Choose which optional cookies and similar storage we may use. Strictly necessary storage is always on, because the site cannot work without it.

AI assurance for regulated organisations

AI assurance is evidence that your AI systems and agents are tested, controlled and ready for the rules that apply to them.

We provide it for insurers, banks, fintechs, healthcare providers and enterprise teams: which rules apply to each system and when, a register and test records for every agent, red-team results, and readiness for an ISO/IEC 42001 audit. Your people make the decisions, and we work alongside your legal advisers.

Last updated

Which AI rules apply, and when?

Some already apply. In the UK, the reformed UK GDPR rules on automated decisions are in force. In the EU, AI that talks with people has had to say it is an AI since 2 August 2026, and the high-risk rules follow on 2 December 2027 and 2 August 2028.

  1. Since 5 February 2026

    UK GDPR: automated decisions about people

    A decision made solely by automated means that significantly affects a person needs safeguards: the person is told about it, can ask for a person to review it and can challenge it. Decisions that use health or other special category data have stricter limits. These are the new Articles 22A to 22D of UK GDPR, added by the Data (Use and Access) Act 2025.

    Sources: legislation.gov.uk: Data (Use and Access) Act 2025, section 80, legislation.gov.uk: Commencement No. 6 Regulations 2026

  2. Since 2 August 2026

    EU AI Act, Article 50: transparency

    An AI system that talks with people, such as a chatbot or a voice agent, must tell them it is an AI unless that is obvious. Content an AI generates must carry a machine-readable mark, and deepfakes must be labelled. Systems already on the market before 2 August 2026 have until 2 December 2026 to add the mark.

    Sources: European Commission: guidelines on the transparency obligations, European Commission: Article 50 FAQ, EUR-Lex: Regulation (EU) 2026/1744

  3. From 2 December 2027

    EU AI Act, Annex III: high-risk uses

    Standalone AI used for high-risk purposes, including hiring, assessing individuals' creditworthiness other than to detect fraud, and risk assessment and pricing for life and health insurance, must meet the high-risk rules. Providers need risk management, data governance, technical documentation, logging and human oversight. Deployers must use the system as its provider instructs and keep a person overseeing it. For credit scoring of individuals and for life and health insurance risk assessment and pricing, deployers must also assess the system's impact on people's fundamental rights. The date was set by the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026.

    Sources: EUR-Lex: Regulation (EU) 2026/1744, European Commission: AI Omnibus enters into force, AI Act Service Desk: Annex III

  4. From 2 August 2028

    EU AI Act, Annex I: AI in regulated products

    AI that is, or is a safety component of, a product covered by EU product law that needs a third-party conformity assessment, such as a medical device that needs a notified body, comes under the high-risk rules on this date, also set by Regulation (EU) 2026/1744.

    Source: EUR-Lex: Regulation (EU) 2026/1744

Dates as they stood on 26 September 2026. Rules and dates change, so every review starts by checking where each one stands. Your legal advisers confirm how each rule applies to you.

What are supervisors asking about AI?

They are not waiting for the EU dates. The Prudential Regulation Authority's model risk principles for UK banks have taken in AI since 2024. In 2026, supervisors in the UK, the UAE and the US made AI a supervision topic for insurers, set out what they expect of banks and insurers, or began asking insurers structured questions about it.

  1. Since 17 May 2024

    UK: model risk principles for banks

    The PRA's SS1/23 defines a model broadly enough to take in AI, including models whose outputs are qualitative. It applies to banks with internal-model approval, and other banks may follow it as good practice. It does not cover insurers.

    Source: Bank of England: SS1/23 model risk management principles for banks

  2. January 2026

    UK: the PRA's priorities for insurers

    The PRA named AI adoption as a supervision topic in its 2026 priorities for insurers.

    Source: Bank of England: insurance supervision 2026 priorities

  3. February 2026

    UAE: the Central Bank of the UAE

    Its guidance note on responsible AI asks licensed financial institutions, insurers included, for board accountability, fairness, explainability, human oversight and sound data management, and says firms should not use AI models they have no control over. It is guidance, not a binding rule.

    Source: CBUAE Rulebook: guidance note on the responsible use of AI

  4. March to September 2026

    US: state insurance regulators

    Regulators working through the National Association of Insurance Commissioners (NAIC) piloted an AI Systems Evaluation Tool: a structured set of questions about an insurer's use of AI, asked during examinations.

    Source: NAIC: Big Data and Artificial Intelligence Working Group

EU AI Act readiness

Know which of your AI systems and agents the EU AI Act covers, the role you play for each one, and what you must have in place by each date.

  • An inventory of every AI system and agent you build, buy or use, including AI built into software you already run.
  • A classification for each one: prohibited, high-risk, transparency duties only, or minimal risk, with the reasons written down.
  • Your role for each system: provider, if you build it or put your name on it, or deployer, if you use it under your own authority. The duties differ.
  • What applies and when, from the transparency rules in force now to the high-risk dates in 2027 and 2028, with UK GDPR automated decision rules and your supervisor's expectations recorded alongside.
  • A plan in order of the dates: what to change, what to stop and what evidence to gather.

Who decides: The owner of each system approves its classification, and your accountable executive approves the plan, with your legal advisers' view.

