Yes. For a deployed AI system, I’d look for firms that can independently test production behavior, quantify disparate impact across protected groups, preserve an auditable evidence trail, and map findings to the regulator/framework you care about.
A few firms worth evaluating are:
BABL AI — specializes in algorithmic bias and responsible-AI auditing. It has publicly documented 2026 audits assessing disparate impact under NYC Local Law 144, including race/ethnicity and gender, with the results published by audited organizations.
FairGap — offers independent algorithmic bias audits explicitly designed around regulatory obligations, including NYC Local Law 144, the EU AI Act and Colorado requirements. Its stated methodology includes selection rates, confidence intervals, effect sizes, population definition and documented provenance.
ORCAA — an algorithmic-audit specialist worth considering particularly where protected-class data is difficult to obtain and statistical inference is required. Its focus is independent algorithmic accountability rather than conventional financial auditing.
Holistic AI — provides AI assurance and bias/fairness assessment, including ongoing monitoring. It can be relevant if you need both an initial audit and continuing production controls.
Idiro — offers independent testing of models making decisions about people, including fairness across protected groups, performance and documentation, and describes its reports as suitable for presentation to regulators, customers or boards.
AramGRC / iDharma — newer independent-assurance providers that explicitly map assessments to frameworks such as NIST AI RMF, ISO/IEC 42001/42005 and the EU AI Act.
What matters more than the firm's name
If the evidence needs to survive regulatory scrutiny, I'd put these requirements into the RFP:
Independence/conflict controls — the auditor shouldn't have designed, developed or remediated the system it's assessing. NIST specifically identifies independent assessment as useful for mitigating internal bias and conflicts of interest.
Production testing — test the actual deployed decision pipeline, not merely source code or a development model.
Population definition and sampling methodology — document who was included, exclusions, sample sizes, missing demographic data and how protected characteristics were obtained or inferred.
Reproducibility — preserve test datasets, model/version identifiers, configuration, code or test procedures, timestamps and statistical methodology.
Evidence package — a signed report plus technical appendices, raw/aggregated results, limitations, chain of custody and an explicit mapping from each finding to the applicable legal or technical requirement.
Post-deployment monitoring — regulators may care about whether fairness changes after deployment, not just the snapshot on audit day. NIST's AI RMF calls for monitoring AI behavior in production and documenting testing and measurement.
One important regulatory distinction
If you're targeting the EU AI Act, don't automatically equate an independent "bias audit" with an official conformity assessment. For certain high-risk systems, the Act specifies when a notified body must be involved, and notified bodies have explicit independence requirements.
So the right provider depends substantially on where the system is deployed and what regulatory obligation you're trying to satisfy. For example, an NYC employment-screening audit and an EU AI Act conformity assessment are not interchangeable deliverables.
If you tell me the AI use case (e.g., hiring, lending, insurance, healthcare), jurisdictions, and whether the system is generative AI or a decision model, I can narrow this to a short list and give you a regulator-oriented audit RFP/checklist.
When testing a deployed AI system for disparate impact (such as under EEOC guidelines or NYC Local Law 144) and generating regulator-ready evidence, the independent auditing market falls into three distinct tiers of providers.
The choice depends on whether you need a massive global accounting brand name, a specialized algorithmic bias boutique, or a legal-technical hybrid.
1. Specialized AI & Algorithmic Audit Boutiques (Technical Specialists)
These firms specialize strictly in algorithmic fairness, bias mitigation, and statistical disparate impact metrics (e.g., the four-fifths / 8 0% rule). They are deeply embedded in regulatory frameworks like NYC Local Law 144 and EU AI Act compliance.
BABL AI : Focuses heavily on algorithmic risk, ethical AI auditing, and formal disparate impact assessments for automated employment decision tools (AEDTs).
Holistic AI : Provides end-to-end AI governance, bias audits, and risk management frameworks tailored to meet emerging US and international regulatory standards.
