06 Monitor · Continuous AI Assurance
Assurance does not stop at deployment.
A standing independent assurance relationship over deployed AI. We reassess control performance, changes, usage drift, incidents, overrides, evidence quality and regulatory movement on a defined cycle, and report to the accountable owners.
The assurance cycle
- 01Reassess controls against current operation
- 02Review change, drift and expanded usage
- 03Examine incidents, overrides and exceptions
- 04Reassess residual risk and acceptance
- 05Report to accountable owners and the board
Who this is for
Organisations operating AI that keeps changing after the sign-off.
- Organisations with deployed AI and no standing independent challenge
- Boards receiving assurance only when something goes wrong
- Firms whose AI vendors ship model and feature changes continuously
- Risk functions without in-house AI assurance capability
- Organisations expanding an approved system into new workflows
Outcomes
What changes for the organisation
Assurance that stays current
A defined reassessment cycle so the position reflects the system as it is now.
Change under challenge
Material change assessed before it quietly moves the system outside its approved scope.
Reporting leadership can use
Periodic independent reporting on control performance, incidents and residual exposure.
What Alacrix does
We keep testing the things that decay.
Controls weaken through change, workaround and expansion. Continuous assurance catches that movement before it becomes an incident or a finding.
- Reassess material controls against current configuration and use
- Review model, prompt, data, vendor and permission changes
- Assess expansion of users, data and decision scope
- Examine incidents, near misses, overrides and exception volumes
- Reassess evidence sufficiency and monitoring coverage
- Track regulatory and client expectation change relevant to the estate
Cycle coverage
What each cycle reassesses
Six areas tracked across the life of the deployed system.
Control performance
Whether the controls that were tested at deployment are still operating as intended in daily use.
Change
Model, prompt, data, vendor, permission and integration changes made since the last assessment.
Usage drift
Expansion into new users, data, workflows or decisions beyond the assessed scope.
Incidents and overrides
What went wrong, how often oversight is overridden, and what those patterns reveal.
Evidence quality
Whether the record still supports reconstruction, investigation and external scrutiny.
Regulatory movement
Changes in obligation, guidance or client expectation that alter what the system must satisfy.
Deliverables
What you leave with
Independent, not self-assured
Standing challenge, not embedded delivery.
We remain outside the build and operation of the system so the challenge stays independent, cycle after cycle.
- We do not take operational ownership of AI systems
- Findings are evidenced against the current configuration
- Residual risk is restated each cycle for accountable acceptance
- This is an independent assurance opinion, not a certification or regulatory approval
Engagement process
How the work runs
- 01
Baseline
Establish the assessed scope, controls, evidence and accepted residual risk.
- 02
Reassess
Test control performance, change, drift, incidents and evidence on cycle.
- 03
Report
Give accountable owners a current, evidenced view of exposure and required action.
Next step
The system you approved is not the system you are running.
Continuous assurance keeps independent challenge in place as models, vendors, usage and obligations move.