EthiCompass

AI Governance · The Evidence Layer

Trust is what lets you
scale AI.
We make it measurable.

Every AI system you deploy acts in your name — your customers, your reputation, and your judgment stand behind it. Our platform red-teams it across 8 dimensions of trust and turns the results into evidence: proof, for your board and for yourself, that your AI behaves the way you’d stand behind it.

8 Dimensions of Measurable Trust·ISO 42001·Immutable Audit Trail
Confidential
Doc Ref: ETHIC-RPT-2026-00147
Version: 1.0 — Final
Eval ID: eval_mock_eurobank
Date: March 15, 2026

EthiCompass

AI Ethics & Compliance
Evaluation Report

EuroBank Virtual Assistant v3.2

Generative AI — Financial Services

HIGH RISK — EU AI Act Annex III

Risk

HIGH

Intake

7.6

Score

7.8

Client

EuroBank AG

Frankfurt, Germany

Evaluator

EthiCompass

7-Dimension Framework

Sample Report — Demonstration Purposes

EthiCompassCONFIDENTIAL

Dimensional Scorecard

Discrimination & Fairness
7.2COND
Toxicity & Harmful Lang.
9.4PASS
Explainability & Transp.
6.1ACTION
Privacy & Data Protection
8.5PASS
Factuality & Accuracy
7.8COND
Robustness & Resilience
8.1COND
Regulatory Compliance
7.5COND
Composite Score
7.8/10CONDITIONAL
Page 6 of 17eval_mock_eurobank_2026Q1
EthiCompassCONFIDENTIAL

Critical Findings

P07 Day Deadline

Incorrect Deposit Insurance Information

Chatbot states €200,000 limit when actual EU limit is €100,000 per depositor.

P014 Day Deadline

Missing MiFID II Suitability Assessment

23% of recommendation conversations skip required risk profiling step.

Key Recommendations

PActionRef
P0Fix deposit insurance to €100KDir. 2014/49
P0Add MiFID II suitability gateMiFID II Art.25
P1Add AI disclosure to responsesAI Act Art.52
P1Implement explanation moduleAI Act Art.13
P1Add confidence indicatorsAI Act Art.14
Page 7 of 17eval_mock_eurobank_2026Q1
EthiCompassCONFIDENTIAL

Risk Classification — ETHI-202

MINIMAL
LIMITED
HIGH
UNACC.

11 / 15 points — HIGH RISK

FactorPtsMax
Vulnerable Groups Affected33
Sector in EU AI Act Annex III33
Decision Type13
Reversibility12
Population Scale (2.3M)33
TOTAL1115

Regulatory Implications

Conformity assessment (Art. 43)
EU AI database registration (Art. 49)
Fundamental rights assessment (Art. 27)
Quality management system (Art. 17)
Post-market monitoring (Art. 72)
Incident reporting (Art. 73)
Page 4 of 17eval_mock_eurobank_2026Q1
Explore the Full 17-Page Report

You’re Trusting AI
You Can’t See.

Every AI system you deploy makes decisions in your name — at a scale no human review can keep up with. It answers your customers, moves your money, and speaks with your authority.

Most organizations deploy first and hope it behaves. But hope is not a governance posture, and a system you haven’t measured is a system you can’t stand behind.

The gap isn’t intent — you already mean to use AI well. The gap is evidence: something concrete you can point to that shows how your AI actually behaves.

73%

Of enterprises deploying AI have no formal governance framework

$2.3M

Average cost when an AI failure reaches production

3 wks → sec

Time to surface a failure: manual review vs. a red-team run

The Methodology

Evidence an Auditor Can Rely On.

Our 8-dimension framework was developed by PhD researchers and validated through peer-reviewed publications.

Because the AI systems we test are non-deterministic, we report registered, hash-citable attack traces and statistical evidence: the rate at which each failure occurs across N runs, with Wilson confidence intervals and Rogan-Gladen correction for judge reliability.

When a budget limits coverage, we report exactly what was measured and what wasn’t. Every score traces back to the attack that produced it.

Explore the framework →

PEER-REVIEWED PUBLICATIONS

Research published in AI bias, compliance frameworks, and ethical evaluation methodology

PhD RESEARCH TEAM

In-house researchers with doctoral expertise in AI/ML and ethics

ACADEMIC COLLABORATION

Ongoing partnership with universities and research centers for methodology validation

TRANSPARENT METHODOLOGY

Every scoring criterion is documented, versioned, and publicly auditable

The Framework

Eight Dimensions of
Measurable Trust.

Each dimension scores your AI system’s behavior, is independently traceable, and rolls up through the nine control areas of ISO 42001 Annex A to the frameworks you report against. The eight dimensions measure behavior; regulatory compliance is the certification that follows once the measurements hold.

01

FAIRNESS & NON-DISCRIMINATION

Detects bias, stereotyping, and unequal treatment across protected groups, using statistical and counterfactual testing

Art. 10

02

SAFETY & HARMFUL CONTENT

Surfaces hate, violence, self-harm, sexual content, and dangerous instructions — including harm that carries no obviously toxic wording

General

03

TRANSPARENCY & EXPLAINABILITY

Measures unfaithful explanations, sycophancy, and undisclosed AI — whether a decision can be understood by the people it affects

Art. 13

04

PRIVACY & DATA PROTECTION

Probes PII leakage, training-data extraction, and system-prompt disclosure across your data-governance boundaries

GDPR

05

FACTUALITY & ACCURACY

Verifies outputs against source material to catch hallucination, fabricated citations, and unsupported claims

Art. 15

06

ROBUSTNESS & ADVERSARIAL RESILIENCE

Tests resistance to prompt injection, jailbreaks, encoding tricks, and adversarial suffixes that bend the model's behavior

Art. 15

07

SECURITY & ACCESS CONTROL

Exercises unauthorized actions, privilege abuse, identity spoofing, and tool misuse wherever your AI can act, not just answer

Agentic AI

08

ACCOUNTABILITY & HUMAN OVERSIGHT

Checks oversight saturation, governance evasion, and whether every action stays traceable to the human accountable for it

Art. 14

Every finding is traceable to the attack that produced it. Every score is a rate you can inspect, not an opinion you have to trust.