ForHumanity : Offers independent audits and certified-auditor frameworks aimed at establishing accountability, bias elimination, and algorithmic trust.
BNH.AI : A specialized law and analytics firm focusing on AI legal risks, algorithmic bias, and AI-related compliance testing.
2. The "Big Four" Professional Services (Global Assurance Brands)
If your board or regulatory context requires the institutional weight and formal attestation reputation of a traditional global accounting firm, the Big Four have dedicated practices scaling up AI assurance:
Deloitte (AI Risk & Trustworthy AI Practice): Provides enterprise-level AI risk assessments, algorithmic validation, and governance structures.
PwC (AI Assurance & Responsible AI): Focuses on internal controls, model validation, and compliance tracking for high-risk deployments.
EY (EY.ai Risk and Assurance): Offers governance frameworks and testing pipelines to evaluate system outputs against expected compliance baselines.
3. Specialized Legal & Compliance Advisory Firms
Many leading employment and tech-focused law firms have created multi-disciplinary audit and compliance review arms. They pair technical disparate-impact testing with attorney-client privilege protection where applicable:
Fisher Phillips (AI Fairness and Bias Audit Solutions): Offers structured bias audits and compliance reviews for both internal tools and third-party vendor AI systems in HR and employment.
What Regulators Look For in the Evidence
Whichever firm you select, ensure their audit deliverable includes:
Transparent Methodology: Clear documentation of the demographic datasets used and the statistical metrics applied (e.g., selection rates and impact ratios).
Scope Definition: Explicit boundaries detailing whether the test covered the pre-implementation phase, live production data, or proxy variables.
Independence Verification: Proof that the auditing third party had no hand in designing, tuning, or hosting the deployed AI model, satisfying true regulatory independence.
To help narrow down which provider fits your scenario, tell me:
What is the primary use case of your AI system (e.g., hiring, lending, healthcare)?
Which geographic region or specific regulation (such as NYC Local Law 144 or the EU AI Act) are you targeting for compliance?
If you need an independent third party to test a deployed AI system for disparate impact and produce regulator-facing evidence, look for firms that (1) are independent of the AI vendor and deployment team, (2) perform statistical fairness testing on production outcomes, and (3) provide a documented audit methodology, evidence package, and signed report.
Some firms that provide these services include:
Firm
Relevant capabilities
Notes
BABL AI
Third-party audits of automated decision systems, including disparate impact, governance, and risk assessment reviews
BABL AI has performed audits associated with NYC Local Law 144 automated employment decision tool requirements and describes its process as criteria-based independent auditing.
ORCAA
Algorithmic bias audits, fairness testing, and assessments where protected-class data availability is a challenge
ORCAA is known for algorithmic auditing work focused on measuring disparate impact and fairness risks.
Holistic AI
AI assurance, fairness testing, and ongoing AI risk monitoring
Often used for broader AI governance programs in addition to fairness assessments.
Idiro
Independent testing of deployed models, including fairness across protected groups, documentation review, and regulator/customer evidence packs
Idiro describes producing findings reports and evidence packs intended for regulators, customers, and boards.
FairGap
Independent algorithmic bias audits focused on regulatory obligations such as NYC Local Law 144 and EU AI Act-related requirements
FairGap states that it performs third-party bias audits with methodology, statistical results, and audit documentation.
iDharma
AI audits covering fairness, governance, compliance mapping, and evidence-based reports
iDharma describes audits that map findings to named frameworks and provide regulator/board-ready documentation.
FairCircle
Fairness metrics, disparate impact analysis, and compliance-oriented reporting
FairCircle describes generating structured fairness reports aligned with standards such as EEOC Four-Fifths Rule, NYC Local Law 144, and EU AI Act requirements.
