← All posts
Frameworks··9 min read

AI Audit for Business: What It Covers and How to Run One

Search 'AI audit for business' and you get two different things: governance checklists and agency sales pages. Here is what an audit actually covers, the frameworks that shape it, and how to run one that ends in a number, not a slide deck.

A printed business checklist and report on a desk under a magnifying glass, representing an AI audit for a business
Answer

An AI audit for business is a structured review that answers two questions: where AI could recover revenue or hours, and whether the AI systems you already run are safe, accurate, and compliant. A good audit prices each gap in money before proposing any build, so the decision becomes arithmetic instead of hype.

Search for an AI audit for business and you land on two completely different kinds of page. One set is governance material: checklists for auditing a model's data, bias, and compliance. The other set is agency sales pages promising to find where AI will save you money. Both call themselves an AI audit, and an owner trying to work out what to actually buy is left guessing. This guide separates the two, shows what each one covers, and gives you a way to run either that ends in a number instead of a slide deck. We run the second kind for a living and publish our method as an audit-first AI consultancy, so the bias here is toward the practical.

What is an AI audit for a business?

An AI audit is a structured review of AI in your business against a clear standard. The word covers two jobs that get confused because they share a name.

The first job is an opportunity audit: a map of where AI could recover revenue or hours you are losing today. It looks at your calls, your manual data entry, your response times, and your reporting, then ranks the gaps by the money attached to them. This is the audit a business runs before it has built anything.

The second job is a governance audit: a review of the AI systems you already run, to check they are accurate, safe, documented, and legal. It looks at the data feeding a model, the model's behaviour, and how the system holds up in production. This is the audit a business runs after it has deployed something, especially in a regulated setting.

Most small and mid-market companies need the first. Companies already running models at scale, or operating under sector rules, need the second. Plenty need both in sequence: find the opportunity, build the system, then keep it audited. Knowing which one you are buying is the first thing a straight consultant will clarify, and the rest of this guide covers both.

Why AI audits matter

The reason an audit comes first is that most disappointment with AI is a scoping failure, not a technology failure. A business buys a tool because a competitor mentioned it, deploys it against a problem that was never measured, and cannot tell afterwards whether it worked. An audit removes that guesswork on both sides of the build.

On the opportunity side, the audit turns "we should probably do something with AI" into a ranked list with euros next to each item. On the governance side, it turns "the model seems fine" into evidence you can show a client, an insurer, or a regulator. Reference bodies like IBM in its write-up on AI audits frame the governance case the same way: an audit exists to make an AI system's behaviour legible to the people accountable for it. The opportunity audit does the mirror image, making the cost of doing nothing legible before a euro is spent on tools.

The core components of an AI audit

Whichever kind you run, the same three layers show up. Governance frameworks describe them as data, model, and deployment. An opportunity audit adds a fourth, the human process around the system, because that is where recoverable money tends to sit.

Data

Every AI system inherits the quality of the data behind it. A data review asks where the data comes from, whether you are allowed to use it, whether it is accurate and current, and whether it carries bias that will surface in outputs. For an opportunity audit, the same review often exposes the real blocker: the data needed to automate a workflow is trapped in PDFs or a system nobody can export from. Fixing the pipe usually matters more than picking the model.

Model

The model layer asks what the system does and how well it does it. For a live system, that means testing accuracy, checking for bias across groups of people, and confirming the outputs can be explained. For a planned system, it means choosing the right approach for the job, which is rarely the largest or most expensive model. What matters is fit to the task, not the brand name on the model.

Deployment

Deployment is where most systems quietly fail. This layer asks how the system behaves under real load, who monitors it, what happens when it is wrong, and how a human stays in the loop. A model that scores well in a test and has no monitoring in production is a risk wearing a demo's clothes. Any credible audit spends more time here than on the model itself.

Process

The fourth layer, specific to the opportunity audit, is the human process around the system. Counting missed calls, timing a manual task, mapping how a lead moves from web form to CRM: this is where the recoverable money usually hides, and where a first system pays for itself soonest. Our closed loop score framework is one short version of this process check you can run yourself.

The regulatory landscape

Governance audits do not happen in a vacuum. A set of real frameworks now defines what "good" looks like, and even a business running the opportunity version should know they exist. Together with the OECD AI Principles, three references do most of the work.

  • The EU AI Act, which entered into force in 2024, sorts AI systems by risk and sets obligations for the higher-risk categories. Any business operating in or selling into the EU should know which category its systems fall into. The European Commission framework page is the primary source.
  • The NIST AI Risk Management Framework, released in 2023, is a voluntary US standard for identifying and managing AI risk. It is the most common reference for structuring a governance audit outside the EU. It lives at NIST.
  • ISO/IEC 42001, published in 2023, is the first international management-system standard for AI, the AI counterpart to the ISO standards businesses already use for quality and security. The ISO listing has the scope.

You do not need to memorise these. You need to know that a credible governance audit maps to at least one of them, and that "we checked and it seemed fine" is not an audit any regulator will accept.

