Assurance Services

Independent assurance of the institutional systems responsible for governing AI

SWANK AI provides defined-scope, evidence-oriented reviews of the human and institutional systems surrounding artificial intelligence.

Our work examines whether governance, evidence, decision-making, communication, challenge, human oversight and accountability operate effectively in practice.

Engagements are structured using the SWANK Institutional AI Assurance Framework — SIAAF where applicable.

The purpose is not simply to determine whether an AI system functions.

It is to determine whether the institution responsible for using it can demonstrate that its surrounding governance system works.


Three Levels of Review

SWANK AI offers three principal forms of engagement.

Short-Form Operational Review

Communication & Feedback Systems Review

Full Institutional AI Assurance Review

The appropriate level depends upon the scope, complexity, consequence and evidence involved.


01 — Short-Form Operational Review

Focused assurance for a clearly defined institutional question

The Short-Form Operational Review applies selected SIAAF domains to one specific problem where a full institutional review would be disproportionate.

It is designed for organisations that need an independent analytical assessment of a defined issue.

Typical questions may include:

  • Is meaningful human review occurring within this workflow?
  • Are AI-generated summaries adequately traceable to source material?
  • Does an escalation route permit genuine reconsideration?
  • Is responsibility for an AI-supported decision identifiable?
  • Does an AI policy operate as described in practice?
  • Are correction pathways adequate?
  • Is AI triage being used appropriately?
  • Are staff relying excessively on automated recommendations?
  • Does a proposed AI use create identifiable governance gaps?
  • Is an existing process sufficiently reviewable?

SIAAF Application

Only the domains necessary to answer the agreed question are applied.

For example, a review concerning source integrity may focus primarily on:

Domain 03 — Evidence & Traceability

A review concerning human decision-making may focus on:

Domain 02 — Decision Integrity & Human Oversight

A review concerning institutional challenge may focus on:

Domain 05 — Escalation, Challenge & Contestability

Typical Deliverable

A concise written assurance report setting out:

  • scope;
  • evidence reviewed;
  • evidence limitations;
  • relevant observations;
  • analytical findings;
  • applicable SIAAF assessment;
  • significance;
  • recommendations;
  • unresolved questions.

Best suited to

A specific operational question requiring independent clarification without the scope or cost of a wider institutional review.


02 — Communication & Feedback Systems Review

Assurance of how information, concerns and corrections move through an institution

Many AI governance failures are not purely technical.

They arise because:

  • information does not reach the right person;
  • uncertainty disappears during communication;
  • source material becomes detached from summaries;
  • concerns cannot be effectively escalated;
  • corrections do not propagate;
  • disagreement becomes flattened into a single narrative;
  • or formal challenge mechanisms exist without producing meaningful reconsideration.

The Communication & Feedback Systems Review examines those institutional pathways.

Primary SIAAF Domains

This review principally applies:

Domain 03 — Evidence & Traceability

Domain 04 — Communication & Feedback Integrity

Domain 05 — Escalation, Challenge & Contestability

Other SIAAF domains may be applied where relevant.


What SWANK May Examine

Evidence movement

  • source-to-summary traceability;
  • information provenance;
  • preservation of contradictory evidence;
  • treatment of missing information;
  • propagation of corrections;
  • record continuity.

Communication

  • internal communication pathways;
  • communication between technical and non-technical teams;
  • treatment of uncertainty;
  • clarification mechanisms;
  • information loss;
  • accessibility;
  • communication with affected individuals.

Feedback

  • how concerns enter the system;
  • who receives them;
  • whether they reach someone with authority;
  • whether responses influence subsequent decisions;
  • whether corrections change downstream records.

Escalation

  • thresholds for escalation;
  • challenge routes;
  • reconsideration pathways;
  • human intervention;
  • barriers to raising concerns;
  • whether escalation can also result in de-escalation or correction.

Institutional learning

  • incident feedback;
  • recurring failure modes;
  • correction data;
  • review mechanisms;
  • whether lessons are incorporated into future practice.

Core Questions

The review asks:

Who noticed?

Could they challenge it?

Who received the information?

Who had authority to act?

Was uncertainty communicated?

Was contradictory evidence preserved?

Could an error be corrected?

