AI Governance and Compliance Services, Ready for Your Auditor

AI Assurance

AI Governance, Testing and Documentation Services for Auditors

Six services that prove your AI does what you say it does: model testing, code audit, EU AI Act documentation, risk and traceability records, oversight for payroll and finance work, and incident logs. Each one ends in a document an auditor, a customer or a regulator can read.

Book a 30-minute scoping call See the six services

2 Dec 2027Annex III high-risk deadline after the Digital Omnibus deferral
2 Aug 2026Article 50 transparency duties applied; they were not deferred
EvidenceDated test sets, logs and named sign-offs, not a deck of assurances
YoursEvery pack handed over as editable files your own team owns

Tested in your own repositories, model endpoints and ticketing · NDA and DPA signed before any data moves · Delivered from Dhaka on UTC+6

Which AI assurance services does EICRA offer?

Each one is a separate engagement with its own scope and price. Testing produces the evidence; documentation turns that evidence into the records a reviewer asks for.

AI Model Testing Services

Structured test sets, accuracy and bias checks, red-team prompts and a written result report you can show a reviewer.

Read more →

AI Generated Code Audit

A review of AI-written code for security holes, licence risk, dead paths and untested logic, with a prioritised fix list.

Read more →

EU AI Act Documentation

Technical documentation, risk management records and human-oversight descriptions mapped to the Articles that apply to your system and its role.

Ask for the pack →

Risk, Governance and Traceability Documentation

Risk register, model cards, data lineage, decision logs and sign-off trails, written so a reviewer can follow every step.

Ask for the pack →

AI Oversight for Payroll, AP and EOR

Domain reviewers check AI output on payslips, invoices and contracts against your rules, and record every exception they raise.

Read more →

Error and Incident Documentation

Incident templates, severity rules, root-cause write-ups and a register you can hand to a customer after a failure.

Read more →

Which AI assurance service do I need?

Start from who is asking. If an engineer asks, you need testing or a code audit. If a customer’s security team asks, you need risk and traceability records. If counsel or a regulator asks, you need EU AI Act documentation. If it already went wrong, you need incident records.

Find your situation on the left, then read across
Your situation What you need Where we start
You cannot say how accurate the model actually is AI Model Testing Services Test set built from your own cases
AI wrote large parts of the codebase AI Generated Code Audit Repository scan and a fix list
Your system falls under an Annex III use case EU AI Act Documentation Classification check against the Act
A customer’s due-diligence form asks about AI Risk, Governance and Traceability Documentation Gap review of what you already hold
AI touches payslips, invoices or contracts AI Oversight for Payroll, AP and EOR Calibration sample on your real output
Something went wrong and nobody recorded it Error and Incident Documentation Incident register and severity rules

Two-minute fit check: which AI assurance service suits you?

Five questions. Read across your answer and note the service named. Whichever service appears most often is where to start — and if testing appears twice or more, start there, because every document below it rests on measured evidence.

Answer each question, then count which service appears most
Question Option A Option B Option C
1. Can you state your model’s accuracy today? Yes, measured on a held-out set → EU AI Act Documentation Only the vendor’s benchmark → AI Model Testing Services No number at all → AI Model Testing Services
2. How much of the codebase did AI write? A little, fully reviewed → AI Model Testing Services A lot, reviewed quickly → AI Generated Code Audit Nobody has counted → AI Generated Code Audit
3. Who has asked you about AI risk? Nobody yet → Risk, Governance and Traceability A customer or insurer → Risk, Governance and Traceability Counsel or a regulator → EU AI Act Documentation
4. Does AI touch pay, invoices or contracts? No, internal drafts only → AI Model Testing Services Yes, with a human check → AI Oversight for Payroll, AP and EOR Yes, unchecked → AI Oversight for Payroll, AP and EOR
5. What happens when AI output is wrong? Logged with a root cause → EU AI Act Documentation Fixed quietly in a chat thread → Error and Incident Documentation Nobody records it → Error and Incident Documentation
Six possible outcomes: AI Model Testing Services · AI Generated Code Audit · EU AI Act Documentation · Risk, Governance and Traceability Documentation · AI Oversight for Payroll, AP and EOR · Error and Incident Documentation. If two services tie, start with testing — documentation without measured evidence is a claim, not a record.

In what order should AI assurance work be done?

Three rules in plain language. We apply them in this order, and we say so when the cheaper step is the one you actually need.

