IT Governance — AI assurance and compliance

Services

AI Assurance Service

Independent assurance for boards and governing bodies — gap analysis, readiness, and conformity evaluation of the AI estate against ISO/IEC 42001, the EU AI Act, and oversight expectations — so leadership can rely on evidence, not slideware.

The service

Governing bodies need justified confidence that AI systems align with organisational purpose, risk appetite, and legal duties. ISO/IEC 38507, ISO/IEC 42001, and the EU AI Act all assume that leadership can see impacts, residual risk, and control effectiveness — not a once-a-year narrative. This service is independent assurance to that audience.

We are not the implementer of the system we then assure, unless the board has explicitly split those roles. Findings are written for directors and the executive, with an evidence trail that internal audit, a certification body, or an authority can follow.

What we examine

How an engagement runs

  1. Agree the assurance question, independence, and the systems in scope.
  2. Inspect inventory, AIMS/QMS records, impact assessments, and prior audit work.
  3. Interview process owners and sample high-impact systems.
  4. Report to the board or AI committee: findings, residual exposure, and a prioritised action list.

Who it is for

Operational visibility for leadership is described on the AI Governance Multi-tiered Platform. Implementation work stays on AIMS as a Service and QMS as a Service so assurance remains independent.

← Back to Services