Did the correction reach downstream records?

Did escalation lead to meaningful review?

Can the institution prove what happened afterwards?


Typical Deliverable

A structured written report may include:

  • communication and decision-system mapping;
  • evidence-flow analysis;
  • identified feedback pathways;
  • escalation and challenge assessment;
  • applicable SIAAF domain ratings;
  • evidence-confidence assessment;
  • material risks;
  • recommendations;
  • unresolved questions.

Where useful, the report may include an Institutional Systems Map showing how evidence, decisions, communication and escalation interact.

Best suited to

Organisations where the principal concern is not simply the AI model itself, but what happens to information and human judgment around it.


03 — Full Institutional AI Assurance Review

Comprehensive independent review using all seven SIAAF domains

The Full Institutional AI Assurance Review is SWANK AI’s principal assurance engagement.

It applies the complete SWANK Institutional AI Assurance Framework to a defined organisational system, programme, policy or AI-use environment.

The review examines whether the institution can demonstrate that its AI governance arrangements operate coherently as a system.


Seven-Domain Assessment

Domain 01 — Governance & Accountability

Who is responsible, and can that responsibility be demonstrated?

Examines ownership, authority, governance structures, approval pathways and accountability.


Domain 02 — Decision Integrity & Human Oversight

Are humans genuinely governing AI-supported decisions, or merely approving them?

Examines meaningful human review, automation bias, override authority and responsibility for final decisions.


Domain 03 — Evidence & Traceability

Can the organisation prove how an important conclusion was reached?

Examines provenance, documentation, decision records, contradictory evidence and reconstruction.


Domain 04 — Communication & Feedback Integrity

Does important information move through the institution accurately and effectively?

Examines clarification, communication, feedback, uncertainty and correction pathways.


Domain 05 — Escalation, Challenge & Contestability

What happens when someone believes the AI, evidence or decision is wrong?

Examines escalation, contestability, reconsideration and institutional tolerance of challenge.


Domain 06 — Risk, Harm & Operational Resilience

Does the institution understand what could go wrong and what it will do when something does?

Examines foreseeable harms, incident response, operational failure, third-party dependencies and resilience.


Domain 07 — AI Literacy & Organisational Readiness

Do the people using and governing AI understand it well enough to exercise judgment?

Examines staff capability, leadership understanding, verification practices, training and inappropriate reliance.


Five Assurance Tests

Across the relevant domains, SIAAF applies five cross-cutting tests.

Reality Test

Does actual practice match written policy?

Evidence Test

Can the organisation demonstrate the claim it is making?

Challenge Test

Could a reasonable person question or correct this decision?

Failure Test

What happens when the AI, human or process gets something wrong?

Reconstruction Test

Could an independent reviewer later determine what happened, why it happened and who was responsible?


Assurance Outcomes

Relevant areas may receive a SIAAF assurance status.

A1 — Effective

The institutional system is clearly defined, evidenced and functioning consistently.

A2 — Partially Effective

Core arrangements exist, but identifiable weaknesses limit reliability or consistency.

A3 — Weak

Material deficiencies exist in design, implementation, evidence or operation.

A4 — Not Demonstrated

Available evidence is insufficient to establish that an effective system exists.

Not Demonstrated does not mean that something necessarily did not occur.

It means the available evidence is insufficient to demonstrate it.


Evidence Confidence

Findings may also receive a separate evidence-confidence designation:

HIGH
Strong, direct and consistent evidence.

MODERATE
Credible evidence exists, but material limitations remain.

LOW
Evidence is incomplete, indirect or materially disputed.

This prevents effectiveness, certainty and severity from being treated as the same question.


Recommendation Priority

Recommendations may be classified as:

P1 — Immediate

P2 — High

P3 — Planned

P4 — Enhancement

Priority reflects the significance and urgency of action required rather than the evidential confidence of the underlying finding.


Standard Review Process

A substantial SIAAF engagement follows a documented sequence.

01 — Scope Definition

The assurance question, timeframe, evidence expectations, exclusions and intended deliverable are agreed in writing.

02 — Evidence Intake

Relevant documentation is collected and registered.