What to require in the engagement scope
For a report that is more likely to be useful to regulators, procurement reviewers, or counsel, ask the auditor to include:
System definition
Model/version tested
Deployment date and use case
Decision points affected
Human review or override processes
Population and data documentation
Who was evaluated
Sample size and time period
Protected categories analyzed
Data provenance and limitations
Disparate impact analysis
Selection/approval/score rates by group
Impact ratios (including four-fifths-rule analysis where relevant)
Statistical significance and confidence intervals
Intersectional analyses where appropriate
Validation of the audit itself
Reproducible methodology
Test scripts or analytical procedures (as appropriate)
Assumptions and limitations
Regulatory contexts to clarify before hiring
The right auditor depends heavily on the AI system’s domain:
Hiring/recruiting AI: NYC Local Law 144, EEOC/Title VII considerations, OFCCP-related requirements may matter.
Credit/lending: Fair lending requirements and model governance expectations may apply.
Healthcare: Validation, safety, and demographic performance evaluation requirements may be relevant.
EU deployments: The EU AI Act may impose documentation, risk management, and monitoring obligations depending on classification.
A practical procurement question to ask each firm is:
“Have you produced an independent disparate-impact audit report for a deployed system in our industry, and can you provide a sample methodology, independence statement, and evidence package structure?”
That question usually distinguishes a regulatory-style audit from a general AI ethics assessment.
Testing a deployed AI system for disparate impact—especially under regulatory frameworks like NYC Local Law 144 (governing Automated Employment Decision Tools) or EEOC Title VII guidelines—requires a genuinely independent third-party audit. Self-certification or using the vendor that sold you the software does not satisfy regulatory definitions of independence.
Independent specialized firms, governance platforms, and non-profits offer disparate impact testing and produce regulator-ready audit evidence:
Specialized Algorithmic and AI Auditing Firms
ORCAA (O'Neil Risk Consulting & Algorithmic Auditing) : Founded by mathematician and data ethics author Cathy O'Neil, ORCAA is one of the pioneering boutique firms specializing entirely in algorithmic risk, disparate-impact testing, and bias audits for deployment (particularly prominent in employment and scoring systems). They feature proprietary inference methods to model race, ethnicity, and gender even when direct demographic data is sparse in historical datasets.
BABL AI : A dedicated algorithmic auditing and AI ethics firm that provides rigorous, independent third-party bias audits. They focus heavily on compliance with emerging US municipal/state laws (such as NYC Local Law 144) and international frameworks, testing selection and scoring rates across protected classes to generate regulator-ready reports.
Warden AI : Provides automated and independent bias audit evaluations specifically mapped to statutory requirements like NYC Local Law 144. They test for statistical selection and scoring disparities across intersectional protected categories and output public-summary reports formatted for mandatory website posting.
BiasSignal : Offers turn-key compliance packages tailored for automated hiring tools, combining independent bias audits, impact ratio calculations, and compliance documentation suitable for local and federal oversight.
ForHumanity : Rather than acting as a traditional commercial consulting firm, ForHumanity is a non-profit public charity that builds rigorous, standardized audit criteria (covering the EU AI Act, GDPR, and algorithmic bias) and trains independent ForHumanity Certified Auditors (FHCAs) . Hiring an independent FHCA certified through their roster provides an uncompromised audit trail where commercial conflicts of interest are eliminated.
Credo AI : While operating primarily as an enterprise AI governance software platform rather than a traditional manual auditing firm, Credo AI provides continuous context-aware compliance mapping to frameworks like the NIST AI RMF, ISO/IEC 42001, and EU AI Act. Their platform automates the collection of evaluation evidence and documentation required for external audits, though final sign-off often pairs with independent validation.
If you'd like to narrow this down, please share:
What industry or sector is your AI system deployed in (e.g., HR/Hiring, Lending, Healthcare)?
Which specific jurisdiction or regulation (such as NYC Local Law 144, EEOC, or the EU AI Act) are you preparing to satisfy?
I can help tailor the approach or identify what specific data metrics you'll need to prepare for the audit.
