iDharma publishes three fixed prices for an AI audit: $5,000 for a Quick Scan, $15,000 for a Compliance Audit, and $25,000 for a Risk Audit. The price is agreed with the scope, before any payment, and it does not move during the engagement.
That is the short answer. The longer one — which tier a given system actually belongs in, and when the honest answer is "none of them yet" — is what the rest of this is for.
Why the price is fixed
Professional services default to hourly rates, and for AI work that default is bad for the buyer in a specific way. Nobody entering an AI audit knows in advance how tangled the evidence is going to be, and under an hourly arrangement the person who discovers that it is tangled is not the person who pays for it. It also creates a quiet incentive against efficiency.
Fixing the price at agreed scope moves that risk to us. It has one consequence worth stating: scope has to be settled properly before the engagement starts, which is why scoping is five specific questions rather than a form.
What the three tiers actually differ on
Not depth-as-a-vibe. Each tier adds a distinct kind of work.
Quick Scan — $5,000, about a week
Up to three AI systems, reviewed for top-priority risk and gaps, ending in a prioritised action list and fourteen business days of written follow-up in your portal. This is a read, done by someone who has read a lot of these. It will tell you where you are exposed and what to do first. It will not tell you whether your model is fair, because measuring that takes longer than a week.
It is the right tier for a team shipping its first AI features, and for anyone who needs to know whether the bigger engagement is warranted before committing to it.
Compliance Audit — $15,000, about two to three weeks
A full check of where you fall short of the rules that actually apply to you, mapped against the EU AI Act, GDPR Article 22 and the sector standards in scope, with documentation and policy review and an executive summary. The extra fortnight is spent on the gap between "we have a policy" and "the policy describes what happens."
This is the tier most organisations in regulated markets need, and the one most often under-bought — a scan is cheaper and does not produce the record a counterparty is asking for.
Risk Audit — $25,000, about four weeks
Everything in the Compliance Audit, plus bias and fairness testing, a security review including adversarial probing, model and training-data provenance review, and a briefing built to be presented to a board.
The step up in price is a step up in testing, not in reading. Fairness evaluation means running the system against constructed populations and analysing outcomes; adversarial probing means attacking it; provenance review means tracing where training data came from and what rights came with it. Each is measurement work, and measurement is what costs.
The four things that decide which tier you need
1. How many systems are genuinely in scope
Organisations routinely under-count this, and the under-count is nearly always the same shape: the AI features inside SaaS tools already in use. A CRM with an AI summariser, a support desk with a suggested-reply model and a hiring tool with a ranking feature are three AI systems, whoever built them. Whether they belong in scope depends on the next question.
2. Whether the AI influences a consequential decision
This is the single largest driver, because it changes which rules apply rather than how much work there is. A model that drafts internal text sits in a light regime almost everywhere. A model that affects credit, care, employment, insurance, pricing or access to a service is in scope of the EU AI Act's high-risk provisions if it touches EU users, and of sector rules regardless. The high-risk category is narrower and stranger than most summaries suggest, and it is worth checking properly rather than assuming.
3. How many frameworks the review has to answer to
A US health system with EU patients is answering to HIPAA, to its state's AI rules and to the EU AI Act at once. Mapping one deployment against three frameworks in a single engagement is more work than mapping it against one — but it is considerably less work than three sequential reviews producing three reports that disagree about severity.
4. Whether you need testing or a gap review
The honest question is what you will do with the answer. If you need to know where the gaps are so you can close them, a Compliance Audit is the tier. If you need to be able to show a third party that the system was tested — a partner bank, an enterprise buyer, a board that has started asking — then the testing has to actually happen, and that is the Risk Audit.
What we do not charge for
Scoping. The conversation that establishes what should be reviewed, which tier fits and whether an audit is the right spend at all happens before any payment, and it ends with a written scope you approve. If the outcome of that conversation is "not yet," that is a legitimate outcome and it costs nothing.
There is also a free Risk Snapshot — five questions, about a minute, producing a prioritised exposure summary. It is not an audit and it tests nothing. Its job is to tell you whether the paid thing is worth buying.
Setting it against the other number
The comparison people reach for is the cost of an audit against the cost of a penalty, and that framing is worse than it looks: it invites a fear-based decision using a number nobody can honestly quote for a system they have not seen.
The more useful comparison is against your own exposure, calculated with your own figures — decision volume, what a wrong decision costs you to remediate, what a counterparty walking away costs, what a rebuild costs if a provenance problem surfaces after launch rather than before. We set out that calculation in how to put a number on your AI exposure, and deliberately with no fine figures in it.
What comes after the number
An audit is a fixed cost that produces a variable amount of work, and that is the part worth budgeting for. Findings arrive graded, and a serious report will name things that are genuine rebuilds rather than configuration changes. Reading the report is a skill in itself — what the risk rating on a finding actually means is not obvious — and turning it into work that happens is its own discipline, which is why the fix roadmap gets its own article.
If you already know which tier you need, the audit page lists what each one includes. If you do not, that is what the scoping conversation is for.
Frequently asked questions
- How much does an AI audit cost?
- iDharma publishes three fixed prices: $5,000 for a Quick Scan, $15,000 for a Compliance Audit and $25,000 for a Risk Audit. The price is fixed at the point scope is agreed, before any payment, so the number does not move during the engagement.
- Why are AI audit prices fixed rather than hourly?
- Because an hourly engagement puts the risk of a difficult scope on the buyer, and it gives the auditor a reason not to be efficient. Fixing the price at agreed scope moves that risk to us and makes the number a decision you can take once.
- What makes one AI audit more expensive than another?
- Four things, in order of impact: how many systems are in scope; whether the AI influences a consequential decision about a person; how many separate frameworks the review has to be mapped against; and whether fairness, security and provenance testing are needed rather than a documentation and gap review.
- Is there a cheaper way to find out where we stand?
- Yes. The Risk Snapshot is free, takes about a minute, and produces a prioritised exposure summary from five questions. It is not an audit and it does not test anything — it tells you whether an audit is the right next spend.
- Does an audit include fixing what it finds?
- The report includes a prioritised fix path, and the Quick Scan includes fourteen business days of written follow-up. Doing the remediation work is a separate engagement — an auditor who also implements the fixes is no longer independent of the thing being audited.