Insights

We show our work.

Teardowns of real AI enforcement cases, plain-English guides to the standards we audit against, and our methodology notes — published, dated, and cited. This is how we’d rather prove competence than claim it.

EU AI Act explained: what it actually requires, and who it applies to
STANDARDS EXPLAINED

EU AI Act explained: what it actually requires, and who it applies to

A plain-English walkthrough of what the EU AI Act requires, which systems are in scope, and the obligations that apply — so you can assess your exposure before your board asks.

July 23, 2026 · By iDharma
Read the guide →

More from Insights

NIST AI RMF for financial services: what the framework means in practice
STANDARDS EXPLAINED

NIST AI RMF for financial services: what the framework means in practice

The NIST AI Risk Management Framework is not a compliance checklist — it is a governance architecture. Here is what it asks for and why fintech and lending teams find it harder than expected.

July 23, 2026 · Fintech
Read the guide →
The six jobs enterprises hire an AI audit to do — and how we serve each one
METHODOLOGY NOTES

The six jobs enterprises hire an AI audit to do — and how we serve each one

Enterprises do not hire an AI audit because they want a report. They hire one because they have a specific, high-stakes problem. Understanding which job a buyer is hiring us to do shapes ever

July 23, 2026
Read the notes →
The cost of not auditing: how to put a number on your AI exposure
METHODOLOGY NOTES

The cost of not auditing: how to put a number on your AI exposure

Every AI compliance team knows their audit costs money. Almost none have quantified what non-compliance costs. Here is the cost cascade model we use to turn "vague fear" into a number the cli

July 23, 2026
Read the notes →
High-risk AI in healthcare: what EU and US frameworks actually require
STANDARDS EXPLAINED

High-risk AI in healthcare: what EU and US frameworks actually require

AI diagnostic tools, clinical decision support, and triage systems are explicitly classified as high-risk under the EU AI Act — and US regulators are signalling the same direction. Here is wh

July 23, 2026 · Healthcare
Read the guide →
Why 'our AI is 95% accurate' tells you almost nothing — and what to ask instead
METHODOLOGY NOTES

Why 'our AI is 95% accurate' tells you almost nothing — and what to ask instead

Accuracy claims without a defined test set, ground truth definition, or methodology are marketing, not evidence. Here are the five questions that reveal whether a vendor's claimed accuracy nu

July 23, 2026
Read the notes →
AI in financial services: what MiFID II, the EU AI Act, and US regulators actually require
STANDARDS EXPLAINED

AI in financial services: what MiFID II, the EU AI Act, and US regulators actually require

Banks, wealth managers, and investment firms using AI face a layered compliance stack — EU AI Act, MiFID II, and US federal guidance all apply simultaneously. Here is what each framework actu

July 23, 2026 · Finance
Read the guide →
Model risk management for AI: what SR 11-7 covers, and where the EU AI Act goes further
METHODOLOGY NOTES

Model risk management for AI: what SR 11-7 covers, and where the EU AI Act goes further

Banks have had model risk management frameworks since 2011. The EU AI Act adds obligations SR 11-7 does not cover. Here is the gap map — and what a unified audit looks like.

July 23, 2026 · Finance
Read the notes →