A 3-week, fixed-fee engagement that inventories your AI agent fleet, maps it against EU AI Act Art. 9–15, NIST AI RMF, and ISO 42001, and delivers a signed report whose findings a third party can independently verify — not just read.
3 weeks · fixed fee, no hidden overages · deliverable is a signed report + on-chain verifiable evidence package
Book a 30-minute scoping callOrganizations deploying AI agents in financial services, trading, or KYC/AML workflows need to demonstrate documented agent identity, functioning human oversight and kill-switches, auditable delegation chains, and a monitored risk-management process. Most organizations deploying agents today have none of this documented, and no clear path to evidence that satisfies an auditor or regulator.
The EU AI Act's high-risk obligations took effect 2 August 2026 — fines up to €35M or 7% of global turnover. ISO 42001 certification is increasingly a procurement gate for enterprise buyers evaluating an AI-agent vendor, whether or not the vendor is EU-based.
| Week | What you get |
|---|---|
| 1 — Inventory & Assessment | Map every agent in your fleet (identity, capability scope, deployment context); run an OWASP ASI Top 10 security assessment against each agent; assess delegation chains (who authorized what, to whom, when); evaluate kill-switch and human-override controls; identify high-risk agents under EU AI Act Art. 6 classification criteria. |
| 2 — Evidence & Gap Analysis | Document findings against EU AI Act Art. 9–15; map controls to NIST AI RMF (Govern, Map, Measure, Manage); map controls to ISO 42001 Annex A; produce a gap matrix (present / missing / partial); Merkle-commit findings with salted, keyed-HMAC leaves so completeness is bound into the root. |
| 3 — Report, Attestation & Roadmap | Issue a signed OWNER_REPORT.md with a verify recipe; emit ProofOfAuditReport (kind 30105) — HMAC-signed, content-hashed, verifiable offline; optional anchor to Base mainnet + Sepolia + Nostr (gas estimate provided in advance, operator confirms before spend); deliver a prioritized remediation roadmap; include the Sanctions & Wallet Binding Readiness module (below). |
Included in every engagement: whether each agent's identity is verifiably bound to controlling wallet address(es); whether delegation-event logs (ProofOfDelegation chains) exist and are complete; whether x402 payment rails have a documented binding to a known legal counterparty; whether a process exists for periodic screening of controlling wallets against OFAC SDN and equivalent sanctions lists.
This assessment documents your readiness posture — it does not constitute a sanctions determination, legal clearance, or compliance certification. Ongoing wallet screening (Chainalysis, TRM, or equivalent) is available as a follow-on engagement.
Most audit firms issue PDF reports. Ours are independently verifiable.
Every finding is committed to a Merkle root with the leaf count N bound in — completeness is cryptographically enforced, not asserted.
The report is content-hashed into a signed proof; it cannot be silently revised after delivery.
Anchor to Base mainnet + Nostr on request — a third party verifies without trusting us.
The proof links into your agent's passport, so a future auditor or regulator sees the audit trail immediately.
Built on the BlindOracle attestation rail, which has processed on-chain settled evidence since 2025.
| Framework | Articles / Controls Covered |
|---|---|
| EU AI Act | Art. 9 (Risk Management), Art. 10 (Data Governance), Art. 11 (Technical Documentation), Art. 12 (Record-Keeping), Art. 13 (Transparency), Art. 14 (Human Oversight), Art. 15 (Accuracy & Robustness) |
| NIST AI RMF | Govern (1.1–6.2), Map (1.1–5.2), Measure (1.1–4.2), Manage (1.1–4.3) |
| ISO 42001 | Annex A: A.2 (Policies), A.3 (Internal Organization), A.4 (Resources), A.5 (Assessments), A.6 (System Impact Assessment) |
| Scope | Price | Agents Covered |
|---|---|---|
| Starter | $15,000 | Up to 10 agents |
| Standard | $20,000 | 11–30 agents |
| Extended | $25,000 | 31–60 agents |
Larger fleets: contact for custom pricing. Multi-framework discount available when EU AI Act + NIST + ISO 42001 are bundled into one engagement.
Crypto-native fund deploying trading or research agents with DeFi exposure; fintech operator deploying KYC/AML or credit-decision agents; agent-as-a-service company seeking a trust signal for enterprise buyers; any org that has received a regulatory inquiry about its AI agent governance.
Regulated bank or broker-dealer requiring an auditor independence opinion (we are not a licensed audit firm); an organization that needs a SOC 2 Type II or ISO 42001 certification itself (refer to Big 4 + accredited certification body).
This offer is advisory in nature. BlindOracle is not a licensed audit firm, law firm, or regulated financial institution. Nothing in this engagement constitutes legal advice, a legal opinion, or a regulatory determination.
30-minute scoping call, no obligation. We'll tell you honestly whether this is the right engagement for your fleet size and timeline.
Book a scoping call