AI ETHICS · GOVERNANCE AUDIT · ANNUAL

Your published AI ethics principles are not a programme.

Six pillars, one governance structure and the evidence that each one operates - read against UNESCO, the OECD and IEEE, once a year.


A compliance professional seated at a desk in a warm, low-lit office, signing a printed document with a pen, further papers and a cup of coffee on the desk beside them and a window throwing daylight across the page.
Oversight only counts once it is written down
Fairness Transparency Accountability Privacy Human oversight

Our promise

“Values are a statement. Practice is evidence.”

Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $6,500, and nothing is charged until you approve it.

Each additional tool
$1,500
Re-audit, same scope
$4,200
Renewal, every twelve months
$5,500 locked

This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.

Request this audit
The case file

AI ethics, in three chapters

The Principles

Between 2019 and 2021 the OECD, UNESCO and IEEE each set out what a responsible AI system owes the people it affects. Six ideas recur in all three - fairness, transparency, accountability, privacy, safety and human oversight - and every AI law written since has borrowed all six of them.

The Gap

Most organisations have published a version of those six and stopped there. The principles have no owner, block no decision, and have never once held a release. Meanwhile the systems shipped and the thresholds moved, and nobody wrote any of it down while it was happening.

The Office

Our work is to close that gap in writing. We test the six pillars against records you already hold, review the four structures meant to keep them running, and hand you findings, a charter with an owner against every principle, and a policy register - written so you can defend each line.

What is an AI ethics programme?

Principles that can stop a release.

Principles with a named owner, and a record of where they blocked something.

Who needs one № 01
  • Anyone whose systems shape decisions about people
  • Teams selling AI into regulated or enterprise buyers
  • Organisations that have published AI principles already
  • Boards asked to state what their AI exposure actually is
AI ethics · iDharma · Presented for assay
When the work triggers № 02
  • Before a system that touches people reaches production
  • When a buyer or regulator asks you to evidence a principle
  • Every twelve months a system stays in use
  • Whenever a model, threshold or use case materially changes
AI ethics · iDharma · Presented for assay
Whose duty is it

The duty is yours. The model is theirs.

You

The organisation that deploys it

Every instrument in this field puts the duty on whoever puts the system in front of a person. Setting the principles, deciding who signs off, keeping the evidence and telling people how the system affects them are all yours. None of them can be discharged by the people who built the model, however good they are.

Your model provider

The people who built the model

Carries duties of its own under the EU AI Act and under contract, but not yours. Many providers publish genuinely good model and system cards. The difficulty is not their quality - it is that they describe the model, while the ethical question is about your particular use of it, in your own context.

The catch

When a published principle counts

A principle counts when it has a named owner, a decision it can block, and a record of it having blocked one. Published on a web page with no owner, no gate and no evidence, it is a statement of intent - and that is exactly how a regulator, a journalist or a procurement reviewer will read it.

What most teams assume

“We published principles, so we have a programme.”

What the instruments ask

A principle that stopped nothing is a statement.

It is the most common finding we write up.

  • Who it is for
  • Product & platform teams
  • Boards & audit committees
  • Risk & compliance
  • Legal & privacy
  • AI vendors under procurement review
Why this matters in 2026
A black ring binder closed on a dark desk, a brass-framed label plate screwed to its cover with its ruled lines left completely blank, a red ribbon and wax seal holding the page block shut, and a clipped stack of printed sheets, reading glasses and a fountain pen laid out beside it: the record nobody wrote.
01 No fine attaches to a principle. The cost arrives through the instruments that adopted them - and through the buyer who asked you to evidence one and got a web page.
02

The EU AI Act, the Colorado AI Act and NYC Local Law 144 all enforce the same six ideas. The principles are voluntary; their content is not.

03

An assessment ages. Models drift and thresholds get relaxed, so a finding from last year describes a system you are no longer running.

04

Your principles page is checkable from the outside. A fairness claim you cannot evidence is still a claim, and that is how a regulator reads it.

The 60-second check

Three questions. Then you’ll know.

No email. No signup. A starting point, not a finding.

0 of 3

Reaches people -

Bought counts as built. A scoring or ranking feature inside a product you licensed is your system for this purpose - you chose it, you set the threshold, and it is your name on the outcome.

