EthiCompass

AI Compliance Audit

Know Where You Stand.
Before a Regulator Asks.

A comprehensive audit of your AI systems in 3 weeks. Every system scored across 7 scientifically validated dimensions. EU AI Act gap analysis. Defensible documentation. No platform commitment required.

View Sample Report →
3-Week Delivery·Expert-Validated·Executive-Grade Report
Confidential
Doc Ref: ETHIC-RPT-2026-00147
Version: 1.0 — Final
Eval ID: eval_mock_eurobank
Date: March 15, 2026

EthiCompass

AI Ethics & Compliance
Evaluation Report

EuroBank Virtual Assistant v3.2

Generative AI — Financial Services

HIGH RISK — EU AI Act Annex III

Risk

HIGH

Intake

7.6

Score

7.8

Client

EuroBank AG

Frankfurt, Germany

Evaluator

EthiCompass

7-Dimension Framework

Sample Report — Demonstration Purposes

EthiCompassCONFIDENTIAL

Dimensional Scorecard

Discrimination & Fairness
7.2COND
Toxicity & Harmful Lang.
9.4PASS
Explainability & Transp.
6.1ACTION
Privacy & Data Protection
8.5PASS
Factuality & Accuracy
7.8COND
Robustness & Resilience
8.1COND
Regulatory Compliance
7.5COND
Composite Score
7.8/10CONDITIONAL
Page 6 of 17eval_mock_eurobank_2026Q1
EthiCompassCONFIDENTIAL

Critical Findings

P07 Day Deadline

Incorrect Deposit Insurance Information

Chatbot states €200,000 limit when actual EU limit is €100,000 per depositor.

P014 Day Deadline

Missing MiFID II Suitability Assessment

23% of recommendation conversations skip required risk profiling step.

Key Recommendations

PActionRef
P0Fix deposit insurance to €100KDir. 2014/49
P0Add MiFID II suitability gateMiFID II Art.25
P1Add AI disclosure to responsesAI Act Art.52
P1Implement explanation moduleAI Act Art.13
P1Add confidence indicatorsAI Act Art.14
Page 7 of 17eval_mock_eurobank_2026Q1
EthiCompassCONFIDENTIAL

Risk Classification — ETHI-202

MINIMAL
LIMITED
HIGH
UNACC.

11 / 15 points — HIGH RISK

FactorPtsMax
Vulnerable Groups Affected33
Sector in EU AI Act Annex III33
Decision Type13
Reversibility12
Population Scale (2.3M)33
TOTAL1115

Regulatory Implications

Conformity assessment (Art. 43)
EU AI database registration (Art. 49)
Fundamental rights assessment (Art. 27)
Quality management system (Art. 17)
Post-market monitoring (Art. 72)
Incident reporting (Art. 73)
Page 4 of 17eval_mock_eurobank_2026Q1
View Full Sample Report

What You Get in 3 Weeks

OneCheck delivers a complete AI compliance baseline — the evidence you need to understand your risk posture and prepare for regulatory scrutiny.

7-DIMENSION SCORECARD

Every AI system in scope evaluated across all 7 dimensions. Disaggregated scores that show exactly where risk concentrates and why.

EU AI ACT GAP ANALYSIS

Your current AI systems mapped against EU AI Act Articles 9–15 requirements. Clear identification of compliance gaps and regulatory exposure.

REMEDIATION ROADMAP

Prioritized action items ranked by risk severity. Each recommendation mapped to the specific dimension and regulation it addresses.

IMMUTABLE DOCUMENTATION

Every finding stored in an immutable audit trail. Documentation you can present to regulators, your board, or external auditors.

Three Weeks. One Methodology.
Defensible Results.

1

SCOPE & INGESTION

We identify your AI systems in scope — chatbots, decision engines, AI-generated communications. Content and metadata are ingested and normalized.

No internal system access required.

2

ANALYSIS & VALIDATION

Every AI system is evaluated across all 7 dimensions using our peer-reviewed methodology. Senior analysts validate findings to ensure accuracy and eliminate false positives.

3

REPORTING & ROADMAP

You receive an executive-grade report: dimension scores, regulatory gap analysis, and a prioritized remediation roadmap. All findings stored in an immutable audit trail.

Board-ready. Regulator-ready.

Methodology

Built on Published Research.
Not Vendor Claims.

The 7-dimension framework used in every OneCheck audit was developed by PhD researchers in AI ethics, bias detection, and regulatory compliance. It is validated through peer-reviewed publications — not vendor whitepapers.

When your report references a compliance gap in Factuality & Accuracy or flags a risk in Discrimination & Fairness, the methodology behind that finding has been published, reviewed, and validated by the research community.

This is the difference between a vendor opinion and defensible evidence.

Built for the People Who Own the Risk.

FOR THE CRO

A quantified risk baseline across your AI portfolio. The numbers your board needs. The evidence your regulator will ask for.

FOR THE DPO

A compliance assessment that maps your AI systems to EU AI Act and GDPR requirements in a single view. Audit-ready evidence.

FOR THE CISO

A robustness assessment covering adversarial resilience, prompt injection, and jailbreak resistance across your AI systems. No production access required.

FOR THE BOARD

A clear answer to "What is our AI risk posture?" Delivered as an executive-grade report in 3 weeks. One AI incident costs $2.3M on average. Knowing your risk is cheaper.

Proven in Production.

“Deployed with a Fortune 500 financial services organization managing 100+ AI systems. $265K first-year engagement. Live in production and preventing compliance incidents.”

SOC 2 ControlsEU AI Act AlignedGDPR CompliantEncrypted End-to-End

Start with Clarity.
Scale with Confidence.

OneCheck gives you a compliance baseline. When you’re ready for continuous monitoring, real-time alerting, and an immutable audit trail across every AI system in your organization, the Enterprise platform picks up exactly where OneCheck left off.

Every finding, every score, every recommendation from your OneCheck audit transfers directly into Enterprise. No repeated work. No lost context.

Your AI Systems Are Already Deployed.
Your Compliance Baseline Shouldn’t Wait.

A complete AI compliance audit in 3 weeks. 7 dimensions. EU AI Act mapping. Defensible documentation.

View Sample Report

Questions

How quickly can we see results?

OneCheck delivers a complete audit in 3 weeks. Week 1 covers scope and ingestion, Week 2 is analysis and expert validation, Week 3 delivers your executive report with a prioritized remediation roadmap.

What AI systems can OneCheck audit?

Any AI system generating communications or decisions — chatbots, content generation engines, recommendation systems, automated decision tools. We work with public-facing content and can ingest through API, URL, or document export.

What does the report include?

A 7-dimension scorecard for every system in scope, an EU AI Act gap analysis mapped to Articles 9–15, real-world examples of flagged content with full traceability, and a prioritized remediation roadmap ranked by risk severity. All findings are stored in an immutable audit trail.

Do we need to involve our IT team?

For most OneCheck audits, no internal system access is required. We work with public content, document exports, and API endpoints. If deeper integration is needed, we scope that during Week 1.

How is this different from a generic compliance audit?

Generic compliance tools weren’t built for AI-specific risks — hallucinations, bias drift, adversarial attacks, factuality failures. OneCheck uses a 7-dimension framework developed by PhD researchers and validated through peer-reviewed publications. Every finding is traceable to a specific dimension and mapped to regulatory requirements.

What happens after the audit?

You receive your report and can act on the recommendations immediately. If you want continuous monitoring, the Enterprise platform picks up where OneCheck left off — every finding transfers directly, no repeated work.