All Insights 🌐 General & Cross-Sector
AI Insights for GENERAL & CROSS-SECTOR

AI Governance: Frameworks, Standards & Methodology

EU AI Act explained, NIST AI RMF in practice, and audit methodology — the foundational intelligence for any organization deploying AI in a regulated context.

3 frameworks
Every iDharma audit maps against NIST AI RMF, ISO/IEC 42001 and the EU AI Act simultaneously
Full coverage
1 gap register
One prioritized report, not three separate reviews
One engagement
1–4 weeks
Approved scope to a board-ready report
Typical turnaround
Most AI governance failures are not sector-specific. They stem from explainability gaps, undocumented training data, oversight mechanisms that exist on paper but not in practice, and accuracy claims that cannot withstand independent scrutiny. These cross-sector guides apply wherever AI makes consequential decisions about people.
STANDARDS EXPLAINED

ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For

One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.

STANDARDS EXPLAINED

Who Can Run a Local Law 144 Bias Audit, and What It Has to Measure

The law asks for an independent bias audit of the tool you hire with. Two words there do the work — independent, and audit — and a vendor certificate satisfies neither.

METHODOLOGY NOTES

What Is an AI Audit? Scope, Standards, and What You Get

An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.

METHODOLOGY NOTES

How Much Does an AI Audit Cost? What Actually Drives the Number

Fixed prices, published turnarounds, and an honest account of the four things that decide which tier a system belongs in — including when the answer is "none of them yet".

METHODOLOGY NOTES

How to Prepare for an AI Audit: The Readiness Checklist

Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.

STANDARDS EXPLAINED

What an AI Governance Framework Actually Contains

Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.