For the CRO

When the supervisor says show me.

Under the Senior Managers & Certification Regime, AI governance is personally yours to prove. AIssure turns that proof from a spreadsheet into a cited trail back to primary regulatory text — a board pack you can put in front of a supervisor without flinching.

The pressure you carry

AI risk did not arrive with its own accountability regime. It landed inside the one you already answer for. Under SMCR, the models your firm deploys, the decisions they drive and the governance around them all fall within a Senior Management Function — and the "reasonable steps" standard means the question is never simply "is it governed?" but "can you evidence that it is?"

Supervisors have made the expectation explicit. The FCA's SYSC sourcebook requires systems and controls proportionate to the risk an activity carries, and the PRA's SS1/23 model-risk principles now set a clear bar for how banks identify, own and validate the models — increasingly AI models — that shape material decisions. When either regulator asks you to demonstrate control, the answer has to be a cited trail to source, not a narrative.

There is a clock on it, too. The urgency is not a distant compliance deadline; it is a procurement gate. Counterparties and clients now ask for evidence of AI governance before they contract — and building a defensible evidence base takes preparation time you cannot compress once the request lands.

What a defensible answer looks like

Most firms can describe their AI governance. Far fewer can prove it on demand — because the proof lives in slide decks, spreadsheets and inboxes, and quietly scopes the awkward cross-jurisdiction findings out. That gap is exactly what a supervisor probes, and it is exactly what sits on the CRO's desk when it opens.

What AIssure gives the CRO

One board-ready document in which every artefact is cited, and nothing has been quietly excluded:

  • An AI Governance Maturity Score — the one number, and the eight domains underneath it, that your board paper opens on.
  • A domain × jurisdiction heatmap — where the risk concentrates, functionally and geographically, across all eight jurisdictions in scope.
  • A risk-weighted remediation plan — ranked by gap severity against the weight of the regulation behind each finding, so your committee time goes where the exposure is.
  • The citation trail — every finding addressable back to the source clause it was tested against, on a regulatory knowledge graph of 14,000+ provisions.

Independence is the whole point

AIssure is an external opinion, not self-marking. It attests to your governance; it never operates, monitors or remediates the AI it assesses. A control the firm runs cannot be objectively attested by the firm that runs it — which is why professional assurance ethics put the assessor outside the business. For a CRO defending a finding, that separation is what turns a report into evidence.

The deliverable, in your language

The output is not a maturity gradient dressed up as risk. It is scored the way a risk function scores: a defensible baseline from the AI Governance Maturity Assessment — 96 questions across eight domains, marked 0–5 — or, where you are heading for accreditation, the ISO Standards Deep Dive across ISO/IEC 42001, 23894 and 38507. Both produce the same board pack, comparable engagement to engagement and reproducible at re-performance. The result is certification-ready — the evidence base an accredited certification body expects — never "certified", because only that body can certify.

Regimes in scope
SMCR accountability · FCA SYSC · PRA SS1/23 model risk
Board artefact
A cited AI Governance Maturity board pack — one score, eight domains, every finding traced to source
Independence
An external opinion — AIssure attests, never operates or monitors
The risk if absent
Answering a supervisory "show me" with a spreadsheet that scopes cross-jurisdiction findings out
FAQ

For the CRO — the questions we get.

What a Chief Risk Officer asks before putting an AIssure board pack in front of a supervisor.

As Chief Risk Officer, am I personally accountable for how we govern AI?

Under the Senior Managers & Certification Regime the answer is effectively yes. AI risk sits inside the risk function you are certified to run, and the 'reasonable steps' standard means you are expected to be able to evidence — not merely assert — that AI-driven decisions are owned, explainable and aligned to your risk framework. AIssure produces that evidence in a form a supervisor will accept.

Will an AIssure assessment hold up if a supervisor challenges a finding?

That is the point of it. Every finding is traced to the primary regulatory provision it was tested against, on a regulatory knowledge graph of 14,000+ provisions across eight jurisdictions. The distinction that matters to a supervisor is the difference between 'the AI says' and 'the regulation says' — and a fabricated citation is stripped before it ever reaches the report. Because the assessment is fixed in scope and run the same way every time, it is reproducible: re-perform it and the same inputs give the same defensible answer.

Does AIssure monitor our models in production?

No — deliberately. AIssure delivers a point-in-time, independent assessment over your governance; it does not operate or monitor the models it assesses. A firm that runs a control cannot objectively attest to it, so keeping the assessor outside the business being assessed is what gives the board pack its standing. Runtime monitoring is second-line tooling; this is the third-line opinion that consumes its evidence.

Next step

Start with a thirty-minute read on your readiness.

A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.