AI Audit

Two audits, one evidence base — and a report that cannot claim more than its evidence carries.

The platform runs two audit disciplines against the same criteria and the same evidence: an internal audit for your organisation's third line, under the IIA Global Internal Audit Standards, and an independent assurance engagement under ISAE 3000 (Revised) for an external practitioner. Neither issues a certificate, neither produces a score, and the engine never writes the conclusion.

Describes the platform as released on 15 September 2026.

Which audit

Internal audit and independent assurance are not the same thing

They differ in purpose, scope, method and output, and the platform keeps them apart from the moment an engagement is created: the discipline is stamped from the creator's role and never edited afterwards.

Internal audit

IIA Global Internal Audit Standards · third line

Your own internal audit function. A separate role inside your tenant — not a flag on an administrator, because a flag does not carry independence. It reads across all of the organisation's AI systems and writes only its own working papers and findings.

  • Risk-based engagement against the criteria library, with the risk tolerance the board said it would carry
  • Findings expressed as condition against criteria, with cause and effect
  • Management's response recorded per finding; corrective and preventive actions tracked to closure
  • Supervision of the engagement recorded, so the file shows who reviewed what

An internal audit communication to the board — findings, root cause and agreed actions — exported as a locked working-papers file with its evidence log.

It cannot sign an ISAE 3000 independent practitioner's report: that turns on independence from the organisation, which a third line by definition does not have.

Independent assurance

ISAE 3000 (Revised) · external practitioner

An external practitioner — typically your audit firm — working in an auditor workspace your organisation cannot see into. Your only surface is granting and revoking read access to one AI system at a time.

  • Limited or reasonable engagement; the type sets the evidence bar and the wording of every downstream template
  • Independence gate before any fieldwork: self-interest, self-review, familiarity and advocacy threats with a twelve-month look-back — an unresolved threat ends the engagement
  • Scoping on a deterministic risk classification, a versioned criteria snapshot, evidence, criterion evaluations (conform, minor or major non-conformity, observation)
  • Conclusion suggested by the engine from the evidence coverage, set by the practitioner: unmodified, qualified, adverse or disclaimer, in the negative form for limited and the positive form for reasonable engagements

An assurance report with nine mandatory sections, locked with a SHA-256 hash when issued; later changes go through an addendum, and a machine-readable findings package can be published back to the auditee.

It is a conclusion by the practitioner about the subject matter, with a use restriction — not a certificate, and not a compliance stamp.

Evidence

The evidence ceiling no role can override

Every piece of evidence records where it came from, and its assurance level is derived from that source. No administrator, owner or auditor can promote evidence past what its provenance justifies; a claim above the ceiling is refused, not quietly lowered.

LevelWhat it meansHow it can be reached
Declared
declared
Somebody said so. Meets no criterion on its own.Any source, including the platform's own compliance output
Documented
documented
A document with a code and a version exists. Shows the control exists, not that it operates.A document on file, or data read from the auditee through a grant
Verified
verified
The auditor checked it against the source or re-performed the control. The only level that can carry a positive conclusion.Only a procedure performed by the practitioner

The platform's own output is declared

What ComplianceEngine produced about a system is a claim to verify, not a fact. It can seed a procedure; it can never be the evidence.

Data pulled through a grant is at most documented

Cross-tenant reads from the auditee can be cited. They cannot be marked verified, because nobody re-performed anything.

Verified needs a human procedure

The practitioner did the work, and the record says which procedure. This is the invariant that keeps the report from presenting an unverified claim as verified.

Criteria

One versioned library, snapshotted per engagement

Library version 1.1 holds 47 criteria with 160 clause references. Each engagement takes a snapshot of the version it started on, so two audits that say "v1.1" ran against the same criteria — repeatability is what makes a second audit comparable with the first.

  • ISO/IEC 42001 (management system clauses 4–10)
  • Regulation (EU) 2024/1689 — the EU AI Act
  • ISO/IEC 27001 (Annex SL and Annex A)
  • NIST AI RMF (by crosswalk)
  • COSO ERM (by crosswalk, plus risk appetite)
  • OWASP Top 10 for LLM Applications

ISAE 3000, the IIA Global Internal Audit Standards and ISACA's AAIA govern the engagement; they produce no criteria of their own and never measure the audited system.

Licensed standards are paraphrased with clause numbers and never redistributed. A criteria set tied to a licensed standard activates when your organisation holds the licence; until then it shows as not yet licensed rather than failing.