03 — Evidence Mapping

SWANK identifies:

  • supporting evidence;
  • contradictory evidence;
  • missing records;
  • disputed facts;
  • assumptions;
  • unresolved questions.

04 — Institutional Systems Analysis

The relevant SIAAF domains are applied.

05 — Challenge Analysis

SWANK tests whether the apparent institutional conclusion survives:

  • alternative interpretations;
  • contradictory documentation;
  • missing evidence;
  • uncertainty;
  • untested assumptions;
  • plausible failure scenarios.

06 — Findings

Findings use the standard analytical chain:

Observation → Evidence → Analysis → Significance → Recommendation

07 — Factual Accuracy Review

Where appropriate, the commissioning organisation may identify factual errors, missing documents, incorrect dates or demonstrably inaccurate descriptions.

The organisation does not receive editorial control over SWANK’s analytical conclusions.

08 — Final Report

The final report records the evidence, findings, limitations, assurance outcomes, recommendations and unresolved questions.


Standard Assurance Report

A substantial SWANK AI assurance report may include:

  • Executive Assurance Summary
  • Scope
  • Methodology
  • Evidence Base
  • Evidence Limitations
  • Institutional Systems Map
  • Findings
  • Domain Assessment
  • Material Risks
  • Recommendations
  • Unresolved Questions
  • Evidence Appendix

The objective is to make the analytical pathway visible and reviewable.


Areas of Application

SWANK AI assurance may be relevant where organisations use or are considering AI in areas such as:

  • governance and administration;
  • complaints and correspondence;
  • summarisation;
  • triage and prioritisation;
  • decision support;
  • records management;
  • education;
  • public services;
  • healthcare;
  • employment;
  • safeguarding;
  • regulatory activity;
  • financial access;
  • professional decision-making;
  • high-consequence institutional processes.

The appropriate depth of assurance should reflect the potential consequences of error.


High-Stakes AI

Not every AI use requires the same level of scrutiny.

A system generating draft meeting notes is not operationally equivalent to a system contributing to decisions affecting:

  • rights;
  • safety;
  • education;
  • healthcare;
  • employment;
  • access to services;
  • safeguarding;
  • disciplinary outcomes;
  • financial opportunity.

As consequence increases, organisations may require stronger controls concerning:

  • evidence quality;
  • source traceability;
  • human judgment;
  • uncertainty;
  • correction;
  • reconsideration;
  • testing;
  • documentation;
  • auditability.

SIAAF applies assurance proportionately to the institutional environment being examined.


Independence

SWANK AI assurance is conducted according to defined independence principles.

These include:

  • no outcome-contingent fees;
  • no predetermined findings;
  • conflict disclosure;
  • evidence traceability;
  • separation of fact and analysis;
  • factual correction without client editorial control over conclusions;
  • disclosure of material evidence limitations;
  • proportionality;
  • vendor neutrality.

The commissioning organisation defines the question.

It does not define the answer.

Read Standards & Independence →


What SWANK AI Does Not Provide

Unless expressly stated otherwise, SWANK AI assurance is not:

  • statutory certification;
  • legal advice;
  • ISO certification;
  • regulatory approval;
  • cybersecurity penetration testing;
  • source-code auditing;
  • financial audit;
  • compliance sign-off;
  • a guarantee that an AI system is safe;
  • a guarantee of regulatory compliance.

SIAAF provides independent analytical assurance concerning institutional systems and available evidence.


Choosing an Engagement

Choose a Short-Form Operational Review when:

You have one defined question requiring independent analysis.

Choose a Communication & Feedback Systems Review when:

The issue concerns how evidence, information, correction, communication or challenge moves through the institution.

Choose a Full Institutional AI Assurance Review when:

You require a system-wide assessment of whether AI governance arrangements work together effectively in practice.

Where the appropriate scope is unclear, it can be defined during the initial enquiry.


Assurance Enquiries

Please provide:

  • the organisation or system concerned;
  • the question requiring review;
  • the relevant AI use or proposed use;
  • the principal evidence available;
  • and the intended purpose of the review.

director@swanklondon.com

Explore SIAAF →

Read Standards & Independence →

View Pricing →


SWANK AI

We do not just review AI. We review the institutional systems responsible for governing it.

Scroll to Top