What it decides -

Ranking is deciding. A system that reorders a queue changes who is seen and who is not, even where no approval or rejection was ever recorded against a name.

Evidence in hand -

A page is not evidence. The question is never whether the principle exists. It is whether anything happened because of it, and whether that was written down at the time.

The calendar

Four moments, and not in the order you’d guess.

Three of these run once and then repeat; the third runs on every release. They overlap, and none of them can be started from the one after it.

  1. Charter

    Weeks 1-6

    Your published principles, the committee that owns them and the decisions it may stop - by name, not by role.

  2. Standards

    Weeks 7-14

    Policies and thresholds written down, so a team can tell before it builds what will fail review later, and why.

  3. Assess

    Before release

    Every system in scope tested against the six pillars, with the evidence kept as it stood on the decision date itself.

  4. Re-review

    Annually

    Models drift, and so do the people who signed them off. A twelve-month re-review against your own baseline.

The trap

Teams write the principles last, after the systems are already live, and the charter then has to describe what shipped rather than govern what ships. Everything downstream inherits that: a committee cannot decline a release it was never asked about, and an assessment cannot find evidence nobody was told to keep.

Requirement & coverage

What the instruments ask, what we ship

12 requirements, and the artefact that answers each one. Paired, so every claim on this page can be checked against the requirement beside it.

Whose duty it is The deployer, not the model provider
A written determination of who owns each system and each principle, so a vendor model card is never mistaken for your programme.
What is actually in scope Systems that shape a decision about a person
An inventory of AI systems with the decision each one touches - including the bought ones nobody logged as AI.
Fairness Disparate outcomes, measured not asserted
Outcome rates by group for every system that affects people, with the comparator and the threshold stated.
Transparency People are told when AI shapes a decision
A check of every disclosure you make against what the system actually does, and the gaps between the two.
Accountability A named person who can stop a release
The decision rights mapped to real names and roles, and the escalation route when a review says no.
Privacy Lawful basis, minimisation, retention
Data provenance and retention tested against your own notices - the pillar most often assumed to be covered.
Safety and robustness What the system does when it is wrong
Failure modes, degradation behaviour and the monitoring that would tell you before a customer does.
Human oversight Review that can change the outcome
Evidence that a human reviewer has overridden the model, with the rate - the difference between oversight and sign-off.
Board oversight AI reaches the board as a standing item
Minutes, terms of reference and the reporting line reviewed for whether AI risk actually arrives there.
Ethics committee A body with membership, quorum and teeth
Charter, membership and decision log reviewed - including how often the committee has said no.
Policies and standards Written before the build, not after it
A policy register mapped to the six pillars, with every gap named rather than left to be inferred.
Monitoring and audit The programme checks itself between reviews
The metrics, the thresholds and who reads them - plus what happened the last time one was breached.
The engagement

Your AI programme, independently read

From a model you trained to a feature you licensed.

  1. Inventory

    Which systems are in scope, and who currently decides they may ship.

  2. Assess

    Six pillars tested against evidence, not against your policy text.

  3. Report and publish

    You see the draft first. Then findings, the charter and the register - dated.

Request your ethics audit
An auditor in a forest-green trouser suit and cream blouse, with braided hair in a high bun, standing against a warm pale wall and pointing into the open space alongside.
Findings you can check line by line - that is what you are buying.
Struck in your favour

Why boards choose iDharma to read their programme

Genuinely independent

We build, resell and operate no AI systems, and we take no fee tied to what the assessment finds.

Evidence, not policy text

Every finding rests on a record you already hold, so a reviewer can check it without taking our word.

One engagement, end to end

Pillars, structures and policies sit in one scope, so no gap falls between two separate reviews.

Mapped to what binds you

Each pillar is tied to the instrument that makes it enforceable, so the work is never only advisory.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

AI ethics audit report

The full assessment in one document: a finding against each of the six pillars - fairness, transparency, accountability, privacy, safety and human oversight - each mapped to the instrument that makes it enforceable, ranked by consequence to the people affected, and written in plain language rather than the standards'.

