AI Act readiness, vendor-neutral.
An open spec and a CLI your audit practice can include in client deliverables without lock-in.
Falsify publishes PRML, a CC BY 4.0 specification for pre-registered machine-learning evaluation manifests, plus four byte-equivalent MIT-licensed reference implementations. It is the layer your AI Act readiness engagements can deploy inside the client environment, cite in the final report, and leave behind for the regulator — without buying SaaS licenses, without naming a vendor, without your team writing the standard from scratch.
New for August 2026: three design-partner pilot slots for audit and assurance practices, €3,000–€7,500 fixed-price by scope — one real evaluation claim from an engagement, locked before the run, with a worked Evidence Pack you keep. Scope and terms →
01The problem this solves
A client retains your practice for AI Act readiness. They want evidence aligned to Article 12 (automatic logging), Article 17 (quality management), and Article 18 (ten-year retention). Often a high-risk Annex III system. Often six figures of fee at stake.
You build a custom deliverable each time. The deliverable looks competent. Then the client’s general counsel asks the unanswerable question: is this an industry-recognized format? If the template was authored inside your firm for this engagement, the answer is no. If you cite a proprietary tool, the answer becomes a procurement conversation you did not want.
PRML is a published specification with a Zenodo DOI, a CC BY 4.0 license, four reference implementations that produce byte-equivalent output, and an Article 12 / 17 / 18 / 50 / 72 / 73 crosswalk under public review. Your deliverable cites the spec. The artifacts are reproducible offline by the notified body. No proprietary tooling enters the client’s environment.
02What audit firms get
- A1A citable specification for Article 12 logging evidence patterns, with a clause-by-clause AI Act crosswalk already drafted for legal review.
- A2A reference CLI you ship into client environments: MIT-licensed, ~400 lines of Python, no runtime dependencies beyond the standard library.
- A3A public conformance vector suite (21 locked vectors across four language implementations) for assurance and second-opinion work.
- A4A GitHub Action and an MLflow plugin so client CI/CD pipelines can verify manifests at build time without bespoke integration.
- A5Zero vendor relationship. Clients verify SHA-256 hashes offline against any reference implementation. Nothing phones home, nothing requires an account.
03What we do not do
- We do not sell compliance dashboards. The open spec never requires a SaaS license: clients verify everything offline, forever. Hosted registry plans and written engagements exist separately for teams that want managed retention; see /pricing.
- We do not bid on Big 4 audit engagements. The conformity assessment market is not our market.
- We do not white-label the spec for any firm. PRML stays CC BY 4.0 under the spec author's editorship, attributable by name.
04How a Big 4 engagement uses PRML
- During client discovery, identify which Article 12, 17, and 18 evidence the client currently cannot produce for in-scope ML evaluation claims.
- Lock a PRML manifest for each in-scope claim during the engagement — metric, comparator, threshold, dataset hash, seed, producer identity — bound to a single SHA-256.
- Verify with the CLI (
falsify verify) before the regulator does. Exit codes are deterministic: 0 PASS, 10 FAIL, 3 TAMPERED, 11 GUARD. - Cite the specification (
spec.falsify.dev/v0.1) and the Zenodo DOI in your final report’s technical-documentation appendix. - Hand the manifest hashes and chain hash to the client for ongoing CI integration and post-market monitoring under Article 72.
The full Article-by-article mapping, with coverage scoring per obligation and open legal questions, is at spec/compliance/AI-Act-mapping-v0.1.md. v0.1 is the current stable spec; substantive comments on the clause-level bindings are welcome via GitHub issues.
05Partnership
We do not pay for placements and we do not accept payment for inclusion. We do publish a Featured implementers page for firms that contribute back: a notified-body case study, a clause-level mapping document against your existing methodology, or a written RFC-quality comment (the v0.2 window closed 2026-05-22; comments roll into the v0.3 cycle). Anything that improves the spec is in scope. Anything that brands the spec is not.
Write to [email protected] with subject prefix [AUDIT-FIRM] and one written question. Expect a written response within two working days.