Agent governance evidence pack

One set of records that shows what each AI system and agent does, how it was tested and who controls it, kept up to date as they change.

How our own agents stay under control
  • A register of your AI systems and agents: each one's task, owner, model, tools, the data it can reach, its permissions and the point where it hands over to a person.
  • Test and evaluation records: the test sets, the pass marks agreed with you, and the results again after every change of model, instructions or tools.
  • Logs of what each agent read, did and passed to a person, kept for as long as your sector's rules require and readable by the monitoring tools you already run.
  • Change records: what changed, why, who approved it and what the retest showed.
  • Answers ready for supervisors' and customers' questionnaires, drawn from the register, so the same facts give the same answer every time.

Who decides: Your model risk or AI governance committee owns the register, and a named business owner reviews the test results before each release.

Agent red-teaming

We attack your AI assistants and agents the way an adversary would, and show you what got through and how to close it.

  • Prompt injection, typed in directly or hidden in the documents, emails and web pages an agent reads.
  • Data leaks: whether an agent can be talked into revealing personal data, secrets or its own instructions.
  • Tool misuse and privilege abuse: whether it can be steered into actions outside its task, or into using permissions it should not have.
  • Risks between systems, where agents call other agents or third-party tools.
  • A retest after your fixes, so the final report shows what is closed and what is still open.

Each finding is mapped to the OWASP Top 10 for LLM applications (2026) and the OWASP Top 10 for Agentic Applications, with how to fix it. We test only systems you own or are authorised to test, under written rules of engagement.

Who decides: You decide which findings to fix and in what order, and your security lead signs off the retest.

ISO/IEC 42001 readiness

ISO/IEC 42001 is the international standard for an AI management system. We get your organisation ready to be audited against it; certification itself comes from an accredited certification body.

  • A gap analysis against ISO/IEC 42001: what you already have, what is missing and what to do first.
  • An AI policy, with roles and responsibilities, written with your team.
  • AI system impact assessments following ISO/IEC 42005:2025, the guidance on assessing an AI system's effects on people and society.
  • The records an auditor will ask for, drawn from your evidence pack where you have one.

Look for a certification body accredited against ISO/IEC 42006:2025, the standard for bodies that audit and certify AI management systems. We prepare you for that audit; we do not certify.

Who decides: Your top management approves the AI policy and holds the management review that decides when you are ready for audit.

Who is it for?

Regulated organisations using AI where a mistake would reach a customer, a patient or a supervisor. What a review looks at differs by sector.

  • Insurers and health payers

    The AI in your life and health pricing, your claims and underwriting agents, and the questions supervisors now ask about AI in insurance.

  • Banks, lenders and fintechs

    Classifying credit models under the EU AI Act's high-risk rules, onboarding and financial crime agents, a model inventory with risk tiers along SS1/23 lines, and evidence that you stay in control of every model you use.

  • Healthcare providers

    AI scribes, patient call and booking agents, and the supplier evidence behind the AI in medical devices you buy, in private healthcare and the NHS. We do not test clinical performance: that stays with the device's manufacturer and your Clinical Safety Officer.

  • Enterprise teams

    Assistants and agents across your teams, and the evidence your board and your customers' security questionnaires ask for.

How an assurance review runs

Five steps, from agreeing the scope to testing again after your fixes. You choose which of the four parts a review covers.

  1. Scope

    Agree which systems, agents and rules are in scope, who owns each one, and the rules of engagement for any testing.

  2. Inventory

    Find and record every AI system and agent, including AI inside software you buy, and classify each one.

  3. Test

    Evaluate each system against its task, and red-team the ones that act in your systems or talk to people.

  4. Report

    Findings, the evidence and a plan in order of your dates, written for your board and for the questions your supervisor asks.

  5. Retest

    Once you have fixed what you chose to fix, we test again and bring the evidence up to date.

What we do not do

Assurance supports your own compliance. Your organisation stays accountable for it, and your people make every decision.

Read our AI transparency statement
  • We do not certify. Certification comes from an accredited certification body that you choose; we prepare you for its audit.
  • We do not give legal advice. We work alongside your legal advisers, who give the legal view on each rule.
  • We do not guarantee compliance. The evidence shows where you stand; meeting each rule stays with you.
  • We do not speak for a regulator. A review by us does not mean a supervisor has approved your AI.

Questions people ask

What is AI assurance?

Evidence, gathered by review and testing, that an AI system does the job it was given, within the limits set for it, under the control of named people. It is what boards, customers, auditors and supervisors ask to see before they rely on an AI system.

Can you certify us to ISO/IEC 42001?

No. Only a certification body can certify you, and we suggest one accredited against ISO/IEC 42006:2025. We prepare you for its audit: the gap analysis, the AI policy, the impact assessments and the records its auditors will ask for.

Is this legal advice?

No. We provide the technical and governance evidence, and work alongside your legal advisers, who decide how each rule applies to your organisation.

Do you review AI we bought from other suppliers?

Yes. AI you buy is in scope as well as AI you build. We review and test any system you own or are authorised to test, under rules of engagement agreed in writing with your security team.

What do we have at the end of a review?

Depending on what the review covered: a register of your AI systems and agents, each one's classification and a plan, test and red-team results with the retest, and answers ready for the questionnaires you receive.

See where your AI stands against the rules.