AI audits across the model, the system, and the management around it.

Independent audits for AI and LLM systems — from adversarial red teaming to ISO/IEC 42001 management system reviews to EU AI Act conformity assessments. Built on our STARED framework, peer-reviewed by 3 to 4 specialists, and aligned with the standards your regulators and customers actually check.
5-part
STARED dimensions cover the full AI audit surface
3-4x
Independent specialists peer-review every audit
02 Aug 26
EU AI Act high-risk system enforcement date
24h
Scoping turnaround from first call to quote

Global Brands That Trust AuditOne

Our Framework

Existing audit frameworks weren't built for AI. We built one that was.

Traditional security and compliance frameworks ignore most of what makes AI systems hard to audit — training data, model behaviour, post-deployment drift, adversarial robustness. STARED is our five-dimension framework purpose-built to close that gap.
STARED
A FIVE-DIMENSION FRAMEWORK FOR AI SYSTEM AUDITS
S
Security
Model and infrastructure security. Adversarial robustness, prompt injection, model extraction, supply-chain integrity of weights and dependencies.
TA
Technical Assessment
Model performance, calibration, evaluation against benchmarks and bespoke evals, monitoring, drift detection, retraining strategy.
R
Regulatory
EU AI Act conformity, ISO/IEC 42001 management system, GDPR Article 22, sectoral rules (MDR, DORA, FDA-equivalent for AI).
E
Ethics
Bias, fairness, explainability, human oversight, stakeholder engagement across the AI system lifecycle. Documented, not asserted.
D
Data Governance
Training data lineage, consent, retention, quality and representativeness. Privacy preservation through inference and deletion workflows.
Request an AI audit
The STARED litepaper covers the framework in depth - mothodology, scoring rubrics, and worked examples across LLM, tradinional ML, and computer vision systems.
What we test for

The failure modes that put AI systems on the front page.

A non-exhaustive map of AI-specific risks covered in every AuditOne engagement, aligned to the OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and our internal STARED catalogue.
LLM01
Prompt Injection
Direct and indirect injection via user input, retrieved documents, tool outputs, and system prompts. Boundary leakage between user and system context.
LLM02 / owasp-a07
Sensitive Information Disclosure
Training-data extraction, memorisation of PII or credentials, system-prompt leakage, retrieval-augmented context exposure.
LLM03
Supply Chain
Compromised model weights, malicious fine-tuning data, third-party adapter integrity, dependency provenance for ML libraries and frameworks.
LLM04
Data & Model Poisoning
Backdoor triggers, label-flipping attacks, RAG-context poisoning, fine-tuning dataset integrity, reinforcement learning reward hacking.
LLM05
Improper Output Handling
Downstream injection via model output, XSS from generated HTML, SQL injection from generated queries, command injection from tool-use outputs.
LLM06
Excessive Agency
Over-permissioned tool access, missing human-in-the-loop on consequential actions, agentic loop escapes, scope creep in multi-step plans.
eu-ai-act Art.10
Bias & Fairness
Disparate impact across protected characteristics, training-data representativeness gaps, calibration failures across demographic slices.
eu-ai-act Art.13
Transparency & Explainability
Decision-traceability for high-risk outputs, user-facing disclosure, technical documentation completeness for conformity assessment.
eu-ai-act Art.14
Human Oversight
Override and stop mechanisms, oversight UI design, operator competence requirements, residual-risk acceptance documentation.
EU AI Act timeline

The clock that matters.

Traditional security and compliance frameworks ignore most of what makes AI systems hard to audit — training data, model behaviour, post-deployment drift, adversarial robustness. STARED is our five-dimension framework purpose-built to close that gap.
aug 2024

AI Act in force

IN EFFECT
FEB 2025

Prohibited practices banned

ENFORCED
aug 2025

GPAI model rules apply

ENFORCED
2 aug 2026

High-risk systems compliance

IN EFFECT
aug 2027

Embedded systems in regulated products

UPCOMING
Important update: The Digital Omnibus political agreement reached in May 2026 may defer some high-risk deadlines to December 2027 — but the proposal has not yet been formally adopted. August 2, 2026 remains the operative legal deadline. Fines reach up to €35M or 7% of global turnover. Either way, a credible conformity assessment takes 8–16 weeks. We scope yours in 24 hours.
talk to an auditor
how we are different

Four sets of eyes on the same system. Always.

A single auditor sees what they have seen before. Four specialists see what an AI system actually does.
Every AuditOne AI engagement is conducted by 3 to 4 independent specialists working in parallel — typically one technical/ML auditor, one security/red-team auditor, one regulatory auditor, and one ethics/fairness reviewer. They evaluate the system separately, then peer-review each other's findings before any issue makes it into your report.

