For the organisations running these systems

Is it your system on the
other side of these reports?

An internal review is worth nothing on your worst day. The moment a company is credibly accused of an unfair algorithm, the first thing anyone asks for is a third-party audit — which is why challenged platforms rush theirs onto their own homepage. Get one before you need one.

The audit test program is built from what actually goes wrong in production — the failure modes across the 3,675 incidents on the public record, ranked by how often they recur — rather than from a compliance checklist written by somebody who has never read a denial letter.

What an audit covers

The audit test program is fixed and published. You know before it starts what will be looked at — and so does anyone you later hand the report to.

Model bias

Counterfactual testing and disparate impact, across the proxies as well as the protected fields. The proxy is usually where it hides.

Data integrity

Where the training data came from, what it encodes about the people in it, how stale it is, and which fields are standing in for something they should not be.

The human in the loop

Whether a reviewer can realistically override the system, whether anyone actually does, and what happens to the ones who try. An override nobody uses is not a control.

Appeal and explanation

What the person on the receiving end is told, whether the stated reason matches the mechanism, and whether the appeal route survives being tested.

Compliance exposure

Mapped to the rule that applies to you — the EU AI Act, Colorado SB 24-205, NYC Local Law 144, the FCRA and ECOA, state insurance and utility regulation.

Change control

Whether a model can be swapped or retrained without anyone outside the team knowing. Silent model change is the failure mode nobody writes a policy for.

How it runs

01ScopeYou tell us which decision the system makes and who it makes it about. We agree on the population, the attributes in play, and the rule set you are exposed to — before anyone touches data.
02TestThe audit test program runs against your model or its outputs, in your environment or ours. Any test we could not run is recorded as skipped. Never as a pass.
03ReportFindings, the exact procedure behind each one, the data that produced it, and a hash manifest so the report can be verified as unaltered by anyone you hand it to.
04Re-testWe say plainly what would move each finding. When you have changed something we run the same audit test program again, and the report says which findings closed and which did not.

An audit does not buy you anything here

Commissioning an audit has no effect on how your organisation appears in the record. Reports are not removed, softened, delayed or reordered for clients, and the audit side has no access to the queue, the reporters, or editorial decisions. The record does not know who the audit clients are.

That is not a disclaimer, it is the point. An audit that could be bought is worth nothing to the regulator you would be showing it to. If a report names your organisation and you believe it is wrong, the corrections process is free and open to everyone.

Request an AI audit

Tell us which system you want looked at and we will come back to you to arrange a scoping conversation.