The method

The method, published, so you can argue with it.

An audit you cannot inspect is a brand exercise. This is how an engagement runs, what each step produces, and the public standards each one answers to.

Four steps · reasonable assurance, direct · re-expressed across regimes

01 / The sequence

Four steps, and the order is the method.

The independence check clears before any analysis starts, and nothing is re-expressed to another framework until an opinion has been signed. A sequence run out of order produces a different engagement.

  1. 01

    Scope & independence check

  2. 02

    Socio-technical analysis

  3. 03

    A signed opinion

  4. 04

    Re-expressed across frameworks

  1. 01

    Scope & independence check

    A clarification session settles what is in scope and confirms we can audit you at all. Sometimes it ends in "we can't, here's why." That is the point.

  2. 02

    Socio-technical analysis

    Assessed across the dimensions the OECD uses to classify AI systems, and NIST adopts: application context, data and input, the model, and task and output. AI systems are socio-technical, so the risk is never in the model alone.

  3. 03

    A signed opinion

    A reasonable-assurance opinion, in positive form, signed by a named auditor of record, with the methodology and evidence published, not just the result.

  4. 04

    Re-expressed across frameworks

    The same audit, mapped to whichever regime a customer, buyer, or regulator invokes. Annual or at agreed intervals, because in some markets it is required every year.

02 / Why socio-technical

The risk is never in the model alone.

A system is characterised across four dimensions: application context, data and input, the model, and task and output. Those are the OECD's[02], adopted into the NIST AI Risk Management Framework[01], which states in terms that AI systems are inherently socio-technical in nature.

We use them because they are public, primary and widely adopted, which means a conclusion built on them can be defended in front of someone who did not commission it. We do not build our published method on any competitor's framework, with or without attribution.

In practice this is the difference between an evaluation that measures a model and one that evaluates a system. Our own work note on red-teaming a health-data guardrail is the clearest illustration we can publish: every control passed, and the defect was in what the service wrote to its logs.

03 / What the opinion is

Reasonable assurance, in positive form, signed.

Assurance comes in levels, and the level is not a detail. Under ISAE 3000 (Revised) a reasonable-assurance engagement supports a conclusion expressed positively, while a limited-assurance engagement supports only a negative form: nothing came to our attention[03]. Firms in this market routinely describe the second as though it were the first.

Ours is a reasonable-assurance, direct engagement, and the opinion carries the name of the practitioner who signed it. The methodology and the evidence are published with the result, not just the result.

Fees are never contingent on the outcome. The prohibition people cite for this is usually the AI Act, which contains no such provision. The real anchors are the New York City rules on auditor independence and the IESBA threats framework, which treats a contingent fee as a self-interest threat[05].

Want this run against your system?

A clarification session settles what is in scope and whether we can audit you at all. If we cannot, you will hear that on the call, and it costs nothing.