Why self-assessment does not clear the bar
IEEE 1012-2024 separates technical, managerial and financial independence. Platform-native evaluation fails all three: built by the team that built the agent, reporting to the executive who owns its adoption, and sold by a vendor paid on consumption. That is the same argument your external auditors make about internal controls, applied to AI.
What lands on the committee’s desk
- A signed assurance case — findings, severities, coverage and the statistics behind them, with a commitment hash pinning the exact configuration tested.
- Independent verifiability. The notary lets a third party confirm a bundle without trusting us. Rare enough that it is worth demonstrating in the meeting.
- Explicit exclusions. Anything we could not verify is counted against coverage, never reclassified as a pass. An assurance report with no exclusions should raise your eyebrow, not lower it.
- A written remedy path. The recall protocol: 4-hour hold, 24-business-hour notice, 5-business-day RCA.
Regulatory position
Evidence maps to NIST AI 100-1, NIST AI 600-1 and TEVV, ISO/IEC 42001 and IEEE 1012-2024. On the EU AI Act: Regulation (EU) 2026/1744 deferred Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028; Article 50 transparency obligations remain live from 2 August 2026. claim: external verification required Vendors still selling urgency against the lapsed August 2026 date are worth discounting on that basis alone. Full mapping.
What this is not
Not statutory certification, not a compliance determination, not a badge. We produce technical evidence; your counsel makes the determination. Any vendor offering you the determination itself is selling something they cannot deliver. Why there is no badge.
Questions worth asking us
How is the cut score derived? (It is not yet — here is the study design.) How often does your judge agree with a human? (Method published; figures pending.) Where does the method fail? (Nine ways, listed.) Ask our competitors the same three.