Geneva, Switzerland

AI systems that survive an audit

I make AI systems defensible for organisations that have to prove how those systems behave — banks, insurers, medical device manufacturers, and the companies that sell to them.

Twenty years building software that had to pass inspection, including the international standard it was measured against. Independent, and with nothing to sell you but the work.

ISO/IEC 23092 International standard developed and edited first-hand
2 × CE Diagnostic software products through conformity assessment
80+ Patents granted worldwide, across 12 families
PhD · EPFL Two decades across research, standards bodies and industry

The problem

Everyone can demo an AI system. Almost nobody can evidence one.

The EU AI Act, ISO/IEC 42001 and the FINMA guidelines on artificial intelligence ask the same question in three different vocabularies: show me how this system behaves, and show me the evidence. Most teams can answer the first half. The second half is where mandates, certifications and audits actually fail.

A demo measures capability. Production measures consistency.

Agent success rates that look strong in a single controlled run collapse across consecutive runs at scale. Without a repeatable evaluation harness there is nothing to show an assessor, and nothing to manage.

Documentation written afterwards describes a company that doesn't exist.

Management systems assembled the month before an audit read as fiction, because they are. The practice has to come first; the documentation then has something true to describe.

You cannot retro-document a dataset nobody characterised.

Data governance requires provenance, characteristics and bias examination across training, validation and test sets. Capture it while the data is in front of you, or accept that the record cannot be reconstructed later.

What I do

Review it, or build it. Not both, not for the same client.

Everything below answers one question in different registers: can you show that this system does what you say it does? Each engagement is scoped in a first conversation and quoted as a fixed price before it starts — no open-ended day rates, no discovery phase that bills for itself.

Independent review

01

Independent model validation

Pre-production validation of an AI system by someone who did not build it, delivered with the evidence file an assessor will ask for.

  • Evaluation design and a harness you keep
  • Failure mode analysis and residual risk
  • Validation report and evidence pack
  • Aligned to FINMA expectations on model risk
Typically 3–6 weeks
02

AI management system

The management system ISO/IEC 42001 describes, built the way an audited quality system is built — the discipline that took two diagnostic products through ISO 13485 and IEC 62304, applied to AI.

  • AI inventory, ownership and risk register
  • Gap analysis against the standard
  • Change, incident and monitoring procedures that fit how you work
  • Documentation an assessor can follow
Typically 3–6 months
03

EU AI Act readiness

Where your systems sit under the regulation, what the deferred deadlines actually mean for your roadmap, and what to build now so 2027 and 2028 are uneventful.

  • Inventory and risk classification
  • Gap matrix against existing technical documentation
  • Article 50 transparency, already in force
  • Prioritised remediation plan with owners
Typically 2–4 weeks

Hands-on

04

Fractional AI lead

Two to four days a month as the technical lead a team doesn't have: the person who decides how the system is built, what evidence it produces as it runs, and which of the things on the roadmap should not be built at all.

  • Architecture and technical arbitration between engineering and compliance
  • Evaluation practice: harnesses, regression suites, what «good» means before you ship
  • Retrieval pipelines and agents taken from prototype to production
  • Coaching an in-house team rather than replacing it
  • Saying no to the features that would make the system indefensible
Monthly retainer, six months renewable

On any given client I will review the systems or build them, never both. Most of the firms now selling AI assurance hold commercial partnerships with the vendors whose systems they would be assessing; I have no such relationships and no product to place. Declining half the work is what makes the other half worth buying.

Track record

Twenty years of software that had to pass inspection

A selection, presented as evidence rather than as a chronology. The full history is on LinkedIn.

ISO/IEC JTC 1/SC 29Standards development

Developed and edited the ISO/IEC 23092 series — MPEG-G — the international standard for compression, transport and processing of genomic sequencing data. Led projects with up to 26 international partners through the full standardisation cycle, from first working draft to published standard.

GenomSys SACo-founder & CTO, EPFL spin-off · 2017–2023

Built the company from inception to twenty people and CHF 14M raised across three rounds. Architected three product lines — desktop, cloud and mobile — and took two diagnostic software products through CE marking and ISO 13485 certification. Filed twelve patent families, over eighty patents granted worldwide.

confinis SAHead of Software · 2024–2026

Led IEC 62304 software lifecycle management for regulatory compliance of software as a medical device, and implemented a quality management system to ISO 13485 with alignment to ISO/IEC 42001. Product owner of an AI regulatory platform co-developed with Zühlke, putting retrieval pipelines and agents into post-market surveillance, clinical documentation and regulatory watch workflows.

EPFLPhD, research and project management · 1999–2006, 2012–2017

Doctorate in digital rights management, followed by coordination of software projects in multimedia security and bioinformatics. Peer-reviewed publications across both fields, and four Swiss and European collaborative grants raised.

EarlierBanking, security, PKI · 2006–2012

Front office production engineering at Lombard Odier, supporting business-critical applications for 1,200 users. CTO and software architect at GlobeX Data on secure data storage. Encryption, digital signature and PKI work at WISeKey. Board member at Sekur Private Data Ltd since 2022.

About

Claudio Alberti

Both sides of the table

I have written an international standard and I have been audited against one. I have built AI systems in production and I have had to prove, afterwards, why they behaved the way they did. Those two experiences are rarely found in the same person, and the gap between them is where most AI governance work goes wrong — frameworks written by people who have never shipped, and systems shipped by people who have never been assessed.

I work from Geneva, in English, French and Italian. Swiss and Italian national. PhD from EPFL, MSc from Politecnico di Milano. Certified Scrum Master and Product Owner, AWS Certified Cloud Practitioner, TensorFlow Developer.

Contact

Start with the question, not the mandate

If you are trying to work out who validates your models before they reach production, or what the AI Act actually requires of your roadmap, that is a conversation worth having before it is a project. Write to me and describe the situation.

What helps

  • What the system does, in one paragraph
  • Who has to be convinced — a regulator, an auditor, a client, your board
  • Where you are: in design, in production, or already in an audit

Languages

  • Italian and French — native level
  • English — full professional
  • Spanish — intermediate