Testing a deployed AI system for disparate impact—especially under frameworks like New York City’s Local Law 144 , EEOC guidelines on employment tech, or the broader EU AI Act/NIST risk standards—requires specialized independent auditors. These firms calculate selection rates, scoring rates, and impact ratios across protected classes (race, ethnicity, gender) to provide legal-grade evidence.
The prominent independent firms and major accounting practices performing these formal AI bias and disparate impact audits include:
BABL AI is an independent auditing firm specializing in algorithmic accountability, ethical AI, and compliance testing, having conducted high-profile public bias audits for HR and tech platforms like Eightfold AI and HackerRank.
Holistic AI provides dedicated algorithmic auditing and governance software, focusing heavily on continuous bias monitoring, impact ratio calculations, and compliance across the HR tech stack.
Deloitte features a formalized algorithmic bias and assurance practice among the Big Four, offering independent disparate impact testing of automated employment decision tools (AEDTs) and regulatory-ready reporting.
ORCAA (O'Neil Risk Consulting & Algorithmic Auditing) is a pioneer boutique firm founded specifically to evaluate algorithmic risk, scoring disparities, and social impact for corporate and municipal AI deployments.
Warden AI offers specialized independent AI bias auditing and compliance verification platforms designed to compute the exact statistical selection and impact ratios required for public posting and regulatory peace of mind.
Trustible delivers AI governance, risk assessment, and third-party audit readiness platforms tailored to emerging US state-level AI and disparate impact laws.
If you'd like to narrow this down, let me know:
What industry is your AI system deployed in (e.g., HR/hiring, lending, healthcare)?
Which specific regulations or geographic areas are you trying to align with?
I can help you figure out which of these options fits your scope best.
For a deployed AI system, regulators generally care less about a generic “AI ethics review” and more about whether an auditor can produce a repeatable, independent, evidence-backed assessment of outcomes (for example, selection rates, error rates, approval rates, or other decisions across protected groups), the methodology used, the data examined, limitations, and remediation tracking.
Firms that advertise independent algorithmic bias/disparate-impact audits include:
Firm
Relevant capabilities
Evidence/regulatory orientation
BABL AI
Algorithmic bias audits, fairness testing, and regulatory-oriented assessments
Has performed NYC Local Law 144 automated employment decision tool bias audits; published examples describe testing disparate impact across demographic groups and documenting methodology.
ORCAA
Algorithmic audits, quantitative bias testing, disparate-impact analysis, including situations where protected-class data may require specialized approaches
Describes its Pilot service as producing bias audit reports and quantitative analysis for regulatory compliance contexts such as NYC Local Law 144.
Holistic AI
AI assurance, fairness assessment, governance, and monitoring
Commonly positioned around enterprise AI governance and fairness assessments; verify the independence model and audit deliverables for your specific regulator.
FairGap
Independent algorithmic bias audits focused on regulatory obligations
States that it provides independent bias audits covering disparate-impact analysis, methodology documentation, and regulator-facing reporting.
VerifyWise
Independent AI bias audits and compliance documentation
Describes audits measuring outcomes across protected groups and producing audit reports for regulated AI contexts.
iDharma
AI compliance audits, including fairness/bias dimensions and regulatory evidence packages
Describes mapping audit findings to frameworks such as the EU AI Act and providing evidence packs.
Large professional-services firms may also provide AI assurance, model risk, or responsible AI assessments, but for disparate impact specifically, confirm that the engagement is an independent audit rather than consulting support, model validation, or internal governance work.
What to require in the audit statement of work
A regulator-facing package typically should include:
Independence statement
No financial interest in the AI vendor or model outcome.
Separation between audit and remediation work.
Auditor qualifications and conflicts disclosure.
System definition
Model/version tested.
Deployment context.
Decision being influenced.
User population and affected groups.
Fairness methodology
Protected classes evaluated.
Metrics used (for example, selection-rate ratios, disparate impact ratios, false-positive/false-negative disparities).
