Four things cost money while an AI estate goes unexamined: a regulator's finding, the engineering time to fix what it finds, deals held up in a buyer's security review, and a launch that has slipped. Only the first of them needs somebody outside to act. The other three are already running.
What is it costing you not to know what your AI is doing?
Four cost streams - regulatory, remediation, commercial and delay - totalled from numbers you enter.
Our promise
“Every number here is one you typed. Nothing is sent.”
The calculator runs entirely in your browser: nothing stored, nothing transmitted, no email asked for. The arithmetic behind it is published below, so you can check the total, not trust it.
Open the calculatorThe cost of not knowing, in three chapters
All four can be priced from figures you already hold. A fifth cannot: what proportion of your models carry an issue nobody has found yet. Not you, not us, not anyone knows that without testing them - which is exactly why the box for it further down this page is deliberately left empty.
An audit is how that empty box gets filled, and it is the only way it does. We test the systems, write each finding against the control it fails, and scope the fix in hours a finance team can price - so what the whole thing costs you becomes arithmetic anyone can check rather than a feeling.
Four streams. Two are already running.
Two of them cost you before anything is found. Two cost nothing until it is.
- Delay - weeks a launch has slipped, times what a week costs
- Spending today, before anybody has found anything at all
- Commercial - deals stalled in review, times their worth
- Waiting on an answer rather than on a finding
- Remediation - models to fix, times hours, times a loaded rate
- Nothing until something is found, then the whole of it at once
- Regulatory - a published penalty, times how likely a finding is
- The only stream with a likelihood in front of it
The figures are yours. The arithmetic is ours.
Every figure on this page is one you typed
Nothing is pre-filled, defaulted or set against an industry benchmark. There is no hidden multiplier and no assumed baseline, and a field you leave blank counts as zero rather than as an average of somebody else. The total is a statement about the numbers you entered and nothing else in your business.
Multiplication, then addition. That is all
Four products and one sum, written out in full further down this page so you can check it against what the fields show. No weightings, no confidence intervals, no adjustment for your sector or your size. If the arithmetic ever disagrees with the formula printed below, then the formula is what we meant.
The one box nobody can fill in
What proportion of your models carry an issue nobody has found yet is not a number you have, and it is not one we will invent for you. It is left empty on purpose. Every stream below is priced as though that figure were knowable; it is not, and testing is the only thing that can ever make it so.
“Give me a number for what an audit saves us.”
Nobody has that number until your models are tested.
It is the most common question this page refuses.
- Who it is for
- AI product teams
- SaaS & platform vendors
- Banking & insurance
- Risk & compliance leads
- Anyone costing an assurance budget
Every other figure on this page is one you typed. This is the only one that cannot be typed, estimated or looked up anywhere.
We will not put a placeholder in it. An industry average here would be a number about somebody else, printed where yours belongs.
Testing is the only thing that fills it. Until then the total below is what is at stake, not what is going wrong.
Three questions. Then you’ll know.
No email, no signup. It will not fill the blank above — it says which way it probably leans.
Four cost streams, added up.
Enter what you know. Blank fields count as zero, and nothing leaves this browser.
Regulatory exposure
Likelihood of a finding × the size of the fine it could carry.
Remediation cost
Engineering time to actually fix what's found, across the models most likely to need it.
Commercial cost
Deals that stall because a buyer's questions about your AI can't be answered yet.
Delay cost
Every week a launch slips while AI risk gets sorted out.
Total exposure
$0
Your inputs, your number — we assert nothing.
Nothing you enter is stored or sent. The math runs entirely in your browser.
The cost of not knowing
Four streams — regulatory, remediation, commercial, delay. Blank counts as zero, nothing is stored or sent.
Four streams, and two are already running.
Two of these are spending money today and two are waiting on a trigger - so they cannot be budgeted as one number, and the waiting two arrive all at once.
-
Delay
Running nowA launch held while AI risk gets sorted out is spending its weekly cost today, before anyone has found anything at all.
-
Commercial
Running nowA deal stalled in a buyer's AI review is already stalled. This stream does not wait for a finding either - it waits for an answer.
-
Remediation
On discoveryEngineering time costs nothing until something is found, and then it costs the whole of it, across every model that needs the fix.
-
Regulatory
On enforcementThe only stream with a likelihood in front of it, because it is the only one that needs somebody outside to act before it lands.
Teams budget for the two that need a trigger and forget the two that are already running. A deal sitting in a security review and a launch that has slipped are spending now - and neither of them waits for anybody to find anything.
What the total asks for, what we ship
12 obligations, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the requirement beside it.
- How many models you run The count every other figure is multiplied by
- A register of every AI system in the estate, with its owner and its status, kept in a workbook your team can maintain.
- Which of them are high-risk Credit, hiring, claims, triage - the ones looked at first
- Each system placed against the decisions it actually changes, with the reasoning written down rather than assumed.
- Whether an issue exists at all The empty box - not knowable without testing
- The tests themselves, and a finding for each one that fails, written against a named control rather than an opinion.
- Hours to fix, per model The figure engineering is asked for and rarely has
- A remediation plan scoped per system, so the hours are estimated against real findings instead of against a fear.
- What a loaded hour costs Salary plus benefits and overhead, not the paycheck
- Nothing - this one is yours, and finance already holds it. It is on the list because it is the figure most often guessed low.
- Which deals are stalled Held in a customer or partner security review
- The report those reviews ask for, so the answer to the question holding the deal is a document rather than a promise.
