SETTING GLOBAL STANDARDS FOR TRUSTED AI CREDENTIALSAI Competence Framework v1.29 · current release
You are reading the current version of the framework, v1.29.Permanent address for this version
O3PUBLISHED

Assurance and audit

Statements for those auditing AI systems and the evidence behind them: engagement scoping, independence, evidence sufficiency and reporting obligations.

11 statements published at v1.29

What this overlay covers
INScoping an engagement so that what was and was not examined is unambiguous.
INMaintaining and demonstrating independence from the system being examined.
INJudging whether the evidence presented is sufficient to support the conclusion sought.
INReporting findings, including reporting that no conclusion can be reached.
INHandling pressure to soften or withdraw a finding.
OUTProducing the assurance evidence, which is D6. The overlay covers the obligations of the person examining it.
OUTStatutory audit competence outside AI systems.
OUTCertification decisions, which belong to the certifying body rather than the auditor.
How it combines with core statements

An audit credential is assembled from D6 evaluation and assurance statements at L3 or L4, plus O3 statements covering engagement, independence and reporting. D6 produces the evidence; O3 governs the person examining it.

Assembly shape
CoreDomain statements at the level the practitioner must hold themselves
OverlayO3 statements covering the obligations of this function

An overlay adds statements. It never modifies or replaces a core statement.

Statements by level

Every identifier is a permanent address. Indicators are normative; they state what would be observed in a person who meets the statement.

L2 Applied

3 statements

Collect evidence for an AI assurance review against a defined scope.

Indicators
Collects evidence against each requirement in scope
Records the source and date of each item
Identifies requirements for which no evidence exists

Test a stated control and record whether it operates as described.

Indicators
Tests the control rather than reading its description
Records the test, the sample and the result
Reports a control that exists but does not operate

Record a finding so that it can be acted on and re-tested.

Indicators
States the requirement, the evidence and the gap
Avoids stating a remedy as a finding
Enables re-testing without repeating the whole review

L3 Proficient

5 statements

Design the scope of an AI assurance review.

Indicators
States what is in scope, what is out, and why
Scopes to the consequence rather than to the available evidence
Records the limitations the scope imposes on any conclusion
O3.L3.02Judgement

Evaluate whether evidence supports the claim being made.

Indicators
Distinguishes evidence of design from evidence of operation
States what the evidence cannot establish
Declines to conclude where evidence is insufficient
O3.L3.03Judgement

Assess a coverage map or conformance claim critically.

Indicators
Checks the claim against the material rather than the summary
Identifies statements claimed as assessed but not assessed
Reports overstatement as a finding, not a comment
O3.L3.04Practice

Maintain independence and manage conflict in an assurance engagement.

Indicators
Declares interests before the engagement begins
Withdraws where independence cannot be maintained
Records the arrangement rather than relying on discretion

Report assurance conclusions, including unwelcome ones, with their basis.

Indicators
States the conclusion, the basis and the limitation together
Does not soften a conclusion the evidence supports
Provides the recipient what they need to act

L4 Advanced

3 statements
O3.L4.01Practice

Establish an assurance programme for AI systems across an organisation.

Indicators
Prioritises by consequence rather than by ease of review
Defines the cycle and the trigger for out-of-cycle review
Establishes how the programme itself is reviewed
O3.L4.02Judgement

Commission and evaluate independent assurance.

Indicators
Specifies scope and independence conditions
Evaluates the assurance provider’s competence and conflicts
Acts on findings that are unwelcome
O3.L4.03Practice

Hold the organisation to the standard its assurance claims imply.

Indicators
Escalates where findings are accepted but not remedied
Treats absence of evidence as a finding
Reports to the governing body without filtering
Relationship to domains
D6D6.L4.03 already references this overlay: an auditor holds the evaluation competences whose output they examine.
D8Security findings form a large share of audit scope; D8 statements define what the auditor must be able to read.
D7Governance statements define who the auditor reports to and what independence means in that structure.

This page displays version 1.29 · release record: /framework/v1.29