AI Governance & Compliance

Independent AI audits for every organisation deploying AI in a regulated context

Three frameworks — NIST AI RMF, ISO/IEC 42001, and the EU AI Act — mapped simultaneously against your deployment. One prioritised gap register. No vendor spin.

3 frameworks
Every audit maps NIST AI RMF, ISO/IEC 42001 and EU AI Act simultaneously
Full regulatory coverage
6 buyer jobs
Six distinct reasons enterprises commission an AI audit — scope and price differ for each
JTBD framework
19/20
Top-scoring opportunity: proving compliance at a regulatory deadline
Opportunity scorecard
What we audit

AI systems in scope for General

Every system below is covered in a standard iDharma engagement. Complex or multi-system deployments are scoped on request.

Decision-making AI

Any model that influences consequential outcomes — hiring, credit, access to services, content moderation.

Generative AI deployments

LLMs and diffusion models in customer-facing or internal workflows — accuracy, hallucination risk, data governance.

Vendor-supplied AI

Third-party models integrated into your product or operations. "Our vendor handles it" has not succeeded as a compliance defence.

Automated monitoring systems

AI used for surveillance, anomaly detection, or fraud scoring where the model acts without per-decision human review.

Regulatory frameworks

What we audit against

Every iDharma General engagement maps simultaneously against the frameworks below — producing one gap register, not three separate reports.

EU AI Act (2024/1689)

Applies to any AI affecting EU users. High-risk systems face conformity assessments, technical documentation, and ongoing monitoring obligations.

NIST AI RMF

A voluntary but widely referenced framework covering Govern, Map, Measure, and Manage functions across the AI lifecycle.

ISO/IEC 42001

The international standard for AI management systems — the AI equivalent of ISO 27001 for information security.

Our methodology

How an iDharma audit works in General

We do not accept vendor documentation as evidence. We do not produce checkbox compliance reports. Every audit produces a named auditor, a cited methodology, and a straight answer on exactly where your AI stands — and what to fix first.

See how we work →
1

We audit against all three frameworks in a single engagement — not three sequential reviews.

2

Every finding is rated by legal severity, so your remediation roadmap is ordered by what creates the greatest regulatory exposure.

3

We do not use the vendor's own documentation as evidence — we independently verify claims against source data, test outputs, and technical specifications.

4

You receive a named auditor, a cited methodology, and a straight answer on exactly where your AI stands.

Not sure which frameworks apply to your AI?

The free Risk Snapshot takes twenty minutes and produces a prioritised exposure summary.