SIAAF
SWANK Institutional AI Assurance Framework
A structured methodology for independently examining the institutional systems responsible for governing artificial intelligence.
Version 1.0 · Published 26 August 2026
AI risk does not exist only inside technology.
It also exists inside the institution responsible for using it.
An AI system may perform as designed while the surrounding organisation fails because responsibility is unclear, evidence is incomplete, human oversight is nominal, uncertainty is poorly communicated, challenge routes do not function, or decisions cannot later be reconstructed.
SIAAF examines that institutional environment.
The Core Assurance Question
Every SIAAF engagement ultimately asks:
Can this organisation demonstrate that its use, oversight and governance of AI is coherent, evidenced, accountable, challengeable and operationally effective?
SIAAF distinguishes between:
what an organisation says happens
and
what the available evidence demonstrates actually happens.
Policies matter.
Operational behaviour matters more.
Seven Assurance Domains
SIAAF examines institutional AI governance through seven connected assurance domains.
A full assurance review may apply all seven.
A defined-scope engagement may apply only those necessary to answer the agreed question.
01 — Governance & Accountability
Who is responsible, and can that responsibility be demonstrated?
SWANK examines:
- ownership of AI systems and processes;
- decision-making authority;
- defined responsibilities;
- governance structures;
- policy ownership;
- approval pathways;
- accountability for AI-assisted decisions;
- responsibility across teams and vendors;
- oversight arrangements;
- gaps between written governance and operational practice.
The existence of governance documentation does not, by itself, demonstrate operational accountability.
SIAAF asks whether responsibility remains identifiable when intervention, explanation or correction is actually required.
02 — Decision Integrity & Human Oversight
Are humans genuinely governing AI-supported decisions, or merely approving them?
SWANK examines:
- where AI enters the decision process;
- which decisions remain human;
- meaningful human review;
- automation bias;
- decision thresholds;
- override mechanisms;
- reliance on AI recommendations;
- responsibility for final outcomes;
- whether reviewers have sufficient information, competence and authority.
Human presence is not the same as human judgment.
Meaningful oversight requires a genuine ability to understand, question, correct and reject AI-supported output.
03 — Evidence & Traceability
Can the organisation prove how an important conclusion was reached?
SWANK examines:
- documentary evidence;
- source traceability;
- records of AI involvement;
- decision logs;
- version history;
- provenance;
- supporting documentation;
- contradictory evidence;
- missing evidence;
- assumptions;
- distinctions between fact, inference and AI-generated material.
SIAAF Evidence Principle
A conclusion is only as reliable as the evidence pathway supporting it.
Important decisions should remain reconstructable.
A later reviewer should be able to determine what evidence existed, how it was interpreted and where AI influenced the process.
04 — Communication & Feedback Integrity
Does important information move through the institution accurately and effectively?
SWANK examines:
- internal communication;
- clarification pathways;
- feedback mechanisms;
- transfer of uncertainty;
- information loss;
- inconsistent messaging;
- communication between technical and non-technical teams;
- documentation of concerns;
- feedback from affected people;
- institutional response to corrections.
AI governance is partly an information problem.
A technically capable system may still produce poor institutional outcomes if important information cannot reach the people with authority to act upon it.
05 — Escalation, Challenge & Contestability
What happens when someone believes the AI, evidence or decision is wrong?
SWANK examines:
- escalation routes;
- challenge mechanisms;
- complaint pathways;
- independent review;
- reconsideration mechanisms;
- thresholds for escalation;
- response to disputed AI outputs;
- institutional tolerance of challenge;
- barriers to raising concerns.
SIAAF Challenge Principle
A system that cannot be challenged cannot be meaningfully assured.
The existence of a challenge route is not sufficient.
The question is whether challenge can result in meaningful reconsideration.
06 — Risk, Harm & Operational Resilience
Does the institution understand what could go wrong and what it will do when something does?
SWANK examines:
- foreseeable harms;
- operational failure;
- inappropriate AI reliance;
- privacy and confidentiality risks;
- data handling;
- security dependencies where relevant;
- discriminatory outcomes;
- vulnerable populations;
- third-party dependencies;
- model or system failure;
- incident response;
- business continuity;
- risk escalation.
Governance should reflect consequence.
