HRMLESS Trust Center
Data as of Jul 9, 2026, 08:35 PM UTC

Assessments & Certifications

HRMLESS maintains a rigorous assessment program that validates our AI governance controls through internal audits, independent assessments, and SOC 2 compliance.

SOC 2 Type II

Certified

HRMLESS has achieved SOC 2 Type II certification, demonstrating the effectiveness of our security controls over an extended audit period. AI governance controls are integrated into our SOC 2 program via NIST AI RMF-to-TSC crosswalk mapping.

Framework

Trust Services Criteria (2017)

Audit Period

Feb 1 – May 1, 2026

Auditor

Johanson LLP

AI Governance Assessment Status

Beyond SOC 2, we conduct targeted assessments of our AI governance program to validate NIST AI RMF alignment and regulatory readiness.

NIST AI RMF Alignment

Annual gap assessment against all four NIST AI RMF functions (Govern, Map, Measure, Manage) with documented findings and remediation plans.

Bias Audit Readiness

Quarterly internal bias audits prepare us for independent assessments required by NYC Local Law 144 and the Colorado AI Act.

Vendor AI Assessments

Third-party AI vendors are assessed for their own AI governance practices, bias testing, and data handling before integration.

Internal Audit Methodology

Our internal AI governance audits follow a structured four-phase methodology.

1

Planning

Define audit scope, objectives, and criteria based on NIST AI RMF functions and applicable regulations.

2

Evidence Collection

Gather artifacts including policy documents, bias test results, model cards, oversight logs, and training records.

3

Testing

Validate control effectiveness through document review, interviews, observation, and re-performance of key procedures.

4

Reporting

Document findings, recommendations, and remediation timelines. Report to AI Governance Committee and executive leadership.

Assessment Schedule

AssessmentFrequencyNext ScheduledStatus
SOC 2 Type II AuditAnnualQ1 2027Certified
AI Bias Audit (Internal)QuarterlyQ3 2026On Schedule
NIST AI RMF Gap AssessmentAnnualQ4 2026On Schedule
Vendor AI Risk AssessmentAnnual / On-boardingOngoingActive
Regulatory Compliance ReviewSemi-AnnualQ3 2026On Schedule
Penetration Testing (AI Systems)AnnualQ4 2026Planned

Assessment Reports

Our SOC 3 report is publicly available. SOC 2 Type II reports, AI governance assessment summaries, and bias audit reports are available to customers and auditors upon request through the authenticated Trust Center portal.