INDEPENDENT AI AUDIT AND ASSURANCE
Is your AI governed, controlled and supported by defensible evidence?
Liajocom Consulting independently assesses AI governance, applications, models and supporting control environments. Our work connects technical behaviour, data, security, human oversight, regulatory expectations and business accountability.
The objective is not merely to determine whether policies exist. It is to establish whether the controls are appropriate for the AI system, operate in practice and produce evidence that can withstand independent challenge.
AI adoption can advance faster than assurance
AI may be introduced through internal projects, cloud services, business applications, productivity tools, external models, retrieval systems and autonomous agents. The resulting risks do not belong to only one function. They cross business governance, technology, cybersecurity, data protection, model risk, third-party management, compliance and operational resilience.
Liajocom Consulting provides an independent view of how these elements work together and whether management’s assertions are supported by reliable evidence.
When an independent AI audit is valuable
Before or during deployment
Obtain an independent assessment of governance, risk classification, design decisions, control requirements and readiness before an AI system becomes operationally critical.
After deployment
Determine whether controls, monitoring, human oversight and incident arrangements continue to work after the system enters real-world operation.
Before independent challenge
Prepare management, Risk, Compliance or Internal Audit for supervisory enquiries, customer concerns, external audit, governance review or formal assurance activity.
Questions the audit can answer
The audit can assess whether the organisation identifies internal, embedded, outsourced and employee-initiated AI use, and whether relevant systems have accountable owners.
The assessment can examine the documented purpose, stakeholder impact, materiality, organisational role, applicable requirements and rationale supporting each classification.
The audit can trace data through prompts, source systems, retrieval components, model providers, logs, storage, subprocessors and administrative access arrangements.
The assessment can examine source attribution, validation procedures, performance information, explainability, human review, override arrangements and escalation.
The audit can evaluate due diligence, contractual responsibilities, information rights, model changes, subcontracting, geographic processing, monitoring, continuity and exit considerations.
The engagement can test whether documented controls produce consistent, traceable and sufficiently reliable evidence rather than existing only as policy statements.
AI audit scope
Scope is selected according to the system’s purpose, risk, architecture, lifecycle stage, operating model and available evidence. Not every engagement requires every area below.
AI Governance
Governance structure, accountability, policies, risk appetite, approval authority, system inventory, lifecycle oversight, management information and escalation.
AI Applications and Models
Intended purpose, architecture, dependencies, model characteristics, configuration, integration, change control, validation and alignment with business requirements.
Generative AI, LLM and RAG
System instructions, model selection, retrieval design, source governance, grounding, citations, hallucination controls, vector-store access and output evaluation.
AI Agents
Agent identity, permissions, tools, APIs, approval gates, transaction limits, segregation of duties, logging, error propagation and emergency suspension.
Data and Privacy
Data provenance, quality, suitability, minimisation, personal and confidential information, retention, processing locations, access, lineage and lawful use.
Human Oversight
Reviewer competence, access to supporting evidence, authority to challenge or override, workload, escalation, exception handling and accountability for final decisions.
Bias, Robustness and Drift
Performance criteria, subgroup analysis, fairness considerations, unusual inputs, stability, adversarial behaviour, operational drift, thresholds and revalidation.
Third-Party AI
Provider due diligence, contractual controls, model and service changes, subprocessors, concentration risk, responsibilities, assurance evidence, portability and exit.
EU AI Act Readiness
Organisational role, risk classification, governance, transparency, documentation, logging, human oversight, monitoring, AI literacy and evidence supporting applicable obligations.
A scope proportionate to the assurance need
Targeted AI Control Review
An assessment focused on one control domain, such as governance, data protection, human oversight, AI security, third-party risk or monitoring.
Suitable when:
- A specific concern has been identified
- A recent change requires independent review
- Management needs a focused conclusion
- The wider control environment has already been assessed
Typical output:
Focused conclusions, findings and recommended actions.
AI System Audit
