EthiCompass
Technical Whitepaper v1.0

AI Governance Architecture for EU AI Act Compliance

A technical framework for scaling AI with confidence: objective measurement across 8 dimensions, grounded adversarial evidence, and an immutable audit trail that holds up before an auditor.

CTOs & AI Engineers
Compliance Officers
Technical Decision-Makers

EthiCompass Whitepaper

Version 1.0 • November 2025

Executive Summary
Three-Pillar Model
8-Dimensional Measurement
EU AI Act Mapping
Evaluation Flow
Governance Structure

Executive Summary

As your AI systems become integral to how you operate, trust in those systems becomes a business asset. Our platform gives you defensible evidence about how your AI behaves — measured across 8 dimensions, grounded in your own domain, and recorded in an immutable audit trail you can stand behind.

Objective Measurement

8-dimensional scoring framework

Immutable Audit Trail

Registered, hash-citable evidence

Grounded Attacks

KB-brain: universal + grounded packs

EU AI Act Aligned

Articles 9-15 mapped

The Three-Pillar Model

Our platform rests on three foundational pillars that together give you trustworthy, defensible AI governance.

Pillar 1: Objective Measurement

8 measurable dimensions with disaggregated scoring and occurrence rates over N runs

Protects Against

  • Biased criteria
  • Cultural bias
  • Subjective judgment

Pillar 2: Separation of Concerns

KB-brain grounding (universal pack + grounded packs) with domain-adapted attacks

Protects Against

  • Generic-only probes
  • Corpus drift
  • Ungrounded findings

Pillar 3: Defensible Evidence

Immutable audit trail, mandatory coverage report, and readiness per framework

Protects Against

  • Ethics washing
  • Silent truncation
  • Unauditable decisions

The Eight-Dimensional Model

Your AI system is measured across 8 independent dimensions, each reported as an occurrence rate over N runs with a mandatory coverage report and detailed sub-metrics.

Art. 10

1.Fairness & Non-Discrimination

Protected group analysis, statistical parity across cohorts

General

2.Safety & Harmful Content

Unsafe and harmful content, severity classification

Art. 13

3.Transparency & Explainability

Reasoning clarity, source attribution, jargon density

Art. 10 + GDPR

4.Privacy & Data Protection

PII detection, GDPR/CCPA alignment, data minimization

Art. 15

5.Factuality & Accuracy

Claim verification, evidence quality, known falsehoods

Art. 15

6.Robustness & Adversarial Resilience

Adversarial resistance, jailbreak and injection resistance

Art. 15

7.Security & Access Control

Unauthorized actions, privilege abuse, tool/function-call misuse

Art. 14

8.Accountability & Human Oversight

High-stakes escalation, decision-to-owner traceability

Sample Score Card Output

See exactly which dimension surfaced a finding, expressed as an occurrence rate over N runs — a founded opinion that enables precise remediation, never a verdict.

Transparency:See exactly which dimension surfaced a finding
Targeted Remediation:Address specific findings without re-running everything
Human Oversight:Reviewers annotate specific dimensions with a recorded justification
Bias Detection:Easier to spot if one dimension is systematically biased
8-DIMENSION SCORE CARD · N = 400 RUNS
1.FAIRNESS & NON-DISCRIMINATION0.5%
2.SAFETY & HARMFUL CONTENT0.0%
3.TRANSPARENCY & EXPLAINABILITY1.8%
4.PRIVACY & DATA PROTECTION0.0%
5.FACTUALITY & ACCURACY4.2%
6.ROBUSTNESS & ADVERSARIAL RESILIENCE0.8%
7.SECURITY & ACCESS CONTROL0.0%
8.ACCOUNTABILITY & HUMAN OVERSIGHT1.2%
COVERAGE:100% · NO TRUNCATION

(Occurrence rate per dimension over N runs. Highest exposure on Dim 5 — remediation recommended.)

