Skip to content

AI assurance: what it is, and how to get assurance-ready

11 min read by John Bagnall

AI assurance is how you prove your AI is trustworthy. More precisely, and this is the UK government’s own definition, it is the process of measuring, evaluating and communicating the trustworthiness of an AI system, so that the people who rely on it can place justified trust in it. The idea is not new: it is borrowed straight from accountancy, cyber security and quality management, where “assurance” has always meant producing reliable evidence that something works as claimed.

Here is why it suddenly matters to you commercially. An AI system can be perfectly trustworthy and still lose you the deal, because the buyer has no way to know it is. Assurance closes that gap. And as enterprise buyers, their security teams and procurement functions start to vet the AI you sell, assurance is turning from a nice-to-have into a condition of selling AI at all. This post is what it is, the techniques involved, how it relates to standards and the law, and how to get assurance-ready before the questions start stalling deals.

Assurance, governance, and “trustworthy AI” are not the same thing

Three terms get used interchangeably and shouldn’t be.

  • Trustworthy AI is the set of properties you want: fairness, safety, robustness, transparency, security, accountability. It is the what.
  • AI governance is how you run and oversee the AI internally to achieve those properties: the policies, roles, controls and management system. It is doing it.
  • AI assurance is the layer that demonstrates it to other people: it measures and evaluates the system and communicates the evidence, so a customer, regulator or board can trust it. It is proving it.

The UK government is explicit that assurance is a key part of broader governance, not a synonym for it. The distinction matters because it is easy to have the first two and fail at the third: to run your AI responsibly and still be unable to show it when someone asks.

There is one line from the government’s guidance worth keeping in mind, because it draws the boundary between real assurance and hand-waving: “without standards we have advice, not assurance.” An opinion that your AI is fine is not assurance. Evidence, measured against an agreed standard, is.

Why assurance is suddenly a commercial issue

For years, “responsible AI” was a marketing page. That is ending. The shift, which we see in enterprise procurement, is from “do you have responsible-AI principles?” to “show us the evidence your AI management system is actually operating.” A policy PDF no longer clears the bar.

Enterprise vendor-risk questionnaires now routinely carry a dedicated AI section: what data your model was trained on and whether you have the rights to it, how you monitor for harmful or hallucinated output, who your AI sub-processors are, whether you align to ISO 42001 or the NIST AI Risk Management Framework. Deals stall where the vendor cannot produce documentation. This is the exact mirror image of the discipline we describe in how to evaluate an AI vendor: the questions you should ask of a supplier are the questions your buyers are now asking of you.

So assurance is a deal-enabler. It is what lets you sell AI into cautious, regulated enterprises, and the government frames it in exactly those terms, as a route to competitive advantage, customer trust and managed reputational risk. Getting assurance-ready is not a compliance chore; it is removing a reason for a buyer to say no.

The assurance toolbox

There is no single technique that “assures” an AI system. Assurance is a spectrum of techniques used in combination across the lifecycle, and the depth scales with risk: a low-risk internal tool needs a few; a high-risk system needs a robust combination. It helps to group them by what they actually do.

Techniques that assess (generate evidence about the system):

  • Risk assessment identifies what could go wrong, bias, privacy, misuse, reputational harm, from developing or deploying the system.
  • Impact assessment anticipates the wider effects on people, rights, equality and society.
  • Bias and fairness audits examine the inputs and outputs of a system to test whether it treats people unfairly.
  • Performance testing and model evaluation measure how well the system does its job against a defined metric, the same discipline as building an evaluation harness.
  • Formal verification uses mathematical methods to prove a system meets a specific requirement.
  • Red-teaming and adversarial testing deliberately try to break the system to surface failures and harms before real users do.

Techniques that assure (attest a claim against a standard, to others):

  • Compliance audits review adherence to internal policies, regulations and legal requirements.
  • Conformity assessment demonstrates a product meets defined requirements before it goes to market (often including performance testing).
  • Certification is an accredited body attesting that a system or organisation meets a standard.

And the layer that communicates: transparent documentation, model cards and the like, which set out a system’s capabilities, limitations and intended use so others can judge it.

Measure, evaluate, communicate. That tripartite shape is the definition of assurance made practical, and it is why documentation is not an afterthought: it is the deliverable.

Who does the assuring: first, second and third party

Not all assurance carries the same weight, and the difference is who is doing it.

