FREE INTERACTIVE TOOL · NOTHING STORED OR SENT

What is it costing you not to know what your AI is doing?

Four cost streams - regulatory, remediation, commercial and delay - totalled from numbers you enter.


A reviewer with braided hair, in a green blazer, seated at a dark stone desk by a window in a warm, low-lit office, signing a printed page with further papers and a stoneware cup beside them.
An independent read of what the risk costs you
Regulatory Remediation Commercial Delay Nothing stored

Our promise

“Every number here is one you typed. Nothing is sent.”

The calculator runs entirely in your browser: nothing stored, nothing transmitted, no email asked for. The arithmetic behind it is published below, so you can check the total, not trust it.

Open the calculator
The case file

The cost of not knowing, in three chapters

The Streams

Four things cost money while an AI estate goes unexamined: a regulator's finding, the engineering time to fix what it finds, deals held up in a buyer's security review, and a launch that has slipped. Only the first of them needs somebody outside to act. The other three are already running.

The Unknown

All four can be priced from figures you already hold. A fifth cannot: what proportion of your models carry an issue nobody has found yet. Not you, not us, not anyone knows that without testing them - which is exactly why the box for it further down this page is deliberately left empty.

The Office

An audit is how that empty box gets filled, and it is the only way it does. We test the systems, write each finding against the control it fails, and scope the fix in hours a finance team can price - so what the whole thing costs you becomes arithmetic anyone can check rather than a feeling.

The four streams

Four streams. Two are already running.

Two of them cost you before anything is found. Two cost nothing until it is.

The two already running № 01
  • Delay - weeks a launch has slipped, times what a week costs
  • Spending today, before anybody has found anything at all
  • Commercial - deals stalled in review, times their worth
  • Waiting on an answer rather than on a finding
Cost of not auditing · iDharma · Presented for assay
The two that wait for a trigger № 02
  • Remediation - models to fix, times hours, times a loaded rate
  • Nothing until something is found, then the whole of it at once
  • Regulatory - a published penalty, times how likely a finding is
  • The only stream with a likelihood in front of it
Cost of not auditing · iDharma · Presented for assay
Whose number it is

The figures are yours. The arithmetic is ours.

Yours

Every figure on this page is one you typed

Nothing is pre-filled, defaulted or set against an industry benchmark. There is no hidden multiplier and no assumed baseline, and a field you leave blank counts as zero rather than as an average of somebody else. The total is a statement about the numbers you entered and nothing else in your business.

Ours

Multiplication, then addition. That is all

Four products and one sum, written out in full further down this page so you can check it against what the fields show. No weightings, no confidence intervals, no adjustment for your sector or your size. If the arithmetic ever disagrees with the formula printed below, then the formula is what we meant.

The catch

The one box nobody can fill in

What proportion of your models carry an issue nobody has found yet is not a number you have, and it is not one we will invent for you. It is left empty on purpose. Every stream below is priced as though that figure were knowable; it is not, and testing is the only thing that can ever make it so.

What most teams assume

“Give me a number for what an audit saves us.”

What the rule says

Nobody has that number until your models are tested.

It is the most common question this page refuses.

  • Who it is for
  • AI product teams
  • SaaS & platform vendors
  • Banking & insurance
  • Risk & compliance leads
  • Anyone costing an assurance budget
The one number nobody can give you
A black archive binder closed on a dark desk under a low lamp, a blank brass label plate screwed to its spine and a wax seal holding the page block shut, with a clipped sheet of bar-charted results, reading glasses, a fountain pen and a photograph of a brass stamp laid out beside it: a record sealed before anyone read it.
01 What share of your models carries an issue nobody has found yet? Neither you nor we know that number. It is the one an audit answers.
02

Every other figure on this page is one you typed. This is the only one that cannot be typed, estimated or looked up anywhere.

03

We will not put a placeholder in it. An industry average here would be a number about somebody else, printed where yours belongs.

04

Testing is the only thing that fills it. Until then the total below is what is at stake, not what is going wrong.

The 60-second check

Three questions. Then you’ll know.

No email, no signup. It will not fill the blank above — it says which way it probably leans.

0 of 3

Models that decide -

A decision about a person is the one that gets looked at. Credit, hiring, claims, triage, eligibility. A model that ranks products for a shopper is a different kind of risk.

Last outside look -

Outside the build team, not outside the company. An internal validation function counts here. What does not count is the people who wrote it checking their own work.

Evidence on demand -

The evidence behind one decision. What the model weighed, on what data, and who signed the version off. This is the question that separates a remediation from an incident.

The cascade

Four cost streams, added up.

