Decision-making AI
Any model that influences consequential outcomes — hiring, credit, access to services, content moderation.
AI Governance & Compliance
Three frameworks — NIST AI RMF, ISO/IEC 42001, and the EU AI Act — mapped simultaneously against your deployment. One prioritized gap register. No vendor spin.
What we audit
Every system below is covered in a standard iDharma engagement. Complex or multi-system deployments are scoped on request.
Any model that influences consequential outcomes — hiring, credit, access to services, content moderation.
LLMs and diffusion models in customer-facing or internal workflows — accuracy, hallucination risk, data governance.
Third-party models integrated into your product or operations. "Our vendor handles it" has not succeeded as a compliance defense.
AI used for surveillance, anomaly detection, or fraud scoring where the model acts without per-decision human review.
Regulatory frameworks
Every iDharma General engagement maps simultaneously against the frameworks below — producing one gap register, not three separate reports.
Applies to any AI affecting EU users. High-risk systems face conformity assessments, technical documentation, and ongoing monitoring obligations.
A voluntary but widely referenced framework covering Govern, Map, Measure, and Manage functions across the AI lifecycle.
The international standard for AI management systems — the AI equivalent of ISO 27001 for information security.
Our methodology
We do not accept vendor documentation as evidence, and we do not produce checkbox compliance reports. Every audit gives you a named auditor, a cited methodology, and a straight answer on where your AI stands.
We audit against all three frameworks in a single engagement — not three sequential reviews.
Every finding is rated by legal severity, so your remediation roadmap is ordered by what creates the greatest regulatory exposure.
We do not use the vendor's own documentation as evidence — we independently verify claims against source data, test outputs, and technical specifications.
You receive a named auditor, a cited methodology, and a straight answer on exactly where your AI stands.
More sectors
Get started
The free Risk Snapshot takes about 60 seconds — five quick questions — and produces a prioritized exposure summary.
“AI is already making general decisions — with no independent proof it holds up.”
One prioritised gap register mapped to the frameworks you answer to — signed by a named auditor.
Scoped before you pay — nothing is charged until you approve what the engagement covers.