METHODOLOGY NOTES

The cost of not auditing: how to put a number on your AI exposure

Every AI compliance team knows their audit costs money. Almost none have quantified what non-compliance costs. Here is the cost cascade model we use to turn "vague fear" into a number the cli

iDharma · July 23, 2026 · 6 min read
The cost of not auditing: how to put a number on your AI exposure

The most common objection to an AI audit is cost. A $15,000 engagement is a real line item with a real budget owner. The exposure it is guarding against — regulatory fines, litigation, reputational damage, engineering remediation — is abstract until something goes wrong. This asymmetry is a decision-making failure, not a financial one. We use a cost cascade model to fix it.

Why the standard pitch does not work

Telling a compliance officer "you could be fined €12M" does not move them to act. They know the fine exists. What they do not know is their specific likelihood of incurring it, given their specific deployment, in their specific regulatory environment. A generic fear appeal is not actionable — and a sophisticated compliance professional will correctly dismiss it as a sales tactic.

What works instead is a tool they can run themselves, with their own numbers, that produces their own estimate of their exposure. People do not argue with numbers they produced themselves.

The cascade structure

The model works backwards from total AI-related exposure to the drivers that can actually be changed. It has three cost streams, each with drivers the client controls:

Cost stream 1: Regulatory exposure

Driver: the probability of a regulatory finding × the likely penalty range for your sector and jurisdiction. The penalty figure is the publicly verifiable anchor — real fine amounts from real enforcement actions, cited to their original source. The probability is the client's own assessment, given their regulatory environment and the enforcement activity they have observed in their sector.

Cost stream 2: Litigation exposure

Driver: the number of affected individuals × the likely claim value in a class or collective action, discounted by the probability of a successful claim. Again, the affected-individual count comes from the client's own model data; the claim values are calibrated to published settlements in similar cases.

Cost stream 3: Remediation and operational cost

Driver: engineering hours to fix identified issues × average loaded engineering cost, plus reputational costs estimated as lost revenue over a recovery period. Both inputs come from the client.

The unknown that makes the cascade work

At the bottom of every cost cascade sits a single input that multiplies through all three streams: the percentage of your AI models that have an undetected material issue. This is the number that drives everything — and it is the one number neither you nor we can know without an audit.

We do not fill this box in. We leave it empty, point at it, and say: "Neither of us knows this number. That is what an audit answers." The empty box does more persuasive work than any claim we could make. It transforms the question from "should we spend $15,000 on an audit?" to "what is the cost of not knowing this number?" Those are very different questions with very different implied answers.

How to use this in a risk conversation

The cascade is a tool for a conversation, not a slide. Walk through it with the relevant stakeholder — a CRO, CISO, or General Counsel — and let them supply the inputs. Ask for their model count, their affected-customer volumes, their average deal sizes for enterprise clients, and their engineering team's loaded cost. They fill in their numbers. You anchor only the publicly verifiable figures — real fine amounts from real enforcement cases, cited to their original source.

By the time the calculation is complete, the number the client is looking at is their own. The audit price is one line item in the model. They can see what it buys, what it reduces, and what it leaves unresolved. At that point, the question of whether to proceed is theirs to make with full information — which is exactly the relationship an independent auditor should have with a client.

What the cascade does not do

It does not predict your outcome. It is a structured way to think about risk, not a probability model backed by actuarial data. The inputs carry uncertainty, and we say so explicitly. What it does is make that uncertainty concrete and actionable rather than vague and paralyzing. A compliance officer who has worked through this model knows which inputs matter most, which they can reduce through action, and which one requires an audit to measure. That is the practical output.

If you want to run this model with your own numbers, contact us — we will walk through it with you before you decide whether an audit makes sense. That is what "proof first" means in practice.

Wondering where your AI stands?