We show our work.
Teardowns of real AI enforcement cases, plain-English guides to the standards we audit against, and our methodology notes — published, dated, and cited. This is how we’d rather prove competence than claim it.
EU AI Act explained: what it actually requires, and who it applies to
A plain-English walkthrough of what the EU AI Act requires, which systems are in scope, and the obligations that apply — so you can assess your exposure before your board asks.
Read the guide →More from Insights
NIST AI RMF for financial services: what the framework means in practice
The NIST AI Risk Management Framework is not a compliance checklist — it is a governance architecture. Here is what it asks for and why fintech and lending teams find it harder than expected.
Read the guide →
The six jobs enterprises hire an AI audit to do — and how we serve each one
Enterprises do not hire an AI audit because they want a report. They hire one because they have a specific, high-stakes problem. Understanding which job a buyer is hiring us to do shapes ever
Read the notes →
The cost of not auditing: how to put a number on your AI exposure
Every AI compliance team knows their audit costs money. Almost none have quantified what non-compliance costs. Here is the cost cascade model we use to turn "vague fear" into a number the cli
Read the notes →
High-risk AI in healthcare: what EU and US frameworks actually require
AI diagnostic tools, clinical decision support, and triage systems are explicitly classified as high-risk under the EU AI Act — and US regulators are signalling the same direction. Here is wh
Read the guide →
Why 'our AI is 95% accurate' tells you almost nothing — and what to ask instead
Accuracy claims without a defined test set, ground truth definition, or methodology are marketing, not evidence. Here are the five questions that reveal whether a vendor's claimed accuracy nu
Read the notes →
AI in financial services: what MiFID II, the EU AI Act, and US regulators actually require
Banks, wealth managers, and investment firms using AI face a layered compliance stack — EU AI Act, MiFID II, and US federal guidance all apply simultaneously. Here is what each framework actu
Read the guide →
Model risk management for AI: what SR 11-7 covers, and where the EU AI Act goes further
Banks have had model risk management frameworks since 2011. The EU AI Act adds obligations SR 11-7 does not cover. Here is the gap map — and what a unified audit looks like.
Read the notes →