Document review
Policies, diagrams, contracts, reports, inventories, and other supplied records.
Assessment services
A named assessor evaluates the scoped environment and evidence, documents what was found and what could not be established, and signs the final assessment.
Software may support the work. Accountability remains with the person who performs and signs the assessment.
Findings trace to the documentation, interviews, configurations, observations, or other evidence included in scope.
The report distinguishes observed, supplied, represented, not-tested, and not-assessed conditions.
The customer and reviewer can see who evaluated the evidence and formed the conclusion.
Assessment scope
SystemsAI products, models, providers, integrations, workflows, owners
InformationSensitive data categories, sources, destinations, retention, processing
ProceduresDocuments, interviews, configuration review, observation, demonstrations, sampling
EvidencePolicies, diagrams, contracts, settings, reports, interviews, records
FindingsContext, severity, evidence references, limitations, recommendations
MappingsRelevant HIPAA Security Rule safeguards and NIST AI RMF concepts
Procedure menu
Not every procedure appears in every engagement. The report identifies the procedures performed, evidence relied upon, and untested areas.
Policies, diagrams, contracts, reports, inventories, and other supplied records.
Statements from system, security, privacy, product, or governance owners.
Read-only review of selected in-scope settings or exports when authorized.
A demonstration or walkthrough observed by the assessor.
A defined sample of records, systems, or events rather than full-population testing.
Performed only when separately scoped; not implied by a standard assessment.
Engagement lifecycle
Confirm the review trigger, entities, systems, data pathways, procedures, intended readers, and exclusions.
Issue a written scope and an approved evidence-transfer plan before sensitive engagement material is exchanged.
Evaluate the agreed documents, interviews, demonstrations, and other evidence using recorded evidence states.
Discuss material observations, missing evidence, limitations, and remediation priorities before finalization.
Deliver the point-in-time assessment with evidence references, findings, mappings, limitations, and sign-off.
Unless separately scoped
— Penetration testing
— Source-code review
— Model-performance evaluation
— AI safety or red-team testing
— Continuous monitoring
— Legal opinion or compliance attestation
— Procurement or insurer acceptance
— Testing of every system or record
Service levels
Targeted scope, evidence review, findings, limitations, and named-assessor sign-off.
Starting at $6,500Expanded evidence review, system and data-flow records, risk prioritization, and relevant mappings.
Starting at $15,000Program-level scoping, defined cadence, tailored evidence requirements, and multiple assessment records.
Custom scopeNext step
Use a 20-minute scoping call to clarify what the reviewer is asking for, what belongs in scope, and whether an independent Ayliea assessment is a fit.