Back to Framework

Assurance and Audit

Control statements and requirements for assurance and audit.

Internal Assessment & AuditAA-1

The organisation shall establish and maintain comprehensive internal assessment and audit procedures for AI systems throughout their lifecycle. This includes documented verification of controls and validation of system behavior in both controlled and real-world conditions. Internal audits must evaluate compliance with organisational policies and procedures. Internal assessment and audit activities must cover normal operations, edge cases, and stress conditions. The organisation shall maintain evidence of all audit activities, findings, and remediation efforts.

ISO42001:9.1 9.2 9.3 A.6.2.4
ISO27001:9.1 9.2 9.3 A.18.2
ISO27701:8.2.3 18.2.2 A.7.2.5 A.7.4.3
EU AI ACT:9.7-9.8 17.1-17.2 60.1-60.9 61.1 61.2
NIST RMF:Map 2.3 Measure 2.1 Measure 2.3 Measure 2.5
SOC2:PI1.1 PI1.2 CC4.1

Independent Assessment and CertificationAA-2

The organisation shall ensure regular independent assessments of AI systems are conducted and maintain necessary certifications. Independent assessors must have appropriate expertise and authority to evaluate compliance with regulatory requirements and performance standards. For stand-alone high-risk AI systems, the organisation shall implement self-assessment processes to verify compliance, ensuring alignment with regulatory requirements. The organisation shall obtain and maintain required certifications, track certification status, and implement corrective actions when gaps are identified. Assessment and certification activities must be documented, including findings and evidence of remediation.

ISO42001:9.1 9.3 10.1 10.2
ISO27001:9.1 9.3 10.1 10.2 A.18.1 A.18.2
ISO27701:7.2.1
EU AI ACT:20.1 22.3-22.4 40.1 43.1-43.4 44.2 44.3
NIST RMF:Measure 1.3 Measure 4.2 Govern 4.3
SOC2:CC4.2 CC3.1

Safety and Security ValidationAA-3

The organisation shall conduct regular testing of AI system safety and security controls, including assessment of cybersecurity measures, resilience against attacks, and ability to fail safely. Testing must verify that systems operate within defined risk tolerances and maintain effectiveness of protective controls. Validation must include both automated testing and expert review of safety measures. The organisation shall maintain documentation of all safety and security assessments, including methodology, results, and remediation of identified issues.

ISO42001:9.1 9.3
ISO27001:9.1 9.3 A.18.1 A.18.2
ISO27701:7.2.5
EU AI ACT:41.1-41.2 42.1-42.2
NIST RMF:Measure 2.6 Measure 2.7
SOC2:CC7.1