Assurance
Evidence that your controls hold.
Claiming you have AI governance and being able to prove it are different things. Assurance is independent verification: that vendor claims are accurate, that your models behave as described, and that the controls you've put in place are working in practice, not just on paper.
The Distinction
Governance without assurance is intention. Assurance is the evidence.
Scope of Assurance Work
Vendor Claims Verification
AI vendors make claims about how their models work, what data they were trained on, and how they perform across different populations. Independent review tests those claims against your actual operating environment. We examine model cards, audit documentation, contractual representations, and performance outputs to determine where vendor claims hold and where they don't.
What you walk away with
→
Vendor documentation review: model cards, data sheets, audit reports
→
Gap analysis between vendor claims and observed model behaviour
→
Contractual representation assessment: what the vendor has committed to in writing
→
Risk rating for each gap with recommended remediation
→
Summary suitable for General Counsel and procurement review
Model Behaviour
How a model behaves in a controlled test environment and how it behaves on your data can differ significantly. We test the model's outputs against your use cases, examine performance across relevant demographic groups where data is available, and identify drift, inconsistency, or behaviour that does not match the stated design.
What you walk away with
→
Output consistency assessment across operational conditions
→
Fairness and bias review where decision-impacting outputs are involved
→
Performance gap analysis between vendor benchmarks and your operational data
→
Drift assessment for models that have been in production for 12 months or more
→
Written findings with evidence for each finding
Operational Guardrails
Controls that exist on paper but are not followed in practice provide no actual protection. We review whether your governance processes are being applied, whether staff are following documented protocols, and whether your escalation paths function as designed. The output is documentation a regulator would accept as evidence of operational governance.
What you walk away with
→
Process walk-through with operational staff to verify documentation reflects practice
→
Escalation path verification: does the documented path match the actual path
→
Oversight mechanism review: who reviews what, how often, and with what authority
→
Gap report with prioritised remediation steps
→
Board-ready assurance summary
The Engagement
This work is delivered through the Model Behaviour & Controls Testing engagement. 3–5 weeks, fixed scope.
Typical Buyers
General Counsel / CCO
When documentation exists but operational evidence does not.
General Counsel and Chief Compliance Officers commission assurance reviews when governance documentation exists but operational evidence does not. A policy nobody has verified is not a defence.
Procurement Teams
Before vendor claims become your liability.
Buying an AI tool based on vendor claims is a liability if those claims are not independently verified. Procurement teams use assurance work to close the gap between what a vendor says their model does and what it actually does in your environment.
Boards & Audit Committees
Something substantive to evaluate not just a policy to accept.
Boards are increasingly accountable for AI governance. An independent assurance review gives the board something substantive to evaluate, not just a policy document to accept.
CEOs Post-Incident
After something has gone wrong and before it goes further.
After an AI-related incident or near-miss, assurance work establishes what the controls were, whether they were followed, and what failed. It is also the basis for remediation.
Most firms give you a report. Meninge gives you a position you can defend.
30 minutes, on the record, no obligation. We'll tell you whether we're the right fit before you spend a dollar.