Enter what you know. Blank fields count as zero, and nothing leaves this browser.

Regulatory exposure

Likelihood of a finding × the size of the fine it could carry.

Use a published fine for your practice as an anchor. No verified examples published yet — see Insights for sourced case studies as they're added.
0%
How likely a regulator flags an issue if they looked at your AI today.
Regulatory $0

Remediation cost

Engineering time to actually fix what's found, across the models most likely to need it.

Credit, hiring, claims, triage — decisions a regulator would look at first.
What an hour of engineering time really costs you — salary plus benefits and overhead, not just the paycheck.
Remediation $0

Commercial cost

Deals that stall because a buyer's questions about your AI can't be answered yet.

Deals where a customer or partner's security/AI review of your system is holding things up.
Commercial $0

Delay cost

Every week a launch slips while AI risk gets sorted out.

Delay $0

Total exposure

$0

Your inputs, your number — we assert nothing.

Nothing you enter is stored or sent. The math runs entirely in your browser.

The four moments

Four streams, and two are already running.

Two of these are spending money today and two are waiting on a trigger - so they cannot be budgeted as one number, and the waiting two arrive all at once.

  1. Delay

    Running now

    A launch held while AI risk gets sorted out is spending its weekly cost today, before anyone has found anything at all.

  2. Commercial

    Running now

    A deal stalled in a buyer's AI review is already stalled. This stream does not wait for a finding either - it waits for an answer.

  3. Remediation

    On discovery

    Engineering time costs nothing until something is found, and then it costs the whole of it, across every model that needs the fix.

  4. Regulatory

    On enforcement

    The only stream with a likelihood in front of it, because it is the only one that needs somebody outside to act before it lands.

The trap

Teams budget for the two that need a trigger and forget the two that are already running. A deal sitting in a security review and a launch that has slipped are spending now - and neither of them waits for anybody to find anything.

Input & artefact

What the total asks for, what we ship

12 obligations, and the artefact that discharges each one. Paired, so every claim on this page can be checked against the requirement beside it.

How many models you run The count every other figure is multiplied by
A register of every AI system in the estate, with its owner and its status, kept in a workbook your team can maintain.
Which of them are high-risk Credit, hiring, claims, triage - the ones looked at first
Each system placed against the decisions it actually changes, with the reasoning written down rather than assumed.
Whether an issue exists at all The empty box - not knowable without testing
The tests themselves, and a finding for each one that fails, written against a named control rather than an opinion.
Hours to fix, per model The figure engineering is asked for and rarely has
A remediation plan scoped per system, so the hours are estimated against real findings instead of against a fear.
What a loaded hour costs Salary plus benefits and overhead, not the paycheck
Nothing - this one is yours, and finance already holds it. It is on the list because it is the figure most often guessed low.
Which deals are stalled Held in a customer or partner security review
The report those reviews ask for, so the answer to the question holding the deal is a document rather than a promise.
What the buyer actually asked Usually narrower than the panic it causes
A mapping of the questionnaire to what exists, showing which answers you already hold and which are genuinely missing.
Weeks a launch has slipped Counted from when risk stopped it, not from the plan
A dated record of what was outstanding and when it cleared, which is also what a board asks for after the fact.
The cost of a slipped week Revenue, burn, or the opportunity - your definition
Nothing here either. The point of printing it is that a week is priced once and then used in four arguments.
A penalty size to anchor on A published action, or nothing at all
The sourced anchors on this page, and no number that has not been read against its original regulatory action.
Likelihood of a finding A judgement, and it is the softest input here
Evidence that moves it: what a regulator would be shown, and whether it currently answers the question they would ask.
Who would answer for it Not an input, and the one most often missing
Named owners against every system in the register, because the question is asked last and takes longest to answer.
The engagement

Your AI estate, independently read

From the model register to the hours behind a fix.

  1. Enter

    The figures you already hold - deal values, hourly rates, weeks lost.

  2. Total

    Four streams multiplied out and added up, entirely in this browser.

  3. Take it away

    One number you can put in a budget line - and one box nobody can fill.

Request your Risk Snapshot
An auditor in a charcoal suit and open-collared white shirt, with silver hair, standing against a warm pale wall and pointing into the open space alongside.
The numbers are what you are buying.
Struck in your favour

Why this tool is worth the paper it prints on

Genuinely independent

We build, resell and operate no AI systems of our own, and take no fee tied to what we find.

The math is printed

Every formula behind the total is written on this page, so the number can be checked by hand.

Nothing is stored

No account, no upload, no telemetry on any field - the arithmetic never leaves your browser.

