ordoia

The practice

Ordoia is a third-party AI assurance practice. We assess LLM and agent systems for grounding, reliability and production readiness before they are put in front of clients, auditors or regulators.

The UK government's Trusted Third-Party AI Assurance Roadmap names unclear quality standards as the first barrier facing this market. Our answer is a published, versioned, reproducible rubric that you can read, score yourself against, and hold us to.

Ordoia is built on twenty years of building and shipping production software. The failures we look for are the ones we have had to fix.

The category

Assurance, not observability. Instrumentation is how we gather evidence — tracing through the agent path, evaluation harnesses that score a distribution rather than a sample, alerting tuned to the shape of the answers. It is not what we sell. What we sell is the assessment it makes possible, and the fact that it came from somewhere other than the team that built the system.

That places the practice alongside auditors rather than alongside development tools. It is also why the constraints matter more than the capability: nobody asks whether their tracing vendor is third-party, because nothing turns on the answer.

The method

We assess under a fixed method, published before we look at anything. The criteria are numbered and dated. Every OAL 2 and OAL 3 in the rubric points at a named artifact — a code path, a configuration, a test run, a trace — rather than at our opinion, so that someone who is not us can check the award. Criteria that could only be satisfied by our say-so have been removed.

Eight dimensions in four pairs, four levels, and a published depth grid stating which levels inspection cannot reach at any price. The rubric is free, ungated and licensed for you to copy into your own internal standards.

The Ordoia Assurance Levels, v1.0

What is on the record

The apparatus, as it currently stands
MethodPublished in full. Current version OAL v1.0, dated 2026-09-19.
VersioningChanges classified as clarifying or breaking, with a one-line reason. Superseded versions stay published at permanent addresses, indefinitely. Changelog
RetentionWorking papers retained for six years, in redacted or derived form, with the redaction rule retained alongside.
LicenceCreative Commons Attribution 4.0, with the level names reserved.
ConstraintsPublished, and binding. What third-party means here
PricesPublished, fixed before an engagement starts, never contingent on the score. Services

Who assesses

Every assessment names the person who performed it and the methodology version it was performed under, and both are published on the face of the scorecard. That is an instrument of accountability rather than a credential: it exists so that a reader can tie a level to a person and a method, and so that a working paper six years old can be traced back to whoever wrote it.

Marketing pages carry no names, because the method is what a reader is being asked to rely on and it outlives whoever is currently applying it. Assessment artifacts carry them, because a score with nobody behind it is an opinion nobody signed.

The blank scorecard

Elsewhere

The practice publishes at infrasights.net.

Pronunciation

Ordoia — or-DOY-a. From ordo: order, sequence, rank.