Know exactly where your AI stands — and what to fix first.
An independent, expert audit of your AI systems, delivered by iDharma-verified experts against a published standard. You get a clear, prioritized report you can act on — independent proof your organization's AI holds up — something you can't provide by checking your own work, and that a general security audit (like a SOC 2) or a penetration test doesn't cover.
- Governance Medium
- Data provenance High
- Bias & fairness Low
- Security Medium
- Compliance High
Unaudited AI is unmeasured exposure
Most AI ships faster than it gets checked, and the cost of finding out after an incident is not the audit fee. The EU AI Act (the EU's binding AI-risk law) is now phasing in, with penalties reaching up to 7% of global annual turnover for the most serious breaches — and a single failure (a biased decision, a data leak, an output a customer relied on) can run into the millions before the reputational damage. An audit is the cheapest way to know before a regulator, the press, or a plaintiff does.
Request an auditScoped before you are charged. No payment until you approve the scope.
One audit, five dimensions
Every iDharma audit — at every tier — checks your AI across the same five dimensions, mapped to our published methodology.
Governance
Is there a written policy for who owns this AI and who's accountable when it goes wrong? We check who's actually watching it, whether you have an up-to-date list of every AI system you run, and whether changes to it go through any kind of review.
Data provenance
Where the data that trained and feeds this AI actually came from — whether you have the right to use it, whether it's good quality, and whether it carries built-in bias or blind spots the AI would inherit.
Bias & fairness
Whether the AI's decisions have actually been tested for treating some groups of people worse than others, how recently, and whether that's actively monitored — not just assumed to be fine.
Security
Whether it can be tricked or manipulated into misbehaving, who has access to it, how the underlying data is protected, and whether there's a reliable, tamper-proof record of what it's done over time.
Compliance
Whether the system actually meets the laws and rules that apply to your business — like the EU AI Act, the U.S. health-data law (HIPAA), India's data-protection law (DPDP), the SOC 2 security standard, and whatever else applies to your industry — and where it falls short.
This is one audit measured five ways, not five separate services. See the full published methodology →
Built for the AI that touches customers, money, or regulated decisions
Fintech
Credit, lending, and fraud-detection AI reviewed for whether it treats applicants fairly and how much financial risk it's carrying.
Request an audit →Healthcare
Clinical, triage, and administrative AI reviewed with patient-data handling and state AI rules in mind.
Request an audit →Insurance
Underwriting and claims AI reviewed for whether it treats people fairly — including indirect bias that isn't obvious at first glance.
Request an audit →General
Any other AI your company runs — chatbots, internal tools, automation — reviewed against the same published standard.
Request an audit →From request to report in four steps
A productized process — scoped, predictable, and built to move at the speed your AI ships.
Request
Tell us about your AI and pick a tier — nothing is charged yet.
Scope call & fixed quote
We confirm scope with you and agree a fixed price before any work begins.
Audit (1–4 weeks)
An iDharma-verified expert reviews your systems against our published methodology — one to four weeks, depending on tier.
Report & walkthrough
You get a prioritized findings report, 14 business days of written follow-up in your portal, and a recorded walkthrough on request.
A report your whole team can use
- A board- and regulator-ready findings report, prioritized by risk
- A remediation roadmap with clear next actions
- Compliance mapping to the regulations that apply to you
- No payment until you approve the scope and price
- 14 business days of written follow-up — ask us anything in your portal
- Optional intro to a verified consultant to fix what's flagged
Not sure which audit you need?
Start a request and tell us about your AI. Our team will help you scope the right tier — at no cost and no commitment until you approve it.
Start a requestChoose the depth your AI needs
Transparent, fixed-scope pricing — scoped with you before anything is charged. No payment until you approve the scope.
Best for: Teams shipping their first AI features
A fast, expert read on where your AI stands.
- Review of up to 3 AI systems or tools
- Top-priority risk and gap findings
- A prioritized action list you can act on
- 14 business days of written follow-up in your portal
Best for: Companies in regulated markets
A thorough review against the laws and rules that apply to you.
- Full check of where you fall short of the rules that apply to you
- Checked against the EU AI Act, HIPAA (health data law), SOC 2 (security standard), India's DPDP (data law), and more
- A prioritized plan for fixing what we find
- Documentation and policy review
- Executive summary report
Best for: High-stakes or board-supervised AI
Our deepest audit — fairness, security, accountability, and how much risk the AI itself carries.
- Everything in the Compliance Audit, plus:
- Bias and fairness testing
- Security review, including attempts to trick or manipulate the AI
- Review of the AI model itself and where its data came from
- A risk briefing you can present to your board
All audits are scoped with you before any payment is taken.
iDharma vs the alternatives
One question — "is our AI safe and compliant?" — answered four ways.
| Do nothing | Internal review | Traditional audit firm | iDharma | |
|---|---|---|---|---|
| Independent & defensible to a board or regulator | No | No | Yes | Yes |
| AI-specialist auditors | — | Sometimes | Generalist bench | Yes |
| Mapped to NIST AI RMF, ISO 42001 & EU AI Act | No | Partial | Yes | Yes |
| Time to a report | Never | Weeks to months | Months | ~1–4 weeks |
| Typical cost | $0, until an incident | Staff time | $100k+ | $5k–$25k |
| Board- & regulator-ready report | No | No | Yes | Yes |
AI audit questions, answered
What is an AI audit?
An AI audit is an independent assessment of an AI system's risks, compliance and governance against recognized standards — NIST AI RMF (the U.S. AI risk framework), ISO/IEC 42001 (the AI management standard), and the EU AI Act — ending in a dated, defensible report of findings and the fixes that matter.
How much does an AI audit cost?
iDharma audits start at $5,000 for a Quick Scan, $15,000 for a Compliance Audit and $25,000 for a full Risk Audit. Every audit is scoped with you before any payment is taken.
What standards do you map to?
NIST AI RMF, ISO/IEC 42001, the EU AI Act, HIPAA (the U.S. health-privacy law), SOC 2 (a security and trust audit standard), and India's DPDP (India's data-protection law), plus the published iDharma Verification Methodology.
How long does it take?
A Quick Scan is about one week, a Compliance Audit two to three weeks, and a full Risk Audit about four weeks.
Is the audit independent?
Yes. Your audit is performed by a verified iDharma expert who did not build your system, which is what makes the report defensible to a board or a regulator.
Do I pay before I know the scope?
No. You request an audit, we confirm the scope with you, and nothing is charged until you approve it.
What do you need from us?
Whatever you have — a system overview, data sources, privacy and security policies, model evaluation and compliance records. You upload them in your secure portal, and we guide you on anything missing.
What do we get at the end?
A prioritized findings report, a remediation roadmap, compliance mapping to the regulations that apply to you, and 14 business days of written follow-up in your portal (a recorded walkthrough is available on request) — plus an optional intro to a verified consultant to fix what is flagged.
How do you handle our data?
Everything you share lives in your secure, private portal and is used only for your audit. We practice data minimization: your uploaded source files are automatically deleted 90 days after your report is delivered, while your finished report stays available in your portal for as long as you need it. You can also request deletion at any time.
Is this legal advice?
No. Your report is an independent technical and compliance-mapping assessment, not legal advice. Confirm specific legal obligations with qualified counsel.
Find out where your AI really stands
Productized, expert-led, and standards-based. Get clarity on your AI risk in weeks.
Request an audit