AI Governance Library

AI Assurance: A Repeatable Process for Assuring AI-enabled Systems

MITRE executive summary of a technical paper setting out a four-step AI assurance process—discovering assurance needs, characterizing and prioritizing risks, evaluating risks, and managing risks—that produces an AI Assurance Plan.
Cover of AI Assurance: A Repeatable Process for Assuring AI-enabled Systems

⚡ Quick Summary

Published by MITRE, this executive summary presents a repeatable process for assuring AI-enabled systems, framed around U.S. federal agencies being encouraged by the White House to accelerate AI use while setting up guardrails to mitigate risks. It defines AI assurance as "a process for discovering, assessing, and managing risk throughout the life cycle of an AI-enabled system so that it operates effectively to the benefit of its stakeholders," and lists governability, accountability, safety, security, privacy, interpretability and equity as characteristics of trustworthy AI.

The process comprises four steps: discovering assurance needs, characterizing and prioritizing risks, evaluating risks, and managing risks. Its output is an AI Assurance Plan, a comprehensive artifact outlining the activities needed to achieve and maintain assurance in a mission context. The plan is completed before deployment, iterated until the desired level of assurance is achieved, and accompanies the system afterwards so stakeholders can make informed acquisition, adoption, deployment and use decisions.

The paper situates the work alongside the NIST AI Risk Management Framework and the Biden administration's AI executive order, and describes MITRE's AI Assurance and Discovery Lab, whose capabilities include AI Assurance Needs Discovery Protocols, the AI Assurance Knowledge Base, ATLAS mitigations, LLM SIREN, an AI Red Teaming Guide, an Assurance Plan Template and an acquisition RFI analysis tool. Five pilot studies and a drone certification example illustrate application.

🧩 What’s Covered

The five-page executive summary covers, in order:

  • Problem framing and definition: begins from White House encouragement for federal agencies to accelerate AI use while setting guardrails, cites the NIST AI Risk Management Framework and the Biden administration's AI executive order as useful catalysts, and notes significant gaps in understanding risks from AI in consequential government functions.
  • The four-step process and its output: discovering assurance needs, characterizing and prioritizing risks, evaluating risks, and managing risks, producing an AI Assurance Plan for a mission context.
  • Laboratory infrastructure: MITRE's AI Assurance and Discovery Lab and its capabilities, including the AI Assurance Needs Discovery Protocol, the AI Assurance Knowledge Base (incorporating anonymized incidents and mitigations from the MITRE ATLAS community), ATLAS Mitigations, LLM SIREN, the AI Red Teaming Guide, the Assurance Plan Template and Development Protocols, the Human Centered AI Test Harness, and an Acquisition RFI Analysis Tool.
  • Pilot studies: five lightweight, rapid investigations—a policy search tool, a course of action recommender, an AI-enabled augmented reality microscope, a healthcare mobile robot and a biometric system—highlighting the need for clear issue definition, separation of AI-specific from broader system assurance issues, comprehensive mitigation strategies and effective communication among stakeholders.
  • Application example: a drone manufacturer seeking certification of AI-based flight software, where the assurance plan captures regulations and guidance such as DO-178C and ARP4761, compliance methods include engineering reviews, analysis, modelling and flight tests, and regulators certify and monitor conformance to requirements such as Part 107.
  • Conclusion and open questions: assurance approaches must be augmented with sector-specific resources; standards are needed to assess an AI system's consequentiality and match it to a commensurate level of assurance; the field resembles cybersecurity two decades ago and depends on investment and public-private partnership.

💡 Why it matters?

Teams that must decide whether an AI-enabled system is fit to deploy get a lifecycle structure rather than a checklist: each of the four steps has defined inputs and outputs, and the assurance plan becomes a maintained artifact that carries evidence from pre-deployment into operation. Anchoring assurance in mission context also gives reviewers a way to separate AI-specific assurance issues from broader system ones, which is what makes the process usable alongside existing regimes—the paper ties it to the NIST AI Risk Management Framework and, in aviation, to certification guidance such as DO-178C, ARP4761 and Part 107.

❓ What’s Missing

The summary states the process and its outputs but not the internal method of each step: no criteria, metrics or thresholds define the "desired level of assurance," and the content and structure of the assurance plan template are not shown. Only the U.S. federal and civil aviation contexts are illustrated; other sectors and jurisdictions are left to sector-specific resources. The authors acknowledge that the science and engineering of AI assurance is "nascent," that significant gaps remain in bringing assurance tools and methods to bear rapidly for specific applications, and that standards for judging consequentiality do not yet exist. References and the full technical paper are absent.

👥 Best For

Government program and acquisition leads deciding how to assess AI-enabled systems; assurance, safety and compliance staff who need a lifecycle structure and a plan artifact to work from; and standards or certification specialists mapping existing regimes such as DO-178C onto AI components. It also serves researchers and laboratory teams building sector-specific assurance capabilities.

📄 Source Details

AI Assurance: A Repeatable Process for Assuring AI-enabled Systems, executive summary, published by MITRE (www.mitre.org); authors Douglas P. Robbins, Ozgur Eris, Ariel Kapusta, Lashon B. Booker and Paul Ward; reference number 24-01019-6; 5 pages; English. The only date printed is a 2024 copyright notice, not a stated publication date. The extraction covers all five pages of the executive summary; the linked technical paper, its references and any figures are not part of this document, and no download URL is printed in the text.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.