From Model Risk Management to AI Assurance: Integrating AI Risk Management, Independent Validation, and AI Auditing for Generative and Agentic AI

Authors

DOI:

https://doi.org/10.14738/tecs.1405.12205

Keywords:

AI assurance, agentic AI, generative AI, independent validation, model risk management, trustworthy AI

Abstract

Generative and agentic artificial intelligence challenge assumptions embedded in traditional model risk management (MRM), including stable system boundaries, direct observability, controllable change, and access to model-development evidence. Yet the enduring purposes of MRM—inventory, materiality assessment, independent validation, monitoring, documentation, effective challenge, and accountable governance—remain necessary. This conceptual and applied article develops a socio-technical assurance architecture for contemporary AI systems by integrating governmental and regulatory guidance, international standards, professional assurance practices, and scholarly literature. The proposed Integrated AI Assurance Framework connects four distinct but interdependent functions: AI governance; AI risk management and MRM; independent AI/model validation; and AI auditing. The article also introduces the AI Assurance Boundary, which defines the technical and organizational components whose evidence is material to justified reliance on an AI-enabled capability, and the Assurance Sufficiency Principle, which addresses circumstances in which complete transparency, traceability, or explainability is unattainable. The resulting architecture is risk-based, with assurance intensity varying according to materiality, consequentiality, autonomy, data sensitivity, regulatory exposure, observability, topology, and third-party dependence. Lending, employment, and agentic-enterprise illustrations demonstrate how the framework supports accountable ownership, effective challenge, evidence, escalation, and independent assurance.

Downloads

Published

2026-09-19

How to Cite

Godlove, T., & Buchanan, J. (2026). From Model Risk Management to AI Assurance: Integrating AI Risk Management, Independent Validation, and AI Auditing for Generative and Agentic AI. Transactions on Engineering and Computing Sciences, 14(05), 19–62. https://doi.org/10.14738/tecs.1405.12205