Your organisation has adopted AI governance arrangements. What evidence shows they are operating?
Ethos Advisory provides independent assurance reviews for boards, audit and risk committees, and the assurance, risk and data functions that report to them. The review takes what the organisation’s AI governance arrangements say will happen, and tests that against what the evidence shows.
The question this answers
A framework has been adopted. A policy has been issued. Someone has been made accountable. Reporting comes to the board or to the audit and risk committee at agreed intervals.
Each of those is a statement about what the organisation intends. None of them is evidence about what is happening. The gap between what is imagined and what is done is not usually visible from a board paper, because the board paper is written by the people responsible for the arrangement.
The question is not whether the organisation has AI governance. It is whether the arrangements the board approved are the arrangements in use, and how anyone would know if they were not.
For the people who have to answer that question, the difficulty is rarely willingness. An assurance or risk function planning work on AI governance is planning it in a subject where the organisation’s own expertise sits with the team being reviewed. A data or technology lead asked to confirm that arrangements are working is being asked to provide assurance over their own function. Neither position is comfortable, and neither produces evidence a board can rely on without something independent alongside it.
What the review tests against
The criteria are the organisation’s own adopted arrangements, whatever form they take. A governance framework, an AI policy, an acceptable use standard, a set of approval requirements, or some combination. The review reports whether the organisation is meeting the standard it set for itself, rather than a standard it never adopted.
Where the adopted arrangements do not address a risk a board would reasonably expect them to cover, that is recorded separately, as an observation about the criteria rather than as a review finding. The two are kept apart. A board is entitled to know both that its arrangements are operating and that its arrangements may not reach far enough.
ISO/IEC 42001 and the NIST AI Risk Management Framework remain useful reference points for that second question. They inform it rather than supplying the test.
What the review examines
Scope is agreed before the work begins and is defined narrowly enough to be tested properly. A review might examine the operation of the AI policy across the organisation, the governance of a single system or use case, or the framework as adopted.
Within the agreed scope, the review looks at what management has asserted, what evidence exists to support it, where practice and policy have diverged, where accountability sits in practice, and whether the reporting that reaches the board reflects what the evidence shows.
There is good reason for a review of this kind to be commissioned by the people closest to the arrangements rather than imposed on them. Independent evidence that arrangements are operating is worth more to the person who has to report on them than an assurance they are asked to give on their own authority.
What the board receives
A written report setting out what was examined, how it was tested, what the evidence supports, and what the board can rely on.
Reports follow a set structure: the scope and its limits, the criteria the review tested against, the evidence examined, findings set out area by area against the adopted arrangements, observations on those arrangements where they do not address a risk a board would expect them to, and the matters put to the board for decision.
The report also states what could not be verified. That is not a caveat added at the end. A board is better served by knowing the limits of the work than by a document that implies more coverage than the scope allowed.
Findings are written for board and audit and risk committee use, with the accountability for each recommendation identified. The report is written to a standard that holds up when it is read closely, whether by an auditor, a regulator or legal counsel. It is not a financial audit, carries no audit opinion, and certifies the organisation against no standard.
How the work is delivered
Two routes, depending on what the organisation already has.
Subject matter support inside your own review. Where an assurance or internal audit function is running its own programme, Ethos provides the AI governance and risk expertise the function does not hold in-house. Your methodology, your fieldwork, your report. Ethos contributes to scoping, informs the test approach, works alongside your team through fieldwork, and reviews findings for technical accuracy before they go to the committee. Charged at a day rate, which keeps the cost proportionate to a defined contribution rather than a full engagement.
The full review. Ethos scopes, conducts and reports the review. This suits organisations with a board or audit and risk committee but without an internal audit function of their own.
Scale depends on how much the framework covers, how many systems and business units fall inside the scope, and how much evidence already exists in a form that can be examined. An organisation with documented arrangements and a maintained record of its AI use is a shorter piece of work than one where the evidence has to be assembled during fieldwork. Scoping settles the number of days before any proposal is put.
Scoping is a conversation and a read of whatever you have adopted. There is no charge for it and no proposal until the scope is settled.
A review can be run once to establish a baseline, or placed on a cycle alongside other assurance work. A repeat review is a shorter piece of work, because the evidence base and the criteria are already established and the question becomes what has changed.
Who does the work
Bruce Johnson does the work. Ethos Advisory is a principal-led practice, and the person who scopes the engagement is the person in the fieldwork and the person who writes the report. The proposal team and the delivery team are the same person, and the work holds at that level from scoping through to the final report.
That model sets a real boundary, and it is better stated than discovered. Ethos suits a review with a defined scope that one experienced practitioner can examine properly and stand behind. Where a review spans several specialist disciplines at once and what is needed is a different specialist for each part of the scope, Ethos will say so at scoping rather than take the work and subcontract the parts it cannot cover.
The trade is straightforward. A large firm offers breadth and depth of resource. A principal-led practice offers seniority on every part of the work, direct accountability for the findings, and recommendations made by someone with nothing to gain from what the organisation does next.
Why independence matters here
A board cannot get independent assurance about AI from anyone who also sells it, builds it, or runs it.
The team that builds the capability cannot also be the one that assures the board it is working. That is the reason independent assurance exists, and it is the reason Ethos runs on a single revenue line. Advisory and assurance work paid for by the client is the whole of the practice. Technology sales, vendor relationships and implementation services sit outside it by design, so a finding puts nothing else at risk.
The same principle applies to Ethos itself. Where Ethos has authored an organisation’s AI governance framework or policy, it does not later review whether those arrangements are operating, because the criteria would be criteria Ethos chose. Where Ethos has previously delivered a readiness diagnostic and management built the arrangements itself, assurance work is available and the earlier engagement is disclosed in the report.
Risk registers, the AI governance role itself, and the operation of controls stay with management throughout. Holding any of them would remove the independence the review depends on.
Who this is for
Organisations where AI governance arrangements are already in place and the question has moved on from what to build.
Typically this is an assurance, internal audit or risk function with AI governance on its plan and no AI specialist in-house, a data or technology lead who carries the board reporting burden and wants independent evidence behind it, or a board or audit and risk committee seeking evidence rather than another management report.
Where nothing has yet been adopted, there are no criteria to test against, and a readiness diagnostic is the better starting point. Where arrangements exist in some form but nobody is certain how far they reach, that is worth establishing in the scoping conversation rather than at fieldwork.