Assurance & compliance

Evidence you can put in front of a board, an auditor, or a regulator.

In APAC the driver is board risk and production incidents first, with regulation as the tailwind. We produce the adversarial-robustness evidence a risk owner needs when asked to show a system was tested under pressure. We do not issue a certificate.

// the argument

Continuous evidence reads as standing assurance.

Frameworks increasingly expect that AI systems are tested under adversarial pressure. A Serpio engagement produces severity-rated findings, reproducible evidence, and a coverage number mapped to named external taxonomies. That is the artifact a board, an auditor, or a regulator reads as proof the testing happened, and that closed classes stay closed.

We produce the technical evidence that supports a compliance argument the client and their advisers own. We are not a certification body, an auditor, or counsel, and we do not issue a compliance certificate.

The line we hold: “evidence you can put in front of a board, an auditor, or a regulator,” never “we make you compliant.”

// framework mapping

Named references, and what our work maps to.

Each row states what a Serpio engagement produces that supports the reference. The right column is evidence we produce, never a claim that the engagement discharges an obligation or certifies a system. The rubric behind every finding is on the method page; the class catalog is the threat register.

ReferenceWhat our work maps to
EU AI Act Reg. (EU) 2024/1689. Adversarial test findings and reproducible evidence against the model, agent, and infrastructure surface; coverage mapped to named classes; hardening recommendations feeding the robustness and cybersecurity argument (Art. 15), and red-teaming records for systemic-risk models (Art. 55).
NIST AI RMF AI 100-1 and the Generative AI Profile (AI 600-1). Structured adversarial testing as a Measure activity; findings tracked to closure under Manage via retest; coverage-over-time as the recurring measurement record.
ISO/IEC 42001 AI management system (42001:2023). Engagement findings and retest history as inputs to AI risk assessment and treatment; recurring coverage as evidence of ongoing performance evaluation.
ISO/IEC 27001 Information security management system (27001:2022). Findings and evidence feeding vulnerability management and control-effectiveness records for the AI systems in scope.
MITRE ATLAS Named adversary tactics for AI systems. Every finding pairs applicable ATLAS tactics, so coverage is stated against named references rather than asserted.
OWASP Top 10 for LLM Applications Application-layer weakness classes (2025). Every finding records its OWASP LLM class or agentic class, the taxonomy findings already map to.
IMDA Model AI Governance Framework Singapore, for generative AI. Adversarial-robustness evidence and coverage supporting the safety and robustness testing dimension, cited by a governance team.
AI Verify Singapore testing framework and toolkit. Findings a governance team can cite alongside an AI Verify process.
MAS guidance For financial institutions. Independent adversarial validation of production AI systems; recurring coverage as an ongoing-monitoring input for the model risk record.
Singapore PDPA Reasonable security arrangements to protect personal data. Findings on paths that could expose personal data (for example LLM02 sensitive-information disclosure, LLM08 RAG weaknesses) supporting the reasonable-security argument.
// what renews it

Ongoing obligations keep coverage on.

Compliance is continuous, so a one-off test lapses while the obligation does not. A framework that expects ongoing adversarial-robustness evidence is the reason a subscription renews rather than ending after a single report.

Standing coverage

Continuous Assurance, the senior-led retainer on the workbench page, keeps operator-led coverage on. Retest history and a coverage-over-time view are the recurring evidence record.

Regression alerts

Continuous Red Team, the automated tier (early access), re-runs the published classes against closed findings and flags a regression: standing proof that a previously-closed weakness has not reopened.

// disclaimer

Positioning, not legal advice.

Exact obligations, thresholds, and clauses depend on a client’s jurisdiction, role, system classification, and facts, and they change over time. The references above are directional and must be verified with qualified counsel before any client-facing use. Several expect testing or risk management broadly and do not prescribe a specific engagement.

Serpio is not counsel, an auditor, or a certification body. We produce the technical evidence that supports a compliance argument. We do not certify a system or make a client compliant.

Bring us the obligation. We produce the evidence.

Lead with production risk and adversarial depth. When an obligation you already carry needs evidence, we produce it.

Scope an engagement