Verification Methodology

The standard every iDharma audit
is measured against.

A published, evidence-based methodology for independently assessing whether the AI you run is accurate, fair, secure, and compliant — mapped to the frameworks that matter, so every finding is traceable to evidence, not opinion.


A printed AI Audit Standard report on a dark wooden desk, showing an executive summary with an overall compliance score, domain score bars, a findings-by-severity table and a framework mapping matrix, beside a navy Independent Audit binder, reading glasses, a calculator, a fountain pen and a magnifier Illustrative sample
Illustrative — how the rubric reads once applied
  • Version 1.1
  • Last updated 1 July 2026
  • Maintained by the iDharma team
  • Published & open
NIST AI RMF ISO/IEC 42001 EU AI Act SOC 2 HIPAA India DPDP
  • What it assesses

    Five dimensions across your AI — governance, data, fairness, security, and compliance.

  • Frameworks mapped

    NIST AI RMF, ISO/IEC 42001, EU AI Act, SOC 2, HIPAA, and India DPDP — explained below.

  • Who conducts it

    The iDharma team — independent of the systems being reviewed.

  • What you get

    A prioritized report, ready to present to your leadership team, with severity ratings and a fix-first plan.

Independent. Objective. Focused on what matters.

What we assess

Five dimensions, checked against evidence

Every audit rates your AI on the same five dimensions — the ones that decide whether a system is trustworthy in production.

How an audit is conducted →
A leather-bound reference volume pulled forward on a dark shelf, tabbed with pale markers at the passages being checked Checked against evidence

Governance

Who's accountable, and whether anyone is actually overseeing what the AI does

Is there a written policy for who owns this AI and who's accountable when it goes wrong? We check who's actually watching it, whether there's an up-to-date list of every AI system in use, and whether changes go through any kind of review.

Data provenance

Where the AI's training data actually came from

Where the data that trained and feeds this AI actually came from — whether you have the right to use it, whether it's good quality, and whether it carries built-in bias or blind spots the AI would inherit.

Bias & fairness

Whether it treats people differently based on things it shouldn't

Whether the AI's decisions have actually been tested for treating some groups of people worse than others, how recently, and whether that's actively monitored — not just assumed to be fine.

Security

Whether it can be tricked, attacked, or manipulated

Whether it can be tricked or manipulated into misbehaving, who has access to it, how the underlying data is protected, and whether there's a reliable, tamper-proof record of what it's done over time.

Compliance

Whether it meets the laws and rules that apply to you

Whether the system actually meets the laws and rules that apply to your business — like the EU AI Act, the U.S. health-data law (HIPAA), India's data-protection law (DPDP), the SOC 2 security standard, and whatever else applies to your industry — and where it falls short.

Mapped to the standards that matter

Findings trace to a clause, not an opinion

Each rating is tied to specific provisions of the frameworks below, so a board, a customer, or a regulator can see exactly what it is measured against.

See all 31 frameworks →
How an audit is conducted

From scope to report, in five steps

A productized process — scoped with you up front, evidence-led throughout, and never charged before you approve the scope.

Scope

We agree the systems, dimensions, and depth with you before anything is charged — you approve the scope first.

Evidence

We collect the documentation, a record of where the training data came from, technical descriptions of the AI model, logs, and any prior assessments the system already has.

Testing

We test the system directly where we can get access — checking for bias, attempts to trick or manipulate it, and whether the safeguards that are supposed to be in place actually work.

Review

Findings are rated on our Low/Medium/High scale and cross-checked against the mapped standards, so nothing rests on a single reviewer's opinion.

Report

You receive a prioritized report, ready to present to leadership — a rating per dimension, findings backed by evidence, and a plan for what to fix first.

Independent. Evidence-led. Built for trust.

  • Scoped with you
  • Evidence first
  • Mapped to standards
  • Actionable results
Evidence & testing standards

What counts as proof

  1. Evidence, not assertion

    Every rating traces to something concrete — a document, a test result, a log. A verbal assurance on its own is not evidence.

