M.O.
AI Auditor & Assurance Professional
Signs the assurance opinions. Leads adversarial testing and classification analysis, and publishes the method he uses on both.
Audit once, and rely on it across the EU AI Act, NYC Local Law 144, ISO 42001 and the NIST AI RMF. Signed by a named practitioner, so enterprise buyers stop re-auditing you on every deal.
Named auditor of record · Trained & certified auditors
Regulatory register · version 2.0
Nine regimes across the EU, UK, US and Canada. One of them requires an independent auditor. We sell that row, and we will tell you on the call if you are not in it. Read the register
No dated obligation: United Kingdom · Canada, federal
The problem
A compliance PDF your team wrote gets re-audited by every enterprise customer, and challenged the moment it matters. A signed, independent audit is the one artefact that travels, and survives.

Why a signature changes everything
01
A named practitioner signs your audit as auditor of record. A report with no human signatory is software output, not an audit. Your competitors' own guidance says so.
02
We never audit a system we helped you build, sell, or run. Audit and consulting never go to the same client, with a 12-month cooling-off. Independence is the product, not a disclaimer.
03
One socio-technical audit, re-expressed to the EU AI Act, NYC Local Law 144, ISO/IEC 42001 or the NIST AI RMF as each customer asks. You audit once, then hand the same result to everyone.
How it works
Two doors, one wall
Never both, to the same client or system. We are the firm that turns down work.
How the wall is enforced, and six questions to ask any auditor
For legal counsel
We establish what a system actually does, on the record. We never issue the classification, and we never give legal advice.

Work notes
No client work appears here. These are demonstrations on systems we built, which is the only way to show a method honestly when every engagement is confidential.
Work note 01 / Adversarial evaluation
An LLM guardrail that catches patient identifiers, including base64 and spaced-out digits, held against every injection we threw at it. The finding that mattered was somewhere else entirely.
Failure modes, adversarial testing, socio-technical scope
Work note 02 / Classification analysis
A worked example of the technical characterisation we hand to legal teams: what the system does, which Annex III heading it touches, and the four places the analysis deliberately refuses to answer.
Art. 6 and Annex III characterisation, the facts/determination line
Vetting an auditor
1. Were you involved in developing, designing, or operating the system?
2. Who performs the analysis, and what qualifies them?
3. Is your independence a documented structure, or a stated value?
4. Do you hold any financial interest in the outcome, or in us?
5. What level of assurance is this, and against which criteria?
6. Will a named individual sign it as auditor of record?
The practice
AI Auditor & Assurance Professional
Signs the assurance opinions. Leads adversarial testing and classification analysis, and publishes the method he uses on both.
AI Auditor & Assurance Professional
Works the governance and evidence side: what a control is meant to do, and what record exists that it did it.
Ethics & independence
Not slogans. They decide which engagements we take, and which we turn down.

No stake in the systems we assess. Audit and consulting never meet on the same client.
Conclusions follow the evidence, not the client's preferred answer, and never a contingent incentive.
Client information is used only for the engagement and protected, during and after it.
Trained and certified auditors, working to current law, guidance, and recognised standards.
Enquiry
Send an enquiry and we will set up a clarification session. Thirty rigorous minutes. Sometimes they end in "we can't audit you, here's why," and that is worth knowing too.