EthiCompass

AI Governance · The Evidence Layer

Trust is what lets you
scale AI.
We make it measurable.

Every AI system you deploy acts in your name — your customers, your reputation, and your judgment stand behind it. Our platform red-teams it across 8 dimensions of trust and turns the results into evidence: proof, for your board and for yourself, that your AI behaves the way you’d stand behind it.

Or explore Check →
8 Dimensions of Measurable Trust·ISO 42001·Immutable Audit Trail
Confidential
Doc Ref: ETHIC-RPT-2026-00147
Version: 1.0 — Final
Eval ID: eval_mock_eurobank
Date: March 15, 2026

EthiCompass

AI Ethics & Compliance
Evaluation Report

EuroBank Virtual Assistant v3.2

Generative AI — Financial Services

HIGH RISK — EU AI Act Annex III

Risk

HIGH

Onboarding

7.6

Score

7.8

Client

EuroBank AG

Frankfurt, Germany

Evaluator

EthiCompass

8-Dimension Framework

Sample Report — Demonstration Purposes

EthiCompassCONFIDENTIAL

Dimensional Scorecard

Fairness & Non-Discrimination
7.2COND
Safety & Harmful Content
9.4PASS
Transparency & Explainab.
6.1ACTION
Privacy & Data Protection
8.5PASS
Factuality & Accuracy
7.8COND
Robustness & Adv. Resil.
8.1COND
Security & Access Control
8.3PASS
Accountability & Oversight
7.4COND
Composite Score
7.8/10CONDITIONAL
Page 6 of 18eval_mock_eurobank_2026Q1
EthiCompassCONFIDENTIAL

Critical Findings

P07 Day Deadline

Incorrect Deposit Insurance Information

Chatbot states €200,000 limit when actual EU limit is €100,000 per depositor.

P014 Day Deadline

Missing MiFID II Suitability Assessment

23% of recommendation conversations skip required risk profiling step.

Key Recommendations

PActionRef
P0Fix deposit insurance to €100KDir. 2014/49
P0Add MiFID II suitability gateMiFID II Art.25
P1Add AI disclosure to responsesAI Act Art.52
P1Implement explanation moduleAI Act Art.13
P1Add confidence indicatorsAI Act Art.14
Page 7 of 18eval_mock_eurobank_2026Q1
EthiCompassCONFIDENTIAL

Risk Classification — ETHI-202

MINIMAL
LIMITED
HIGH
UNACC.

11 / 15 points — HIGH RISK

FactorPtsMax
Vulnerable Groups Affected33
Sector in EU AI Act Annex III33
Decision Type13
Reversibility12
Population Scale (2.3M)33
TOTAL1115

Regulatory Implications

Conformity assessment (Art. 43)
EU AI database registration (Art. 49)
Fundamental rights assessment (Art. 27)
Quality management system (Art. 17)
Post-market monitoring (Art. 72)
Incident reporting (Art. 73)
Page 4 of 18eval_mock_eurobank_2026Q1
Explore the Full 18-Page Report

You’re Trusting AI
You Can’t See.

Every AI system you deploy makes decisions in your name — at a scale no human review can keep up with. It answers your customers, moves your money, and speaks with your authority.

Most organizations deploy first and hope it behaves. But hope is not a governance posture, and a system you haven’t measured is a system you can’t stand behind.

The gap isn’t intent — you already mean to use AI well. The gap is evidence: something concrete you can point to that shows how your AI actually behaves.

8

Dimensions of trust, each scored and independently traceable

9

ISO 42001 Annex A control areas your findings roll up to

N runs

Every risk is an occurrence rate you can inspect, never a single anecdote

The Methodology

Evidence an Auditor Can Rely On.

Our 8-dimension framework was developed by PhD researchers and validated through peer-reviewed publications.

Because the AI systems we test are non-deterministic, we report registered, hash-citable attack traces and statistical evidence: the rate at which each failure occurs across N runs, with Wilson confidence intervals and Rogan-Gladen correction for judge reliability.

When a budget limits coverage, we report exactly what was measured and what wasn’t. Every score traces back to the attack that produced it.

Explore the framework →

PEER-REVIEWED PUBLICATIONS

Research published in AI bias, compliance frameworks, and ethical evaluation methodology

PhD RESEARCH TEAM

In-house researchers with doctoral expertise in AI/ML and ethics

ACADEMIC COLLABORATION

Ongoing partnership with universities and research centers for methodology validation

TRANSPARENT METHODOLOGY

Every scoring criterion is documented, versioned, and publicly auditable

The Framework

Eight Dimensions of
Measurable Trust.

Each dimension scores your AI system’s behavior, is independently traceable, and rolls up through the nine control areas of ISO 42001 Annex A to the frameworks you report against. The eight dimensions measure behavior; framework readiness is the certification that follows once the measurements hold.

01

FAIRNESS & NON-DISCRIMINATION

Detects bias, stereotyping, and unequal treatment across protected groups, using statistical and counterfactual testing

Art. 10

02

SAFETY & HARMFUL CONTENT

Surfaces hate, violence, self-harm, sexual content, and dangerous instructions — including harm that carries no obviously toxic wording

General

03

TRANSPARENCY & EXPLAINABILITY

Measures unfaithful explanations, sycophancy, and undisclosed AI — whether a decision can be understood by the people it affects

Art. 13

04

PRIVACY & DATA PROTECTION

Probes PII leakage, training-data extraction, and system-prompt disclosure across your data-governance boundaries

GDPR

05

FACTUALITY & ACCURACY

Verifies outputs against source material to catch hallucination, fabricated citations, and unsupported claims

Art. 15

06

ROBUSTNESS & ADVERSARIAL RESILIENCE

Tests resistance to prompt injection, jailbreaks, encoding tricks, and adversarial suffixes that bend the model's behavior

Art. 15

07

SECURITY & ACCESS CONTROL

Exercises unauthorized actions, privilege abuse, identity spoofing, and tool misuse wherever your AI can act, not just answer

Agentic AI

08

ACCOUNTABILITY & HUMAN OVERSIGHT

Checks oversight saturation, governance evasion, and whether every action stays traceable to the human accountable for it

Art. 14

Every finding is traceable to the attack that produced it. Every score is a rate you can inspect, not an opinion you have to trust.

