Process

How an AIssure engagement runs.

A board-ready assessment on a fixed clock — roughly five weeks from kick-off to a report the board can act on, run one of three ways. Here is what happens, what we need from you, and where the senior time lands.

What happens in an AIssure engagement

An engagement is a fixed arc, not an open-ended consulting project. It runs in five phases across roughly five weeks, and the shape is the same every time — which is what makes the result comparable across firms and repeatable at re-performance. The senior time is deliberately clustered at the two ends: scoping the assessment correctly, and turning the findings into a board pack that survives challenge.

Phase What happens Where the senior time sits
Firm-profile scoping You declare your jurisdictions and product lines. The scope tailors itself around them — a UK asset manager and a Singapore payments firm are asked different questions, and out-of-scope domains drop away before a single control is tested. Senior — heavy
Evidence gathering Your teams supply the model and use-case inventory, existing monitoring outputs, and governance policies. AIssure organises the evidence against the assessment framework so gaps are visible before scoring begins. Working level
Assessment Each control is scored against the regulatory knowledge graph, so every finding is tested against the primary provision it rests on rather than an analyst's recollection of it. Findings carry a citation trail from the outset. Working level, senior spot-checks
Board-ready report One document: the maturity score and its eight domains, the domain × jurisdiction heatmap, and a risk-weighted remediation plan. Every artefact inside it is cited back to source. Senior — heavy
Remediation tail The ranked plan hands the second line a defensible sequence of work. AIssure re-performs against the same fixed framework when you are ready to evidence progress — the point-in-time opinion, repeated. Light, senior on sign-off

The framework beneath the arc is fixed and versioned. Most firms run the AI Governance Maturity Assessment — 96 questions across eight domains, scored 0–5 — for a defensible baseline; firms heading for accreditation run the ISO Standards Deep Dive of 275 questions across ISO/IEC 42001, 23894 and 38507. Both produce the same shaped board pack.

Delivery

Three ways to run it.

The engine is one thing; who holds the controls is another. Pick the model by who runs the assessment and whose brand the report carries — the framework, scoring and citation trail do not change between them.

Self-serve

Your second line runs it.

Your risk or compliance function runs the assessment on the platform, at its own pace. Pick this when you have the second-line capacity and want the governance owned in-house — with the citation trail doing the heavy lifting.

Client-operated
Run-for-you

poview.ai consultants run it.

poview.ai runs the assessment as an independent engagement and hands you the board pack. Pick this when you want external assurance on the record, or when the first line is too close to the systems to assess them objectively.

Consultant-led
White-label

Ship it under your own brand.

Risk-advisory firms license the engine and deliver the assessment under their own name. Pick this to stand up an AI-assurance practice without building the knowledge graph yourself — AIssure is the engine behind other people's AI-assurance practices.

Licensed

What you bring

The assessment is only as defensible as the evidence under it, and the evidence lives in your firm already. Three inputs carry most of the weight:

  • A model and use-case inventory — what AI is in use, where, and for which decisions. This is what the scope tailors itself around; if it is thin, scoping surfaces that early rather than at reporting.
  • Your existing monitoring outputs — drift, bias and performance reports from whatever second-line tooling you run. AIssure reads these as evidence.
  • Your governance policies — model-risk framework, AI policy, senior-manager responsibilities and sign-off records.

One boundary is deliberate. AIssure consumes monitoring evidence; it does not produce it. It does not instrument your models or watch them in production — that is second-line tooling, operated by the firm that owns the models. Keeping the assessor outside the systems it assesses is what makes the opinion independent, and independence is the point of an assessment rather than a limitation of it.

Start with a pilot

Most firms begin with a fixed-scope, fixed-price pilot rather than a full-estate assessment. The pilot runs the complete arc — scoping through board-ready report — against a bounded slice of the estate, typically one business line or one high-risk model family, over roughly eight weeks end-to-end including reporting.

The pilot answers the question that matters before any wider commitment: does a cited, regulator-defensible assessment change how your firm can defend its AI to a board or a supervisor? Scope and price are agreed up front, so there is a fixed number to weigh against a fixed deliverable.

The outcome is certification-ready, not certified. An assessment prepares you for certification; it does not grant it. Accredited ISO/IEC 42001 certification is issued by accredited certification bodies such as BSI, Schellman or A-LIGN. AIssure produces the evidence base and remediation plan a certification audit expects — which is why we say certification-ready, and never "certified."

FAQ

Running an engagement — the questions we get.

What buyers, second-line teams and procurement ask before committing to an assessment.

How long does an AI governance assessment take?

About five weeks from kick-off to a board-ready report for a full assessment, with senior time clustered at the start (scoping) and the end (reporting). A first pilot is typically scoped at eight weeks end-to-end, including reporting.

Do you run it, or do we?

Either. Self-serve means your second line runs the assessment on the platform. Run-for-you means poview.ai consultants run it as an independent engagement. White-label means a risk-advisory firm licenses the engine and ships the assessment under its own brand. The framework, scoring and citation trail are identical across all three.

What do we need to provide?

Your model and use-case inventory, the outputs of any monitoring you already run, and your governance policies. AIssure consumes monitoring evidence — it does not run monitoring — so you keep operating your controls while an independent assessment is formed over them.

Does the assessment make us ISO 42001 certified?

It makes you certification-ready. Accredited ISO/IEC 42001 certification is issued by accredited certification bodies such as BSI, Schellman or A-LIGN. AIssure produces the evidence base and gap remediation a certification audit expects — the language is deliberately 'certification-ready', not 'certified'.

Next step

Start with a thirty-minute read on your readiness.

A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.