Independent assessment

Technical and methodological audit of health AI systems

Before an investment, partnership or validation step, QSTOM-IT examines whether reported performance is supported by the data, reproducible within the accessible scope and consistent with the stated protocol.

7 to 10 business daysFocused scopeNo investment decision on your behalfDocumented report

Triggers

When should QSTOM-IT be involved?

  • Before a funding round or term sheet
  • Before an industrial or hospital partnership
  • When assessing a HealthTech or MedTech company
  • Before committing to a more expensive evaluation
  • When performance looks strong but is difficult to verify

Scope

What we seek to verify

Data

Provenance, cohort construction, representativeness, missingness, duplicates and potential leakage.

Protocol

Target, train/test split, temporality, comparators, metric selection and reproducibility.

Performance

Metric calculation, thresholds, calibration, subpopulations, false positives and false negatives.

Claims

The gap between observed results and the claims presented to decision makers.

Method

A short audit must stay focused

In 7 to 10 business days, the goal is not to reproduce an entire product. We identify the claims that matter most to the decision and look for risks that could materially change their interpretation.

Materials that may be reviewed

  • Technical data room
  • Data documentation
  • Training and validation protocols
  • Detailed results
  • Notebooks or code extracts
  • Experiment logs
  • Interviews with technical or scientific teams

Deliverables

  • Critical risk summary for decision makers
  • QSTOM Evidence Report
  • List of verified and unverified elements
  • Questions for the team
  • Recommended additional tests or evidence

Limits

What the audit does not do

  • Does not replace a clinical study
  • Does not constitute regulatory certification
  • Does not provide legal advice
  • Does not decide whether to invest
  • Does not conclude beyond accessible evidence

FAQ

Audit FAQ

Do patient data need to be transferred?+

Not necessarily. An initial review can be performed from documentation and the data room. When testing is required, we prefer execution in an environment controlled by the client.

Can you audit a model without code?+

Yes, but the level of conclusion will be limited. We explicitly distinguish what is documented, what has been tested and what could not be verified.

Do you work for the startup or the investor?+

Both are possible, but under different engagement types. Buyer-side due diligence is separated from readiness work commissioned by the company being assessed.

QSTOM-IT

Do you need to review a dossier before a decision?

Tell us the priority technical claims, timeline and available access. We will explain what can reasonably be verified within the window.

Request an audit