Approach

Trust is a property to demonstrate—not a label to apply.

Operisys approaches AI assurance as a disciplined argument supported by evidence: this system, for this purpose, within these boundaries, has behaved well enough to justify this level of reliance.

Assurance does not eliminate uncertainty. It makes uncertainty, control and the basis for a decision visible to the people who remain accountable.

How the models connect

One model for the control. One cycle for the work.

The Control Model identifies what has to be governed. The Assurance Cycle is how Operisys examines it. Each pass through the cycle tests all four control dimensions.

01 · What is governed

Control Model

Purpose
The intended use, accountable owner and legitimate outcome.
Authority
What the system may access, decide and execute—and where approval is required.
Behaviour
How the deployed system performs under normal, difficult and failed conditions.
Evidence
What was designed, tested, approved, observed and changed.
02 · How it is examined

Assurance Cycle

Define

Bound

Test

Observe

The depth of work follows the consequence, whether the system is a narrow assistant or an agent able to take operational action.

  1. 01

    Define

    Frame the intended use, affected people, accountable owner, operating context and consequence of error. Map the model, data, tools, vendors, workflow and human dependencies as one system.

  2. 02

    Bound

    Specify what the system may access, recommend, decide or execute—and when a person must take control.

  3. 03

    Test

    Evaluate normal tasks, edge cases, misuse, tool failure, ambiguity, escalation and recovery under realistic conditions.

  4. 04

    Observe

    Record the deployment basis and residual uncertainty, then monitor the signals, incidents and system changes that trigger reassessment.

What counts as evidence

Useful evidence is specific enough to change a decision.

Relevant

It reflects the actual users, data, tools, actions and consequences of the deployed system.

Traceable

It connects an organisational requirement to a control and to observable system behaviour.

Reproducible

Another reviewer can understand the conditions, method, result and material limitations.

Current

Its validity is reconsidered when the model, vendor, data, permissions or operating context changes.

Working definitions

Precise terms for practical decisions.

AI assurance
An evidence-based examination of whether an AI system is suitable for a defined use and remains within its intended boundaries.
Deployment assurance
Evaluation of the assembled system—model, data, tools, permissions, workflow and people—in its intended operating context.
Agent assurance
Examination of an AI agent’s tools, access, actions, limits and routes back to human control.
Authority controls
Enforced rules that limit what an AI system may access, decide or execute, including when human approval is required.

Operating principles

The positions that guide the work.

01

Authority before autonomy.

Define what a system may do before optimising how independently it can do it.

02

System over model.

Assess the model together with its data, tools, permissions, workflow and users.

03

Evidence over confidence.

Use observable tests and records instead of relying on fluency or vendor claims.

04

Review follows change.

Reopen the assurance position when a change invalidates the evidence beneath it.

Working with Operisys

Clear boundaries apply to the engagement too.

Scope, access, data handling, third-party services and evidence requirements should be agreed before sensitive information is introduced. Where a question or specialist need sits outside the agreed scope, that boundary should be explicit.

Operisys does not claim that governance removes AI risk. The work is designed to make decisions, limits, behaviour and residual uncertainty clear enough for accountable people to act.

Book a call