β‘ Quick Summary
Published by the Ada Lovelace Institute and the Center for Democracy & Technology, this discussion paper examines whether and how the AI assurance field should professionalise. It draws on 15 semi-structured interviews with practitioners and experts conducted between November 2024 and February 2025, covering third- and second-party auditing, model evaluation, technical standards bodies, and AI governance training and certification. Following the UK Department for Science, Innovation and Technology, it defines assurance as the process of measuring, evaluating and communicating the trustworthiness of AI systems, and lists practices that fall under it: impact assessments, formal verification, red teaming, audits and conformity assessments.
The paper reports four findings: that AI assurance must coalesce around a defined scope, competencies and core practices; that standards both enable and constrain assurance; that accreditation or certification is not a silver bullet; and that regulation and market forces are the likely primary drivers of professionalisation. Interviewees identified technical fluency, legal and policy acumen and risk management as the core knowledge areas, best held collectively by interdisciplinary teams rather than by one generalist.
It closes with seven recommendations for policymakers, standards bodies and practitioners, covering modular certification 'tracks', national skills agendas, standards tailored to system types and domains, ecosystem-wide adoption including downstream deployers, business-aligned framing of assurance value, and professional norms and ethical culture.
π§© Whatβs Covered
An executive summary sets out the argument and the seven recommendations; the body then works through glossary, introduction, findings, recommendations, conclusion and methodology.
- Glossary: defines AI assurance, audit, professionalisation, first-, second- and third-party assurance, certification, accreditation and standards, distinguishing technical, safety and process-oriented standards.
- Introduction: traces assurance to safety-critical industries such as aviation and pharmaceuticals, and maps the regulatory landscape β the EU AI Act, New York City's Local Law 144, the proposed US VET AI Act and a California bill establishing multi-stakeholder regulatory organisations β alongside ISO 42001, ETSI TS 104 223 and NIST's AI Risk Management Framework. It cites an estimated 500-plus UK companies offering AI assurance goods and services, around 80 of them specialised.
- Finding 1 β scope and competencies: there is no consensus on the activities that make up AI assurance; three core competencies (technical, legal and policy, risk management) are identified, along with differences between traditional machine learning, generative and frontier systems, including prompt engineering and robustness testing, and the claim that evaluation practices for agentic systems are '80% non-overlapping'.
- Finding 2 β standards: standards as enablers and constraints; criticism of binary, process-based criteria in ISO 42001 and of Local Law 144's reliance on the impact ratio; proposals for domain-specific templates.
- Finding 3 β certification and accreditation: existing schemes from BABL AI, ForHumanity, IAPP and IAAA; debate over who should certify; the UKAS example; internal versus external assurance; obsolescence risk and reciprocal recognition.
- Finding 4 β drivers: regulation and market forces, illustrated by the Volvo three-point seatbelt case study and the Volkswagen emissions scandal, plus the risk of market capture.
- Recommendations: seven measures addressed to practitioners, policymakers and standards bodies.
- Methodology: 15 interviews, three research questions, participant IDs P1βP15.
π‘ Why it matters?
For anyone commissioning, performing or overseeing AI assurance, the paper explains why the field's lack of shared scope, competencies and practices matters in practice: clients cannot easily judge provider quality, and process-based standards can be satisfied by minimal effort. Its practitioner evidence is directly useful to those deciding what to demand from auditors, evaluators or certification bodies, and to standards developers weighing horizontal frameworks against domain-specific ones. The paper also connects professionalisation to concrete regimes, discussing how the EU AI Act, Local Law 144 and proposed US legislation create demand, and how a deregulatory turn shifts incentives towards market and liability arguments.
β Whatβs Missing
The authors state that their evidence is partial, resting on 15 interviews that may not reflect all practitioners or all issues facing the sector. The paper does not define the specific competencies, curriculum content or assessment criteria that certification would require, and leaves open who should certify, according to what criteria, and how reciprocal recognition would work. Recommendations are directional rather than operational: no templates, metrics or implementation steps are provided. The analysis is also tied to a particular policy moment β US deregulation, the UK growth agenda and an uncertain national AI bill β that dates quickly.
π₯ Best For
Best for policy advisers and regulators weighing options for professionalising AI assurance; assurance and audit providers deciding how to position skills, certification and service scoping; standards developers and certification bodies working on competency frameworks and domain-specific criteria; and governance or procurement leads who need to judge what an assurance report or certificate actually demonstrates.
π Source Details
Going pro? Considerations for the emerging field of AI assurance, a discussion paper by Lara Groves (Ada Lovelace Institute), Amy Winecoff and Miranda Bogen (Center for Democracy & Technology), published July 2025 by the Ada Lovelace Institute and the Center for Democracy & Technology. 75 pages, English. ISBN 978-1-0684261-1-7, published under a CC-BY-4.0 licence. Preferred citation: https://www.adalovelaceinstitute.org/report/going-pro/. The full text extraction of all 75 pages was available.