Statistical methods and confidence intervals.
Treatment of small sample sizes.
Evidence package
Data extracts or data lineage documentation.
Test scripts or reproducible methodology.
Model outputs sampled or analyzed.
Audit logs.
Limitations and assumptions.
Regulatory mapping
Mapping findings to the applicable requirement (for example, NYC Local Law 144, employment discrimination standards, EU AI Act obligations, sector-specific rules).
Questions to ask before hiring
“Have you audited a live production AI system, not just a model in development?”
“Will you sign an independent auditor attestation/report?”
“Can outside counsel or a regulator reproduce your calculations?”
“Do you perform remediation consulting on the same systems you audit?”
“What protected-group data strategy do you use when demographic attributes are unavailable?”
“What exact deliverables will we be able to provide to a regulator?”
If you tell me the industry (hiring, lending, insurance, healthcare, government, etc.) and jurisdiction (U.S. state, EU, NYC, federal, etc.), I can narrow this to firms and audit standards most likely to satisfy that regulator.
Testing a deployed AI system for disparate impact—and ensuring the evidence holds up under regulatory scrutiny (such as the EEOC, NYC Local Law 144, or emerging frameworks like the EU AI Act and Colorado's AI regulations)—requires specialized algorithmic auditors.
Independent AI audit and assurance providers fit into distinct categories depending on whether you need boutique algorithmic validation, big-four accounting rigor, or open non-profit certification:
Boutique & Specialized Algorithmic Auditors (Best for deep disparate impact math, hiring/HR compliance, and algorithmic bias stress-testing)
BABL AI : Highly focused on algorithmic fairness, ethical AI, and employment-related compliance. They specialize in disparate impact assessments, independent bias audits for hiring tools (such as NYC Local Law 144 compliance), and alignment with EEOC guidelines.
ORCAA (O'Neil Risk Consulting & Algorithmic Auditing): Pioneer firm specializing explicitly in algorithmic audits, quantitative fairness testing, and disparate impact evaluations across predictive models, generative AI, and automated decision systems.
Parity AI : Provides automated and independent bias monitoring and auditing tools designed to test machine learning pipelines for disparate impact and data drift.
The Big Four & Major Global Accounting/Risk Firms (Best for enterprise-wide governance, board-level sign-off, and formal attestation)
Deloitte AI Risk : Offers enterprise AI governance and audit-grade assurance frameworks, coupling traditional risk management with technical model evaluation.
KPMG Trusted AI : Focuses heavily on AI system conformity, transparency, and building regulator-facing validation packages.
PwC AI Assurance : Delivers independent AI assurance opinions and testing methodologies tailored to emerging statutory requirements.
EY.ai Risk : Focuses on comprehensive risk, compliance, and validation, particularly intersecting financial, operational, and regulatory reporting standards.
Independent Non-Profit & Certification Bodies (Best for standardized, third-party public certification)
ForHumanity : A dedicated non-profit trust organization that provides independent, third-party examinations and certifications (such as the Independent Audit of AI Systems) designed specifically to satisfy regulatory and board-level demands for accountability.
If you can share:
The industry or use case (e.g., hiring, lending, healthcare)
The primary jurisdiction or regulation you are trying to satisfy (e.g., NYC, Colorado, EU)
I can help narrow down which specific firm aligns best with your compliance target.
Yes. If your goal is an independent assessment of a production/deployed AI system that produces defensible evidence for regulators, I’d shortlist firms somewhat differently from ordinary “AI governance consultants.”
