Assessment lifecycle
Assurance that keeps pace with the system
Models change, data drifts and regulations move. Assurance is a cycle, not a certificate issued once and filed away.
The cycle
Scope, assess, evidence, report, monitor
Five phases that repeat. Monitoring is what turns a point-in-time assessment into continuous assurance.
01
Scope
Intended purpose, deployment context and risk tier are fixed and locked.
02
Assess
Detectors run against the live system under defined and adversarial conditions.
03
Evidence
Observations are recorded, versioned and hashed into the evidence set.
04
Report
Findings are mapped to obligations and sealed into an assurance report.
05
Monitor
Re-assessment is triggered by model, data or regulatory change.
Re-assessment triggers
What starts the cycle again
Four categories of change invalidate part of a previous conclusion. Recognising them early is cheaper than discovering them during a supervisory review.
Model change
A new model version, a change of provider, a fine-tune or an altered prompt or tool chain. Any of these can change behaviour without changing a single line of business logic.
Data drift
The population the system decides about moves away from the one it was assessed against. Subgroup performance is usually the first thing to shift.
Regulatory change
A provision enters force, guidance is finalised, or a new sector rule applies. The obligation set moves even when your system does not.
Scope change
The system is used for a new purpose, in a new market, or on a new decision type. Conclusions do not automatically extend to a context that was never tested.
What this means in practice
Honest about what a report still covers
An assurance report that quietly outlives its own validity is worse than no report at all.
Conclusions are version-bounded
Every report states the exact system version, interfaces and decision population it applies to. Outside those boundaries it makes no claim, and says so.
Re-assessment is scoped, not repeated
A change to one component does not require a full re-run. The engine identifies which detectors and obligations the change touches and re-tests those.
Evidence accumulates
Each assessment adds to the same append-only record rather than replacing it, so you can show how a system behaved over time, not just today.
Ready to see Entercept in action?
See how independent, evidence-backed assurance works on a real high-risk AI system, then get an audit-ready report your regulators, board and customers can rely on.