Access

The grant bridge — the one place the auditee and the auditor touch

When a firm using the compliance platform is audited, the auditee grants the practitioner scoped read access, and only that. Every invariant below is enforced in code and written to the access log.

Read-only

The auditor never writes to the auditee's tenant.

One grant, one system

A grant exposes exactly one AI system; a second system is a second grant.

Time-boxed and revocable

Every grant expires and can be revoked instantly. Revocation is forward-only: evidence already pulled is flagged revoked, not deleted, and its criteria become candidates for "unable to conclude".

Consent-based and logged

The auditee accepts a versioned retention consent at grant time and can see a read-log — who read the granted system, when, with personal-data reads flagged. Crossing a tenant boundary is itself auditable.

Boundaries

What the audit platform does not do

  • It does not issue a certificate or a declaration of conformity, and it does not notify any authority on your behalf.
  • It does not produce a compliance score. A number hides missing evidence inside an average; the platform shows which criterion, at which level, and why.
  • The engine does not write the conclusion. It suggests one from the evidence coverage; the practitioner sets it and owns it.
  • Atheros AI is not the independent auditor of a system it advised on. The independence gate applies to us as it applies to anyone: a self-review threat ends the engagement.
  • It does not give legal advice, and an assurance report is not the conformity assessment required by Article 43.
Who uses it

Three ways in

Organisations auditing their own AI systems
Enterprise
Internal-audit and independent-audit workflows on the same evidence base, unlimited seats, SSO, EU data residency with your own keys.
Audit firms and independent practitioners
Auditor engagement pack — €350 per engagement, blocks of 10
The ISAE 3000 workflow with no annual commitment; evidence ledger and working papers per engagement.
Organisations preparing for a first audit
Regulation Ready Consultancy
Readiness work by ISO/IEC 42001 Lead Auditors — on your side of the audit only, never both.
FAQ

Audit questions, answered plainly

Can we run an internal audit of our AI systems in Atheros AI?

Yes. The internal auditor is a separate role inside your organisation's tenant, so no access grant is needed. It runs a risk-based engagement against the criteria library, records findings as condition against criteria with cause and effect, captures management's response and tracks corrective actions, and reports to the board through an internal audit summary. It cannot sign an ISAE 3000 independent practitioner's report, because that requires independence from the organisation.

Does Atheros AI perform independent audits of AI systems?

The platform hosts independent assurance engagements for an external practitioner — usually your audit firm — and enforces the independence gate before any fieldwork. Atheros AI's own Lead Auditors prepare organisations for audit and do not act as the independent practitioner on systems they advised on; a self-review threat ends the engagement, for us as for anyone.

What is an ISAE 3000 assurance engagement for an AI system?

An engagement in which an independent practitioner examines a defined subject matter — here an AI system and its controls — against stated criteria and expresses a conclusion to named intended users. It is limited (a negative-form conclusion: nothing came to our attention) or reasonable (a positive-form conclusion: in our opinion); the type sets how much evidence is needed. The result is a report with a use restriction, not a certificate.

What is the difference between internal audit and independent assurance?

Purpose, scope, method and output. Internal audit gives the board assurance and advice on the organisation's own control environment, under a mandate and a risk-based plan, and reports findings with agreed management actions — not an opinion. Independent assurance expresses a conclusion about the subject matter as a whole to named users, so how much was examined and whether it can be projected to the rest bears directly on whether the conclusion may be given. The platform keeps the two apart from creation.

Which standards can an AI audit be run against?

Criteria library version 1.1 covers ISO/IEC 42001 clauses 4 to 10, the EU AI Act, ISO/IEC 27001, NIST AI RMF and COSO ERM by crosswalk, and the OWASP Top 10 for LLM applications — 47 criteria, 160 clause references. ISAE 3000, the IIA Global Internal Audit Standards and ISACA's AAIA govern the engagement itself. Licensed standards are referenced by clause number and activate when you hold the licence.

Can the platform's own compliance output be used as audit evidence?

Only at the declared level. What ComplianceEngine produced about a system is a claim to verify, not a fact: it can seed a procedure, but it cannot support a criterion on its own and can never be marked verified. Verified evidence requires a procedure performed by the practitioner, and the record names it.

Is an audit report from the platform a certification?

No. An internal audit produces a communication to the board; an independent engagement produces the practitioner's conclusion with a use restriction. Certificates against ISO/IEC 42001 are issued only by accredited certification bodies, and the EU AI Act's conformity assessment is carried out under Article 43. The platform produces the evidence and the report those processes rely on.