Higher-risk uses ordinarily require stronger evidence, oversight, traceability, correction and contingency arrangements.
07 — AI Literacy & Organisational Readiness
Do the people using and governing AI understand it well enough to exercise judgment?
SWANK examines:
- staff AI literacy;
- leadership understanding;
- training;
- hallucination awareness;
- bias awareness;
- verification practices;
- privacy awareness;
- acceptable-use understanding;
- inappropriate reliance;
- understanding of when AI should not be used.
SIAAF Literacy Principle
The appropriate response to powerful technology is not ignorance. It is informed judgment.
AI literacy is not simply the ability to use an AI system.
It is the ability to judge when, how and whether its output should be relied upon.
Five Cross-Cutting Assurance Tests
Every SIAAF engagement applies five tests across the relevant domains.
The Reality Test
Does actual practice match written policy?
The Evidence Test
Can the organisation demonstrate the claim it is making?
The Challenge Test
Could a reasonable person question or correct this decision?
The Failure Test
What happens when the AI, human or process gets something wrong?
The Reconstruction Test
Could an independent reviewer later determine what happened, why it happened and who was responsible?
Together, these tests distinguish institutional aspiration from demonstrable institutional performance.
Evidence Discipline
SIAAF does not collapse fact, interpretation, uncertainty and recommendation into one narrative category.
Findings distinguish between:
Documented Fact
Directly supported by available evidence.
Corroborated Observation
Supported by multiple independent sources or records.
Analytical Inference
A conclusion reasonably derived from available evidence but not directly documented.
Unresolved Issue
A material question for which insufficient evidence exists.
Contradiction
Two or more material sources cannot presently be reconciled.
Recommendation
A proposed improvement arising from the analysis.
Evidence Rule
Fact, observation, inference, uncertainty and recommendation must remain analytically distinguishable.
Absence of evidence is not automatically evidence of absence.
The strength of language used in a finding should remain proportionate to the strength of the evidence supporting it.
Assurance Outcomes
SIAAF separates three different questions:
How effective is the system?
How strong is the evidence?
How urgent is the recommended action?
These should not be conflated.
Assurance Status
A1 — EFFECTIVE
The institutional system is clearly defined, evidenced and functioning consistently.
A2 — PARTIALLY EFFECTIVE
Core arrangements exist, but identifiable weaknesses limit reliability or consistency.
A3 — WEAK
Material deficiencies exist in design, implementation, evidence or operation.
A4 — NOT DEMONSTRATED
Available evidence is insufficient to establish that an effective system exists.
Not Demonstrated does not automatically mean that something did not occur.
It means the evidence supplied or identified during the review was insufficient to demonstrate it.
Evidence Confidence
Findings may additionally receive an evidence-confidence designation:
HIGH — strong, direct and consistent evidence.
MODERATE — credible evidence exists but material limitations remain.
LOW — evidence is incomplete, indirect or materially disputed.
This prevents analytical certainty being presented where the evidence does not support it.
Recommendation Priority
Recommendations may be classified as:
P1 — Immediate
Material governance or operational weakness requiring prompt attention.
P2 — High
Significant issue requiring defined corrective action.
P3 — Planned
Important improvement for normal governance development.
P4 — Enhancement
Good-practice improvement rather than material deficiency.
The SIAAF Review Process
SIAAF engagements follow a documented analytical pathway.
01 — Scope Definition
The review question, timeframe, evidence expectations, exclusions and intended deliverable are agreed in writing.
02 — Evidence Intake
Relevant material is collected and registered.
03 — Evidence Mapping
Supporting evidence, contradictory evidence, missing records, disputed facts, assumptions and unresolved questions are identified.
04 — Institutional Systems Analysis
The relevant SIAAF domains are applied.
05 — Challenge Analysis
SWANK deliberately tests whether the apparent institutional conclusion survives alternative interpretations, contradictory documentation, missing evidence, ambiguity and plausible failure scenarios.
06 — Findings
Findings follow a consistent analytical chain:
Observation → Evidence → Analysis → Significance → Recommendation
07 — Factual Accuracy Review
Where appropriate, the commissioning organisation may identify factual errors, missing documents, incorrect dates or demonstrably inaccurate descriptions.
It does not receive editorial control over SWANK’s analytical conclusions.
