AI Audit and Third-Party Assurance
An independent assessment of whether your AI systems and governance do what you say they do, tested against evidence, for readers who will not accept a self-assessment.
The demand for this is arriving from three directions at once: boards asking whether the controls described to them exist, enterprise customers no longer accepting a vendor's own questionnaire responses, and regulators expecting evidence rather than assertion. All three are asking the same question, which is whether the documentation matches reality.
An AI audit is an independent assessment of AI systems and the governance around them against a stated standard — a regulation, a framework, a customer's requirements or your own published policies — in which claims are tested against evidence rather than accepted as described.
Being clear about what this is
We are not a certification body, and independence has limits
We cannot issue a certificate — that requires an accredited body. Nor will we audit a governance framework or management system that we designed and built, because a firm auditing its own work is not providing assurance. Where we have done the implementation, we will say so and recommend a different assessor for the audit.
What an audit produces is a report with an opinion, the evidence behind it and the findings, addressed to a reader who needs more than your word. That is different from certification and, for many purposes, sufficient.
Auditing against a stated standard
| Standard | The question answered | Typical reader |
|---|---|---|
| Your own published policy | Do you do what you say you do? | Board, audit committee |
| Your governance framework | Is it operating, or only documented? | Executive, internal audit |
| NIST AI RMF | Is the risk process real and evidenced? | US enterprise customers |
| ISO/IEC 42001 | Are you ready for certification audit? | Certification body, executive |
| EU AI Act readiness | Is classification and documentation defensible? | Regulator, counsel, customers |
| A customer's requirements | Do you meet what the contract demands? | The customer's risk function |
The standard has to be named before the audit starts. An audit against unstated criteria produces observations rather than findings, and observations are not something anyone can act on or rely on.
How we test rather than accept
Sample the systems, not the summary
We select systems from the inventory ourselves, including ones that were not offered, and trace them through the controls end to end. An audit that examines only the examples provided is testing the selection rather than the estate.
Re-perform where feasible
Where a control produces a measurable result — a bias test, an evaluation, a monitoring alert — we re-run or independently reproduce it rather than reading the reported figure. Reported results and reproducible results diverge more often than organisations expect.
Interview the operators, not only the owners
The person who runs a review daily knows whether the process described actually happens. The gap between the documented process and the practised one is the single most productive area of any audit.
Trace an incident and a decision
Pick something that went wrong and follow what actually happened, and pick a deployment decision and follow the approval trail. Both reveal in an afternoon whether governance is operating or performing.
Test the inventory's completeness
Not only whether the listed systems are governed, but whether unlisted systems exist. We look in procurement records, expense data and engineering repositories, because completeness is the finding that most often changes an executive's understanding of their exposure.
Rate findings by consequence
With a remediation plan attached, owners named and dates agreed. An audit report with thirty findings and no priority ordering produces paralysis rather than improvement.
What the report contains
- Scope and the standard audited against, stated precisely, including what was excluded and why.
- An opinion, expressed plainly, on whether the controls operate as described.
- Findings rated by consequence, each with the evidence, the affected systems and the recommended remediation.
- Evidence appendix, so a third party can see what was tested and how the conclusion was reached.
- Remediation plan with owners and dates, agreed with you rather than imposed.
- A customer-facing summary where the audit exists to answer enterprise buyers, written to be shared.
How the engagement runs
Systems are sampled by us, including ones that were not offered.
Scope and criteria
The standard named precisely, systems in scope agreed, exclusions documented.
Evidence gathering
Documentation reviewed, inventory completeness tested against procurement and engineering records.
Testing
Controls traced end to end on sampled systems, results re-performed where feasible, operators interviewed.
Findings
Rated by consequence, with evidence attached and affected systems named.
Report and remediation
Opinion issued, remediation plan agreed with owners and dates, customer-facing summary where needed.
What you receive
An independent opinion backed by tested evidence, and a remediation plan someone owns.
Scope and criteria statement
The standard audited against, systems in scope, and documented exclusions.
Audit opinion
Whether controls operate as described, stated plainly.
Findings
Rated by consequence, with evidence, affected systems and recommended remediation.
Evidence appendix
What was tested and how conclusions were reached, inspectable by a third party.
Inventory completeness assessment
Whether unlisted AI systems exist, tested against procurement and engineering records.
Remediation plan
Owners and dates, agreed rather than imposed; plus a shareable summary where the audience is customers.
Is this the right engagement?
Worth being direct. AI Audit and Third-Party Assurance is the wrong spend in some situations, and those are listed rather than buried.
Good fit if
- A board or audit committee has asked whether the described controls exist.
- Enterprise customers no longer accept self-assessment questionnaires.
- Certification is planned and readiness needs independent testing first.
- An incident has raised questions about whether governance operates.
- A regulator has asked for evidence rather than description.
Choose something else if
- You need a certificate, which requires an accredited certification body.
- We designed and built the framework in question, which disqualifies us from auditing it.
- Nothing is in place yet; build first. See framework design.
- The intention is a favourable report rather than an accurate one.
Frequently asked questions
Marked up with FAQPage schema so these answers can surface directly in search results and inside AI assistant responses.
Can you certify our AI systems?
No. Certification requires an accredited certification body, and we are not one. What we provide is an independent audit report with an opinion and tested evidence, which is what boards, enterprise customers and regulators are usually asking for — and we support certification separately where a certificate is the actual requirement.
Can you audit governance you helped us build?
No, and we will say so rather than take the work. A firm auditing its own implementation is not providing assurance to anyone, whatever the report says. Where we did the build, we recommend a different assessor and will support you through their process.
What do you actually test?
Systems we sample ourselves, including ones not offered to us. We trace controls end to end, re-perform measurable results rather than reading reported figures, interview the people who operate processes daily rather than only those who own them, and follow an incident and a deployment decision through the trail they left.
What if you find serious problems?
They go in the report, rated by consequence, with evidence and recommended remediation. That is the purpose of commissioning an audit. Findings are reported to you under NDA; where the audit exists to answer customers, you decide what is shared, and we will not write a summary that misrepresents the findings.
How is this different from a certification audit?
A certification audit assesses conformity to a specific standard and results in a certificate from an accredited body. Ours assesses against whatever standard you name — your own policy, a framework, a customer's requirements — and produces an opinion with evidence. It is more flexible, faster, and carries no certificate.
Often paired with this
Most clients combine two or three engagements from the AI Governance, Security and Compliance pillar. These are the ones that most often run immediately before or after.
ISO/IEC 42001 Implementation
An AI management system built for certification and for use, reusing your ISO 27001 machinery rather than duplicating it.
Read more →AI Risk Assessment and Model Cards
Risk assessments that end in decisions, and model cards that state limits honestly rather than advertising.
Read more →AI Inventory and Model Registry
A complete inventory including shadow and vendor AI, kept current by discovery rather than by annual survey.
Read more →Is this the right engagement?
Tell us what you are trying to build. If a different service fits better, or if you do not need us at all, we will say so.