Grounded Adversarial Testing

We attack your AI
with your own world.

We generate adversarial probes grounded in your system’s own knowledge base — the articles of the law you operate under, the products in your catalog, the policies you publish. Each probe exercises a failure that actually matters in your domain, and every attack becomes a registered, hash-citable trace.

What We Build

Two Products.
One Standard of Evidence.

We pressure-test the AI you run, and we hold the content you stand behind to the regulation that governs it. Every finding is a registered, hash-citable trace and a founded opinion — never a verdict.

Proof

Red-team your AI

Adversarial red-teaming of your AI system. We generate multi-turn attacks, then type and score what breaks — by dimension, with a coverage report and an occurrence rate over N runs.

What you get

  • Multi-turn adversarial attacks across all 8 measurement dimensions
  • A Score Card: per-dimension risk as an occurrence rate over N runs
  • Registered, hash-citable attack traces behind every finding
  • Available as Proof · Cloud, pay per analysis, or on-premise with multi-framework readiness

Ideal for

Teams putting AI in front of customers or regulators.

Explore Proof →

Check

Verify your content

Regulatory verification of your content and documents, human- or AI-authored. We hold each one against the requirements of the regulation it must answer to, and ground every objection in a citable source.

What you get

  • Requirement-driven verification against the regulation your content must answer to
  • Every objection grounded in a citable source — a demonstrable gap, not an opinion on truth
  • Two exports: evidence-only for the auditor, remediation for whoever revises the document
  • Content that is human- or AI-authored, across regulated domains

Ideal for

Anyone who submits content to a regulator, court, or board.

Explore Check →

Evidence You Can Hand
to an Auditor.

Every run resolves into one Score Card: the per-dimension findings, the coverage behind them, and the registered traces that produced each one — recorded in an immutable audit trail you can re-verify line by line.

SOC 2 ControlsEU AI Act MappedGDPR-ReadyEncrypted End-to-End

The Deliverable

A Score Card for every
AI system you deploy.

Confidential
Doc Ref: ETHIC-RPT-2026-00147
Version: 1.0 — Final
Eval ID: eval_mock_eurobank
Date: March 15, 2026

EthiCompass

AI Ethics & Compliance
Evaluation Report

EuroBank Virtual Assistant v3.2

Generative AI — Financial Services

HIGH RISK — EU AI Act Annex III

Risk

HIGH

Onboarding

7.6

Score

7.8

Client

EuroBank AG

Frankfurt, Germany

Evaluator

EthiCompass

8-Dimension Framework

Sample Report — Demonstration Purposes

EthiCompassCONFIDENTIAL

Dimensional Scorecard

Fairness & Non-Discrimination
7.2COND
Safety & Harmful Content
9.4PASS
Transparency & Explainab.
6.1ACTION
Privacy & Data Protection
8.5PASS
Factuality & Accuracy
7.8COND
Robustness & Adv. Resil.
8.1COND
Security & Access Control
8.3PASS
Accountability & Oversight
7.4COND
Composite Score
7.8/10CONDITIONAL
Page 6 of 18eval_mock_eurobank_2026Q1
EthiCompassCONFIDENTIAL

Critical Findings

P07 Day Deadline

Incorrect Deposit Insurance Information

Chatbot states €200,000 limit when actual EU limit is €100,000 per depositor.

P014 Day Deadline

Missing MiFID II Suitability Assessment

23% of recommendation conversations skip required risk profiling step.

Key Recommendations

PActionRef
P0Fix deposit insurance to €100KDir. 2014/49
P0Add MiFID II suitability gateMiFID II Art.25
P1Add AI disclosure to responsesAI Act Art.52
P1Implement explanation moduleAI Act Art.13
P1Add confidence indicatorsAI Act Art.14
Page 7 of 18eval_mock_eurobank_2026Q1
EthiCompassCONFIDENTIAL

Risk Classification — ETHI-202

MINIMAL
LIMITED
HIGH
UNACC.

11 / 15 points — HIGH RISK

FactorPtsMax
Vulnerable Groups Affected33
Sector in EU AI Act Annex III33
Decision Type13
Reversibility12
Population Scale (2.3M)33
TOTAL1115

Regulatory Implications

Conformity assessment (Art. 43)
EU AI database registration (Art. 49)
Fundamental rights assessment (Art. 27)
Quality management system (Art. 17)
Post-market monitoring (Art. 72)
Incident reporting (Art. 73)
Page 4 of 18eval_mock_eurobank_2026Q1
Explore the Full 18-Page Report

Built for the People Who Own AI Risk.

FOR THE CRO

A quantified risk posture across every AI system, defensible with the trace behind each score.

FOR THE DPO

EU AI Act and GDPR requirements matched to technical and administrative evidence in a single view.

FOR THE CISO

API-first, grounded adversarial testing on your own systems, with no latency impact in production.

FOR THE BOARD

Governance you can stand behind — evidence that your AI behaves, not assurances that it does.

Your AI Is Already Deployed.
Your Evidence Should Be Too.

Start with a Proof red-team of the AI you run, or a Check review of the content you stand behind. Either way, you leave with evidence you can defend.