Rule 1: measure first, then write it down

A risk register written before anything was tested records opinions, not facts. The first question a reviewer asks is how you know, and a policy document cannot answer it.

So testing comes first: a test set from your own cases, a recorded result, a date. The documents are then descriptions of something real.

Rule 2: write for the person who will challenge it

Assurance documents are not marketing. The reader is an auditor, a customer’s security team or your own counsel, and each of them is looking for the gap you did not mention.

So we state limits plainly: what was tested, what was not, what remains open and who owns it. A stated gap survives review; a hidden one does not.

Rule 3: keep evidence dated and reproducible

Evidence that cannot be repeated is an anecdote. Models change, prompts change and data drifts, so a result without a date and a method is worth very little six months later.

You receive the test set, the scripts and the run dates, so your team can repeat the same test after the next model upgrade and compare.

What the 2027 deferral does not change: the high-risk deadline moved, but the work behind it did not shrink. Transparency duties are already live, customers and insurers are asking now, and a conformity file still needs test evidence that takes months to accumulate. A later deadline is time to build the record, not a reason to start later.

Why choose EICRA for AI assurance?

The EU AI Act (Regulation (EU) 2024/1689) still applies. The Digital Omnibus on AI, in force since 27 July 2026, moved standalone Annex III high-risk duties from 2 August 2026 to 2 December 2027 and product-embedded duties to 2 August 2028, while the Article 50 transparency duties applied from 2 August 2026 as planned (Freshfields, July 2026).

What a typical AI compliance effort leaves out, and what we include
Item Without With EICRA
Model accuracy “We use a leading model” Measured on a held-out test set built from your own cases
Bias and safety Assumed handled by the vendor Tested with documented prompts and a recorded pass or fail
AI-written code Merged because it runs Audited for security, licence and untested paths, with a fix list
EU AI Act A blog post and a hope Documentation mapped article by article to your system’s role
Traceability Screenshots in a chat thread Dated records, model cards, data lineage and named sign-offs
Payroll and finance output Spot-checked when someone remembers Domain reviewers on a written rubric, every exception logged
Incidents Fixed quietly, never recorded Severity rules, root-cause write-up and a register you can share
Contracts A freelancer invoice Company contract with GDPR Article 28(3) processor terms where they apply

AI assurance FAQs: cost, deadlines and scope

Cost is at the top, because that is the question everyone opens with.

How much does AI assurance documentation cost?

Documentation packs are quoted after a 30-minute scoping call, with every deliverable listed before you approve anything. AI oversight for payroll, AP and EOR is $20 per reviewer hour, or $3,000 per reviewer per month. Model testing and code audits are scoped the same way, on our pricing page.

Did the EU AI Act deadline move?

Yes, in part. The Digital Omnibus on AI moved standalone Annex III high-risk obligations to 2 December 2027, and product-embedded high-risk systems to 2 August 2028. The Article 50 transparency obligations were not deferred and applied from 2 August 2026, so disclosure duties are already live.

Which AI assurance service should I start with?

AI Model Testing Services, in almost every case. A risk register, a model card or an EU AI Act file is only as good as the measurement behind it, and writing documentation first usually means rewriting it. Start with a code audit instead if AI wrote most of your codebase.

Do you certify our AI system?

No. We are not a notified body and we do not issue certificates or CE marks. We produce the test evidence and the documentation your own conformity assessment, auditor, insurer or customer security review will ask for, and we say plainly where a gap remains.

Does this replace our lawyer?

No. We prepare technical and process documentation; legal interpretation of how a regulation applies to your business stays with your counsel. Most clients give the pack to their lawyer, who then reviews positions instead of building the whole record from scratch.

What is inside a documentation pack?

A scope statement, a system description, the risk register, data and model cards, the test evidence with dates, the human-oversight design, the monitoring plan and a named owner for each control. Everything is delivered as editable files, not a locked PDF.

Can you test a model you did not build?

Yes, and that is the usual case. We test through your API or a copy of the system, using cases you supply plus adversarial prompts we write. You receive the test set, the scripts and the results, so your team can re-run them later.

How do you handle our data during testing?

NDA and DPA first, then least-privilege named access that is removed at handover. We prefer synthetic or masked records for test sets, and where real records are needed the processing terms, the retention period and the deletion date are written into the contract.

Send us one AI system and the question your auditor asked. We will tell you which records are missing.

Book a 30-minute scoping call