligations as things that have to be true
- Each requirement stated as a condition you either meet or do not, mapped to the clause it comes from.
- Where it overlaps One system is routinely inside two or three of these
- A map of which duties are satisfied once and which have to be met separately under each instrument.
- What evidence is examined What an assessor asks to see, before they ask for it
- The evidence list per instrument, and a note against each item saying whether you hold it today.
- Where the dates stand In force, phasing in, or still being amended
- The dates that bind you, with the ones still moving flagged as moving rather than quietly picked.
- Audit or readiness Who is allowed to issue the certificate at the end
- Stated before you buy: whether we can give you the finding, or prepare you for the body that does.
- What a certificate covers Its own scheme, at its own scope, on its own date
- What each certificate you already hold discharges, and which obligations it leaves entirely open.
- Which gaps matter first Ranked by consequence, not by ease of fixing
- A remediation shortlist ordered by what happens to the people affected if the gap stays open.
- What it costs to cover Per instrument, flat, before you commit to anything
- The fee for each instrument in scope, quoted against the scope you approved and never metered.
- What happens next year On modification, and on the next instrument
- A re-read against your known baseline, so the second engagement is not the first one done again.
Your AI estate, read against the list
From one instrument to the handful that actually reach you.
-
Scope
Which instruments actually reach you, and in which role under each.
-
Assess
Your systems read against what each one requires, evidence by evidence.
-
Report and re-read
You see the draft first. Then findings, gaps and a plan - each dated.
Why teams bring the whole list to iDharma
Genuinely independent
We build, resell and operate no AI systems of our own, and take no fee tied to what we find.
Scoped, not sold
You are quoted for the instruments that reach you. Nobody here is sold thirty-one of anything.
One engagement, end to end
Overlapping instruments read together in one scope, so no duty falls between two vendors.
The split stated up front
Where a certificate is somebody else's to issue, the page says so before you spend a fee.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Scope determination
The whole assessment in one document: every instrument in this catalog tested against what your systems actually do, the ones that reach you listed with the reasoning recorded, your own role settled under each, the overlaps between them marked, and the ones that do not reach you written down as excluded rather than left unmentioned.
Instrument register
Every system against every instrument that reaches it, with its role, its status and its owner, in a workbook your team can keep current.
Overlap map
Which duties are satisfied once across several instruments and which have to be met separately under each, drawn rather than asserted.
Evidence index
What each instrument in scope asks to see, broken into its sections, showing what you already hold, what is thin, and what is missing.
Exclusion memo
Which instruments were tested and found not to reach you, and why each call was made - the written record standing behind a shorter scope.
Remediation shortlist
Where the gaps sit, what to do first, and why each one is where it is. Ranked by consequence to the people affected, not by ease of fixing.
Certificate coverage read
What the certificates and attestations you already hold actually discharge, at what scope and to what date, and which obligations they leave open.
Real numbers, upfront.
- Scope
- Set by the instruments, not by us
- Priced
- Per instrument, flat — 31 of 31 published
- Together
- Each further instrument 40% of its own fee, in the same scope
The instruments fixed the scope, not us, so each fee is flat - nothing is charged until you approve it.
Ask what yours would cost- Scope determination for every instrument
- Instrument register and overlap map
- Each further instrument at 40% in the same scope
- Re-audit after a change at 65% of the band
- Annual renewal at 85%, locked
Four things every entry has to answer
Thirty-one pages, one shape. Each of these is settled on the page before you spend a call asking for it.
Who it binds,
exactly
The scope test in plain terms: whether the instrument reaches you at all, and in which role it does. Most pages in this catalog settle that inside one short paragraph.
What it requires,
listed
The obligations set out as things that have to be true, each mapped to the clause it comes from - so a finding against it can be checked rather than simply trusted.
What we examine,
named
The evidence an engagement asks for and the findings it lands on. Named on the page before you buy, so what arrives at the end is what the page said would arrive.
Where it stands,
dated
Which dates are in force, which are phasing in, and which are still being amended - the moving ones flagged as moving rather than quietly resolved in our favour.
Four answers, on all 31 pages. Not four out of four on the ones we like.
Ours is not on this list. Now what?
Ask. The method does not change with the instrument - these are the ones we are asked for most often, not the limit of what an engagement can be scoped against.
How many of these are actually going to reach us?
For most organisations it is between three and six, not thirty-one - and it is almost never only the one they arrived worrying about. Scoping settles it before anything is charged.
Why do some entries say readiness assessment instead of audit?
Because only an accredited body can issue those certificates. Against a certification scheme we prepare the evidence and the gap list; the certificate is somebody else's to sign, and the card says so before you buy.
Do we have to cover all of them at once?
No, and almost nobody should. An engagement is scoped against the instruments that actually reach you - typically three to six - and the overlap between them makes the second much cheaper than the first.
How long does one take?
Two to four weeks from hand-over for a single instrument, and a multi-instrument scope is longer but not proportionally - the overlap does most of the work. Scope is agreed before anything is charged.
Not sure which of these apply to you?
That is the first thing a scoping call settles - tell us what your AI does and where, and we come back within one business day.
What we need from you
Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.
- Which AI systems you build or use, and what each decides
- Where they operate, and where their output is used
- Any documentation - model cards, contracts, DPIAs
- Any certificates or attestations you already hold
- Whether an instrument has already been named to you
What happens next
- You send the five items we need.
- We come back with the instruments that reach you.
- Nothing is charged until you approve the scope.