Grounded Adversarial Testing

We attack your AI
with your own world.

We generate adversarial probes grounded in your system’s own knowledge base — the articles of the law you operate under, the products in your catalog, the policies you publish. Each probe exercises a failure that actually matters in your domain, and every attack becomes a registered, hash-citable trace.

Two Ways to Start.
One Standard of Rigor.

OneCheck

Your AI, Red-Teamed

A full red-team of your AI system, scored across all 8 dimensions of trust, delivered in 3 weeks.

What you get

  • An executive Score Card with a per-dimension risk score, computed as an occurrence rate over N runs
  • Registered, hash-citable attack traces behind every finding
  • Prioritized findings with the evidence that produced them
  • Immutable audit documentation you can put in front of an auditor

Best for

Organizations that need to understand their AI risk posture before committing to a platform.

Enterprise

Full Platform

Continuous Certification

The full platform for continuous certification: technical and administrative evidence matched to every framework requirement.

Everything in OneCheck, plus

  • Framework certification readiness — ISO 42001 and EU AI Act, matched to each requirement
  • Longitudinal tracking across runs, including verified remediation — proof a fix actually worked
  • Custom grounded packs that generate attacks from your own knowledge base
  • Board-ready and auditor-ready documentation
  • API integration with your existing AI infrastructure

Best for

Organizations deploying AI at scale that need continuous compliance assurance.

Proven in Production.

75%

Reduction in compliance violations detected

100%

Audit trail coverage for all AI decisions

Seconds

Time to detect compliance drift

7+ Years

Immutable audit trail retention

“Deployed with a Fortune 500 financial services organization managing 100+ AI systems in a regulated environment. $265K first-year engagement. Live in production.”

SOC 2 ControlsEU AI Act AlignedGDPR CompliantEncrypted End-to-End

The Deliverable

A Score Card for every
AI system you deploy.

Confidential
Doc Ref: ETHIC-RPT-2026-00147
Version: 1.0 — Final
Eval ID: eval_mock_eurobank
Date: March 15, 2026

EthiCompass

AI Ethics & Compliance
Evaluation Report

EuroBank Virtual Assistant v3.2

Generative AI — Financial Services

HIGH RISK — EU AI Act Annex III

Risk

HIGH

Intake

7.6

Score

7.8

Client

EuroBank AG

Frankfurt, Germany

Evaluator

EthiCompass

7-Dimension Framework

Sample Report — Demonstration Purposes

EthiCompassCONFIDENTIAL

Dimensional Scorecard

Discrimination & Fairness
7.2COND
Toxicity & Harmful Lang.
9.4PASS
Explainability & Transp.
6.1ACTION
Privacy & Data Protection
8.5PASS
Factuality & Accuracy
7.8COND
Robustness & Resilience
8.1COND
Regulatory Compliance
7.5COND
Composite Score
7.8/10CONDITIONAL
Page 6 of 17eval_mock_eurobank_2026Q1
EthiCompassCONFIDENTIAL

Critical Findings

P07 Day Deadline

Incorrect Deposit Insurance Information

Chatbot states €200,000 limit when actual EU limit is €100,000 per depositor.

P014 Day Deadline

Missing MiFID II Suitability Assessment

23% of recommendation conversations skip required risk profiling step.

Key Recommendations

PActionRef
P0Fix deposit insurance to €100KDir. 2014/49
P0Add MiFID II suitability gateMiFID II Art.25
P1Add AI disclosure to responsesAI Act Art.52
P1Implement explanation moduleAI Act Art.13
P1Add confidence indicatorsAI Act Art.14
Page 7 of 17eval_mock_eurobank_2026Q1
EthiCompassCONFIDENTIAL

Risk Classification — ETHI-202

MINIMAL
LIMITED
HIGH
UNACC.

11 / 15 points — HIGH RISK

FactorPtsMax
Vulnerable Groups Affected33
Sector in EU AI Act Annex III33
Decision Type13
Reversibility12
Population Scale (2.3M)33
TOTAL1115

Regulatory Implications

Conformity assessment (Art. 43)
EU AI database registration (Art. 49)
Fundamental rights assessment (Art. 27)
Quality management system (Art. 17)
Post-market monitoring (Art. 72)
Incident reporting (Art. 73)
Page 4 of 17eval_mock_eurobank_2026Q1
Explore the Full 17-Page Report

Built for the People Who Own AI Risk.

FOR THE CRO

A quantified risk posture across every AI system, defensible with the trace behind each score.

FOR THE DPO

EU AI Act and GDPR requirements matched to technical and administrative evidence in a single view.

FOR THE CISO

API-first, grounded adversarial testing on your own systems, with no latency impact in production.

FOR THE BOARD

Governance you can stand behind — evidence that your AI behaves, not assurances that it does.

Your AI Is Already Deployed.
Your Evidence Should Be Too.

Start with a OneCheck red-team to see how your AI behaves, or talk to our team about continuous certification.