The audit, answered.
Straight answers on the productised AI governance audit — what it is, how it differs from runtime monitoring, and how an engagement actually runs.
What buyers and boards ask us.
The questions a CRO, a procurement team or an AI assistant asks about the productised AI governance audit — answered plainly, and cited where it matters.
What is a productised AI governance audit?
A point-in-time, regulator-defensible assessment of how your firm governs its AI, packaged as a fixed-scope product rather than a bespoke consulting project. Every finding is traced to primary regulatory text and the output is one board-ready report. It assesses governance; it does not monitor models in production, because that would compromise the independence assurance depends on.
How is AIssure different from a platform like Credo AI or Holistic AI?
Platforms such as Credo AI and Holistic AI are continuous, runtime tools that instrument deployed models and watch them for drift, bias and performance decay. AIssure is the independent, point-in-time assessment that sits over your governance and cites primary regulatory text. Different job, different shelf: the audit consumes monitoring evidence, it does not produce it.
Are we ISO 42001 certified when the audit finishes?
No — the audit makes you certification-ready, not certified. Accredited ISO/IEC 42001 certification is issued only by accredited certification bodies after their own audit. AIssure produces the evidence base and gap remediation a certification audit expects, so we say certification-ready and never claim to issue the certificate ourselves.
Which regulations and jurisdictions does AIssure cover?
AIssure is built for regulated finance and maps to the regimes that bind banks, asset managers and insurers across eight jurisdictions: the UK, EU, US, Singapore, Hong Kong, Australia, South Africa and China. Coverage spans the supervisory instruments within them alongside the ISO/IEC 42001, 23894 and 38507 standards, rather than a generic AI-ethics checklist.
What is regulatory drift?
Regulatory drift is a compliant model silently becoming non-compliant because the rules changed, not the model. Nothing in your system was altered, yet an amended provision or a new supervisory expectation has moved the line beneath it. A point-in-time assessment catches drift by re-testing governance against the current state of the regulation.
Can we run it ourselves, have you run it, or white-label it?
Three ways. Self-serve, where your team runs the assessment on the platform; run-for-you, where AIssure conducts it and delivers the board pack; and white-label, where an advisory firm delivers AIssure's assessment under its own brand. The framework, scoring engine and citation trail are identical across all three.
Do you monitor our models in production?
No. AIssure attests to how your AI is governed; it does not operate, tune or monitor your models in production. A firm cannot objectively vouch for a control it runs, so the attester stays outside the business being assessed. That separation is exactly what makes the opinion defensible.
How long does an assessment take?
About five weeks from kick-off to a board-ready report for a full assessment, with senior time clustered at the start and end. A first pilot is typically scoped at around eight weeks end-to-end, including reporting.
What are the two frameworks?
Two. The AI Governance Maturity Assessment is the baseline — 96 questions across eight domains, each scored 0–5 — and most firms start there. The ISO Standards Deep Dive is the accreditation track — 275 questions mapped across ISO/IEC 42001, 23894 and 38507. Both produce the same shaped board pack.
Is our evidence used to train AI models?
No. Evidence you provide is used to assess your governance and nothing else. It is not used to train AI models, and the assessment runs on a pinned, deterministic model so findings are reproducible rather than shaped by other clients' data.
How current is the regulatory knowledge graph?
The regulatory knowledge graph is refreshed on a quarterly cadence, so findings rest on the current state of the rules. It holds more than 14,000 provisions drawn from over 13,700 regulations across the eight jurisdictions, and re-performing an assessment against the updated graph is how a firm stays defensible as regulation moves.
Is AIssure point-in-time or continuous monitoring?
It is point-in-time. AIssure gives an independent assessment as at a defined date, not a live monitoring feed. Continuous, runtime monitoring is second-line tooling operated by the firm that owns the models; the audit is the third-line opinion over it, re-performed on a cadence as regulation changes rather than streamed.
Related
The AI governance audit
What the productised audit is and what it delivers.
→ ReferenceGlossary
Every term the audit rests on, defined plainly.
→ The moatThe regulatory knowledge graph
How the citation trail is built, versioned and verified.
→ ProcessHow an engagement runs
Five weeks, three delivery models, one board pack.
→Start with a thirty-minute read on your readiness.
A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.