AI Governance Library

AI assurance? Assessing and mitigating risks across the AI lifecycle

Ada Lovelace Institute report surveying methods for assessing, monitoring and mitigating risks from AI systems across the lifecycle, in literature, industry practice and emerging legislation, and proposing a UK assessment ecosystem.
Cover of AI assurance? Assessing and mitigating risks across the AI lifecycle

⚡ Quick Summary

Published by the Ada Lovelace Institute, this report surveys how the risks AI systems pose to people and society are assessed, monitored and mitigated across the AI lifecycle, drawing on a desk-based review of grey and academic literature and on analysis of draft legislation that requires anticipation of AI risks.

It defines impact assessment, risk assessment and algorithmic audit, and sets out four ways of thinking about AI risk: risks of particular harms, risks associated with scenarios, with particular technologies, and with specific domains of application. Assessment methods, it finds, typically share five components: risk identification, risk prioritisation, risk mitigation planning, risk monitoring and communicating risks.

The report describes methods in practice, including Canada's algorithmic impact assessment (AIA), the Netherlands' FRAIA, human rights impact assessments, Microsoft's Responsible AI Impact Assessment, HUDERAF, SMACTR, NIST's AI Risk Management Framework and the ICO's AI and Data Protection Risk Toolkit, and emerging legal requirements in the EU AI Act, the UK Online Safety Bill, Brazil and Canada. Its conclusion is that identifying risk alone does not avoid it: an ecosystem of assessment, assurance and audit is needed, with consensus standards, case studies, domain guidance, regulatory capacity and empowered third-party assessors.

🧩 What’s Covered

  • Executive summary and key takeaways: five takeaways argue that no single standardised assessment process or vocabulary exists, that methods share five components, that the EU, USA, Brazil and Canada are mandating assessments, and that standards, case studies, skills and third-party assessors are needed.
  • Definitions and risk framing: key terms distinguish impact assessment, risk assessment and algorithmic audit; risk is defined as a function of the magnitude of harm and the likelihood of occurrence, and four ways of thinking about AI risk are set out.
  • Methods for assessing risks, outcomes and impacts: the five components — risk identification, prioritisation, mitigation planning, monitoring and communicating risks — are explained, with differences in actors, scope of impacts, mandate and communication.
  • Methods in practice: profiles of the Canadian AIA (48 risk and 33 mitigation questions), the Dutch FRAIA, HRIAs, Microsoft's Responsible AI Impact Assessment, HUDERAF, the stakeholder impact assessment, the NHS AIA, SMACTR, NIST's AI RMF and the ICO toolkit, each with actors, lifecycle timing, communication and maturity.
  • Worked examples: a Google celebrity recognition API human rights impact assessment by BSR, and the NHS National Medical Imaging Platform data-access AIA, shown as a seven-step process from reflective exercise to iteration and publication.
  • Emerging law and other mechanisms: requirements in the EU Digital Services Act, proposed EU AI Act fundamental rights impact assessments, the US Algorithmic Accountability Act, Brazil's draft law, Canada and the UK Online Safety Bill; audits, oversight bodies, red teaming, safety checklists, model cards, datasheets and transparency registers.
  • Enabling an ecosystem and further questions: seven proposals, from incentives and case studies to standards, sector guidance, skills, regulatory capacity and third-party assessors; nine open research questions; and the desk-based methodology.

💡 Why it matters?

For regulators, public-sector teams and AI developers, the report turns a fragmented field into a common structure: five components any risk or impact assessment has to deliver, and criteria for comparing methods. It shows what instruments such as Canada's AIA, the Dutch FRAIA and the ICO toolkit actually require, and where legal mandates are emerging. It also argues that assessment alone is insufficient without monitoring, audit and disclosure, connecting everyday assessment practice to the wider assurance ecosystem that government and regulators would have to build.

❓ What’s Missing

The review is desk-based and records few published examples of assessments of real systems, which the authors note makes methods hard to compare or evaluate. Detail on how individual methods work in practice is uneven, and several entries record unclear communication or maturity. The methodology is limited to legislation drafted or documented in English, and the authors acknowledge the need for wider linguistic, geographic and political contexts. The document does not assess how effective the methods it surveys are, and its UK and EU framing is fixed at July 2023, when EU AI Act negotiations were still in progress.

👥 Best For

Policy analysts and regulators shaping AI risk-assessment requirements; public-sector teams procuring or deploying algorithmic systems; compliance and assurance leads designing impact assessment and audit processes; and researchers needing a comparative, referenced map of assessment methods and the emerging legal mandates behind them.

📄 Source Details

AI assurance? Assessing and mitigating risks across the AI lifecycle, published by the Ada Lovelace Institute in July 2023, 43 pages, ISBN 978-1-7392615-5-9, released under CC-BY-4.0. Authored by Jenny Brennan with substantive contributions from Lara Groves, Elliot Jones and Andrew Strait, funded by BRAID. The preferred citation prints the URL https://www.adalovelaceinstitute.org/report/risks-ai-systems/. The extraction covered all 43 pages, ending with the ISBN and citation page.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.