A technical framework for scaling AI with confidence: objective measurement across 8 dimensions, grounded adversarial evidence, and an immutable audit trail that holds up before an auditor.
Version 1.0 • November 2025
As your AI systems become integral to how you operate, trust in those systems becomes a business asset. Our platform gives you defensible evidence about how your AI behaves — measured across 8 dimensions, grounded in your own domain, and recorded in an immutable audit trail you can stand behind.
8-dimensional scoring framework
Registered, hash-citable evidence
KB-brain: universal + grounded packs
Articles 9-15 mapped
Our platform rests on three foundational pillars that together give you trustworthy, defensible AI governance.
8 measurable dimensions with disaggregated scoring and occurrence rates over N runs
Protects Against
KB-brain grounding (universal pack + grounded packs) with domain-adapted attacks
Protects Against
Immutable audit trail, mandatory coverage report, and readiness per framework
Protects Against
Your AI system is measured across 8 independent dimensions, each reported as an occurrence rate over N runs with a mandatory coverage report and detailed sub-metrics.
Protected group analysis, statistical parity across cohorts
Unsafe and harmful content, severity classification
Reasoning clarity, source attribution, jargon density
PII detection, GDPR/CCPA alignment, data minimization
Claim verification, evidence quality, known falsehoods
Adversarial resistance, jailbreak and injection resistance
Unauthorized actions, privilege abuse, tool/function-call misuse
High-stakes escalation, decision-to-owner traceability
See exactly which dimension surfaced a finding, expressed as an occurrence rate over N runs — a founded opinion that enables precise remediation, never a verdict.
(Occurrence rate per dimension over N runs. Highest exposure on Dim 5 — remediation recommended.)
The EU AI Act (effective August 2024, enforcement 2025-2027) introduces mandatory requirements for high-risk AI systems. We map the 8 measurement dimensions, through the 9 ISO 42001 Annex A control areas, to the key articles.
| EU AI Act Article | Title | Dimensions → 9 → Framework Mapping |
|---|---|---|
| Article 9 | Risk Management System | Certification axis: findings roll up through the 9 ISO 42001 Annex A control areas to per-framework readiness |
| Article 10 | Data and Data Governance | Fairness & Non-Discrimination dimension with DPR & BDI metrics |
| Article 13 | Transparency | Transparency & Explainability dimension + mandatory explanation logs |
| Article 14 | Human Oversight | Accountability & Human Oversight dimension with HSEC, DOT, HIR metrics |
| Article 15 | Accuracy, Robustness, Cybersecurity | Factuality, Robustness & Adversarial Resilience, and Security & Access Control dimensions with CER, ASR, UAR metrics |
Ratio of favorable outcomes between protected/reference groups
Statistical distance in scores between groups for identical prompts
% of decisions with human-readable explanation
% of outputs with high-severity factual failures
% of jailbreak/injection attempts that bypass guardrails
Occurrence rate of unauthorized actions or privilege-scope abuse over N runs
Share of high-stakes decisions routed to human oversight over N runs
Share of decisions with an attributable, hash-citable owner in the audit trail
Share of evaluations flagged for human review over N runs
Content submission to final decision with immutable audit trail.
Authenticate client, rate limiting, begin audit trail
8 dimensions in parallel → base score card
Universal pack + grounded packs → domain-adapted probes from the client's real entities
Type and score findings by dimension; occurrence rate over N runs, never a verdict
Mandatory coverage per dimension; budget caps reported, never silently truncated
Findings roll up through the 9 ISO 42001 areas to per-framework readiness
Registered, hash-citable, tamper-evident trace with 7-year retention
Scope
KB-brain changes
Cadence
Quarterly
Authority
2/3 supermajority vote
Scope
Immutability enforcement
Cadence
Monthly
Authority
Domain experts
Scope
Custom policy changes
Cadence
Real-time
Authority
Automated + CCO escalation
A progressive readiness framework — from a first measured baseline to per-framework readiness that is defensible before an auditor.
Requirements
No coverage report
What You Can Claim
No readiness evidence available
Requirements
50+ runs, coverage report per dimension
What You Can Claim
Baseline readiness across the 8 dimensions
Requirements
500+ runs, mapping through the 9 ISO 42001 areas, annual review
What You Can Claim
Readiness evidence rolled up to governance controls
Requirements
Continuous runs, per-framework readiness, quarterly monitoring
What You Can Claim
Readiness defensible before an auditor, per framework
Measure your AI across 8 dimensions, ground the evidence in your own domain, and build a defensible, EU AI Act-aligned audit trail you can stand behind.
For technical integration support: hello@ethicompass.com