Sector-specific considerations

The frameworks are general; the risks are not. What an audit weighs shifts by industry. A healthcare practice cares most about patient data handling and the accuracy of anything touching a clinical decision. A law firm cares about confidentiality and the risk of a model inventing a citation. A property business cares about fair-housing exposure in any automated messaging, and about never dropping an inbound lead. An ecommerce brand cares about the data flowing between its store, its ads, and its support desk. The opportunity audit shifts the same way: the biggest recoverable leak in a clinic is missed calls, while in a property management business it is document hours. A good audit is scoped to your sector, not run off a generic template.

How to run an AI audit

Whether you hire someone or start internally, the shape is the same. Here is the sequence we use.

  1. Set the standard first. Decide what you are auditing against: recoverable money for an opportunity audit, or a named framework for a governance one. An audit with no standard is just an opinion.
  2. Inventory the reality. List where AI already runs, or where hours and leads already leak. Count and time things: missed calls over two weeks, minutes per manual task, hours per reporting cycle.
  3. Review the layers. Walk data, model, and deployment for anything live; walk data, process, and money for anything planned.
  4. Price every gap. Attach a euro figure to each finding. A leak or a risk without a number cannot be ranked, and unranked findings never get fixed.
  5. Rank and recommend. Output a short, ordered list: highest-value fix first, with the expected return beside it. That document is the audit.

Notice what is missing: a product recommendation on page one. If anyone proposes a specific platform before step four, that is a sales motion wearing an audit's name. We wrote about why we give the audit away for free for exactly this reason: the value is in the map, not the upsell.

How to tell a real audit from a sales pitch

The market is full of "free AI audits" that are lead forms in disguise. A few tests separate the real thing from the brochure.

  • It measures before it proposes. No credible recommendation can precede a look at your calls, workflows, or live systems.
  • It talks in your units. Missed calls, hours per task, days to report, error rates, not model names and buzzwords.
  • It prices the gap, not just the fix. The cost of the leak should be as clear as the cost of the solution.
  • It will say no. If your volume does not justify a build, an honest audit says "not yet" and tells you why.
  • You keep the document. The findings are yours whether or not you buy anything, and they should read clearly without the auditor in the room.

What it costs and what you get

Governance audits from large consultancies are scoped projects and priced like them, in line with standard AI consultant pricing. Our opportunity audit works differently: it is free, it runs in about 30 minutes, and it ends with a written map of where your business leaks money and what to fix first. If you decide to build afterwards, ongoing build-and-run starts at 600 euros per month plus VAT, quoted after the audit instead of before it. Either way, the document is yours to keep, even if you take it and build with someone else.

The deliverable is the point. A real audit hands you something you can act on without the auditor: a ranked list, a number against each item, and a clear first move. Anything vaguer than that is a brochure with a nicer name.

What is an AI audit for a business?

It is a structured review of AI against a clear standard. An opportunity audit maps where AI could recover revenue or hours and prices each gap in money. A governance audit reviews AI systems you already run for accuracy, bias, documentation, and legal compliance. Small and mid-market firms usually need the first; regulated or model-heavy firms need the second.

How much does an AI audit cost?

It depends which kind. A governance audit from a large consultancy is a scoped, paid project priced like standard AI consulting. kratt's opportunity audit is free and runs in about 30 minutes, ending in a written map of where your business loses money. Ongoing build-and-run afterwards starts at 600 euros per month plus VAT, quoted after the audit.

What does an AI audit check?

Three layers plus one. Data: where it comes from, whether you may use it, whether it is accurate and unbiased. Model: what the system does and how well. Deployment: how it behaves in production and who watches it. An opportunity audit adds the human process around the system, which is where recoverable money usually hides.

Do I need an AI audit if I follow the EU AI Act?

The EU AI Act tells you which risk category your systems fall into and what obligations follow. An audit is how you prove you meet them. The Act sets the standard; the audit is the evidence. Frameworks like the NIST AI Risk Management Framework and ISO/IEC 42001 play the same role outside or alongside the EU.

How long does an AI audit take?

An opportunity audit is short: about 30 minutes to map the business, then a written summary back to you. A full governance audit of a live, regulated system takes longer and ships in stages, because it tests data, model behaviour, and production monitoring against a named framework. Anything sold as instant and comprehensive is neither.

If you are not sure which audit you need, start with the cheaper question: where is the business losing money today, and could AI recover it? That is a free conversation. Book the audit through contact or read how we work as an AI consultancy. Thirty minutes, your numbers, and a straight answer on where AI pays off first.

Next move

Find your leak. Book the audit.

The free AI audit maps your inbound, qualification, booking, and follow-up. We rank exactly where the leak is before you spend a dollar.

AI consultancyShip in daysGlobalNow booking July
kratt

The AI consultancy that finds the money your business is losing, then builds, hosts, and runs the AI to get it back. Shipped in days, not months.

★ Now bookingEU + APAC
The newsletter

Occasional notes on
what’s actually working.

No spam. Cancel anytime. Occasional notes only.
DOC · KRATT-FOOT-001 · © 2026 Kratt · All rights reserved
Book your free AI audit