Sample report
A complete AI Assurance Report
Not an excerpt or a mock-up. This is a full 25-page assessment of a reference decision agent, produced by the same pipeline that runs a live engagement.
What you are reading
An independent assessment of a decision agent
The subject is a reference loan agent, assessed against the UK GDPR automated decision-making provisions as amended by the DUAA 2025, and the EU AI Act. The conclusion is non-compliant, and the report explains precisely why.
- Report reference
- ENT-AR-20260726-95C1F59F
- Subject
- Reference Loan Agent, version 1.0
- Profile
- Automated Decision-Making (ADM) profile
- Conclusion
- NON-COMPLIANT, 7 findings
- Length
- 25 pages
- Issued
- 26 July 2026
AI Assurance Report
Independent assessment · Automated Decision-Making (ADM) profile
7 findings · 5 critical / 1 high / 1 medium
6 decisions · 5 in scope · 5 breached
- Report reference
- ENT-AR-20260726-95C1F59F
- Subject
- Reference Loan Agent, v1.0
- Profile
- Automated Decision-Making (ADM) profile
- Issued
- 26 July 2026
- Human oversightCritical
- Representations and contestCritical
- Special category dataCritical
- Transparency to the individualHigh
- Risk assessment (DPIA)Medium
SHA-256 95c1f59f10586dee… · ED25519 · KEY DA70692152E97C1C
Report contents
What is inside
The same sections, in the same order, every time. Consistency is what makes reports comparable across systems, vendors and years.
- 01
Report identity and integrity seal
The reference, conclusion, content hash, digital signature and audit chain head. Everything needed to prove the document is the one we issued.
- 02
Document control
Version, issue date, distribution status and the boundaries the conclusions apply to.
- 03
Executive summary
The assurance opinion, the count of decisions assessed and breached, and the areas affected with their highest severity.
- 04
Material matters and priorities
The findings that change what you should do next, each tied to an obligation and a priority action.
- 05
Basis of assessment
The subject, the decision population sampled, and the in-scope gate that determines which decisions were tested.
- 06
Regulatory corpus
The exact provisions assessed against, quoted in full, each with its obligation, legal status, content hash and corpus version.
- 07
Findings in detail
Each finding with the behaviour observed, the conditions that produced it, its severity and the provision it engages.
- 08
Audit trail annex
The append-only record of the assessment, from scope lock through detector runs to issuance.
How to read it
Interpreting the findings
An assurance report is a working document, not a verdict to be filed. This is the order we recommend reading it in, and what each part is actually telling you.
Start with the conclusion, not the findings
The seal on page one states the overall opinion and the finding counts by severity. In this specimen the conclusion is non-compliant, driven by five critical gaps. That single line is what a supervisor or an enterprise buyer will read first.
Check what was in scope before you read anything else
Section 2 states the decision population and which decisions the in-scope gate excluded. Here, six decisions were assessed, five fell inside the automated decision-making provisions and one fell outside them. Conclusions apply only to what was in scope.
Read severity as a sequencing tool
Critical means a mandatory safeguard is absent, not that the system is unusable. High and medium findings matter, but the priorities table exists so remediation happens in the order that reduces regulatory exposure fastest.
Trace any finding you intend to challenge
Every finding cites the provision it engages and the evidence that produced it. If you disagree with a conclusion, that trail is where the argument happens, which is exactly what an assurance report is for.
Verify the document before you rely on it
Recompute the content hash and compare it against the value printed in the integrity seal. If they differ, the copy you hold is not the copy we issued.
Evidence and integrity
Why the report can be trusted
Three mechanisms make an Entercept report verifiable by someone who has never met us: how evidence is collected, how the document is sealed, and what the audit trail preserves.
Evidence collection
Findings reference evidence, not memory
Observations are captured at the moment they occur, together with the inputs and method version that produced them, then committed before anyone interprets them. A finding cites its evidence by digest.
