The Decision Layer™ · Prove

Know what you can rely on, what you cannot yet defend, and what must happen next.

AI System & Lifecycle Assurance™ connects a consequential decision to the system evidence needed to support it. Start with what leadership is being asked to rely on. The assurance path follows from there.

Decision
What are we approving, relying on, delegating or accepting?
Evidence
What must be true for that decision to remain defensible?
Horizon
What change would invalidate today's conclusion and force it to reopen?
01 · Start with what you are trying to rely on

Do not choose an assurance module because the technology label sounds familiar.

The decision comes first. The module follows from the thing management is being asked to trust.

Generated answers

“We want people to rely on GenAI or RAG outputs.”

Use: GenAI & RAG Assurance™. Test prompts, retrieval, source content, foundation models, output controls and human validation.

Open module →
Autonomous action

“We want an AI agent to take consequential actions.”

Use: Agentic AI Decision & Control Assurance™. Test authority, access, action, constraints, observation and recovery.

Open module →
Model output

“A business decision depends on this model remaining fit for purpose.”

Use: Model Risk Assurance™. Test fitness for purpose, independent validation, change, monitoring and residual uncertainty.

Open module →
Supplier dependency

“We depend on an AI provider whose claims we cannot simply inherit.”

Use: AI Third-Party Assurance™. Test supplier evidence, responsibility boundaries, data use, change, resilience and exit.

Open module →
02 · Choose the assurance depth

Not every decision needs the deepest possible test.

The right depth depends on consequence, novelty, autonomy, existing evidence and how difficult the decision would be to reverse. Start with the least burdensome level capable of resolving the reliance question.

Level 1 · Decision Evidence Review

Is there enough existing evidence to support the decision?

Review the current evidence base, assumptions, ownership and known gaps. Appropriate when the system is understood and the immediate question is whether the existing position is decision-ready.

Level 2 · Targeted Assurance

Does the evidence withstand focused challenge?

Test selected failure modes, controls or dependencies that matter most to the consequential decision. Appropriate where current evidence exists but material uncertainty remains.

Level 3 · Deep Assurance

Can reliance be independently substantiated?

Deeper system, model, autonomy or supplier examination where the consequence, novelty or evidence gap justifies specialist testing and greater organisational involvement.

Assurance depth should follow the exposure. Not the size of the consulting engagement.
03 · What we need from you

Make the evidence burden visible before the work starts.

Decision owner

One accountable sponsor.

Someone able to state what decision is being made, why it matters, what authority sits behind it and what consequence follows if the answer is wrong.

Use case

A defined system boundary.

The relevant product, model, workflow, agent, supplier or business use case must be bounded before assurance claims are made.

Evidence

The artefacts currently relied upon.

Architecture, data lineage, validation records, test results, prompts, retrieval evidence, model documentation, contracts, incident records, logs or equivalent evidence depending on scope.

People

Access to those who know how it really works.

Relevant business owner, technology, data, security, risk, legal, procurement, model or supplier specialists as required by the defined question.

Access

Enough visibility to test the claim.

Read-only access, demonstrations, test environments, logs or supplier evidence may be required at deeper assurance levels. Requirements are agreed upfront.

Constraints

Know what cannot be examined.

Missing access, unavailable evidence and supplier restrictions become explicit limitations to the conclusion rather than invisible assumptions.

04 · What the work tests

From fragmented assurance artefacts to one decision position.

SignalConsequenceDecisionEvidenceChallengeHorizonAction

Decision clarity

Define whether leadership is deciding to approve, deploy, rely, delegate, scale, constrain, pause, remediate or exit.

Evidence confidence

Separate what is proven, assumed, stale, incomplete or missing. Evidence quality is attached to the decision, not stored as an unrelated artefact.

Failure modes

Test the failures that would materially alter the business outcome, authority boundary or decision confidence.

Human authority

Make approval, override, escalation, stop authority and residual-risk acceptance explicit where human judgement still matters.

Reversibility

Examine whether the organisation can pause, recover, replace, exit or contain the system or supplier if conditions change.

Reopening triggers

Define what model change, supplier change, data shift, incident, regulatory movement or business-condition change forces the decision back onto the table.

05 · The conclusion

Assurance should end in a decision state, not a coloured box.

PROCEEDEvidence supports the defined decision within the agreed scope.
PROCEED WITH CONDITIONSReliance is defensible only within explicit limits, controls or monitoring conditions.
PAUSEMaterial evidence, authority or control is insufficient to support reliance.
REMEDIATESpecific deficiencies must change before the decision can be supported.

Every conclusion should state the evidence basis, decision owner, residual exposure, conditions, limitations, review date and reopening trigger.

06 · When the evidence is not enough

We will tell you when our conclusion has reached its limit.

A governance review cannot substitute for quantitative model validation. A document review cannot prove robustness. Supplier assertions cannot replace unavailable technical evidence. And missing access cannot be quietly converted into confidence.

Supported

The evidence is sufficient.

The defined decision is supported within the agreed scope and stated horizon.

Supported with conditions

Reliance is bounded.

The decision can proceed only with explicit constraints, compensating controls or monitoring.

Not yet supported

The evidence remains incomplete.

Leadership can see exactly which gaps prevent a defensible conclusion and what evidence would change that position.

Specialist testing required

The question exceeds the current scope.

Where fairness, robustness, red teaming, penetration testing, quantitative validation, legal interpretation or other specialist work is required, that need is made explicit.

Missing evidence is a finding. It is not permission to pretend confidence.
07 · What you leave with

A reconstructable decision position.

Executive Decision Brief™

What matters, why it matters, what leadership is deciding and the recommended decision state.

Assurance Map

What was tested, against which decision claims, and where evidence is strong, conditional, stale or absent.

Failure-Mode & Evidence Record

The consequential failure scenarios, test evidence, observed limitations and residual uncertainty.

Authority & Ownership Position

Who can approve, accept, override, stop, remediate and reopen the decision.

Conditions & Remediation

What must change, who owns it, by when and what evidence demonstrates closure.

Horizon & Reopening Triggers

How long the conclusion should be relied upon and which changes invalidate it.

08 · What happens next

Finding a problem does not automatically create a remediation programme.

The assurance conclusion belongs to the client. The next step may be internal remediation, supplier action, specialist testing, a change in operating conditions, a different provider, a paused deployment or no further intervention.

If The Decision Layer™ is asked to support remediation or continuing assurance, that is a separate decision with a separately defined scope.

The purpose of assurance is not to manufacture more assurance. It is to make reliance explicit, bounded and defensible.
09 · Related decision routes

Assurance is one part of the decision architecture.

Govern

AI Oversight Product Suite™

Use when the recurring question is what the Board or Committee should see, challenge, record and reopen.

Change

AI Services

Use when the evidence has exposed a governance, policy, leadership or transaction problem that now needs to move.

Result first. Evidence next. Method after.

What are you being asked to rely on?

Bring the use case, the consequential decision and the evidence you currently trust. We will identify the smallest assurance depth capable of resolving the question.

Know what you can defend. Know what must change. Know when the decision needs to reopen.