Services
AI Assurance Service
Independent assurance for boards and governing bodies — gap analysis, readiness, and conformity evaluation of the AI estate against ISO/IEC 42001, the EU AI Act, and oversight expectations — so leadership can rely on evidence, not slideware.
The service
Governing bodies need justified confidence that AI systems align with organisational purpose, risk appetite, and legal duties. ISO/IEC 38507, ISO/IEC 42001, and the EU AI Act all assume that leadership can see impacts, residual risk, and control effectiveness — not a once-a-year narrative. This service is independent assurance to that audience.
We are not the implementer of the system we then assure, unless the board has explicitly split those roles. Findings are written for directors and the executive, with an evidence trail that internal audit, a certification body, or an authority can follow.
What we examine
- Gap analysis — AI estate versus ISO/IEC 42001, EN 18286 / Article 17 QMS, Article 9 risk, and deployer or provider duties that actually apply.
- Readiness assessment — completeness of inventory, impact and FRIA files, residual-risk acceptance, human oversight, and post-market monitoring.
- Conformity evaluation — structured review of evidence packs (AIMS hub, QMS file, AIIA/FRIA, audit results) and whether they support the claims management is making.
- Oversight design — whether the governing body has a usable line of sight from strategy to the processing envelope: inventory, KRIs, incidents, CAPA, and management review.
How an engagement runs
- Agree the assurance question, independence, and the systems in scope.
- Inspect inventory, AIMS/QMS records, impact assessments, and prior audit work.
- Interview process owners and sample high-impact systems.
- Report to the board or AI committee: findings, residual exposure, and a prioritised action list.
Who it is for
- Boards, AI committees, and governing bodies that must oversee AI
- Executives who need an independent view before certification or market launch
- Organisations that already run our platforms and want assurance on top of operation
Operational visibility for leadership is described on the AI Governance Multi-tiered Platform. Implementation work stays on AIMS as a Service and QMS as a Service so assurance remains independent.