- Captured with inputs, parameters and method version
- Committed to immutable storage before interpretation
- Referenced by content digest throughout the report
- Reproducible by an independent reviewer
Observation captured
detector.bias.demographic_parity
Inputs recorded
12,480 scored decisions
Method versioned
Digest computed
sha256:9c4e…b71a
Committed to log
block 84,192
Integrity verification
Anyone can check the document is unaltered
The finished report and its evidence set are hashed at issuance and those digests are printed in the integrity seal, alongside an Ed25519 signature. Verification requires nothing from Entercept, just the document and a hash function.
- Content hash printed on page one: 95c1f59f10586deed3adcc85…
- Signed with Ed25519 · key da70692152e97c1c
- Audit trail annex ENT-AA-20260726-4F1DB057 carries the chain head
- No dependency on Entercept infrastructure to verify
- Document digest
- sha256:3f9a…c1d7
- Evidence set digest
- sha256:22a7…4f9d
- Issued
- 17 April 2026, 09:19 UTC
- Issuer
- Entercept AI Ltd
- Verification
- Passed
Recompute the digest of any report you receive and compare it against the issued value. A single altered character changes the result.
Audit trail
The full history, preserved
Every event across the assessment is written to an append-only log: scope decisions, detector runs, reviewer judgements and overrides, and issuance. Entries are added, never rewritten.
- Chronological record from scoping through to issuance
- Reviewer decisions recorded with rationale
- Chain of custody from observation to published finding
- Available for inspection long after the engagement ends
| Time | Event | Digest |
|---|---|---|
| 17 Apr 09:14:02 | run.created | sha256:1f0a…8e33 |
| 17 Apr 09:14:07 | scope.locked | sha256:74bd…c012 |
| 17 Apr 09:18:19 | detector.completed | sha256:9c4e…b71a |
| 17 Apr 09:18:28 | evidence.sealed | sha256:22a7…4f9d |
| 17 Apr 09:19:03 | report.issued | sha256:3f9a…c1d7 |
FAQ
Questions we are asked
Usually by compliance officers, internal auditors and the people who will have to defend the deployment.
Something not covered here? Ask the assurance team from the contact section.
Is an Entercept report a certification?
No. Entercept issues an independent assurance report, not a certificate or a conformity marking. It states what was assessed, what was observed, how that maps to your obligations and where the limits of the assessment lie. Certification schemes for AI are still emerging, and an honest assurance opinion is more useful to a regulator than a badge.
Why does this specimen conclude non-compliant?
Because that is what the assessment found. The reference agent takes decisions with no route to meaningful human intervention, uses special category data without a lawful condition, and provides none of the three safeguard routes the provisions require. Publishing a clean specimen would misrepresent what an honest assessment looks like.
Who is the report written for?
It is written to be read by four audiences without being rewritten: your board and executive team, your internal audit and compliance functions, your enterprise customers performing due diligence, and supervisory authorities. The executive summary serves the first, and the regulatory corpus and audit trail serve the rest.
How is a report kept tamper-evident?
The finished document and its evidence set are each hashed, and those digests are printed in the integrity seal alongside an Ed25519 signature and the audit chain head. Anyone holding a copy can recompute the digest and compare it. Any alteration, however small, changes the result.
What access does Entercept need to run an assessment?
Scoped, read-only access to the system under assessment and the documentation describing its intended purpose. Access is minimised to what the agreed scope requires, sampling is controlled, and nothing in your environment is modified. The access granted is itself recorded in the audit trail.
What happens when the model changes?
Conclusions apply to the version boundaries stated in the scope. Material changes to the model, its training data, its interfaces or the regulations in scope trigger re-assessment. Assurance is a lifecycle, which is why the report records precisely what it does and does not still cover.
Can we share the report with customers and regulators?
Yes, that is what it is for. Reports are written so they can be handed to an enterprise customer's due diligence team or a supervisory authority without redacting the method. Commercially sensitive detail is confined to clearly marked annexes you control.
See a report built on your system
Bring a system in scope and we will walk you through exactly what the assessment would test, what the report would say, and how a third party would verify it.