Maison Sasson / methodology & evidence

/

AI assurance that can cross borders without losing the trail.

A practical method for regulated organisations that need to understand how an AI system is governed, tested and evidenced across jurisdictions.

This page separates what is verified, what is declared as a capability, and what remains to be documented for a specific engagement.

Evidence register

A readable trail from question to action.
Verified in scope

Label each conclusion by the artefacts and interviews that support it, and record gaps instead of filling them with assumptions.

04phases
04reference lenses

01 / Perimeter

Start with a defensible perimeter

The examination begins with the system, decision, data flows and jurisdictions actually in scope—not with a generic compliance label.

Declared capability

System boundary

Identify the model, product surface, operators, vendors, interfaces and change points that can affect the assurance question.

Editorial reference: Engagement scoping brief

Declared capability

Risk context

Map intended use, affected people, decisions, human oversight and the operational context in which harm could occur.

Editorial reference: Risk and control interview record

Verified in scope

Evidence boundary

Label each conclusion by the artefacts and interviews that support it, and record gaps instead of filling them with assumptions.

Editorial reference: Public evidence policy / this page

02 / Method

Four phases, one evidence trail

Each phase produces an inspectable hand-off. The exact tests and sampling depth are agreed once the system perimeter is known.

01
Declared capability

Frame

Turn the business question into a bounded assurance brief with owners, uses, dependencies and decision criteria.

  • Assurance brief
  • System and jurisdiction register

Editorial reference: Proposed engagement method

02
Declared capability

Trace

Follow data, model, human and vendor pathways to test whether the control story matches the operating reality.

  • Control map
  • Evidence request list

Editorial reference: Proposed engagement method

03
Declared capability

Test

Review selected documentation, records, controls and samples; record observations with their source and confidence.

  • Findings log
  • Evidence register

Editorial reference: Proposed engagement method

04
Declared capability

Close

Translate observations into prioritised actions, accountable owners and a plan for evidence that is still missing.

  • Assurance report
  • Remediation roadmap

Editorial reference: Proposed engagement method

03 / Evidence

Evidence is a chain, not a badge

A conclusion is only as strong as its source, recency, ownership and connection to the control being examined.

Evidence has a source, an owner and a date.

A gap is a useful finding when it is named clearly and assigned a next action.

Documentary evidence

Declared capability

Policies, system descriptions, model cards, risk assessments, contracts, approvals and change records.

Editorial reference: Evidence request list

Operational evidence

Declared capability

Logs, tickets, monitoring views, test results, incident records and samples showing how controls operate in practice.

Editorial reference: Evidence register

Human evidence

Declared capability

Interviews and walkthroughs with accountable owners, operators, risk, security, legal and procurement teams.

Editorial reference: Interview record

Traceability

Verified in scope

Every observation points back to an artefact, interview or sample; unresolved material gaps remain visible.

Editorial reference: Public evidence policy / this page

04 / Outputs

Outputs built for decisions

The deliverable is designed to help a regulated team decide what to accept, fix, test again or document next.

Declared capability
Assurance brief

A concise record of scope, assumptions, owners, systems, uses and evidence thresholds.

Declared capability
Findings and evidence report

Source-linked observations, control status, residual uncertainty and material limitations.

Declared capability
Remediation roadmap

Priorities, owners and next evidence actions, mapped to the organisation’s operating rhythm.

05 / Boundaries

What this examination does not claim

Assurance is bounded work. A report is not a universal certification, legal opinion or substitute for management accountability.

Verified in scope

No certification or accreditation claim

Maison Sasson does not present this methodology as a certification, accreditation or regulator approval.

Verified in scope

No conclusion beyond the sample

A reviewed sample, period or deployment cannot by itself prove every control works everywhere or forever.

Verified in scope

Not legal advice

The crosswalk supports structured questions; it does not replace jurisdiction-specific legal advice or regulatory interpretation.

Declared capability

Open gaps stay open

Where source material, system access or jurisdictional analysis is missing, the appropriate result is a documented gap and a next step.

06 / Crosswalk

A working matrix across four reference frameworks

This crosswalk organises questions and possible evidence across governance, risk, management systems and resilience. It is a working correspondence, not a compliance result.

