Vetting
AI System Vetting
Assurance over AI systems: the model, the data, the supply chain and the disclosure duty.
The situation
What the client receives
Schedule of deliverables
- AI Act scope and classification assessment (prohibited / high-risk / transparency-only / GPAI)
- AI-specific threat model (prompt injection, data poisoning, model extraction, excessive agency)
- Model and data supply chain review
- Article 50 transparency and disclosure readiness
- AI usage policy and shadow-AI discovery
- Testing and human-oversight control design
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- EU AI Act
- ISO/IEC 42001
- NIST AI RMF
- OWASP Top 10 for LLM Applications
Related services
Discuss this engagement
Tell us about the model, its deployment and the decisions it affects and we will set out the scope, the method and the reporting format.