Skip to main content

Assessment lifecycle

Assurance that keeps pace with the system

Models change, data drifts and regulations move. Assurance is a cycle, not a certificate issued once and filed away.

The cycle

Scope, assess, evidence, report, monitor

Five phases that repeat. Monitoring is what turns a point-in-time assessment into continuous assurance.

  1. 01

    Scope

    Intended purpose, deployment context and risk tier are fixed and locked.

  2. 02

    Assess

    Detectors run against the live system under defined and adversarial conditions.

  3. 03

    Evidence

    Observations are recorded, versioned and hashed into the evidence set.

  4. 04

    Report

    Findings are mapped to obligations and sealed into an assurance report.

  5. 05

    Monitor

    Re-assessment is triggered by model, data or regulatory change.

Re-assessment triggers

What starts the cycle again

Four categories of change invalidate part of a previous conclusion. Recognising them early is cheaper than discovering them during a supervisory review.

Model change

A new model version, a change of provider, a fine-tune or an altered prompt or tool chain. Any of these can change behaviour without changing a single line of business logic.

Data drift

The population the system decides about moves away from the one it was assessed against. Subgroup performance is usually the first thing to shift.

Regulatory change

A provision enters force, guidance is finalised, or a new sector rule applies. The obligation set moves even when your system does not.

Scope change

The system is used for a new purpose, in a new market, or on a new decision type. Conclusions do not automatically extend to a context that was never tested.

What this means in practice

Honest about what a report still covers

An assurance report that quietly outlives its own validity is worse than no report at all.

Conclusions are version-bounded

Every report states the exact system version, interfaces and decision population it applies to. Outside those boundaries it makes no claim, and says so.

Re-assessment is scoped, not repeated

A change to one component does not require a full re-run. The engine identifies which detectors and obligations the change touches and re-tests those.

Evidence accumulates

Each assessment adds to the same append-only record rather than replacing it, so you can show how a system behaved over time, not just today.

ENTERCEPTAI

Ready to see Entercept in action?

See how independent, evidence-backed assurance works on a real high-risk AI system, then get an audit-ready report your regulators, board and customers can rely on.