Skip to main content

How it works

Five steps from AI system to assurance report

A disciplined assessment lifecycle. Each stage produces a durable artefact, and each artefact feeds the next, so the conclusion at the end can be traced back to the observation at the start.

The five assessment stages

  1. 01

    Connect AI System

    Give Entercept scoped, read-only access to the model, its interfaces and the documentation describing its intended purpose. Nothing in your environment is changed.

    OutputScoped system profile

  2. 02

    Identify Applicable Regulations

    The system is classified against the regimes that actually apply to it, covering EU AI Act risk tier, UK GDPR automated decision-making duties and sector rules, so the assessment tests the right controls.

    OutputRegulatory scope statement

  3. 03

    Run Independent Assessment

    Detectors probe behaviour under defined and adversarial conditions: accuracy, robustness, bias, explainability, oversight and data governance. We observe the system rather than accept its description.

    OutputAssessment run record

  4. 04

    Generate Evidence

    Every observation is captured with its inputs, method version and result, then hashed and written to an append-only log. Findings can be traced back to the evidence that produced them.

    OutputVerifiable evidence set

  5. 05

    Produce AI Assurance Report

    Findings, regulatory mapping and remediation actions are compiled into a sealed, tamper-evident report written for auditors, regulators, boards and customers alike.

    OutputSealed assurance report

Access and scope

What an assessment asks of you

Engagements are deliberately light on your engineering team. The work happens on our side of the boundary.

What we need

Scoped, read-only access to the system under assessment and the documentation describing its intended purpose. Access is minimised to what the agreed scope requires.

What we change

Nothing. Assessments observe the system as deployed. Where a live system cannot safely be exercised, we agree a representative environment in advance.

What gets recorded

The access granted, the sampling applied and every operator action, all written to the audit trail alongside the assessment results.

Assessed against the frameworks your regulators, auditors and customers already use.

  • UK GDPR
  • EU AI Act
  • DUAA 2025
  • ISO/IEC 42001
  • NIST AI RMF
  • DPA 2018
ENTERCEPTAI

Ready to see Entercept in action?

See how independent, evidence-backed assurance works on a real high-risk AI system, then get an audit-ready report your regulators, board and customers can rely on.