The four frameworks are not equivalent or interchangeable. This matrix does not establish compliance, certification, accreditation, regulatory approval or universal coverage; legal and entity-specific analysis remains necessary.

Theme

Governance, role and risk context

Perimeter

Clarify the system, intended use, actors, decision rights and affected people before mapping any obligation or control.

Working correspondence

EU AI Act

Declared capability

Identify the potentially relevant provider, deployer and system context; applicability and obligations depend on the use, role and facts of the case.

NIST AI RMF

Declared capability

Use Govern and Map questions to record accountability, intended purpose, context, impacts and risk assumptions.

ISO/IEC 42001

Declared capability

Look for organisational context, leadership, policy and assigned responsibilities in the AI management system evidence.

NIS2

To document

Test whether the entity, sector and services fall within the directive’s national scope and how management responsibility is evidenced.

Sources and review date

Limits and open questions

  • The AI Act mapping is not a classification decision and needs facts about the system, role and use.
  • NIST AI RMF is voluntary guidance and does not create a legal duty by itself.
  • ISO/IEC 42001 references are paraphrases only; no conformity or certification conclusion is made.
  • NIS2 scope depends on the entity, sector, size, national transposition and competent authority.

Theme

Lifecycle, monitoring and evidence

Perimeter

Connect design, testing, human oversight, monitoring, incidents and records to the operating reality of one bounded system.

Working correspondence

EU AI Act

Declared capability

Ask which risk controls, technical records, logging, human oversight, monitoring and incident records may apply to the system in scope.

NIST AI RMF

Declared capability

Use Measure and Manage questions to relate testing, monitoring, residual risk, responses and continuous learning to named owners.

ISO/IEC 42001

Declared capability

Trace operational planning, performance evaluation and continual-improvement evidence without reproducing protected standard text.

NIS2

To document

Map AI dependencies into cybersecurity risk management, incident handling, continuity and supply-chain evidence where the entity is in scope.

Sources and review date

Limits and open questions

  • The matrix does not say that one artefact satisfies every framework or obligation.
  • Sampling depth, system access, time period and evidence quality are engagement-specific.
  • Incident and monitoring expectations depend on the applicable legal and operational perimeter.
  • A documented control or policy does not prove that it operated effectively in production.

Theme

Cross-border applicability and resilience

Perimeter

Separate territorial reach, entity scope, sector duties, supplier dependencies and the jurisdictional assumptions behind each conclusion.

Working correspondence

EU AI Act

To document

Check territorial reach, supply-chain roles and the system facts that can change which provisions are relevant across markets.

NIST AI RMF

Declared capability

Use the framework as a flexible risk vocabulary, recording where local law, sector practice or organisational priorities add requirements.

ISO/IEC 42001

Declared capability

Consider the organisation’s context, boundaries, interested parties and management-system interfaces across locations and suppliers.

NIS2

To document

Check national transposition, entity designation, sector, supply chain, reporting route and resilience obligations with the relevant authority.

Sources and review date

Limits and open questions

  • A cross-border row cannot replace jurisdiction-by-jurisdiction legal and entity analysis.
  • NIS2 is transposed and supervised through national arrangements; the directive is not an AI governance standard.
  • The ISO source is a paid standard; this page uses a limited paraphrase and does not reproduce its text.
  • The conclusion is bounded by the selected sample, period, system version and supplier evidence.

The 14-jurisdiction matrix is now published with an evidence boundary

Verified in scope

The public matrix links the current source set, consultation dates and open gaps. Rows marked declared or to document are not verified evidence of coverage; no legal advice, certification or regulatory approval is implied.

/jurisdictions

07 / Engagement

Choose the next useful conversation

The public methodology is a starting point; the pre-assessment turns it into a scoped discussion.

Pre-assessment

A short multilingual intake to identify which governance questions deserve attention first.

Start the pre-assessment

Evidence-led assurance

A scoped examination of a system, control set or cross-border operating question.

Request an AI audit

Control roadmap

A prioritised path from open questions to owned evidence and repeatable review.

Discuss a roadmap

Illustrative assurance report

A synthetic, public example of the Ledger structure: useful for orientation, never a real audit or certification.

Read the demo report

Next step / scoped audit request

Bring the real system into the frame.

Share the context, jurisdictions and evidence questions that matter. The first conversation is about scope, not a pre-written conclusion.