NIST AI RMF, ISO/IEC 42001 & EU AI Act, mapped simultaneously
Independent AI audits for every organization using AI in a regulated context
NIST AI RMF, ISO/IEC 42001 and the EU AI Act, mapped at once against your deployment — one prioritized gap register.
Where this sector stands
General at a glance
One prioritized report, not three separate reviews
Approved scope to board-ready report
Free, no signup — five questions and a real, specific finding about your AI in 60 seconds.
Get your free Risk Snapshot →What we audit
AI systems in scope for General
Every system below is covered in a standard iDharma engagement. Complex or multi-system deployments are scoped on request.
See how it worksDecision-making AI
Any model that influences consequential outcomes — hiring, credit, access to services, content moderation.
Generative AI deployments
LLMs and diffusion models in customer-facing or internal workflows — accuracy, hallucination risk, data governance.
Vendor-supplied AI
Third-party models integrated into your product or operations. "Our vendor handles it" has not succeeded as a compliance defense.
Automated monitoring systems
AI used for surveillance, anomaly detection, or fraud scoring where the model acts without per-decision human review.
Regulatory frameworks
What we audit against
Every iDharma General engagement maps simultaneously against the frameworks below — producing one gap register, not 3 separate reports.
EU AI Act (2024/1689)
Applies to any AI affecting EU users. High-risk systems face conformity assessments, technical documentation, and ongoing monitoring obligations.
Key obligationsNIST AI RMF
A voluntary but widely referenced framework covering Govern, Map, Measure, and Manage functions across the AI lifecycle.
Key obligationsISO/IEC 42001
The international standard for AI management systems — the AI equivalent of ISO 27001 for information security.
Key obligationsOne engagement.
Three frameworks.
Mapped together.
Measured once.
Our methodology
How an iDharma audit works
We do not accept vendor documentation as evidence, and we do not produce checkbox compliance reports. Every audit gives you a named auditor, a cited methodology, and a straight answer on where your AI stands.
We audit against all three frameworks in a single engagement — not three sequential reviews.
Every finding is rated by legal severity, so your remediation roadmap is ordered by what creates the greatest regulatory exposure.
We do not use the vendor's own documentation as evidence — we independently verify claims against source data, test outputs, and technical specifications.
You receive a named auditor, a cited methodology, and a straight answer on exactly where your AI stands.
More sectors
Explore other domains
Get started
Not sure which frameworks apply to your AI?
The free Risk Snapshot takes about 60 seconds — five quick questions — and produces a prioritized exposure summary.
“AI is already making general decisions — with no independent proof it holds up.”
One prioritised gap register mapped to the frameworks you answer to — signed by a named auditor.
Scoped before you pay — nothing is charged until you approve what the engagement covers.
From Insights
Related reading
Colorado SB 26-189: Four Duties, and the One Nobody Budgets For
Notice before, disclosure after, human review on request, records for three years. Three are policy changes. The second is an engineering project, and it arrives late.
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.
Who Can Run a Local Law 144 Bias Audit, and What It Has to Measure
The law asks for an independent bias audit of the tool you hire with. Two words there do the work — independent, and audit — and a vendor certificate satisfies neither.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.