Workbook

Fairness results

The outcome tables in a workbook, so your own analysts can reproduce every figure in the report, cell by cell, without asking us for it.

HTML + PDF

Ethics charter

Your principles rewritten with an owner and a decision gate against each, marked up ready to publish - as HTML and PDF.

Templates

Committee pack

Terms of reference, a membership and quorum model, the escalation route, and the decision log the committee is meant to leave behind.

Memo

System scope memo

Which systems were in scope, which were not, and why each call was made - the written record that stands behind your AI inventory.

Ranked

Remediation shortlist

Where a pillar fails, what to look at first, and why. Findings ranked by consequence to the people affected, not by ease of fixing.

Register

Policy register

Your existing policies mapped to the six pillars, with each gap named and sized - so the writing that follows is scoped, not guessed.

Format & fee

Real numbers, upfront.

Scope
Six pillars, four structures
Evidence
Records you already hold
Re-review
Every rolling twelve months - $5,500 against your known baseline

The pillar set is fixed, so the fee is flat - only the inventory varies, and we count it with you before we start.

Request this audit
AI ethics · Named engagement $6,500 flat
  • Findings across all six pillars
  • Outcome rates by group, with comparators
  • Ethics charter with owners against it
  • Policy register and committee pack
Show your hand

Four things you have to be able to produce

An ethics programme is not graded on intent. Each of these is either in your hand on the day someone asks, or it is not.

The charter,
owned

Your principles with a named owner against each one, and the route a concern travels. A principle nobody owns cannot be breached, so nobody ever reports one.

The register,
current

Every AI system in use, what decision it touches and who signed it off. Most inventories we are shown are missing the systems that were bought in rather than built.

The decision,
logged

A record of a review that actually changed something - a release held, a feature cut, a model rejected. Oversight either leaves a trace or it never really ran.

The numbers,
by group

Outcome rates by group for every system that affects people, with the comparator stated and the date on the run. The table itself is the evidence, not the assurance.

Four cards, and the date on each one is part of the card.

FAQ

Plain answers

Binding, what we measure, and what wrong costs. Answered straight.

Request this audit
Are AI ethics frameworks actually binding on us?

Not of their own force - UNESCO, the OECD and IEEE bind nobody directly. Their content is what became binding: the EU AI Act, sector regulators and your own contracts all borrowed from them.

We published our AI principles. Is that a programme?

Almost never - this is the most common finding we write up. A principle counts when it has a named owner, a decision it can block, and a record of having blocked one. Most published sets have none of the three.

What exactly gets measured?

Six pillars against evidence: fairness, transparency, accountability, privacy, safety and human oversight - plus the four governance structures behind them. Every finding rests on a record you already hold.

How long does an assessment take?

Typically three to five weeks from document hand-over for a first assessment, longer where the system inventory turns out to be bigger than expected - which it usually does. Scope is agreed with you before anything is charged.

What are the consequences of getting this wrong?

No fine attaches to the principles themselves - it arrives through the instruments that adopted them: the EU AI Act, sector regulators, consumer-protection law, contract termination, and a failed procurement review.

Get started

Request your ethics audit

Tell us what you run, and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we tell you exactly which documents we need before you commit.

  1. Which AI systems are in use, and what each one decides
  2. Your published principles, if any, and who wrote them
  3. Any review or sign-off records from the past year
  4. Outcome data for the systems that affect people
  5. What is driving the timing: a buyer, a regulator, a date

What happens next

  1. You send the five items we need.
  2. We call to scope it within one business day.
  3. Nothing is charged until you approve the scope.
Request your ethics audit
Sources & standing

Where this page gets its facts

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • UNESCO Recommendation on the Ethics of AI
  • OECD AI Principles · IEEE 7000 series
OECD
May 2019, revised 2024
UNESCO
November 2021

What it means

  • None of these instruments binds a company of its own force — their content binds through the laws that adopted it.
  • Where a fairness definition is genuinely contested, our reports show the result under each reading rather than pick one.

Scope & limitation

  • General information, not legal advice, and no professional relationship arises from reading it.
  • There is no accredited certification for AI ethics. This is an independent assessment, and it does not issue one.

Something on this page out of date?

Tell us