08 — Final Report
The final report records scope, methodology, evidence considered, limitations, findings, assurance status, recommendations and unresolved questions.
Standard SWANK Deliverable
A substantial SIAAF assurance report may include:
- Executive Assurance Summary
- Scope
- Methodology
- Evidence Base
- Evidence Limitations
- Institutional Systems Map
- Findings
- Domain Assessment
- Material Risks
- Recommendations
- Unresolved Questions
- Evidence Appendix
Consistency makes the analytical product easier to review, compare and revisit over time.
Independence Standard
SIAAF depends upon the credibility of the analytical process.
Independence is therefore treated as an operating condition rather than a marketing claim.
SWANK AI applies principles including:
No Outcome-Contingent Fees
Payment does not depend upon reaching a particular conclusion.
No Predetermined Findings
The commissioning organisation may define the question.
It may not define the answer.
Conflict Disclosure
Actual or potential conflicts should be identified before substantive review begins.
Evidence Traceability
Material findings should remain traceable to an identified evidence base.
Separation of Fact and Analysis
Documented facts, analytical inferences and recommendations remain distinguishable.
Correction Without Editorial Control
Clients may correct factual inaccuracies.
They may not rewrite analytical conclusions.
Limitation Disclosure
Material gaps in evidence must be stated.
Proportionality
The depth of review should reflect the significance, complexity and risk of the issue.
Vendor Neutrality
SWANK should remain independent of vendor relationships that could compromise — or reasonably appear to compromise — objectivity.
Read Standards & Independence →
Relationship With External Frameworks
Where useful, SIAAF assessments may be:
aligned with,
informed by,
or
mapped against
recognised external frameworks, standards, organisational requirements or applicable regulatory provisions.
SIAAF does not imply certification, accreditation or regulatory endorsement where none exists.
External frameworks may provide useful reference points.
SIAAF remains an independent analytical methodology.
What SIAAF Is Not
Unless separately stated and appropriately qualified, a SIAAF review is not:
- statutory certification;
- legal advice;
- ISO certification;
- regulatory approval;
- cybersecurity penetration testing;
- source-code auditing;
- financial audit;
- a guarantee that an AI system is safe;
- a guarantee that an organisation will comply with every applicable law.
SIAAF provides independent analytical assurance concerning institutional systems and available evidence.
How SWANK AI Services Use SIAAF
Short-Form Operational Review
Applies selected SIAAF domains to one clearly defined institutional problem where a full assurance review would be disproportionate.
Communication & Feedback Systems Review
Primarily applies:
Domain 03 — Evidence & Traceability
Domain 04 — Communication & Feedback Integrity
Domain 05 — Escalation, Challenge & Contestability
Other domains may be applied where relevant.
Full Institutional AI Assurance Review
Applies all seven SIAAF domains to a defined organisational system, programme, policy or AI-use environment.
View Assurance Services →
Signature Assurance Questions
SIAAF ultimately reduces complex institutional systems to a set of deliberately simple questions:
Who knew?
Who decided?
What evidence supported the decision?
What did the AI contribute?
What uncertainty existed?
Was that uncertainty communicated?
Could someone challenge the conclusion?
Where would a concern be escalated?
Who had authority to intervene?
Did they actually exercise that authority?
What happened when information contradicted the original conclusion?
Can the institution prove what happened afterwards?
The SIAAF Principle
Good AI governance is demonstrated by institutional behaviour under uncertainty, challenge and error — not by the existence of a policy alone.
AI should not make institutions less accountable.
It should remain possible to determine:
- what happened;
- why it happened;
- what evidence was relied upon;
- where AI influenced the outcome;
- who remained responsible;
- whether concerns could be raised;
- whether errors could be corrected;
- and whether the institution learned from the result.
If an organisation cannot answer those questions, its AI governance is incomplete.
SIAAF exists to find out whether it can.
SIAAF v1.0
SWANK Institutional AI Assurance Framework
Version 1.0
Publication date: 26 August 2026
Classification: Methodology
Publisher: SWANK AI / SWANK London LLC
Download SIAAF v1.0 →
View Assurance Services →
Read SWANK AI Guidance →
SWANK AI
We do not just review AI. We review the institutional systems responsible for governing it.
