Skip to main content

The platform

What runs the assessment

Five components carry an assessment end to end. Each has one responsibility and one output, and evidence only ever flows forward.

Platform components

Assessment engine

Orchestrates the run, fixes the scope

The engine resolves what is being assessed, classifies it against the regimes that apply, then schedules and controls the run. Scope is locked before testing begins, so results cannot be quietly renegotiated afterwards.

  • Intended purpose, deployment context and risk tier captured as structured scope
  • Method versions pinned for the lifetime of the run
  • Deterministic replay where the system under test permits it
  • Run state, timings and operator actions recorded as they happen

Detector framework

Probes behaviour, not documentation

Detectors are grouped into families that correspond to regulatory concerns. Each states what it measures, how it measures it and where its limits are, so a flag can be argued about on the merits.

  • Families for bias and fairness, robustness, explainability, data governance and human oversight
  • Defined-condition and adversarial probes run against the live system
  • Every detector declares its method, thresholds and known limitations
  • Extensible for sector-specific and bespoke obligations

Evidence pipeline

Turns observations into evidence

A result is only useful if you can show where it came from. The pipeline captures each observation with its inputs and method version, computes a digest, and commits it before any finding is written.

  • Observations captured with inputs, parameters and method version
  • Content-addressed digests computed at capture time
  • Immutable commit before any interpretation takes place
  • Findings reference evidence by digest, never by description

Audit trail

An append-only record of everything

Every event in an assessment, from scope changes to reviewer decisions and report issuance, is written to an append-only log. Entries can be added but never rewritten, and the chain is verifiable after the fact.

  • Chronological, append-only event log per assessment
  • Chain of custody from raw observation to published finding
  • Reviewer actions and overrides recorded with rationale
  • Independently verifiable long after the report is issued

Regulatory mapping

Findings tied to the obligations that matter

Results are mapped clause by clause to the regimes in scope. Instead of a generic risk score, you get a statement about a specific obligation, backed by specific evidence.

  • UK GDPR automated decision-making duties, as amended by the DUAA 2025
  • EU AI Act obligations by risk tier, including Annex III classifications
  • ISO/IEC 42001 and ISO/IEC 23894 control alignment
  • Sector overlays for financial services, healthcare and public bodies

Architecture

How an AI system becomes an assurance report

Each layer has one responsibility and one output. Evidence only ever flows forward, and every layer is independently inspectable.

  1. Your AI systems

    Subject of assessment

    • Models
    • Agents & pipelines
    • Inference APIs
    • Technical documentation
  2. Scoped ingress

    Read-only, permissioned access

    • Connectors
    • Sampling controls
    • Scope lock
    • Data minimisation
  3. Assessment engine

    Orchestration & run control

    • Scope resolution
    • Regulatory classification
    • Run scheduling
    • Method versioning
  4. Detector framework

    Behavioural & adversarial probes

    • Bias & fairness
    • Robustness
    • Explainability
    • Data governance
    • Human oversight
  5. Evidence pipeline

    Capture, version, hash

    • Observation capture
    • Input records
    • Digest computation
    • Immutable commit
  6. Audit trail

    Append-only record

    • Event log
    • Chain of custody
    • Reviewer actions
    • Integrity proofs
  7. AI Assurance Report

    Sealed, verifiable output

    • Regulatory mapping
    • Findings
    • Evidence references
    • Remediation plan
ENTERCEPTAI

Ready to see Entercept in action?

See how independent, evidence-backed assurance works on a real high-risk AI system, then get an audit-ready report your regulators, board and customers can rely on.