Assessment services

The assessment is the product.

A named assessor evaluates the scoped environment and evidence, documents what was found and what could not be established, and signs the final assessment.

Software may support the work. Accountability remains with the person who performs and signs the assessment.

01

Evidence-led

Findings trace to the documentation, interviews, configurations, observations, or other evidence included in scope.

02

Explicit limitations

The report distinguishes observed, supplied, represented, not-tested, and not-assessed conditions.

03

Named sign-off

The customer and reviewer can see who evaluated the evidence and formed the conclusion.

Assessment scope

Built around the environment—not a generic checklist.

SystemsAI products, models, providers, integrations, workflows, owners

InformationSensitive data categories, sources, destinations, retention, processing

ProceduresDocuments, interviews, configuration review, observation, demonstrations, sampling

EvidencePolicies, diagrams, contracts, settings, reports, interviews, records

FindingsContext, severity, evidence references, limitations, recommendations

MappingsRelevant HIPAA Security Rule safeguards and NIST AI RMF concepts

Procedure menu

The written scope says what was actually done.

Not every procedure appears in every engagement. The report identifies the procedures performed, evidence relied upon, and untested areas.

01

Document review

Policies, diagrams, contracts, reports, inventories, and other supplied records.

02

Stakeholder interviews

Statements from system, security, privacy, product, or governance owners.

03

Configuration inspection

Read-only review of selected in-scope settings or exports when authorized.

04

Observation

A demonstration or walkthrough observed by the assessor.

05

Sampling

A defined sample of records, systems, or events rather than full-population testing.

06

Technical testing

Performed only when separately scoped; not implied by a standard assessment.

Engagement lifecycle

From scope to a point-in-time signed report.

  1. 01

    Scope

    Confirm the review trigger, entities, systems, data pathways, procedures, intended readers, and exclusions.

  2. 02

    Plan

    Issue a written scope and an approved evidence-transfer plan before sensitive engagement material is exchanged.

  3. 03

    Review

    Evaluate the agreed documents, interviews, demonstrations, and other evidence using recorded evidence states.

  4. 04

    Readout

    Discuss material observations, missing evidence, limitations, and remediation priorities before finalization.

  5. 05

    Report

    Deliver the point-in-time assessment with evidence references, findings, mappings, limitations, and sign-off.

Unless separately scoped

Important procedures and outcomes are not implied.

Penetration testing

Source-code review

Model-performance evaluation

AI safety or red-team testing

Continuous monitoring

Legal opinion or compliance attestation

Procurement or insurer acceptance

Testing of every system or record

Service levels

Three ways to structure the engagement.

FOCUSED ASSESSMENT

A bounded AI system, workflow, customer review, or evidence question.

Targeted scope, evidence review, findings, limitations, and named-assessor sign-off.

Starting at $6,500
COMPREHENSIVE ASSESSMENT

Multiple systems, data flows, stakeholders, or a broader evidence package.

Expanded evidence review, system and data-flow records, risk prioritization, and relevant mappings.

Starting at $15,000
ENTERPRISE PROGRAM

Multiple entities, recurring assessments, or complex evidence requirements.

Program-level scoping, defined cadence, tailored evidence requirements, and multiple assessment records.

Custom scope

Next step

Have a healthcare security review coming up?

Use a 20-minute scoping call to clarify what the reviewer is asking for, what belongs in scope, and whether an independent Ayliea assessment is a fit.

  • Clarify the review request
  • Identify systems and evidence
  • Define a defensible scope