Methodology

How Truveil scores AI agents.

Truveil is a rule-based, deterministic scoring engine. Same evidence in, same scores out. Calibrated against primary regulatory text across six major frameworks. This page explains the methodology at the level that matters for buyers, auditors, and the customers who will trust your audit reports.

Four dimensions, one accountability picture.

Truveil scores every agent run against four accountability dimensions. Each dimension corresponds to a category of regulatory obligation that recurs across all six frameworks Truveil covers.

How Truveil cites: two layers.

Every accountability signal is classified as either an AI-conduct signal (how the agent behaves: oversight, disclosure, reversibility) or a data-handling signal (how personal data is treated: accuracy, freshness, validation). Conduct signals anchor to binding AI law where one exists, such as the EU AI Act in the European Union. In jurisdictions without binding AI-conduct law, they anchor to Truveil methodology, informed by the EU AI Act and NIST AI RMF as reference standards, and the report says so in those words. Data-handling signals anchor to the jurisdiction's data-protection law: the DPDP Rules in India, the GDPR in the EU. Where a provision is not yet in force, the report carries its effective date rather than asserting a present-tense breach. An audit that cites law you are not yet bound by, as if you were, is not an honest audit.

Dimension 01
Transparency
What it captures

Can the agent explain what it did, why, and on what evidence? Does it disclose its AI nature to affected users?

Why it matters

EU AI Act Articles 12, 13, and 50. NIST AI RMF Measure. DIFC Regulation 10 transparency obligations. Singapore MGF-GenAI. In India, transparency signals anchor to Truveil methodology informed by the EU AI Act and NIST as reference standards; DPDP notice obligations apply to personal-data collection from 13 May 2027.

Dimension 02
Accountability
What it captures

Is there a named owner? A documented risk assessment? Human oversight where required? Approval gates on consequential decisions?

Why it matters

EU AI Act Articles 9, 14, 16, and 26. NIST AI RMF Govern. DIFC Regulation 10 accountability and Accountable Senior Officer provisions. UAE AI Charter. In India, accountability signals anchor to Truveil methodology informed by these reference standards; DPDP Rule 13 binds Significant Data Fiduciaries from 13 May 2027.

Dimension 03
Data Trust
What it captures

Is input data sourced from documented places? Is it fresh, validated, and grounded in cited evidence? Has bias evaluation happened where applicable?

Why it matters

EU AI Act Articles 10 and 15. NIST AI RMF Measure. Singapore MGF-GenAI data governance. In the EU, the GDPR. In India, DPDP Rules 6 and 8, effective 13 May 2027.

Dimension 04
Reversibility
What it captures

Can decisions be reversed? Is there a kill switch? Override controls? An appeal channel?

Why it matters

EU AI Act Articles 14(4), 20, 85, and 86. NIST AI RMF Manage. DIFC Regulation 10. UAE AI Charter principles on significant decisions. In India, DPDP Rule 14 anchors appeal and correction rights, effective 13 May 2027.

A research assistant is not graded like a hiring AI.

Truveil's engine recognises that not all AI agents carry the same regulatory weight. The engine classifies every registered agent into one of four categories at registration time.

Category 1
High-consequence decision-support

Hiring, lending, diagnosis, eligibility determination.

Subject to the strictest scoring across all four dimensions.

Category 2
Safety-critical autonomous control

Grid management, vehicles, surgery assistance, industrial automation.

Reversibility and human oversight signals weighted highest.

Category 3
Autonomous research and intelligence

Market briefs, literature review, competitive analysis, commercialisation strategy.

Scored on completeness and traceability of reasoning, with regulatory carve-outs for fields like bias evaluation that do not apply to research agents with no protected attributes in scope.

Category 4
Low-consequence analytical

Recommendations, tagging, content categorisation.

Lighter weighting on accountability and reversibility. Transparency baseline still required.

Customers buying Truveil for a Cat 1 hiring agent and Cat 3 research agent receive audit reports calibrated to the obligations that actually apply to each.

Six regulatory frameworks. One scoring engine.

Truveil's scoring engine is calibrated against primary regulatory text from six major frameworks. When your agent operates in a single jurisdiction, the audit cites that framework directly. When your agent operates across jurisdictions, Truveil applies the strictest rule per dimension and cites every applicable framework in the audit report.

EU AI Act

Articles 5, 9 to 15, 22, 25 to 27, 49, 72 to 73. Annex III high-risk categories. Article 14 human oversight. FRIA scope for essential services. Provider-deployer determination. Article 22 GDPR automated decisions.

NIST AI Risk Management Framework

Govern, Map, Measure, Manage functions. Generative AI profile (AI 600-1). Sectoral overlays for credit (FCRA), employment (EEOC), clinical (FDA), and housing (FHA).

India DPDP Rules 2025

Rule 3 disclosure, Rule 8 data freshness, Rule 9 owner identification, Rule 12 DPIA scope, Rule 13 audit cadence, Rule 14 reversibility controls. Significant Data Fiduciary obligations. Section 33 penalties. Substantive Rules take effect 13 May 2027; Truveil applies forward-looking framing until then.

DIFC Regulation 10

Autonomous Systems Officer appointment. Five ethical principles. Significant-decision oversight. Certification pathway.

UAE AI Charter

Federal AI Strategy principles. Significant-decision human oversight. Transparency and accountability standards. PDPL coordination.

Singapore Model AI Governance Framework

Nine dimensions of accountability. AI Verify testing alignment. MGF-GenAI profile. IMDA expectations for deployers and developers.

Truveil's engine is updated when these frameworks change. Updates flow through to your audit reports automatically. No version drift between what regulators require and what Truveil scores against.

Deterministic. Regulator-grounded. Model-independent.

Deterministic
Same logs in, same scores out.

Every audit Truveil produces is reproducible. The engine is rule-based with no probabilistic inference, no LLM-driven scoring decisions, no hallucinated compliance claims. Two auditors running your logs through Truveil reach the same conclusion every time. This matters for regulatory defensibility: an audit report that cannot be reproduced cannot be defended.

Regulator-grounded
Primary text, not approximations.

Truveil's scoring engine is calibrated against primary regulatory text retrieved from authoritative sources. Truveil's analytical layer sits on top of structured, JSON-grounded primary regulatory text. When the EU AI Act is updated, the JSON updates and Truveil's scoring follows. When India DPDP Rules issue clarifications, they propagate through the engine. Your audit report cites the framework, the article, and the obligation that applies.

Model-independent
Audit what the agent did, not how it was built.

Truveil does not care what model powers your AI agent. GPT-4o, Claude, Gemini, an open-source fine-tune: the audit layer treats them identically. Switch models without losing your audit history or your compliance baseline.

Your audit report.

Truveil generates audit-grade reports in under 30 seconds. Reports include grade, dimension scores, agent category context, framework citations, and remediation guidance. Plain language for legal and procurement teams. Regulatory citations for defence. Tracked over time so you can demonstrate improvement to regulators, auditors, and clients.

See sample reports