- What the buyer actually asked Usually narrower than the panic it causes
- A mapping of the questionnaire to what exists, showing which answers you already hold and which are genuinely missing.
- Weeks a launch has slipped Counted from when risk stopped it, not from the plan
- A dated record of what was outstanding and when it cleared, which is also what a board asks for after the fact.
- The cost of a slipped week Revenue, burn, or the opportunity - your definition
- Nothing here either. The point of printing it is that a week is priced once and then used in four arguments.
- A penalty size to anchor on A published action, or nothing at all
- The sourced anchors on this page, and no number that has not been read against its original regulatory action.
- Likelihood of a finding A judgement, and it is the softest input here
- Evidence that moves it: what a regulator would be shown, and whether it currently answers the question they would ask.
- Who would answer for it Not an input, and the one most often missing
- Named owners against every system in the register, because the question is asked last and takes longest to answer.
Your AI estate, independently read
From the model register to the hours behind a fix.
-
Enter
The figures you already hold - deal values, hourly rates, weeks lost.
-
Total
Four streams multiplied out and added up, entirely in this browser.
-
Take it away
One number you can put in a budget line - and one box nobody can fill.
Why this tool is worth the paper it prints on
Genuinely independent
We build, resell and operate no AI systems of our own, and take no fee tied to what we find.
The math is printed
Every formula behind the total is written on this page, so the number can be checked by hand.
Nothing is stored
No account, no upload, no telemetry on any field - the arithmetic never leaves your browser.
We refuse the last number
What an audit saves is not knowable before testing, so this page puts no figure against it.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
Findings report
The assessment in one document: every system tested and placed, every issue written against the control it fails rather than against an opinion, the remediation scoped per model in hours a finance team can price, and the whole of it in plain language rather than in a framework's.
AI system register
Every system, its owner, its risk band and its status, in a workbook your own team can keep current after we hand it over.
Buyer question pack
The answers a customer security review actually asks for, written once and formatted to drop straight into the questionnaire.
Remediation plan
Each finding scoped into hours against the model it belongs to, so the second column of this calculator stops being a guess.
Evidence index
What you hold, what is thin and what is missing, so the file is assembled before somebody outside is ever its first real reader.
Owner map
A named person against every system, which is the question asked last in every review and the one that takes longest to answer.
Board summary
The findings and what they cost, in the two pages a board reads - written from the same numbers rather than from a second set of them.
Real numbers, upfront.
- Scope
- Fixed before we start, not by the hour
- Input
- Your systems and what exists on them
- Re-read
- Annually, or on modification - $0 against your known baseline
The scope is fixed before we start, so the fee is flat - nothing to meter, and nothing charged until you approve it.
Request your Risk Snapshot- Independent classification report
- System register, model by model
- Findings written against named controls
- Remediation scoped in hours, per model
Four figures you have to be able to produce
A total is not graded on effort. Each of these is either in your hand on the day somebody asks for the number, or it is not.
The count,
settled
How many AI systems you run, and how many of them change what happens to a person. Every figure below is multiplied by this one, and most estates cannot state it.
The hours,
scoped
What fixing one model actually takes, at a loaded rate finance recognises. An engineering guess made under pressure is the most expensive number on this page.
The deals,
named
Which specific deals are held in a buyer's AI review, and what each one of them is worth. This stream is running today, and it is the one most often left out of the total.
The anchor,
sourced
A published penalty you would be measured against, read against its original action. A fine you half-remember is not an anchor, it is a mood with a number on it.
Four cards, and the one you cannot turn over is the fifth.
Plain answers
Scope, timing, and the cost of getting it wrong. Answered straight.
Request your Risk SnapshotIs this number real for my company?
The arithmetic is real - it is exactly your inputs multiplied together. Whether the inputs are realistic is a judgement only you can make.
Why doesn't it show a return, or a saving?
Because a saving figure would mean asserting how much of your exposure an audit removes, and that is not knowable before your models are tested.
Why is the "undetected issue" box empty?
Because nobody knows that number for your AI without testing it. That is the entire point of the box, and an audit is how you find out.
Do I have to fill in every field?
No. Blank fields count as zero, so a stream you leave empty adds nothing - read the total as "at least this much, on the streams I could fill in."
Do you store what I enter?
No. The calculation runs entirely in your browser. Nothing you type is sent to iDharma or saved anywhere, not even locally on your device.
Turn the unknown into a number you can act on
Tell us about your AI systems and we come back with a scoping call within one business day.
What we need from you
Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.
- Which AI systems you build or use, and what each decides
- How many of them change what happens to a person
- Any documentation - model cards, contracts, test records
- Whether you built each system, bought it, or modified one
- Your target readiness date, if you have one
What happens next
- You send the five items we need.
- You get a scoping call within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its numbers
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- Your own inputs - every figure in the total
- Published regulatory actions, for the penalty anchors only
- Effective
- 1 January 2023
- Enforced from
- 5 July 2023
What it means
- Arithmetic on figures you supplied — not advice, and no professional relationship arises from using it. It determines nothing about your own systems.
- Where a figure is not knowable, this page leaves it blank rather than filling it conveniently.
Scope & limitation
- Do not rest a binding decision on it; the inputs are estimates you made.
- It totals four streams only - insurance, reputation and staff time are outside it.
- Use it as a starting point for a budget conversation, not as your final word.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
ISO/IEC 42001, SOC 2 and NIST AI RMF: Which One Your Buyer Is Actually Asking For
One certifies an organisation, one is an opinion about controls over a window, one is a method with nothing to issue. What each covers — and what none of them answers.