Live Webinar | Building AI Governance That's Audit-Ready on September 23 @ 1:00PM ET

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

AI Doesn’t Just Need Guardrails. It Actually Needs Independent Assurance.

Artificial Intelligence | ISO 42001

Published: Sep 17, 2026

There have been a lot of conversations about AI safety lately, but one idea really caught my attention: Anthropic CEO Dario Amodei spoke about the need for independent evaluators to have deeper access to AI companies and their models so they can actually test whether the safety measures being put in place are functioning. 

When I read that, I immediately thought this is exactly where AI assurance needs to go. And it is also exactly why we have been investing so heavily in this space at Schellman. 

Why AI Should Be Held to the Same Security Standard as Everything Else 

For years now, we have been independently assessing the technology that companies and consumers rely on every day, spanning cybersecurity, cloud environments, privacy, financial systems, and some of the largest technology companies in the world.  

As AI increasingly becomes embedded into those same environments, the security expectations shouldn’t be any different — companies should be able to demonstrate that their AI systems have been independently tested and that the controls around them actually work.  

However, our new research report on the 2026 State of AI Governance found that, while 74% of organizations believe they could pass an AI compliance audit today, only 27% say their governance is actually mature.  

That gap is exactly why self-assessment alone doesn’t suffice. Confidence and proof are not the same thing, and right now, most companies using AI only have one of the two.

Why Traditional Compliance Isn’t Enough to Address AI Assurance

Moreover, AI assurance can’t just be traditional compliance with “AI” added to the name.  

These systems change quickly. Models evolve, agents can take actions, and new risks can emerge much faster than they do in traditional technology environments. In fact, this is already happening. 

Our research found that 46% of organizations already have AI agents live in production today, and 86% have at least tested them. Once agents move from testing into production, we’ve seen the risk profile change with them as the AI begins acting inside real environments, accessing real customer data, executing real transactions, and touching real systems.  

It’s not enough to use assurance models for slower, more predictable, and traditional kinds of technology. The way companies assess AI agents has to evolve too, or else organizations may find themselves falling behind, particularly because clients are soon going to start asking much harder questions. 

The AI Assurance Questions Being Asked Today 

As AI agents become more embedded in businesses, organizations will need to be able to answer: 

  • What data can the agent access?  
  • What actions can the agent take?  
  • How was the AI agent tested?  
  • What happens when the agent does something unexpected?  
  • Who independently evaluated the AI agent, and when was the last time that evaluation happened? 

Companies developing and deploying AI need a way to show their customers, boards, and other stakeholders that their AI governance isn’t just a set of policies or promises. There needs to be evidence behind it, and this is where I think AIUC-1, together with broader independent AI assurance, becomes incredibly important.  

What AIUC-1 Tests in AI Systems  

As the world's first standard focused specifically on the security, safety, and reliability of AI agents, AIUC-1 combines independent assessment of operational controls with technical testing across security, safety, reliability, privacy, and accountability. That technical testing also isn’t a one-time event—it continues at least quarterly. 

And because Schellman is the first accredited auditor for AIUC-1, we are already seeing what that looks like in practice. As part of the first independent audit for the first end-to-end AIUC-1 certification, we reviewed more than 250 pieces of evidence alongside more than 2,000 adversarial testing scenarios. 

To me, that is where this gets really interesting. We aren’t just asking a company whether it has an AI policy. We are looking at whether the controls actually work and how the technology performs when it is tested. 

How AI Governance Frameworks Complement Each Other   

Of course, this kind of technical testing shouldn’t live in isolation.  

To secure their broader AI systems, companies are already navigating ISO 42001, NIST AI RMF, the EU AI Act, and an increasing number of AI compliance requirements, but they lack a way to bring governance, technical testing, and independent assurance together. 

This fragmentation shows up clearly in our research: framework adoption is split across NIST AI RMF (38%), ISO 42001 (23%), and proprietary or internal AI governance frameworks (36%). Nearly a quarter of organizations told us that simply choosing the right framework is their biggest obstacle in making any progress.  

By adding AUIC-1, organizations can bring governance, testing, and assurance together, turning their previously disconnected compliance checklists into one program. 

Not only will this verify more thoroughly that these systems are more secure and safe, this type of governance, testing, and assurance has also proven to accelerate AI scale and innovation.  

According to our research, organizations with mature AI governance run agents in production at more than 3x the rate of organizations still building their programs, a difference of 78% vs. 22%. Independent testing isn't the brake on agentic AI, it's what lets the most advanced organizations move faster with it. 

The Growing Importance of Independent Assurance 

At Schellman, we made the decision early that AI assurance needed to become a real capability for us, not an afterthought. We became the first ANAB Accredited Certification Body for ISO 42001, and the first accredited auditor for AIUC-1, and we continue to invest in the people and expertise needed to assess emerging technology. 

There is still a lot we don’t know about exactly how AI will continue to evolve. But we do know this: as these AI systems become more capable and more autonomous, independent assurance is going to matter more, not less. 

About Avani Desai

Avani Desai is the CEO at Schellman. Avani has more than 15 years of experience in IT attestation, risk management, compliance and privacy. Avani’s primary focus is on emerging healthcare issues and privacy concerns for organizations. Named as one of the 2017 Global Leaders in Consulting by Consulting Magazine she has also been featured and published in the ISSA Journal, ITSP Magazine, ISACA Journal, Information Security Buzz, Healthcare Tech Outlook, and many more. Avani also sits on the board of Catalist, a not for profit that empowers women by supporting the creation, development and expansion of collective giving through informed grantmaking. In addition, she is co-chair of 100 Women Strong, a female only venture philanthropic fund to solve problems related to women and children in the community.