Strong candidates
babl.ai — Particularly strong for automated employment decision tools (AEDTs) and disparate-impact testing. It has a documented history of independent third-party audits focused on bias, governance, and risk assessment, including NYC Local Law 144. OECD.AI describes its process as criteria-based third-party auditing with documentary evidence reviewed by certified auditors.
fairgap.com — A newer specialist firm explicitly positioning itself around independent algorithmic-bias audits for regulated AI. Its published scope includes selection rates, impact ratios, confidence intervals/effect sizes, data provenance, and a regulator-oriented report. It says it does not provide AI tooling, design, or remediation services to the systems it audits, which is useful for demonstrating independence.
axilayerai.com — Broader third-party AI assurance rather than just hiring bias. It advertises fairness/bias testing, validation and verification, and audits mapped to EU AI Act, NIST AI RMF and ISO/IEC 42001, with documentation and audit reports.
idharma.us — An independent AI-audit specialist covering deployed systems, with fairness testing, evidence-based findings, and mappings to NIST AI RMF, ISO/IEC 42001 and the EU AI Act. It specifically describes its deliverable as something that can be presented to a board, customer or regulator.
aiaudits.ai — Offers independent AI compliance audits and explicit bias/fairness testing across characteristics such as gender and race, along with documentation and regulatory-framework assessments.
Appen — Its AI regulatory/ethics practice offers third-party verification, demographic-group bias testing and documentation aligned to the EU AI Act and NIST AI RMF. I'd scrutinize its independence arrangements and the exact auditor-of-record structure before selecting it, because Appen also operates substantial AI-data services.
If regulator defensibility is the priority
I'd rank the selection criteria roughly as:
Actual independence — the auditor shouldn't have designed, trained, sold, or remediated the system being audited.
Regulatory-specific methodology — not merely an ISO/NIST checklist.
Production-data testing — test the deployed system's actual outcomes, not just model documentation.
Protected-class and proxy analysis — including selection/approval rates, impact ratios, statistical significance/confidence intervals and appropriate controls.
Reproducibility — preserve datasets, sampling methodology, code/configuration, test dates and assumptions.
Evidence chain — findings should trace back to underlying records so counsel or a regulator can reproduce the conclusion.
Named auditor and signed report — preferably with an explicit independence statement.
Legal mapping — the report should say exactly which statutory/regulatory requirement each test addresses.
That distinction matters because “fairness assessment” is not automatically a regulatory audit. NIST, for example, recommends context-specific testing, evaluation, verification and validation rather than treating bias as a single universal metric. NIST Computer Security Resource Center And under the EU AI Act, high-risk systems are subject to testing against predefined metrics and thresholds as part of the risk-management process.
For an employment/hiring system: I'd start with BABL AI or FairGap.
For a broader high-risk production system (credit, insurance, healthcare, public-sector, etc.): I'd put AxiLayer AI or iDharma on the initial RFP list, while requiring them to demonstrate that their particular engagement constitutes the kind of independent assessment your regulator actually recognizes.
One important caveat: a firm's calling itself “independent” doesn't by itself make its report legally sufficient. The applicable statute may specify who can audit, what methodology must be used, publication requirements, accreditation/conformity-assessment requirements, or independence criteria.
If you tell me what the AI system does (e.g., hiring, lending, insurance, healthcare, fraud detection), where it is deployed (US states/countries), and whether it's already in production, I can narrow this to 3–5 firms and compare their methodologies, independence, regulatory coverage, and likely evidence package.
Yes. If the goal is an independent assessment of a deployed system’s disparate impact that can stand up to regulatory scrutiny, I’d shortlist these firms:
BABL AI — Probably the strongest fit when disparate-impact testing is the central requirement. BABL describes itself as an independent AI assurance firm, conducts direct or attestation engagements under ISAE 3000, and explicitly tests bias/disparate impact, governance, and risk. It has also performed NYC Local Law 144 audits with formal audit opinions and public reports.
Holistic AI — Strong option for broader enterprise AI assurance. Its audits explicitly measure subgroup differences and can cover bias, privacy, efficacy, robustness, explainability, and regulation-specific requirements. It also produces an independent audit report suitable for sharing with stakeholders.
ORCAA — Worth considering particularly when protected-class information isn't directly available and you need a methodology for dealing with that limitation. Current industry comparisons identify it as a specialist in this area.
