Version 1.0 • Published July 2026 • AegisRT

AI Assurance Framework (AIAF)

An Interoperable Framework for Independent AI Assurance. A structured, evidence-based methodology for Independent and Continuous AI Assurance across the full lifecycle of AI systems.

Independent AI AssuranceContinuous AI AssuranceEvidence-Based EvaluationHuman Professional Judgement
AIAF Assurance Architecture
1. Assurance ObjectivesDefine what must be evaluated and why.
2. Evidence & EvaluationCollect sufficient, appropriate evidence through governance review and technical testing.
3. Professional JudgementInterpret evidence in the context of system purpose, risk and operating environment.
4. Reporting & Re-AssuranceCommunicate findings and repeat assurance as systems and risks change.

Independent AI Assurance is the systematic, evidence-based and professionally governed evaluation of an AI system against defined assurance objectives, undertaken to establish justified confidence in its governance, performance, security, reliability and continuing operation.

Why AIAF was created

AI governance frameworks define principles, controls and organisational expectations. AIAF focuses on the assurance methodology required to evaluate whether those expectations are supported by sufficient and appropriate evidence in practice.

What AIAF does not replace

AIAF does not replace legislation, regulation, AI management systems, risk-management frameworks, sector rules or professional standards. It provides an interoperable assurance methodology that can be applied alongside them.

The AIAF assurance architecture

The framework connects governance expectations with evidence, technical evaluation, professional judgement, reporting and continuous re-assurance.

Governance Context

Understand system purpose, accountability, policies, controls, risk classification and applicable requirements.

Assurance Objectives

Translate governance and risk expectations into clear, testable assurance questions.

Evidence Collection

Obtain documentation, records, system outputs, evaluation results and other relevant evidence.

Technical Evaluation

Apply validation, testing, red teaming, robustness assessment and other procedures appropriate to the AI system.

Professional Judgement

Assess the sufficiency, appropriateness, limitations and significance of the available evidence.

Findings & Conclusions

Form proportionate conclusions against the defined assurance objectives and risk context.

Assurance Reporting

Communicate evidence, limitations, findings and recommendations to intended users.

Continuous Re-Assurance

Repeat or update assurance after material system, model, data, prompt, tool, workflow or operating changes.

Core principles

AIAF is designed to support credible, proportionate and repeatable assurance while preserving the role of accountable human judgement.

Independence

Assurance should be sufficiently separate from development, implementation and commercial interests to support objective conclusions.

Evidence-Based

Conclusions should be grounded in evidence that is relevant, reliable and appropriate to the assurance objective.

Risk-Proportionate

The nature, timing and extent of assurance procedures should reflect system impact, complexity and exposure.

Lifecycle-Oriented

Assurance should address development, deployment, production operation and significant change—not only a single pre-deployment review.

Human-Governed

AI and automation may support assurance procedures, but accountable professional judgement remains necessary.

Transparent Limitations

Reports should clearly communicate scope, evidence boundaries, assumptions, limitations and residual uncertainty.

Independent and Continuous AI Assurance

AIAF treats assurance as a lifecycle discipline rather than a one-time certification event.

Assurance stagePurposeTypical triggers
Initial AssuranceEstablish evidence before deployment or material use.New model, new application, first production release.
Production AssuranceEvaluate whether the system continues operating within approved expectations.Periodic review, monitoring signals, incidents or emerging risks.
Change AssuranceRe-evaluate the system after material change.Model, data, prompt, RAG, tool, workflow, agent or environment changes.
Enterprise Assurance EvidenceProvide decision-useful evidence for oversight and accountability.Board, risk, audit, customer, regulator or procurement requirements.

Standards interoperability

AIAF is intended to complement applicable governance, risk, security, privacy and AI management frameworks. It standardises the methodology of assurance—not the regulation of artificial intelligence.

  • AI governance and management systems
  • Enterprise and model risk frameworks
  • Security, privacy and resilience requirements
  • Sector-specific laws and supervisory expectations

Operationalised through AegisRT

AegisRT applies the framework through independent assessments, AI red teaming, technical evaluation, assurance reporting and Continuous AI Assurance engagements.

Official publication and citation

AIAF Version 1.0 was published in July 2026. ResearchGate is the official public publication page for this framework.

Official AIAF Publication

AI Assurance Framework (AIAF): An Interoperable Framework for Independent AI Assurance

Read the complete framework on ResearchGate.

Publication Details

AIAF Version 1.0
Author: Chenyi Ang
Published July 2026
Published by AegisRT

Framework Position

AIAF provides an interoperable methodology for Independent AI Assurance and Continuous AI Assurance. It is distinct from AegisRT's separate technical research and LinkedIn thought-leadership articles.

Recommended citation (APA 7th style)

Ang, C. (2026). AI Assurance Framework (AIAF): An Interoperable Framework for Independent AI Assurance (Version 1.0). AegisRT. https://www.researchgate.net/publication/410600679_AI_Assurance_Framework_AIAF_An_Interoperable_Framework_for_Independent_AI_Assurance

Build assurance into the AI lifecycle.

Use AIAF as a methodological foundation and engage AegisRT for independent assessment, AI red teaming, re-assurance and Continuous AI Assurance.