The AI assurance framework

A practical AI assurance framework: pillars, controls and evidence requirements aligned to ISO/IEC 42001, NIST AI RMF and the EU AI Act.

A cross-jurisdiction governance framework

A cross-jurisdiction AI governance framework, structured around four pillars and built on recognised global standards. Developed with AIGP-credentialled practitioners and reviewed by an advisory council of legal, risk, and AI experts.

Four pillars cover every governance obligation

The framework is organised into four pillars: Regulatory and Legal Exposure, Board and Leadership, Operational Risk and Control, and Culture and People. Each pillar groups the controls that a board, regulator, or insurer would expect to see evidenced, regardless of jurisdiction.

Design principles

Evidence over assertion: every score is backed by a named artefact, policy, log, register, or attestation, not a self-declared maturity claim. Jurisdiction-aware by default: the same control library is mapped to each regulator's language, so one assessment speaks to multiple supervisors. Role-sensitive: obligations differ for providers, deployers, distributors, and importers of AI. Proportionate: controls scale with risk classification and company size, with no enterprise-only checklist forced onto a 50-person team. Human oversight is treated as a first-class control, with approval gates, escalation paths and override rights.

Mapped to the regulations that matter where you operate

AI Assured assessments translate one set of controls into the language of each regulator your company answers to. The mapping covers the EU AI Act's risk-tiered obligations for prohibited, high-risk and general-purpose AI, the UK's principles-based regulator-led approach, the NIST AI RMF Govern, Map, Measure and Manage functions, UAE and Singapore guidance, Canada's risk-tiered obligations and model risk expectations, and ISO/IEC 42001 as the cross-jurisdiction management system baseline.

ISO/IEC 42001 coverage, sized for your business

AI Assured maps directly to ISO/IEC 42001, the NIST AI Risk Management Framework, the EU AI Act, and the OECD AI Principles. ISO 42001 cost and timeline ranges reflect public-market pricing for external certification by an accredited body.

All pages

Independent AI governance assurance About AI Assured How AI Assured works The AI assurance framework AI Assured tiers Pricing Find your tier The assessment Governance templates Enterprise Compliance What AI assurance certification means Verify a certificate Knowledge base Become an assessor Contact Privacy policy Terms of service Terms of service (United States) Cookie policy Refund policy Tax information