Loading...
Governance · AI assurance
We review the AI you run, or plan to run, and show where people stay in control. Practical AI assurance services for UK organisations, mapped to the standards your auditors know.
In focus →
Where the line sits
The UK government describes AI assurance as measuring, evaluating and communicating the trustworthiness of AI systems.
In practice, that means evidence: who checks the AI’s work, when a case goes to a person, and what gets logged.
Most organisations have AI in use but no single record of where it sits or who owns it.
Our work closes that gap with a review you can hand to a board, an auditor or a client.

What the AI and tooling handle
What stays with a person
What we assure
We start with the question regulators ask first: can a person understand, question and override what the system does?
The ICO’s guidance on individual rights in AI is clear that a rubber-stamp review is not meaningful human oversight.
So we test the review step itself, not just the model.
We check who reviews, what they see, how long they have and whether they can overturn the output.
We then look at escalation rules, logs and the paper trail that proves the rules were followed.
If you are still choosing where to use AI, our AI readiness assessment is usually the better first step.
Illustrative batch with a typical confidence spread. Your real split comes from a pilot on your own work. Some decisions go to a person whatever the score.
Standards
The government’s Introduction to AI assurance lists techniques such as impact assessments, bias audits and performance testing.
We use those techniques, then map what we find to recognised standards.
ISO/IEC 42001 sets requirements for an AI management system.
The NIST AI Risk Management Framework gives a shared language for mapping, measuring and managing AI risk.
DSIT built its free AI Management Essentials self-assessment on those two frameworks and the EU AI Act.
Mapping to them means the work carries over if you later seek formal certification.
What we are not
We are not a UKAS-accredited certification body, and we do not issue ISO certificates.
Our AI audit is a structured, evidence-based review that prepares you for certification, procurement questions or a regulator’s enquiry.
That distinction matters, because the UK assurance market is still maturing.
DSIT’s own roadmap notes that none of the existing AI assurance competency certifications are issued by UKAS-accredited organisations.
The government is convening a consortium to work towards a future AI assurance profession.
Until that exists, ask any provider exactly what their report does and does not certify.
We are not a UKAS-accredited certification body, and we do not issue ISO certificates.
Outputs
You receive a written assurance report with findings ranked by risk.
Each finding names the control, the evidence we saw and the person who should own the fix.
You also get an oversight map showing every point where a person reviews, approves or can stop the system.
We include a control map against ISO/IEC 42001 and the NIST AI RMF.
Where your people will run the controls themselves, our AI governance training covers the practical skills.
You receive a written assurance report with findings ranked by risk.
How it works
Each system ships with a named person accountable for what it does.
01
We list the AI systems in scope, who owns each one and which decisions it touches.
02
We review logs, samples, supplier documents and the escalation rules as they actually run.
03
We sample outputs for accuracy and bias, and walk through the review step with the people who do it.
04
You get ranked findings, an oversight map and a control map, and we agree who fixes what.
Questions
Further reading
Keep reading
Next step
A 30-minute call. We map one workflow, what the AI could take, and where a person must stay in the loop.