 |
AI Governance, Security and Compliance Audit
As a Certified Information Systems Auditor,
Altius IT's AI Governance Audit reviews the program
around your Artificial Intelligence rather than a
single application, and whether it meets security
and compliance requirements.
Altius IT audits help ensure that your Artificial Intelligence
is trustworthy and operate in an accurate, reliable, safe, and non-discriminatory manner.
Our project scope includes a review and evaluation of:
- Policies, procedures, guidelines, and other controls that maintain
the security and privacy of your Artificial Intelligence. These include
written documents such as an Information Security Program, Annual Report on the
Status of the Information Security Program, Artificial Intelligence Policy,
Environmental Social and Governance Policy, Artificial Intelligence training materials,
written agreements with Artificial Intelligence service providers, Risk Assessment,
and other written documents appropriate to the engagement.
- Your AI systems against the requirements specified in the
White House AI Bill of Rights - Making Automated Systems Work for the American People.
- Your AI program against the requirements
of the National
Institute of Standards and Technology's
Artificial Intelligence Risk Management
Framework.
- Security controls related to your AI systems
Frameworks We Audit Against
Which of these applies depends on where you operate and what
your AI decides. The audit establishes that first, then tests
against the ones that bind you:
- EU AI Act: risk classification of each system
(prohibited, high risk, limited risk, minimal risk),
conformity assessment, technical documentation,
transparency obligations, human oversight, and
post-market monitoring
- ISO/IEC 42001, the AI management system standard, and
ISO/IEC 23894 for AI risk management
- NIST Artificial Intelligence Risk Management Framework
and its Generative AI Profile
- United States state law, including the Colorado AI Act,
California automated decision-making regulations under
CCPA/CPRA, and New York City Local Law 144 bias audits for
automated employment decision tools
- Sector rules where they apply: HIPAA for AI in
healthcare, GLBA and SR 11-7 in financial services, FERPA
in education, and FDA guidance on AI-enabled medical
devices
- The security controls around the models themselves,
including the data they were trained on, the interfaces
they expose, and the service providers behind them
AI
Audit Report
Altius IT's AI Governance Audit Report
provides specific
recommendations and detailed steps to address security
vulnerabilities and meet compliance
requirements. Our report identifies specific
"gaps" and provides instructions to
address each security or compliance issue. After delivery of our
reports, Altius IT provides three months
of free support to answer any questions
you may have. This ensures the issues
identified in the AI audit are properly mitigated or
eliminated.
Certified Auditor Letter
Let your clients and prospects know that your
AI is governed and secure. As an IT
security audit company with Certified
Information Systems Auditors, we provide you with our
Auditor Opinion
Letter stating your Artificial
Intelligence
meets security and compliance requirements.
Audit Team
Altius IT provides a certified auditor with each engagement:
- Certified Information Systems Auditor
- Experienced Project Manager
- Senior Security Engineer
Proposal
Our proposal provides you with detailed
information so you know exactly how we will
help you:
- Project scope and list of major project tasks
- Pricing options
- CV's of our audit and security team
members
- Security and compliance certification
- Why Altius IT
Client Experience
Altius IT works with a diverse number of
clients across a wide range of industries.
We help organizations of all sizes, from the
smallest mom and pop start-up to the world's
largest and most recognized names. Our
case
studies show how we have helped
organizations identify, manage, and reduce their
risks.
|