Responsible AI assurance

AI Assurance, Evaluation & Impact Assessment

A reusable control framework for evaluating AI systems before and after deployment. It extends Raeburn's existing AI transparency, model cards, responsible-use policy and governance reference architecture.

Purpose & accountable owner

Document intended task, affected users, business owner and prohibited uses.

Data & privacy

Classify inputs/outputs, personal/confidential data, retention and provider boundaries.

Accuracy & task quality

Use task-specific test sets, error taxonomy, citation/grounding checks and acceptance thresholds.

Security

Test prompt injection, untrusted content, data exfiltration, excessive agency, tool misuse and permission boundaries.

Autonomy & consequence

Record tools/actions, reversibility, financial/external consequence, approval gates, spend/iteration limits and kill path.

Fairness & impact

Assess affected groups, accessibility, contestability and plausible adverse impacts proportionate to use.

Reliability & resilience

Measure failure rate, fallback, timeout, provider dependency, observability and incident response.

Cost & performance

Track latency, token/compute cost and quality/cost trade-offs rather than benchmark quality alone.

Human oversight

Define when review is mandatory, reviewer competence, escalation and who remains accountable.

Change management

Re-evaluate material model, prompt, tool, data-source and permission changes; retain version/evidence history.

Assurance status

Inventory → Impact screen → Evaluation plan → Tested → Approved with controls → Monitored → Re-evaluated/retired. A framework assessment is not a statutory certification or guarantee of safety.