Agentic AI / assurance by evidence

Agentic AI Assurance Program

A scoped review of agentic systems that connects goals, tools, permissions, human intervention and operational records to the decisions your organisation needs to make.

Who this is for

System owners

Teams accountable for an agent moving from experiment toward production.

Risk and compliance leads

People who need a clear, proportionate view of autonomy, oversight and evidence.

Engineering and security

Builders responsible for tool access, boundaries, logging and incident response.

Questions this addresses

Unclear autonomy

The system can plan, call tools or hand work across steps, but its effective decision boundary is not documented.

Weak intervention paths

Escalation, approval, override and shutdown responsibilities are assumed rather than tested.

Thin operational trace

Prompts, tool calls, inputs, outputs and human decisions cannot yet be reconstructed with confidence.

What we examine

Behaviour and authority

Goals, planning loops, memory, tool permissions, external effects and failure modes in the defined use case.

Human control

Approval gates, escalation thresholds, role separation, intervention powers and operating procedures.

Evidence boundary

Selected system documentation, test results, logs, monitoring views, change records and incident material.

Context and dependencies

Provider services, data flows, connected systems and jurisdictions relevant to the assignment.

What you receive

Agent behaviour map

A readable map of actions, tools, permissions, hand-offs and human decision points.

Evidence and gap register

A bounded register of reviewed material, open questions and evidence that still needs confirmation.

Assurance brief

A concise account of observed controls, limits and proportionate next actions for the agreed scope.

What success looks like

Shared system model

Owners can explain what the agent can do, under which conditions and with whose authority.

Testable control points

Intervention, escalation and shutdown paths have named owners and evidence to review.

Decision-ready record

The organisation has a bounded record of known behaviour, open gaps and the next verification step.

Cross-border perimeter

Operating footprint

Teams, providers, users and evidence locations across borders are listed rather than treated as interchangeable.

Local questions remain visible

Language, records, roles and jurisdiction-specific questions are separated from common control themes.

Limits and dependencies

The real perimeter governs

Conclusions depend on access to the system, records and people agreed for the assignment; they do not extend automatically to other deployments.

A review is a point in time

Agent behaviour, models, prompts and connected tools can change, so the evidence date and change boundary matter.

Not a legal conclusion

The work can organise technical and governance evidence, but it does not replace legal advice, management accountability or a regulator’s decision.

Engagement levels

Readiness review

A first, bounded review of roles, evidence and open questions. It identifies what to clarify; it is not assurance, an audit or a certification.

Assurance

An evidence-led conclusion for the agreed scope, evidence date and criteria. It does not create a universal compliance conclusion.

Audit

A more formal examination of agreed criteria, records and controls. The audit scope, method and reporting basis are set in the engagement letter.

Certification

Certification is a separate route performed by an appropriate certification body. This service does not issue a certificate or replace that body’s process.

Scope note

This is a scoped evidence review. It does not establish universal compliance, regulatory approval or a conclusion beyond the system, evidence and jurisdictions expressly agreed.

Official contacts

Maison Sasson ltd - United Kingdom

Email: info@ai-eu-act.xyzWhatsApp: +393381639136Legal entity: Maison Sasson ltd - United Kingdom