  • First-party (self-assessment): you assure yourself, your own impact and risk assessments, your own model cards. It is the foundation everything else builds on, and fine for lower-risk systems, but it is the least independent, so the least persuasive to a wary buyer.
  • Second-party: a party with a direct interest assesses you, typically the customer, through their vendor questionnaire and procurement due diligence. Credible, but buyer-driven and specific to their needs.
  • Third-party: an independent, accredited body assesses or certifies you against a standard. This is the most credible and the most costly, and it is what high-risk systems, regulated contexts and deal-making increasingly call for. It is also the layer the UK is actively trying to grow (more on that below).

The rule of thumb: the higher the stakes and the more sceptical the audience, the further toward independent third-party assurance you need to go.

Where assurance meets the standards and the law

Two mechanisms turn assurance from a concept into something an auditor or regulator recognises.

ISO/IEC 42001 is the first internationally certifiable standard for an AI Management System. An accredited third party can audit your management system and certify that it meets the standard, typically on a three-year cycle with annual surveillance audits. A companion standard, ISO/IEC 42006, sets the requirements for the certification bodies themselves, their competence and impartiality, which is what makes a 42001 certificate worth anything. In assurance terms: 42001 is what you get certified against; 42006 governs who is competent to certify you. We cover whether you actually need it in do you need ISO 42001?. One caveat to state plainly: 42001 certifies the management system around your AI, not the correctness of any single model’s outputs. It says you govern your AI well, not that the model is never wrong.

The EU AI Act makes third-party-style assurance effectively mandatory for high-risk AI, through conformity assessment. Article 43 sets out two routes: an internal-control (self-assessment) route, and a notified-body (independent) route, depending on the system and whether harmonised standards have been applied. The provider then draws up an EU declaration of conformity (Article 47) and affixes the CE marking (Article 48). In practice most high-risk categories currently self-assess against the Act’s requirements, and the standards machinery is still being built, but the direction is clear: for high-risk AI, “prove it” becomes a legal duty, not a courtesy.

The through-line is simple. Assurance is what lets you answer the question “prove your AI is safe and compliant.” ISO 42001 is the management-system proof; the EU AI Act conformity route is the product proof for high-risk systems; and the assessment techniques are the granular evidence that feeds both.

How to get assurance-ready

You do not become assurance-ready the week a buyer sends the questionnaire. You build the evidence base in advance. A defensible sequence:

  1. Know your AI. Build an inventory of every AI system and use, built, bought or embedded, with owners, purpose and data. You cannot assure what you cannot see, and it is the first thing an auditor or a procurement team asks for.
  2. Classify each use by risk. Tier them, and align to the EU AI Act categories if you touch the EU. Proportionality is the governing principle: effort follows risk.
  3. Run impact and risk assessments on the higher-risk uses. This is the assessing layer that generates your evidence.
  4. Put controls and documentation in place. Policy, human oversight, monitoring, incident handling, and the records and model cards that make it all demonstrable. This is what an ISO 42001 management system systematises.
  5. Choose assurance techniques matched to the risk. Bias audit, evaluation, red-teaming, compliance audit, underpinned by standards so it is assurance, not advice.
  6. Get independent assurance where it earns its place. ISO 42001 certification, an independent audit, or EU AI Act conformity assessment for high-risk systems. Do not certify everything; certify where the risk and the commercial payoff justify it.
  7. Keep the evidence current. Assurance is continuous: surveillance audits, re-assessment when the model changes, ongoing monitoring. Certificates and assessments go stale.

The spine of all of this is a working AI Management System. It is what turns scattered good intentions into the auditable artefacts, the governance intent made operational proof, that a buyer’s questionnaire and a regulator both want to see.

The UK is trying to build an assurance market

This is not a fringe idea. The UK government has made AI assurance a deliberate policy priority. Its Department for Science, Innovation and Technology published “Introduction to AI assurance” in early 2024, and the CDEI, now DSIT’s Responsible Technology Adoption Unit, maintains a Portfolio of AI Assurance Techniques (with techUK), a growing catalogue of real-world assurance case studies. In September 2025 DSIT went further, publishing a roadmap to grow a trusted third-party AI assurance market, projecting it could exceed £18.8 billion in value by 2035, up from around £1 billion in 2024, and setting out plans for professional certification and accreditation to make independent assurance credible at scale.

Why does that matter to you? Because it tells you where this is heading. A market is forming around independent verification of AI, precisely because self-declared trust is not enough for the organisations, and regulators, buying and overseeing AI. Being early to assurance is a commercial position, not just a compliance one.