We refuse the last number

What an audit saves is not knowable before testing, so this page puts no figure against it.

Four marks, struck on every report.

Deliverables

What you get

Concrete artefacts, each with a name and a format - you know what lands before you buy.

Findings report

The assessment in one document: every system tested and placed, every issue written against the control it fails rather than against an opinion, the remediation scoped per model in hours a finance team can price, and the whole of it in plain language rather than in a framework's.

Workbook

AI system register

Every system, its owner, its risk band and its status, in a workbook your own team can keep current after we hand it over.

HTML + PDF

Buyer question pack

The answers a customer security review actually asks for, written once and formatted to drop straight into the questionnaire.

Templates

Remediation plan

Each finding scoped into hours against the model it belongs to, so the second column of this calculator stops being a guess.

Index

Evidence index

What you hold, what is thin and what is missing, so the file is assembled before somebody outside is ever its first real reader.

One page

Owner map

A named person against every system, which is the question asked last in every review and the one that takes longest to answer.

Two pages

Board summary

The findings and what they cost, in the two pages a board reads - written from the same numbers rather than from a second set of them.

Format & fee

Real numbers, upfront.

Scope
Fixed before we start, not by the hour
Input
Your systems and what exists on them
Re-read
Annually, or on modification - $0 against your known baseline

The scope is fixed before we start, so the fee is flat - nothing to meter, and nothing charged until you approve it.

Request your Risk Snapshot
AI audit · Fixed scope $0 flat
  • Independent classification report
  • System register, model by model
  • Findings written against named controls
  • Remediation scoped in hours, per model
Show your hand

Four figures you have to be able to produce

A total is not graded on effort. Each of these is either in your hand on the day somebody asks for the number, or it is not.

The count,
settled

How many AI systems you run, and how many of them change what happens to a person. Every figure below is multiplied by this one, and most estates cannot state it.

The hours,
scoped

What fixing one model actually takes, at a loaded rate finance recognises. An engineering guess made under pressure is the most expensive number on this page.

The deals,
named

Which specific deals are held in a buyer's AI review, and what each one of them is worth. This stream is running today, and it is the one most often left out of the total.

The anchor,
sourced

A published penalty you would be measured against, read against its original action. A fine you half-remember is not an anchor, it is a mood with a number on it.

Four cards, and the one you cannot turn over is the fifth.

FAQ

Plain answers

Scope, timing, and the cost of getting it wrong. Answered straight.

Request your Risk Snapshot
Is this number real for my company?

The arithmetic is real - it is exactly your inputs multiplied together. Whether the inputs are realistic is a judgement only you can make.

Why doesn't it show a return, or a saving?

Because a saving figure would mean asserting how much of your exposure an audit removes, and that is not knowable before your models are tested.

Why is the "undetected issue" box empty?

Because nobody knows that number for your AI without testing it. That is the entire point of the box, and an audit is how you find out.

Do I have to fill in every field?

No. Blank fields count as zero, so a stream you leave empty adds nothing - read the total as "at least this much, on the streams I could fill in."

Do you store what I enter?

No. The calculation runs entirely in your browser. Nothing you type is sent to iDharma or saved anywhere, not even locally on your device.

Get started

Turn the unknown into a number you can act on

Tell us about your AI systems and we come back with a scoping call within one business day.

What we need from you

Nothing you do not already have. Most of this is a folder someone can assemble in an afternoon, and we name every document first, in writing, before you commit.

  1. Which AI systems you build or use, and what each decides
  2. How many of them change what happens to a person
  3. Any documentation - model cards, contracts, test records
  4. Whether you built each system, bought it, or modified one
  5. Your target readiness date, if you have one

What happens next

  1. You send the five items we need.
  2. You get a scoping call within one business day.
  3. Nothing is charged until you approve the scope.
Request your Risk Snapshot
Sources & standing

Where this page gets its numbers

Where the claims on this page come from, and what they are worth - stated, not assumed.

What it is drawn from

  • Your own inputs - every figure in the total
  • Published regulatory actions, for the penalty anchors only
Effective
1 January 2023
Enforced from
5 July 2023

What it means

  • Arithmetic on figures you supplied — not advice, and no professional relationship arises from using it. It determines nothing about your own systems.
  • Where a figure is not knowable, this page leaves it blank rather than filling it conveniently.

Scope & limitation

  • Do not rest a binding decision on it; the inputs are estimates you made.
  • It totals four streams only - insurance, reputation and staff time are outside it.
  • Use it as a starting point for a budget conversation, not as your final word.

Something on this page out of date?

Tell us