Guide

What is AI assurance

An explainer on AI assurance, what it means, how it differs from AI governance, who provides it and what evidence it depends on.

What is AI assurance?

AI assurance is the work of giving a reader outside the team confidence that an organisation's AI is governed as it claims to be. Where AI governance is the practice of controlling AI, assurance is the practice of evidencing that control to someone who was not there and will not take your word for it. It runs from an internal review, through an independent opinion from an assurance provider, to certification against a standard, and each rests on the same foundation, records that show the governance actually happened. This explainer sets out what assurance means and what it depends on, anchored to ISO 19011 and ISO/IEC 42001. It is written for the senior owner who has to stand behind the claim, the chief audit executive, the chief risk officer or the audit committee.

AI governance and AI assurance are not the same thing

Governance is what you do. Assurance is how you show it. A function can govern its AI well and still fail at assurance, because doing the work and being able to prove it are different capabilities. Governance produces controls, owners and decisions. Assurance produces confidence in those controls for a reader who needs to rely on them, the board deciding whether to trust the program, the regulator testing whether it is real, the enterprise customer deciding whether to buy. A maturing function usually has governance in hand and is reaching for assurance, because that is the harder half.

The levels of AI assurance

Assurance comes in degrees, and it helps to name them. The first is self-assessment, where the organisation reviews its own governance against a reference and states where it stands. The second is independent assurance, where an internal audit function or an external provider examines the governance and gives an opinion on it. The third is certification, where an accredited body audits the organisation against a standard such as ISO/IEC 42001 and issues a certificate. Each level asks more of the evidence, and each carries more weight with the reader precisely because it does. The Institute of Internal Auditors’ Three Lines Model describes how these roles separate, with management owning the controls and an independent function providing assurance over them.

What every level of assurance depends on

Under all three levels sits the same requirement, evidence. ISO 19011 describes an audit as the gathering of evidence and its evaluation against criteria, and that holds whether the audit is internal or external. Assurance is only as strong as the records it draws on. A control someone describes in a meeting is a claim. A control with a dated record showing it operated is evidence. This is where most AI assurance is thin, because governance records often live in shared drives and email, where they prove their contents but not their history. Records that a reader can confirm are unchanged since capture move the assurance off the organisation’s word.

Why AI raises the assurance bar

AI makes assurance harder in specific ways. Systems change without a release, as a model is retrained or a vendor updates it underneath you, so a control that held at assessment may not hold now. Systems act, so the record of what a system did matters as much as the record of what it was allowed to do. And the population itself drifts, as teams adopt AI tools without a formal decision, so the first assurance question, what AI is even in scope, is one many organisations cannot answer confidently. Assurance over AI therefore depends on a current picture of the AI footprint, not a point-in-time snapshot.

What AI assurance is not

Assurance is not a guarantee that nothing will go wrong, and it is not a score that collapses the judgment into a number. An assurance provider forms an opinion. It does not certify that a system is safe or compliant in some absolute sense. The reader who understands assurance reads a clean opinion as confidence built on evidence, not as a promise. Framing assurance as a green light or a pass mark misrepresents what it is, and the sophisticated reader this work is for will notice.

Frequently asked questions

Who provides AI assurance? It depends on the level. Self-assessment is done by the organisation itself. Independent assurance is provided by an internal audit function or an external assurance firm. Certification is provided by an accredited certification body auditing against a standard. The three are complementary, and many organisations use all of them over time.

Is AI assurance the same as an AI audit? An audit is one way to provide assurance. Assurance is the broader idea, the confidence given to an outside reader, and an audit, whether internal or external, is the structured method most often used to produce it. Certification is an audit against a specific standard.

Do we need certification to have assurance? No. Certification is the highest-weight level of assurance but it is not the only one. Many organisations build strong internal and independent assurance without pursuing certification, and the evidence that supports certification is the same evidence that supports the other levels.

Does Aicura provide assurance? No. Aicura surfaces the governance picture and holds the evidence that assurance draws on. It does not audit your systems, provide an assurance opinion or certify anything. The assurance is provided by your internal audit function, an external provider or a certification body, and the accountable owner stands behind the governance.

Where Aicura fits

Aicura is your AI Register, so the first assurance question, what AI is in scope, has a current answer rather than a reconstructed one. It holds the AI systems in use as the record and versions each as it changes. Impact Assessments and Incidents hold the risk decisions and the events that assurance examines, sitting against the systems they concern and attributed to the people who did the work.

The Evidence Vault seals each record so it can be shown unchanged since capture, evidence you don’t have to trust us for, cryptographically anchored and verifiable without Aicura in the loop, which is what moves assurance off your word and onto the record. The Trust Centre lets you share that evidence with an auditor or an assurance provider directly, and Attestation lets an accountable owner sign a statement against it. Aicura surfaces the picture and holds the evidence. It does not audit your systems, provide an opinion or certify anything. Your assurance providers do that, and you stand behind the governance.

For the related work, read what counts as AI audit evidence and how to demonstrate AI governance. When an audit is coming, how to prepare for an AI governance audit sets out the preparation. The AI governance software overview sets out what Aicura supports.

Sources

  • ISO 19011:2018, Guidelines for auditing management systems, International Organization for Standardization, iso.org
  • ISO/IEC 42001:2023, AI management system, International Organization for Standardization, iso.org
  • The IIA’s Three Lines Model, Institute of Internal Auditors, theiia.org
  • Voluntary AI Safety Standard, Department of Industry, Science and Resources, industry.gov.au

A note on this page

This explainer is general information on what AI assurance means and what it depends on. It is not legal advice and it does not tell you what level of assurance a particular obligation or counterparty requires. For how assurance applies to your organisation, read the primary sources above and take your own professional advice.

When you need to show your work

Aicura is your AI Register, and Pro adds the assurance layer, meaning impact assessments, incident records, attestation and the Evidence Vault, which seals each record so it can be verified without taking anyone's word for it, ours included. Pro is sales-led, so the best next step is a conversation and a walkthrough.