Methodology

Standards-based approach to AI ethics governance and policy coherence. From contextual analysis to implementation oversight.

Implementation Process

From initial assessment to periodic reassessment through a structured methodology

Authentication

Institutional access credentials

System Specification

AI system context and parameters

Standards Assessment

Benchmark evaluation mapped to ten anchor frameworks

Policy Guidance

Detailed assessment with recommendations

Periodic Reassessment

Re-run evaluations as systems change

Authentication

Step 1 of 5

Secure API authentication for government and organizational deployment with institutional-grade security protocols.

Visual Workflow Process

What happens between submitting a model and receiving its results

1

Model Submission

Register a text-generating model by Hugging Face model ID or API endpoint. No access to model weights or training data is needed.

  • Chat and completion models
  • OpenAI-compatible endpoints
  • Custom REST endpoints
  • Encrypted endpoint credentials
2

Benchmark Evaluation

The model is tested against published bias benchmarks and harmful-output safety tests.

  • WinoBias
  • StereoSet
  • CrowS-Pairs
  • BOLD
3

Scoring

Each test produces a score on a 0–100 scale (higher is better) with a bootstrap confidence interval.

  • Canonical 0–100 scale
  • Confidence intervals
  • Measurement basis per result
  • Tamper-evident record
4

Framework Mapping

Results are mapped to 40 provision-level requirements across ten anchor frameworks, with recommendations.

  • Pass or fail per requirement
  • Prioritized recommendations
  • Compliance certificate
  • Estimated environmental impact

The Six Assessment Dimensions

Our research maps every analysed provision onto these six dimensions. Dimension-level scoring is part of the use-case assessment, now in development.

Data Governance

Data quality, provenance, privacy, and management practices

Transparency

Explainability, documentation, and disclosure of AI involvement

Human Oversight

Human-in-the-loop controls, decision authority, and escalation

Security

Cybersecurity, safety, and robustness of the system

Digital Inclusion

Accessibility, non-discrimination, and equitable access

Right to Liberty

Individual autonomy and protection from harmful impacts

Regulatory Mapping Coverage

A sample of the 40 mapped requirements, from four of the ten anchor frameworks

EU AI Act

Art. 9, 10, 13, 15 · Annex III

GDPR

Art. 5(1)(a), 22, 35

NIST AI RMF

MEASURE 2.1–2.3

OECD AI Principles

Principles 1.1–1.4

What can be assessed

The bias and safety tests score the text a model writes in response to a prompt. That makes text generation the requirement: a model that produces no text has nothing to score.

Supported

Chat and completion models

Chat and instruction models that answer a prompt in their own words — Llama, Mistral, Gemma, Qwen and the like.

Your own API endpoint

Any endpoint that returns generated text: OpenAI-compatible chat or completion APIs, or a custom REST endpoint. Credentials are encrypted.

Not supported

Models that fill in blanks

BERT, RoBERTa and similar models fill in blanks in text rather than writing a response.

Models that sort text into categories

These return labels and scores, not text.

Models that turn text into numbers

Used for search and matching, these return numbers rather than text.

Models that only rework text you supply

Question answering from a passage, summarising and translating all work on text you provide rather than answering an open question.

Vision, audio, multimodal and tabular models

These do not read or write text at all.

Hugging Face models are run by third-party inference providers, and not every model on the Hub has one. A model that no provider currently serves cannot be called, so it is refused with that reason rather than assessed. Models served through your own API endpoint are unaffected.

Submitting a model we cannot assess returns an error explaining why, naming the model's task and what is supported instead. We would rather refuse than report a score that measured nothing.

Technical Architecture

How an assessment is produced, end to end

System Components

API Layer

REST + JSON

Authenticated REST API with rate limiting for submitting models and retrieving results

FastAPIJWT & API keysRate limiting

Evaluation Engine

4 published benchmarks

Runs published bias and safety benchmarks against your model's outputs

WinoBiasStereoSetCrowS-PairsBOLD

Framework Mappings

40 requirements

Provision-level requirements from ten anchor frameworks, each result tagged with its measurement basis

EU AI ActGDPRNIST AI RMFOECD

Integrity Layer

Tamper-evident

Stored endpoint credentials are encrypted; audit results carry a hash that can be re-verified

Encrypted credentialsTLSSHA-256

Request Processing Flow

1
Submit
Hugging Face model ID or API endpoint
2
Validation
Input validation and connectivity check
3
Evaluation
Bias and safety benchmarks run against the model
4
Scoring
0–100 scores with confidence intervals
5
Mapping
Results mapped to framework requirements

Scoring Engine

Scoring Methodology

  • 1The model is queried with prompts from published bias and safety benchmarks
  • 2Each test produces a canonical score on a 0–100 scale (higher is better) with a bootstrap confidence interval
  • 3Results are mapped to provision-level requirements, each labelled with its measurement basis (direct, derived, proxy, or not measured)
  • 4Recommendations are generated from the findings and prioritized by severity

Technical Specifications

Coverage
4 published benchmarks · 10 anchor frameworks · 40 provision-level requirements
Models
Text (NLP) models via Hugging Face or an OpenAI-compatible / custom REST endpoint
Integrity
Every completed audit stores a hash of its results that can be re-verified later