Book an AI audit and compliance assessment.
Lightbridge Automation's AI Audit & Compliance Assessment is a scoped, evidence-based engagement that tests one AI system, a portfolio of systems, or an entire AI program against defined criteria: performance and accuracy, bias and fairness, security and robustness, governance and documentation, and regulatory conformance, then delivers a findings report and a prioritized remediation roadmap.
This is a fixed-scope, direct-response engagement, weeks not months, for a team that wants an evidenced answer on where its AI systems stand before committing to a longer program. Read what an AI audit is for the underlying concept, or go straight to booking below.
What's included in the engagement
Six steps, from the first scoping call to a roadmap your team can execute. Every finding is evidenced, not asserted.
Scoping call and criteria selection
We define what is being audited, one system, a set of systems, or the whole program, and agree the criteria to test against: your own AI policy, the NIST AI Risk Management Framework, ISO/IEC 42001 requirements, or an EU AI Act obligation where one applies.
Evidence collection
We assemble the artifacts that show whether controls exist: model documentation, test results, risk assessments, approval records, and monitoring logs. Where evidence is missing, that absence becomes a finding in its own right.
Control testing
We test each control against its criterion rather than accepting a claim: measured performance and accuracy, bias and fairness across relevant groups, security and robustness under adversarial input, and governance and documentation quality.
Findings report
A written report records where controls meet the criteria and where they fall short, with each finding evidenced and rated by severity, so leadership can act on specifics rather than an impression.
Remediation roadmap
Every finding is assigned a priority, an owner, and a sequence, built around your risk and your engineering capacity rather than a generic checklist.
Optional re-test
A follow-up engagement, booked once remediation is complete, confirms that each control now operates as intended. This is the step that turns a report into a closed gap.
How the engagement runs
A single-system audit typically closes out in 2 to 4 weeks. A full AI program audit, covering governance and multiple systems, typically runs 4 to 8 weeks. Scope and cost are set on the scoping call once we know what is in play.
Scoping and kickoff
3 to 5 daysAgree scope, criteria, and the systems or program in scope. Set the evidence request list.
Evidence and testing
1 to 4 weeksCollect evidence and test controls against the agreed criteria. Duration scales with the number of systems in scope.
Findings readout
2 to 3 daysPresent the findings report and walk leadership through severity and evidence for each gap.
Remediation roadmap handoff
1 weekDeliver the prioritized, owned roadmap your team executes against.
Optional re-test
Booked separatelyConfirm remediation closed the findings once your team has done the work.
What the assessment tests against
Every engagement measures against explicit criteria, chosen on the scoping call: your own AI policy, the NIST AI Risk Management Framework, ISO/IEC 42001 requirements, or an EU AI Act obligation where one applies. Across those frameworks, the same five areas recur.
Performance and accuracy
Measured behavior on representative data, checked against a stated standard rather than a demo.
Bias and fairness
Outcomes examined across relevant groups against a fairness definition the organization set and can show it measured against.
Security and robustness
Evidence that the system withstands adversarial input and unexpected conditions and fails safely.
Governance and documentation
A named owner, a risk assessment, defined oversight, an audit trail, and documentation that explains the system.
Regulatory conformance
Where a law applies, such as the EU AI Act for a high-risk system, whether the system meets it.
This assessment references NIST AI 100-1, ISO/IEC 42001, and the EU AI Act for identification only. Lightbridge Automation is an independent consulting firm, not a certification body, and is not affiliated with or endorsed by the National Institute of Standards and Technology, the International Organization for Standardization, or the European Union. Lightbridge Automation makes no claim about its own ISO 42001, ISO 27001, or SOC 2 certification status.
When to book this, and when to start somewhere else.
Book the AI Audit & Compliance Assessment when you want an evidenced, weeks-long answer on where a system or program stands right now, without committing to a certification build. If the findings point to standing up a full governance program, that work continues with AI governance consulting. If the goal is accredited certification against the international standard, the assessment can serve as the gap analysis that opens the ISO 42001 certification program, a 4 to 6 month engagement in its own right. And if you are still working out what an AI audit even covers before committing to any of the three, start with what is an AI audit.
Frequently asked questions about the AI audit and compliance assessment
- What does the AI Audit & Compliance Assessment include?
- The engagement runs six steps: a scoping call that fixes what is being audited and the criteria to test against, evidence collection against that scope, testing of each control, a written findings report rated by severity, a prioritized remediation roadmap with owners, and an optional re-test once your team closes the gaps. You leave with a specific, evidenced picture of where your AI systems or program stand, not a generic checklist.
- How is this different from ISO 42001 certification readiness?
- This is a scoped audit engagement, typically weeks, not a multi-month management-system build. Lightbridge Automation's ISO 42001 consulting builds the full AI Management System an accredited body later certifies: policies, processes, and controls across gap analysis, framework design, implementation, and certification audit preparation. The AI Audit & Compliance Assessment can stand alone, or it can serve as the gap analysis that starts an ISO 42001 program. See the full ISO 42001 certification path for the longer build.
- How is this different from the 'what is an AI audit' resource guide?
- The resource guide is educational: it explains what an AI audit is, the types, how it differs from a risk assessment, and how the process generally runs. This page is the bookable engagement where Lightbridge Automation actually runs that process against your systems, with criteria we agree together, evidence we collect from your program, and a report and roadmap built for your organization specifically.
- What standards can the assessment measure against?
- Whatever criteria fit your situation. Common choices are your own internal AI policy, the NIST AI Risk Management Framework, the requirements of ISO/IEC 42001, or an EU AI Act conformity obligation where a system falls in the high-risk tier. We help you choose during the scoping call rather than defaulting to one framework regardless of fit.
- How long does the engagement take?
- A focused audit of a single AI system typically runs 2 to 4 weeks from scoping to findings report. A full AI program audit, covering governance, multiple systems, and documentation, typically runs 4 to 8 weeks. Scope and cost are set on the scoping call once we know how many systems are in play and what evidence already exists, not against a fixed price list.
- Do we need an AI governance program already in place before booking?
- No. Absent evidence is itself a finding, so an organization early in its AI governance maturity gets just as much value from the assessment as one with a mature program: it tells you exactly what is missing. If the findings point to building out a governance program rather than fixing point gaps, that work sits with the Lightbridge Automation AI governance practice.
- What happens after the findings report?
- You get a remediation roadmap with each finding assigned a priority, an owner, and a sequence. Your team executes it. Lightbridge Automation is available for an optional re-test once the work is done, to confirm the control now operates as intended, and can carry the program forward into AI governance consulting or ISO 42001 readiness if certification becomes the goal.
- Is Lightbridge Automation itself ISO 42001 or SOC 2 certified?
- Lightbridge Automation is an independent consulting and assessment firm, not a certification body, and makes no claim about holding ISO 42001, ISO 27001, or SOC 2 certification for its own operations. The AI Audit & Compliance Assessment is a service we deliver to test your systems against these standards, not a statement about our own compliance posture.
Get an evidenced answer, not an impression.
Book a scoping call. We will agree the criteria, run the audit, and hand you a findings report and remediation roadmap your team can act on.