Common misconceptions

  • Assurance is not a one-off certificate. It is a continuous process. Models drift, certificates expire, evidence goes stale.
  • A policy is not assurance. Having principles is not the same as evidencing they operate. “Without standards we have advice, not assurance.”
  • You cannot assure what you cannot measure or see. No inventory and no metrics means no assurance. That is why it starts with the register.
  • Third-party audit does not remove your accountability. Under the EU AI Act the provider still signs the declaration and carries the liability. A certifier attests; it does not take on your responsibility.
  • Assurance does not mean the AI is perfect. It means justified trust proportionate to risk, communicating limitations and residual risk honestly, not claiming flawlessness.
  • Beware ethics-washing. A lone certificate waved as blanket proof, or “responsible AI” as a slogan, invites scrutiny. Assurance claims must be specific, scoped and evidenced. Being certified to ISO 42001 says your management system is sound; it does not say your model is guaranteed accurate. Be precise about what each mechanism actually covers.

The short version

AI assurance is how you prove your AI is trustworthy: measuring it, evaluating it and communicating the evidence, so others can place justified trust in it. It is distinct from governance (running the AI) and from trustworthy AI (the properties themselves), and it is fast becoming a condition of selling AI, because buyers now want evidence, not principles. Build it as a real capability: inventory and classify your AI, assess the risky uses, put controls and documentation in place, apply assurance techniques proportionate to risk, get independent certification where it pays, and keep the evidence current on top of an ISO 42001 management system. Do that and when a customer, board or regulator asks how you control your AI, the answer, with evidence, is already there.

Want to know how assurance-ready you are? The free AI governance readiness assessment gives you a quick, no-email read on your governance and assurance maturity in about ten minutes. When you want to build the evidence base and get certification-ready, talk to us.

For the full picture, see the AI governance guide.

Frequently asked questions

What is AI assurance?

AI assurance is the process of measuring, evaluating and communicating the trustworthiness of an AI system, so that people who rely on it can place justified trust in it. That is the UK government's own definition. The idea is borrowed from accountancy, cyber security and quality management: assurance closes the gap between an AI system being trustworthy and other people actually trusting it, by producing reliable, standardised evidence. It covers everything from risk and impact assessments to independent audits and certification.

What is the difference between AI assurance and AI governance?

Governance is how you run and oversee AI internally: the policies, roles, controls and management system that keep it safe and compliant. Assurance is the layer that demonstrates that to others: it measures and evaluates the system and communicates the evidence so a customer, regulator or board can trust it. The UK government frames assurance as a key part of broader governance, not a synonym. Put simply, governance is doing it; assurance is proving it.

What are AI assurance techniques?

A toolbox used in combination and matched to risk: risk assessment, impact assessment, bias and fairness audits, compliance audits, conformity assessment, formal verification, performance testing and model evaluation, red-teaming, transparent documentation such as model cards, and certification. Some techniques assess the system to generate evidence; others assure others by attesting a claim against a standard; documentation communicates it. Low-risk uses need a few; high-risk uses need a robust combination.

Can you get AI certified?

You can certify your AI management system. ISO/IEC 42001 is the first internationally certifiable standard for managing AI, and an accredited third party can audit and certify that your management system meets it, on a three-year cycle with annual surveillance. A companion standard, ISO/IEC 42006, sets the requirements for the bodies that do that certifying, which is what makes the certificate credible. Note the scope: 42001 certifies the management system around your AI, not the correctness of any single model's outputs.

Why do businesses need AI assurance?

Because assurance is becoming a condition of doing business. Enterprise buyers, their security teams and procurement now vet the AI you sell, and increasingly ask for evidence that an AI management system is actually operating, not just a responsible-AI policy. Assurance is what lets you answer those questionnaires, win the deal and manage reputational and regulatory risk. The UK government itself frames assurance as a source of competitive advantage and customer trust.

How do you become assurance-ready?

Build the evidence base before anyone asks for it: inventory your AI, classify each use by risk, run impact and risk assessments on the higher-risk ones, put controls and documentation in place, choose assurance techniques proportionate to the risk, get independent audit or certification where it earns its place, and keep the evidence current. An ISO 42001 management system is the spine that produces the auditable artefacts assurance depends on.


Building something you need to govern?

Start with a fixed-scope AI Opportunity & Risk Audit.

Meet an Expert