AI Assurance
Methods for establishing that AI systems behave safely, reliably and in accordance with their intended purposes across contexts of deployment.
Overview
AI assurance is the engineering and organisational discipline that sits between AI ethics (what we want AI to do) and AI governance (the policies requiring it) — translating both into verifiable practice.
AI assurance concerns the methods, processes and standards by which AI systems can demonstrate they are safe, reliable, fair and fit for purpose — before deployment, during deployment, and over time. It is an applied discipline: its job is not to specify what AI should do (that is ethics) or to require it (that is governance) but to establish evidential warrant for claims about what AI systems actually do in practice. AI assurance asks: given a system with specified intended purposes and performance requirements, what evidence would you need to be confident it meets those requirements in the relevant deployment contexts?
The field has developed rapidly in response to the increasing deployment of AI in high-stakes contexts. The UK Government's AI Assurance Framework (DSIT, 2022) provides a structured approach: mapping AI risks, identifying assurance techniques (audits, evaluations, red-teaming, testing, certification), and establishing what evidence is required to demonstrate a system meets its requirements. ISO/IEC 42001:2023 — the AI Management Systems standard — provides an organisational framework parallel to ISO 27001 for information security: a systematic approach to managing AI risks across the development and deployment lifecycle. The NIST AI Risk Management Framework (2023) structures this organisational work under four functions: Govern, Map, Measure, Manage.
Technical assurance work has focused substantially on model documentation and auditing. Margaret Mitchell et al.'s "Model Cards for Model Reporting" (2019) introduced the concept of standardised disclosure documents for ML models — covering intended use, evaluation results across different population groups, ethical considerations, and known limitations. These are assurance artefacts: structured evidence that a model has been evaluated against the relevant requirements. Inioluwa Deborah Raji et al.'s "Closing the AI Accountability Gap" (2020) examined what internal model auditing actually requires in practice, finding that accountability requires structured processes, institutional authority, and systematic documentation — not just technical testing.
Assurance connects directly to the validation tradition in measurement: an AI system making inferences about people is making claims about what those inferences represent, and those claims require validation evidence. The interpretive argument framework from measurement theory — stating the chain of inferences and systematically testing each link — is the natural language for AI assurance programmes. Every inference has a claim structure; assurance is the process of evaluating the evidence for each claim.
Key Texts
Foundational works in this research tradition.
The UK policy framework for AI assurance: mapping AI risks, identifying appropriate assurance techniques, and establishing what evidence is required to demonstrate fitness for purpose. Sets out a layered assurance ecosystem from internal governance to third-party audit to standards certification.
The organisational standard for AI management: policies, processes, responsibilities, and evidence for responsible AI development and deployment. The AI equivalent of ISO 27001; provides a certifiable framework for AI governance across the development lifecycle.
Govern, Map, Measure, Manage: a structured approach to AI risk integrating technical and organisational practice. Provides detailed guidance on what each function requires and how they connect. Widely adopted as a baseline for AI assurance programmes in the US and internationally.
Standardised model disclosure documents: intended use, performance evaluation across population groups, ethical considerations, known limitations. Assurance artefacts that make model properties auditable. The most widely adopted format for ML model documentation.
What internal AI auditing actually requires: structured processes, institutional authority, systematic documentation, and clear criteria. Accountability cannot be achieved through technical testing alone — it requires organisational conditions that enable findings to be acted upon.
Related Research
Connected areas of inquiry.