An end-to-end audit of one AI application, model, RAG solution or agent, including its business use, architecture, data, controls, human involvement and monitoring.
Suitable when:
- The system is operational or approaching deployment
- The use case affects important processes or stakeholders
- Management needs an independent system-level conclusion
Typical output:
Scope-specific audit report and remediation register.
Enterprise AI Assurance Review
An organisation-wide assessment of AI governance, inventory, classification, lifecycle controls, risk ownership, third-party dependencies and management oversight.
Suitable when:
- AI is used across several business areas
- There is no consolidated assurance view
- Management needs prioritised enterprise-wide action
Typical output:
Executive assurance report and risk-based roadmap.
Risk-based and evidence-driven
1
Understand
Establish the system’s purpose, stakeholders, architecture, lifecycle stage, decisions, dependencies, operating context and material risks.
2
Determine criteria
Identify applicable internal requirements, contractual obligations, governance expectations, control objectives and agreed assessment criteria.
3
Examine evidence
Review documentation, configurations, records, data flows, validation results, contracts, monitoring information, logs and other relevant evidence.
4
Test and challenge
Evaluate control design and operation, investigate exceptions, challenge assumptions and determine whether evidence supports management’s assertions.
5
Conclude and report
Connect observations to risks, control objectives, causes, consequences and practical remediation priorities.
Evidence, not promises
The precise evidence depends on the engagement scope, system type and access rights. The presence of a document is not treated automatically as proof that a control operates effectively.
Governance and lifecycle evidence
- AI inventory and classifications
- Policies, standards and procedures
- Roles and decision authorities
- Roles and decision authorities
- Risk and impact assessments
- Approval and exception records
- Model or system documentation
- Validation and testing results
- Monitoring and incident records
- Management reporting
- Training and competence records
Technical and operational evidence
- Architecture and data-flow diagrams
- Access and permission configurations
- Prompts and system instructions
- Retrieval and vector-store configurations
- Model and provider information
- Sample inputs and outputs
- Logs and traceability records
- Performance and drift measures
- Third-party contracts and assurance reports
- Change and release records
Clear conclusions for management and control functions
Deliverable 1: Executive summary
Key conclusions, principal exposures, decisions required and areas requiring management attention.
Deliverable 2: Scope
and assessment criteria
Clear record of the systems, processes, locations, evidence and control objectives included and excluded.
Deliverable 3:
Detailed findings
Evidence-based observations linked to risks, control expectations, consequences and recommended actions.
Deliverable 4:
Remediation register
Prioritised actions with agreed ownership and target information where included in the engagement.
Deliverable 5:
Evidence trail
Traceability between questions, evidence reviewed, testing performed, exceptions identified and conclusions reached.
Deliverable 6:
Closing presentation
Structured communication of conclusions, open matters and management decisions to relevant stakeholders.
Every material conclusion should be explainable. Every finding should be supported. Every recommendation should be actionable.
Technical understanding combined with audit discipline
Independent

Liajocom Consulting does not resell AI products or receive platform commissions. Audit conclusions are not influenced by an implementation agenda.
Technically grounded

The assessment considers how systems, infrastructure, data, models, security and operational processes work together.
Audit-grade

Conclusions are based on defined criteria, relevant evidence, proportionate tests and professional judgement.
Founder-led

Engagements receive direct senior involvement from scoping through assessment, conclusions and reporting.
Important clarification
Frequently asked questions
No. An assessment may be performed during design, before deployment, after deployment or following a significant change. The criteria and testing available will differ according to the lifecycle stage.
No. Testing depth depends on purpose, risk, system type, contractual access, available evidence and the agreed scope. An audit of an externally provided model may focus more heavily on integration, data, governance, provider evidence, monitoring and human controls.
Yes. A targeted review may address one concern, such as data leakage, RAG controls, human oversight, provider risk, agent permissions or AI Act classification.
No. AI systems outside a particular regulatory risk category may still create material security, privacy, operational, conduct, contractual, reputational or business risk.
Yes. Stakeholder involvement is agreed during scoping. Responsibilities and independence should remain clear throughout the engagement.