  2. Gaps aren't assumed away

    Where a control can't be evidenced, it's rated as a gap — not quietly assumed compliant. Absence of proof is a finding.

  3. Method is disclosed

    Testing is hands-on where access allows and documentation-based where it doesn't — and the report states which was used for each finding.

Our guiding principles

  • Verifiable
  • Traceable
  • Reproducible
  • Transparent
  • Accountable
Scoring & ratings

How exposure is rated

Each dimension gets one of three exposure ratings, on defined criteria. The scale is the same one your AI Risk Snapshot uses.

Overall exposure = the weakest link
Low
  • Controls are documented, owned, and evidenced
  • The dimension meets the mapped standard
Medium
  • Controls exist but are partial, informal, or carry gaps that need to be closed
  • Not urgent, but not clean
High
  • Controls are missing or inadequate
  • Material exposure that warrants priority remediation
If any single dimension is High, overall exposure is High; otherwise if any is Medium, it's Medium; otherwise Low. Overall risk is driven by the biggest gap, and stating it conservatively is the honest call — a system is only as trustworthy as its weakest dimension.
What the report delivers

A read you can act on — and defend

The same methodology runs at three depths — Quick Scan, Compliance, and Risk.

See what each tier covers →

Core deliverable

AI Audit Report
DimensionRating
GovernanceMedium
Data provenanceHigh
Bias & fairnessLow

Illustrative sample

Value & analysis

  • A prioritized roadmap

    What to fix first — sequenced by exposure, so remediation effort goes where the risk actually is.

  • Compliance mapping

    How your system lines up against the frameworks that apply to you, and where the gaps sit.

Findings & ratings

  • Findings with evidence

    Each finding carries its severity, the evidence behind it, and the standard clause it maps to.

  • A rating per dimension & overall

    Low / Medium / High across all five dimensions, plus the overall exposure — the same picture your board sees at a glance.

Who conducts the audit

Independent of the systems reviewed

  • Conducted by
    the iDharma team

    Every audit is run by the iDharma team. We don't build or sell the AI we assess — that independence from the system under review is exactly what makes the report something a board or a regulator can actually trust.

  • Applied
    consistently

    The same published methodology and rubric apply to every engagement, so two audits of comparable systems are comparable — the standard doesn't move with the reviewer.

As iDharma grows its bench of independent expert auditors, they will be listed here and held to this same published standard. Today, that work is done by the iDharma team.

Scope & limitations — stated plainly

An iDharma audit is an independent, standards-based assessment — it is not a certification, accreditation, or legal advice, and it does not confer regulatory approval.

  • It is a point-in-time review, based on the evidence provided and the scope agreed. AI systems change; a clean audit is a snapshot, not a permanent guarantee.
  • Findings reflect the evidence available at the time. An audit reduces and surfaces risk — it does not eliminate it, and it doesn't guarantee a particular outcome with any regulator.
  • Sample reports are illustrative and built for fictional companies to show format and depth; they are not records of real clients.

Governance & transparency

Published, owned, and versioned

This methodology is maintained by the iDharma team and published openly, so clients and their stakeholders can see exactly what an audit measures. Material changes bump the version, and the history is on the record below.

  1. v1.1 Current
    1 Jul 2026
    • Formalized the Low/Medium/High exposure rubric and the weakest-link overall rule
    • Expanded framework mapping to the EU AI Act and India DPDP
  2. v1.0 Archived
    Jun 2026
    • Initial published methodology at audit launch
    • The five assessment dimensions and the core framework mapping

Superseded editions are kept on record and available on request.

See the standard applied to your AI.

What it assesses

An iDharma audit runs this methodology against the systems you actually operate.

What you get

A clear, prioritized read you can act on and defend.

This page describes iDharma's verification methodology (current edition v1.1) and how our audits are structured. It is provided for transparency and is not a contract, warranty, or guarantee. An audit is an independent assessment against this published standard — it informs your decisions but is not a certification or a guarantee that any system is safe or compliant, and findings are specific to each engagement's scope. Nothing here is legal advice.