AI is too multidimensional for a single auditor to cover credibly. Our model assigns the right specialist to each STARED dimension and forces cross-validation between them.
Specialist-matched assignment — a fairness auditor reviews bias claims, an ML engineer reviews drift detection, a regulatory auditor reviews Annex IV documentation.
Cross-dimension validation — findings in one STARED dimension are checked against the others. A "safe" technical answer that fails on ethics doesn't ship.
Skin in the game — auditors earn bonuses on valid findings, rewarding depth and accuracy over checklist completion.
how it works

From scoping to audit report in 6 to 16 weeks

01
Scoping & risk classification
24 to 48 hours
We classify your AI system under EU AI Act Annex III, identify applicable obligations, and confirm scope across STARED dimensions. You receive a fixed quote, a target audit window, and a documentation checklist within 48 hours.
02
Documentation review
1 to 2 weeks
We review your technical documentation (Annex IV pack for EU AI Act, Statement of Applicability for ISO 42001), model cards, data sheets, evaluation reports, and operational procedures. Gaps flagged with specific evidence requests.
03
Technical & adversarial testing
2 to 6 weeks
Hands-on testing across STARED dimensions: red teaming against OWASP LLM Top 10 and MITRE ATLAS, bias and fairness evaluation, drift and calibration analysis, infrastructure security review. Critical findings escalated immediately.
04
Peer review & consolidation
1 week
Each specialist's findings are reviewed by at least one auditor from a different STARED dimension. The team produces one consolidated report with classified findings, evidence, and remediation guidance.
05
Peer review & consolidation
Project-dependent
You remediate the documented issues. We verify closure and issue the final report — formatted to satisfy your certification body (ISO 42001), notified body (EU AI Act high-risk), or customer due-diligence requirements.
feedback

What clients say.

FAQs

Is my AI system "high-risk" under the EU AI Act?

High-risk classification is determined by Annex III of the regulation. The main categories are: biometric identification, critical infrastructure, education, employment (hiring, monitoring, termination), access to essential services (credit scoring, insurance, public benefits), law enforcement, migration, and administration of justice. AI systems used as safety components in products covered by EU product safety law (medical devices, vehicles, machinery) are also high-risk. We classify your system formally as the first step of every engagement — and the classification itself is a piece of evidence regulators may ask for.

What's the difference between an ISO 42001 audit and an EU AI Act conformity assessment?

ISO/IEC 42001 audits your management system — the governance, policies, and processes around AI in your organisation. EU AI Act conformity assessment audits a specific high-risk AI system against the regulation's technical and documentation requirements (Articles 9–17). The two are complementary: a mature ISO 42001 management system makes EU AI Act conformity dramatically easier to evidence. We deliver both, separately or as an integrated engagement.

Do you audit LLM and generative AI systems specifically?

Yes — LLM and generative AI are now the majority of our AI audit engagements. Our red-team specialists test against the OWASP LLM Top 10 (2025 edition), MITRE ATLAS adversarial taxonomy, and protocol-specific failure modes for RAG systems, agentic workflows, and multi-modal models. We cover prompt injection (direct and indirect), jailbreaking, training-data extraction, tool-use boundary abuse, output handling vulnerabilities, and the agentic-loop and excessive-agency risks unique to AI agents.

What documentation do I need to prepare?

For EU AI Act conformity work, the Annex IV technical documentation pack: system description, intended purpose, training data documentation, evaluation results, risk management documentation, post-market monitoring plan. For ISO 42001 work, your AI policy, Statement of Applicability, risk register, and process documentation. For technical red teaming, model access (API or weights), system prompts, and any deployment guardrails. We send a tailored checklist after the scoping call — most clients have 60–70% of what they need and we identify the gaps quickly.

How long does an AI systems audit take?

Six to sixteen weeks end-to-end, depending on scope. A targeted LLM red-team engagement against a single deployed system can close in 4–6 weeks. A full ISO/IEC 42001 internal audit across an organisation typically runs 8–12 weeks. An EU AI Act conformity assessment for a single high-risk system, including remediation cycles, runs 10–16 weeks. We commit to a specific window in the engagement letter.

How is the audit priced?

Pricing depends on three factors: the AI system's complexity (single model vs. multi-model pipeline vs. agentic system), the depth of audit required (focused dimension vs. full STARED), and the auditor-days needed across the relevant specialists. Fixed-price quote returned within 24 hours of scoping. SME-friendly engagement sizes start in the low-five-figures; full enterprise EU AI Act conformity assessments scale up from there. Contact us at hello@auditone.io for an indicative range.

Are you a Notified Body for EU AI Act conformity?

No. Most high-risk AI systems (Annex III) follow the self-assessment route under Article 43, where the provider conducts the conformity assessment using internal procedures. Our role is to deliver the conformity assessment as an independent third party, producing documentation that satisfies the requirements without requiring a Notified Body's involvement. For the narrow set of high-risk products that do require Notified Body involvement (certain biometric ID systems), we work alongside accredited Notified Bodies — including partners in our certification body network — and produce the evidence base they need.

What's the STARED framework, and where can I read about it?

STARED is our five-dimension framework for AI audits: Security, Technical Assessment, Regulatory compliance, Ethics, and Data governance. It was built specifically because existing security or compliance frameworks don't cover what makes AI systems hard to audit — training data lineage, model behaviour under adversarial conditions, drift, agentic risk. The full methodology, scoring rubrics, and worked examples are available in the STARED litepaper.

Will you also help us prepare, or only audit?

Both functions are kept strictly separate. We do not write your policies, build your AI governance, or implement your controls — doing so would compromise the independence required for the audit itself. What we do offer is a pre-audit gap assessment (lighter, advisory) followed by the formal audit (independent, evidence-based). The gap assessment tells you what to fix; the audit verifies you've fixed it. Different scoping, different deliverables.