| AI assurance profile | Intended use, owners, risk tier, dependencies, obligations, metrics and review frequency. | AI owner, risk, compliance, internal audit | Whether assurance coverage is proportionate. |
| Monitoring and control specification | Signals, thresholds, evidence sources, review steps, escalation and acceptance rules. | ML engineering, platform, operations, governance | How the AI system will be observed and controlled. |
| Periodic assurance report | Performance, drift, controls, incidents, exceptions, unresolved risks and recommendations. | Executives, governance committees, product owners | Continue, restrict, remediate, revalidate or retire. |
| Evidence register | Control evidence, test results, approvals, exceptions, model changes and review history. | Risk, audit, compliance, procurement | Whether decisions are traceable and supportable. |
| Incident and action log | Events, severity, containment, root cause, owner, due date and closure evidence. | Operations, security, model owners, leadership | What must be corrected and by when. |
| Improvement roadmap | Prioritised monitoring, control, documentation, tooling and capability improvements. | AI leadership, transformation, finance | Where to invest to improve assurance maturity. |