Assessments & Certifications
HRMLESS maintains a rigorous assessment program that validates our AI governance controls through internal audits, independent assessments, and SOC 2 compliance.
SOC 2 Type II
CertifiedHRMLESS has achieved SOC 2 Type II certification, demonstrating the effectiveness of our security controls over an extended audit period. AI governance controls are integrated into our SOC 2 program via NIST AI RMF-to-TSC crosswalk mapping.
Framework
Trust Services Criteria (2017)
Audit Period
Feb 1 – May 1, 2026
Auditor
Johanson LLP
AI Governance Assessment Status
Beyond SOC 2, we conduct targeted assessments of our AI governance program to validate NIST AI RMF alignment and regulatory readiness.
NIST AI RMF Alignment
Annual gap assessment against all four NIST AI RMF functions (Govern, Map, Measure, Manage) with documented findings and remediation plans.
Bias Audit Readiness
Quarterly internal bias audits prepare us for independent assessments required by NYC Local Law 144 and the Colorado AI Act.
Vendor AI Assessments
Third-party AI vendors are assessed for their own AI governance practices, bias testing, and data handling before integration.
Internal Audit Methodology
Our internal AI governance audits follow a structured four-phase methodology.
Planning
Define audit scope, objectives, and criteria based on NIST AI RMF functions and applicable regulations.
Evidence Collection
Gather artifacts including policy documents, bias test results, model cards, oversight logs, and training records.
Testing
Validate control effectiveness through document review, interviews, observation, and re-performance of key procedures.
Reporting
Document findings, recommendations, and remediation timelines. Report to AI Governance Committee and executive leadership.
Assessment Schedule
| Assessment | Frequency | Next Scheduled | Status |
|---|---|---|---|
| SOC 2 Type II Audit | Annual | Q1 2027 | Certified |
| AI Bias Audit (Internal) | Quarterly | Q3 2026 | On Schedule |
| NIST AI RMF Gap Assessment | Annual | Q4 2026 | On Schedule |
| Vendor AI Risk Assessment | Annual / On-boarding | Ongoing | Active |
| Regulatory Compliance Review | Semi-Annual | Q3 2026 | On Schedule |
| Penetration Testing (AI Systems) | Annual | Q4 2026 | Planned |
Assessment Reports
Our SOC 3 report is publicly available. SOC 2 Type II reports, AI governance assessment summaries, and bias audit reports are available to customers and auditors upon request through the authenticated Trust Center portal.