TKOResearch
Menu

External review for AI developers and operators

Independent AI Control Review

Your team has written the policy and put controls in place. An outside reviewer should be able to tell you whether those controls work, where they fall short, and what the board needs to know.

TKOResearch assesses specified AI controls, monitoring and detection. Engagements can be mapped to the external-review commitment in the White House Accord on Super Intelligence, with findings prepared for technical leadership and board oversight.

Scope an independent review

Commitment and scope

What the White House accord asks for

The September 29, 2026 accord describes four layers of controls and review for companies training and deploying frontier models. It is a voluntary commitment. The published text does not establish an auditor accreditation, certification, audit schedule or pass/fail standard. Read the original accord.

Accord layer 01

Controls during training and deployment

Monitor model capabilities and alignment, address serious risk domains, and prevent unintended access to technical systems.

How the review supports it

Review the agreed access, monitoring and escalation controls against their intended behavior. Identify risk domains that need a separate specialist assessment.

Accord layer 02

An empowered internal team

Give an internal team responsibility for checking controls, monitoring, detection and remediation.

How the review supports it

Check ownership, internal review records, exception handling and whether reported problems reach someone with authority to act.

Accord layer 03

Independent external assessment

Engage an independent external auditor or evaluator to assess whether those mechanisms operate as intended.

How the review supports it

Assess the named controls using configuration inspection, operating records and agreed checks. Report supported conclusions, failures and gaps in coverage.

Accord layer 04

Independent board oversight

An independent board committee oversees and receives reports from control teams and internal and external reviewers, and ensures identified issues are remediated.

How the review supports it

Deliver the findings and remediation register to the agreed committee or sponsor. The company establishes the committee and remains responsible for action.

This service supports the external assessment and reporting work. A scoped report does not establish compliance with the entire accord, certify a model as safe, or replace the company's internal team and board responsibilities. TKOResearch is not a White House approved or accredited auditor.

What gets reviewed

We start with named controls and the behavior they are supposed to enforce: access boundaries, tool permissions, approval requirements, monitoring coverage, alert handling, escalation and remediation. The scope identifies the systems, model and configuration versions, review period and reporting recipients.

We inspect configurations and representative operating records, speak with the people responsible, and observe agreed checks in an authorized environment. A policy document or a vendor statement alone cannot establish that a control works.

The limits are part of the scope.

The accord also addresses model capabilities and alignment, biosecurity and chemical threats. This service focuses on security controls and their oversight. Specialized capability, biological or chemical evaluations require separately agreed work and named, qualified specialists. A cybersecurity review cannot stand in for those assessments.

If operating access or records are unavailable, we can scope a readiness review. Its report identifies preparation gaps; it does not conclude that the controls operate effectively.

What you receive

Control assessment

Each control is tied to a stated expectation, the records examined, the checks performed and a conclusion. Versions, dates, sampling limits and unavailable access stay in the report.

Board report

A concise account of material gaps, their consequences and the decisions needed. Findings trace back to the technical assessment so a board member can ask how a conclusion was reached.

Remediation register

Named owners, agreed priorities, target dates and closure criteria. A retest records what changed and what was checked again; a promised fix remains open until verified.

Findings distinguish observed behavior, client-supplied records and untested claims. Follow-up reviews are agreed around material changes, unresolved findings and the client's reporting needs; the accord does not prescribe a recurring audit interval.

Independence comes first.

Before accepting a review, we disclose relevant financial, product and prior advisory relationships. We do not provide an independent conclusion on controls we have designed, implemented or operated. Fees do not depend on a favorable result.

Kevin O'Connor leads the technical scoping. The proposal names the reviewers, their responsibilities and any specialist work required. Read Kevin's background.

Related commitments

The Seoul Frontier AI Safety Commitments also address mitigation effectiveness, external evaluations, governance and transparency. Where relevant, a scope can identify the specific commitments and the client's published safety framework being assessed.

These commitments concern frontier developers. An enterprise using an AI product can commission the same kind of control review without being a signatory. Any separate legal or contractual requirement needs its own criteria and coverage assessment.

Bring the controls you need reviewed.

Start with a short description of the system, the commitment or decision involved, the reporting audience and the deadline. We agree on scope and secure handling before receiving confidential materials. Keep credentials and sensitive records out of the initial contact form.

Discuss the review

Source notes · reviewed September 30, 2026

The mapping above uses the original accord text published by the President on September 29. The separately issued executive order on Super Intelligence concerns federal terminology; it does not establish an auditor certification. The assessment methods and deliverables on this page come from TKOResearch, not either government source.