From Model Risk Management to AI Assurance: Integrating AI Risk Management, Independent Validation, and AI Auditing for Generative and Agentic AI
DOI:
https://doi.org/10.14738/tecs.1405.12205Keywords:
AI assurance, agentic AI, generative AI, independent validation, model risk management, trustworthy AIAbstract
Generative and agentic artificial intelligence challenge assumptions embedded in traditional model risk management (MRM), including stable system boundaries, direct observability, controllable change, and access to model-development evidence. Yet the enduring purposes of MRM—inventory, materiality assessment, independent validation, monitoring, documentation, effective challenge, and accountable governance—remain necessary. This conceptual and applied article develops a socio-technical assurance architecture for contemporary AI systems by integrating governmental and regulatory guidance, international standards, professional assurance practices, and scholarly literature. The proposed Integrated AI Assurance Framework connects four distinct but interdependent functions: AI governance; AI risk management and MRM; independent AI/model validation; and AI auditing. The article also introduces the AI Assurance Boundary, which defines the technical and organizational components whose evidence is material to justified reliance on an AI-enabled capability, and the Assurance Sufficiency Principle, which addresses circumstances in which complete transparency, traceability, or explainability is unattainable. The resulting architecture is risk-based, with assurance intensity varying according to materiality, consequentiality, autonomy, data sensitivity, regulatory exposure, observability, topology, and third-party dependence. Lending, employment, and agentic-enterprise illustrations demonstrate how the framework supports accountable ownership, effective challenge, evidence, escalation, and independent assurance.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Tim Godlove, John Buchanan

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
