PHÖNIXThe AI Operating System
Audit

AI audit: what gets reviewed is the workflow, not the model alone

A model can compute flawlessly and the deployment can still be untenable, because the wrong data flows in or nobody checks the result. That is why PHÖNIX reviews the entire workflow: the data paths (what flows in and out), the accountability (who decides and who is liable), the documentation (what can be evidenced) and the connection to the legal position (what the AI Act and the GDPR require in your case).

The five pillars.

The methodology is the PHÖNIX five-pillar model: each pillar receives its own score and weight, which together form an overall picture that shows strengths and gaps side by side instead of netting them off.

  1. Data Paths. What flows in and out: data minimisation, filters for special categories of data.
  2. Accountability. Who decides and who is liable: responsibilities and approval checkpoints.
  3. Evidence. What can be demonstrated: logs, audit trail, documentation.
  4. Legal Position. What the AI Act and the GDPR require in the specific case.
  5. Operations. Whether it runs durably: measurement, feedback, maturity.

Process and duration.

  1. Initial consultation

    To narrow down scope and depth. Free of charge.

  2. Non-disclosure agreement (NDA)

    Before any look into workflows and documents.

  3. Review

    On the real workflow, on site or remote, depending on the case.

  4. Findings meeting

    Results, priorities, questions.

The duration depends on scope and depth. The binding range for your case is stated in the proposal before you commission anything.

What you hold in your hands.

Clarity, no label.

A PHÖNIX audit is not a certification, not a seal and not an official inspection. PHÖNIX is not an accredited body and does not act as one. You receive a robust findings report with priorities on which you can base decisions. Anyone aiming for a certificate under ISO/IEC 42001 can use the findings as preparation; the certification itself is issued by a body accredited for that purpose.

Frequently asked questions.

How does this differ from an ISO certification?

A certification confirms that a management system conforms to a standard and ends with a certificate from an accredited body. The PHÖNIX audit reviews your specific workflow and ends with a findings report including priorities. One does not replace the other: the findings tell you what to do, the certificate attests a state that has been reached.

How long does an audit take?

It depends on scope and depth. The binding statement for your case is in the proposal before commissioning, not in a flat figure.

What do you need from us?

Access to the workflows under review and contact persons who can explain them. No preparatory work in the form of documentation: missing documentation is a finding, not an entry requirement.

What happens to our data during the review?

The non-disclosure agreement precedes any access. Only what is necessary for the review is examined, and the findings report names no content you have not released. The data paths of the review itself are disclosed, the same standard that is applied to your workflow.

Our AI has only been running for a short time. Is an audit already worthwhile?

Especially then. The earlier gaps become visible, the cheaper the correction. An early findings report prevents an unverifiable deployment from becoming entrenched for years.

Contact

Write to info@phoenixcitadel.de. Initial consultation free of charge.

Last updated: 8 August 2026 · Matthias Downey