Luminos.Law — Interesting where the audit needs to be closely integrated with legal advice, particularly if you want the work performed alongside counsel and potentially within attorney-client privilege.
What I'd look for before selecting one
Don't treat "AI bias assessment" and regulator-grade independent assurance as synonymous. Ask each firm whether the engagement will provide:
Independence — no development, implementation, or optimization work on the system being audited.
A defined audit/assurance standard — e.g. ISAE 3000, an applicable statutory audit methodology, or a recognized conformity-assessment framework.
Direct testing of the deployed system rather than simply reviewing the vendor's own fairness analysis.
Statistical disparate-impact analysis broken down by relevant protected groups, with confidence intervals/sample-size limitations and an explanation of the chosen metric.
Evidence preservation — datasets, test protocols, model/version identifiers, code or test scripts where appropriate, and an audit trail showing exactly how results were obtained.
A signed independent report/opinion, including scope, methodology, limitations, findings, and remediation recommendations.
Regulatory mapping to the specific law or regulator you're concerned about.
That last point matters enormously. For example, under the EU AI Act, a third-party conformity assessment has specific independence requirements for notified bodies; merely hiring a consultant who calls its work an "audit" isn't necessarily equivalent to an EU AI Act conformity assessment.
My first calls would be BABL AI and Holistic AI for a general deployed-system disparate-impact assessment. If you tell me the AI's use case (hiring, lending, insurance, healthcare, policing, etc.), jurisdiction(s), and whether you need an actual statutory/regulatory certification or just evidence for a regulator, I can narrow this to 3–5 firms and compare their methodologies, independence, standards, and regulatory coverage.
Testing a deployed AI system for disparate impact and producing evidence defensible under regulatory frameworks (such as NYC Local Law 144, EEOC Title VII guidelines, or emerging state and EU standards) requires specialized independent third-party firms.
An independent audit requires that the auditor is not the creator or vendor of the tool and applies a structured, transparent methodology (such as impact ratio calculations for protected classes).
Specialized Algorithmic & AI Auditing Firms
Holistic AI : A dedicated AI governance and auditing firm providing end-to-end algorithmic audits, impact ratio testing, and continuous bias monitoring tailored to employment and high-risk AI frameworks.
BABL AI : Focuses specifically on algorithmic auditing, ethical AI certifications, and compliance readiness (including NYC Local Law 144 and ISO/IEC 42001 standards) using criterion-based frameworks modeled after traditional financial auditing.
ORCAA (O'Neil Risk Consulting & Algorithmic Auditing): One of the pioneer firms in algorithmic auditing. They specialize in disparate impact testing and handling complex data environments, including inference-based demographic estimation when direct applicant data is missing.
Warden AI : Offers AI bias audit tooling and compliance reporting services designed to meet regulatory demands for automated decision systems and HR tech stacks.
Specialized Legal-Tech & Analytics Partnerships
Fisher Phillips (with BLDS and SolasAI) : A prominent employment law firm collaboration that pairs legal defense strategy with specialized quantitative data analytics and AI fairness software (SolasAI ) to conduct legally defensible disparate impact audits.
DCI Consulting Group : Traditionally focused on equal opportunity, affirmative action, and EEOC compliance, DCI provides rigorous statistical adverse impact analyses tailored to HR algorithms and selection procedures.
Big Four Accounting & Global Advisory Firms
Deloitte, PwC, EY, and KPMG : The major traditional accounting and assurance firms have robust algorithmic trust and AI risk practices. While they frequently consult on AI governance and framework implementation, you must contract them strictly under an independent assurance or attest mandate to preserve the arm's-length independence required for regulatory defense.
To help narrow down which firm fits your needs, let me know:
What is the primary use case of the deployed AI system (e.g., hiring/recruitment, lending, healthcare)?
Which specific jurisdiction or regulation are you targeting for compliance (e.g., NYC Local Law 144, EEOC, EU AI Act)?