Independence
Independence is the product, not a disclaimer.
Two doors · 12-month cooling-off · six questions, six sources

01 / The wall
You cannot buy the preparation and the sign-off from us.
Ask our competitors that question. The wall is what makes the opinion worth anything, so we protect it in writing rather than in a values statement.
Never both, to the same client or system. A 12-month cooling-off before we would audit a former consulting client. We are the firm that turns down work, and the engagement letter says so.
Technical classification analysis for counsel sits on the audit side of this wall, because it establishes facts rather than building or remediating anything. Where we have done that work, we disclose it before accepting an audit of the same system, and the audit team re-performs the analysis instead of relying on it.
02 / Six questions
Six questions the law already answers for you.
No approved-auditor list exists, so vetting falls to you. You do not have to invent the test. The EU AI Act sets out what independence means for a body performing conformity assessment, the New York City rules define when an auditor is not independent, and assurance practice settles what a report has to disclose. We put all six to ourselves here, with the source beside each, and answer all six.
1. Were you involved in developing, designing, or operating the system?
No. We never build, sell, or operate the systems we audit. Clean, by rule. This is the first test in both regimes: the EU AI Act requires a notified body to be independent of the provider, and of the provider's competitors (Art. 31(4)), and the NYC rules say an auditor is not independent if they were involved in using, developing, or designing the tool.
EU AI Act Art. 31(4) · NYC DCWP AEDT rules
2. Who performs the analysis, and what qualifies them?
The named auditor of record performs and signs the analysis, including the disparate-impact tests: selection rates, impact ratios, the four-fifths rule. At Probus that is an AIGP-trained AI auditor with hands-on experience in technical testing, AI red teaming, and data privacy. The Act asks for the highest degree of professional integrity and demonstrated competence in the specific field, including experience of the relevant type of AI system. Ask for the person, not the firm.
EU AI Act Art. 31(10)-(11)
3. Is your independence a documented structure, or a stated value?
Documented. The Act does not accept independence as a claim: it requires a body to be organised and operated so as to safeguard independence, objectivity and impartiality, and to document and implement the structure and procedures that do it. Ours are written into the engagement letter and the code of conduct: we never audit a system we helped build, sell, or run; audit and consulting never go to the same client or system, with a 12-month cooling-off; and where we previously established the technical facts for counsel, we disclose it and re-perform the analysis rather than rely on it. Ask to see the procedure, not the promise.
EU AI Act Art. 31(6)
4. Do you hold any financial interest in the outcome, or in us?
None. Fees are agreed up front and never contingent on the finding. No equity, no revenue share, no referral fee. The NYC rules disqualify an auditor holding a direct or material indirect financial interest in the employer or the vendor, and professional ethics frameworks treat a contingent fee as a self-interest threat to objectivity, because a charge that moves with the finding corrupts the finding.
NYC DCWP AEDT rules · IESBA threats framework
5. What level of assurance is this, and against which criteria?
Reasonable assurance, expressed in positive form, against criteria stated in the report itself, with the methodology published rather than only the conclusion. Assurance practice distinguishes reasonable from limited assurance, and a report that says a system is "assured" without naming the level, the criteria, or the method has not told you what was actually tested. You, and anyone challenging you, can see how the opinion was reached.
ISAE 3000 (Revised)
6. Will a named individual sign it as auditor of record?
Yes. A named practitioner signs it, and their reputation is attached to it. Every mature assurance regime puts an accountable human signature on the opinion, and a report generated by software with no signatory is output, not an audit. That is the whole thesis.
Assurance practice
Put these to us directly.
If any answer here does not hold up when you ask it on a call, you should not engage us. That is the point of publishing them.