EU AI Act Compliance

Article Mapping

The EU AI Act (effective August 2024, enforcement 2025-2027) introduces mandatory requirements for high-risk AI systems. We map the 8 measurement dimensions, through the 9 ISO 42001 Annex A control areas, to the key articles.

EU AI Act ArticleTitleDimensions → 9 → Framework Mapping
Article 9Risk Management SystemCertification axis: findings roll up through the 9 ISO 42001 Annex A control areas to per-framework readiness
Article 10Data and Data GovernanceFairness & Non-Discrimination dimension with DPR & BDI metrics
Article 13TransparencyTransparency & Explainability dimension + mandatory explanation logs
Article 14Human OversightAccountability & Human Oversight dimension with HSEC, DOT, HIR metrics
Article 15Accuracy, Robustness, CybersecurityFactuality, Robustness & Adversarial Resilience, and Security & Access Control dimensions with CER, ASR, UAR metrics

Key Quantitative Metrics

Demographic Parity Ratio (DPR)

Ratio of favorable outcomes between protected/reference groups

0.8 - 1.25

Bias Disparity Index (BDI)

Statistical distance in scores between groups for identical prompts

< 0.05

Explainability Coverage Index (ECI)

% of decisions with human-readable explanation

100%

Critical Error Rate (CER)

% of outputs with high-severity factual failures

< 0.1%

Adversarial Success Rate (ASR)

% of jailbreak/injection attempts that bypass guardrails

0%

Unauthorized Action Rate (UAR)

Occurrence rate of unauthorized actions or privilege-scope abuse over N runs

0%

High-Stakes Escalation Coverage (HSEC)

Share of high-stakes decisions routed to human oversight over N runs

100%

Decision-to-Owner Traceability (DOT)

Share of decisions with an attributable, hash-citable owner in the audit trail

100%

Human Intervention Rate (HIR)

Share of evaluations flagged for human review over N runs

5-15%

Evaluation Flow Architecture

Content submission to final decision with immutable audit trail.

API Gateway

Authenticate client, rate limiting, begin audit trail

1

KB-brain Evaluation

8 dimensions in parallel → base score card

2

Grounded Attack Generation

Universal pack + grounded packs → domain-adapted probes from the client's real entities

3

Interpretation Layer

Type and score findings by dimension; occurrence rate over N runs, never a verdict

4

Coverage Report

Mandatory coverage per dimension; budget caps reported, never silently truncated

5

Roll-Up

Findings roll up through the 9 ISO 42001 areas to per-framework readiness

6

Immutable Audit Trail

Registered, hash-citable, tamper-evident trace with 7-year retention

7

Three-Tier Governance

Tier 1: Board

Scope

KB-brain changes

Cadence

Quarterly

Authority

2/3 supermajority vote

Tier 2: Standards

Scope

Immutability enforcement

Cadence

Monthly

Authority

Domain experts

Tier 3: Client

Scope

Custom policy changes

Cadence

Real-time

Authority

Automated + CCO escalation

Readiness Levels

A progressive readiness framework — from a first measured baseline to per-framework readiness that is defensible before an auditor.

Level 0

Requirements

No coverage report

What You Can Claim

No readiness evidence available

Level 1: Measured

Requirements

50+ runs, coverage report per dimension

What You Can Claim

Baseline readiness across the 8 dimensions

Level 2: Governed

Requirements

500+ runs, mapping through the 9 ISO 42001 areas, annual review

What You Can Claim

Readiness evidence rolled up to governance controls

Level 3: Defensible

Requirements

Continuous runs, per-framework readiness, quarterly monitoring

What You Can Claim

Readiness defensible before an auditor, per framework

Scale Your AI With Confidence

Measure your AI across 8 dimensions, ground the evidence in your own domain, and build a defensible, EU AI Act-aligned audit trail you can stand behind.

DOWNLOAD PDF

For technical integration support: hello@ethicompass.com