Independent AI assurance.

Audit once, and rely on it across the EU AI Act, NYC Local Law 144, ISO 42001 and the NIST AI RMF. Signed by a named practitioner, so enterprise buyers stop re-auditing you on every deal.

Named auditor of record · Trained & certified auditors

Independent assurance opinionRef. PA-000
Auditor of record
A named practitioner
Engagement
Reasonable assurance, direct
Basis
Socio-technical, published method
Re-expressed to
EU AI Act · LL144 · ISO 42001 · NIST AI RMF
Signed. Positive opinion.

Regulatory register · version 2.0

Most of the deadlines you have been sold are not real yet.

Nine regimes across the EU, UK, US and Canada. One of them requires an independent auditor. We sell that row, and we will tell you on the call if you are not in it. Read the register

The problem

A compliance PDF your team wrote gets re-audited by every enterprise customer, and challenged the moment it matters. A signed, independent audit is the one artefact that travels, and survives.

Why a signature changes everything

Three things a real audit carries that software cannot.

01

A named signature

A named practitioner signs your audit as auditor of record. A report with no human signatory is software output, not an audit. Your competitors' own guidance says so.

02

An independence wall

We never audit a system we helped you build, sell, or run. Audit and consulting never go to the same client, with a 12-month cooling-off. Independence is the product, not a disclaimer.

03

Audit once, rely many

One socio-technical audit, re-expressed to the EU AI Act, NYC Local Law 144, ISO/IEC 42001 or the NIST AI RMF as each customer asks. You audit once, then hand the same result to everyone.

How it works

A socio-technical audit, signed and re-usable.

  1. 01

    Scope & independence check

  2. 02

    Socio-technical analysis

  3. 03

    A signed opinion

  4. 04

    Re-expressed across frameworks

Read the published method

Two doors, one wall

You cannot buy the preparation and the sign-off from us.

The independence wallTwo service doors, independent audit and governance consulting, separated by a wall. Work never crosses it for the same client or system, and a twelve-month cooling-off applies before a former consulting client can be audited.DOOR 1Independent auditSigned. Named auditor of record.12-MONTH COOLING-OFFDOOR 2Governance consultingNever the same client or system.

Never both, to the same client or system. We are the firm that turns down work.

How the wall is enforced, and six questions to ask any auditor

For legal counsel

The determination is yours. The technical facts it turns on are ours.

We establish what a system actually does, on the record. We never issue the classification, and we never give legal advice.

Work notes

We publish the method, including where it found something against us.

No client work appears here. These are demonstrations on systems we built, which is the only way to show a method honestly when every engagement is confidential.

Work note 01 / Adversarial evaluation

We red-teamed our own PHI guardrail, and the logs were the problem.

An LLM guardrail that catches patient identifiers, including base64 and spaced-out digits, held against every injection we threw at it. The finding that mattered was somewhere else entirely.

Failure modes, adversarial testing, socio-technical scope

Work note 02 / Classification analysis

Where a classification analysis stops, and counsel begins.

A worked example of the technical characterisation we hand to legal teams: what the system does, which Annex III heading it touches, and the four places the analysis deliberately refuses to answer.

Art. 6 and Annex III characterisation, the facts/determination line

All work notes

Vetting an auditor

Six questions the law already answers for you.

  1. 1. Were you involved in developing, designing, or operating the system?

  2. 2. Who performs the analysis, and what qualifies them?

  3. 3. Is your independence a documented structure, or a stated value?

  4. 4. Do you hold any financial interest in the outcome, or in us?

  5. 5. What level of assurance is this, and against which criteria?

  6. 6. Will a named individual sign it as auditor of record?

Our answers, with the source behind each

The practice

You deal with the people who sign the work.

M.O.

AI Auditor & Assurance Professional

Signs the assurance opinions. Leads adversarial testing and classification analysis, and publishes the method he uses on both.

M.E.

AI Auditor & Assurance Professional

Works the governance and evidence side: what a control is meant to do, and what record exists that it did it.

Who signs the work

Ethics & independence

Held to a written code of professional conduct.

Not slogans. They decide which engagements we take, and which we turn down.

Independence

No stake in the systems we assess. Audit and consulting never meet on the same client.

Objectivity

Conclusions follow the evidence, not the client's preferred answer, and never a contingent incentive.

Confidentiality

Client information is used only for the engagement and protected, during and after it.

Competence & due care

Trained and certified auditors, working to current law, guidance, and recognised standards.

Enquiry

Find out what your customers will ask for.

Send an enquiry and we will set up a clarification session. Thirty rigorous minutes. Sometimes they end in "we can't audit you, here's why," and that is worth knowing too.

hello@probusai.com

Opens your email. Or write to hello@probusai.com