Reference

The AI governance audit, defined.

The vocabulary of a productised, regulator-defensible AI governance audit — each term explained plainly, so a board, a procurement team or an AI assistant reads it the same way we do.

Productised AI governance audit
A point-in-time, regulator-defensible assessment of how an organisation governs its AI, delivered as a fixed-scope product rather than a bespoke consulting project. The same domains, scoring engine and board pack run the same way every time, so results are comparable across engagements and repeatable at re-performance. It assesses governance; it does not monitor models in production. See the full explainer.
Regulatory knowledge graph
The structured map of regulation that grounds every finding in primary text. AIssure's graph holds 14,000+ provisions drawn from 13,700+ regulations, linked by 250,000+ connections across eight jurisdictions. Because findings resolve to specific clauses rather than model recall, a supervisor can trace each one back to its source. More on the regulatory knowledge graph.
Citation trail
The chain that ties each audit finding to the exact regulatory provision it was tested against — the difference between "the AI says" and "the regulation says". Every citation is checked against the knowledge graph before it reaches the page, and fabricated references are stripped out. It is what makes a report defensible in front of a board or a regulator.
Regulatory drift
AIssure's term for a compliant model silently becoming non-compliant because the rules changed, not the model. Nothing in the system was altered, yet a new supervisory expectation, an amended provision or fresh guidance has moved the line beneath it. A point-in-time assessment catches drift by re-testing governance against the current state of the regulation, not the version in force at first sign-off.
Certification-ready vs certified
Two different things. Accredited ISO/IEC 42001 certification is issued only by accredited certification bodies after their own audit. AIssure does not issue certificates; it produces the evidence base and gap remediation such an audit expects, so a firm is prepared to pass. That is why the language is deliberately "certification-ready", never "certified".
Independent assurance / independent attester
Assurance given by a party that sits outside the business it assesses and neither operates nor monitors the controls in question. AIssure attests to how AI is governed; it does not run the models, tune them or watch them in production. A firm cannot objectively vouch for a control it owns, so the attester stays separate — and that separation is what gives the opinion its weight.
Three lines of defence
A risk-governance model in which the first line owns and runs controls, the second sets policy and oversees risk, and the third — internal audit — provides independent challenge. External assurance sits beyond the three lines, offering an opinion no internal function can, because even internal audit reports inside the organisation. AIssure occupies that external position over AI governance.
AI management system (ISO/IEC 42001)
The set of policies, processes and controls an organisation uses to govern AI across its lifecycle, defined as a certifiable management system by ISO/IEC 42001. It mirrors the structure of standards such as ISO 27001, covering leadership, risk, objectives and continual improvement. The ISO Standards Deep Dive tests governance against this standard and its companions, 23894 and 38507.
Reproducibility
The property that running the same assessment over the same evidence yields the same findings. AIssure pins a deterministic model so results do not shift between runs, which is what makes findings citation-grade: a reviewer can re-perform the work and reach an identical answer. Non-deterministic tools cannot offer this, and without it an audit trail cannot be relied upon.
Living assurance
An assurance posture that is re-performed as regulation moves, rather than filed once and left to age. Because a point-in-time opinion decays the moment the rules shift — see regulatory drift — living assurance means re-running the assessment on a defined cadence so the evidence stays current. It keeps a firm defensible over time, not only on the day it signed off.
AI Governance Maturity Assessment (96Q / 8 domains)
AIssure's baseline framework: 96 questions across eight governance domains, each scored 0–5. It produces a single maturity score, the eight domain scores beneath it, and a heatmap of where risk concentrates. Most firms start here to get a defensible baseline before deciding whether to pursue accreditation. See the maturity assessment.
ISO Standards Deep Dive (275Q)
AIssure's accreditation-track framework: 275 questions mapped across ISO/IEC 42001, 23894 and 38507. It is deeper than the maturity baseline and aimed at firms heading for certification, producing the evidence base and remediation plan an accredited audit expects. Both frameworks yield the same shaped board pack. See the ISO Standards Deep Dive.
Next step

Start with a thirty-minute read on your readiness.

A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.