⚡ Quick Summary
Published by The MITRE Corporation, this report sets out the AI Assurance (AIA) Landscape, a concept map built as a step toward a standard set of AI assurance concepts. The landscape comprises a superordinate node, Trustworthy AI, 11 primary categories of AIA needs and 66 sub-ordinate concepts called specific assurance needs, each defined in an accompanying glossary. MITRE defines AI assurance as "a process for discovering, assessing, and managing risk throughout the life cycle of an AI-enabled system".
The report explains the landscape's purpose, the process used to build it and the rationale for it. The landscape was synthesised from approximately 50 AIA documents, with 10 frameworks judged most comprehensive; the starting list of concepts came from Fjeld et al. (2020) and the NIST AI RMF (Tabassi, 2023). Concepts were disambiguated, combined under common terms and grouped by thematic analysis, then peer-reviewed, pilot tested with Stakeholders and cross-validated against randomly sampled frameworks. Tables 1 and 2 map the landscape's categories to those source frameworks.
The stated conclusion is that no standard assurance scheme yet captures the full range of AIA needs, and that the landscape is a first step toward integrating frameworks to identify a standard set of assurance needs and a common set of definitions.
🧩 What’s Covered
The report moves from definition to development to rationale; the landscape itself and the glossary sit in the appendices.
- Introduction: defines an AI-enabled system through the OECD (2024) formulation and gives MITRE's definition of AI assurance as "a process for discovering, assessing, and managing risk throughout the life cycle of an AI-enabled system", together with four accepted assurance goals.
- What the AIA Landscape is: a visual synthesis of existing AIA frameworks and reports in the form of a concept map with one superordinate node (Trustworthy AI), 11 primary categories of AIA needs and 66 specific assurance needs, each defined in the glossary; needs left unaddressed can result in technological, mission-related and societal risks.
- Purpose: a first step toward a standard set of AIA concepts in a single, domain-agnostic representation; disambiguating related or synonymous assurance concepts; a supplement to, not a replacement for, an organisation's own framework; a key tool in the Risk Discovery Protocol for AI Assurance (RDP-AIA).
- Development process: environmental scan of approximately 50 AIA documents and selection of the 10 most comprehensive; generation of a list of unique assurance concepts from Fjeld et al. (2020) and Tabassi (2023); categorisation with definitions cross-validated against standards and literature; iterative refinement through peer review, Stakeholder pilot testing and cross-validation.
- Mapping tables: Table 1 maps each AIA category and specific need to Fjeld et al.'s themes and to the NIST AI RMF trustworthy characteristics and core functions; Table 2 gives a more cursory approximate mapping to eight further comprehensive frameworks, among them GAO (2021), DIB (2019), Leslie (2019), ODNI (2020a, 2020b), Shneiderman, ELATE, the CDAO Responsible AI Toolkit and Executive Orders 14110 and 13960.
- Rationale: more than 50 frameworks and over 500 reports, varied naming conventions (Accountable AI, Responsible AI, Trustworthy AI and others), inconsistent and sometimes tautological definitions; section 5.1 covers the consequences, 5.2 earlier synthesis efforts such as Fjeld et al.'s 47 principles in eight themes, and 5.3 the difficulty of translating between schemes.
- Appendices: A lists references; B lists the AIA Landscape Resources reviewed; C lists additional resources used to define terms; D is the glossary of all 11 categories and 66 specific assurance needs with definitions and sources.
💡 Why it matters?
Teams asked to demonstrate that an AI system is trustworthy face a fragmented vocabulary: frameworks use different names, groupings and definitions for overlapping needs. The report supplies a single set of 11 categories and 66 specific assurance needs, each with a definition and a source, so risk registers, assessment questions and assurance arguments can be phrased consistently and compared across frameworks. It also documents where existing schemes diverge — for example, Fjeld et al. combine safety and security while the NIST AI RMF separates safety from security and resilience — which helps auditors explain why an item in one framework does not map cleanly onto another.
❓ What’s Missing
The landscape is a conceptual vocabulary rather than an assessment method: it gives no criteria, scoring or maturity levels for deciding whether a specific assurance need is satisfied, and no procedure for selecting which of the 66 needs apply to a given system. Inputs were limited to resources available in early-mid 2023, and the report states that future versions will add frameworks unavailable at publication. The mappings in Table 2 are described as approximate and cursory, with implied categories added in parentheses and grey text. The landscape is a graphic, so its structure can only be read through the glossary and tables.
👥 Best For
Best for AI assurance and risk practitioners who need a shared vocabulary, for framework authors and standards teams comparing assurance schemes, and for organisations using MITRE's Risk Discovery Protocol for AI Assurance. Also useful for governance and audit staff who must reconcile requirements drawn from several frameworks, and for analysts mapping NIST AI RMF or Fjeld et al. concepts onto their own assurance scheme.
📄 Source Details
The AI Assurance Landscape (v1.0): Toward a Standardized Framework of Unique and Differentiated AIA Concepts, by Paul Ward, Jeff Stanley, Ron Ferguson and Joanna Korman, The MITRE Corporation, McLean, VA, September 2024, 41 pages, English. Public Release Case Number 24-2962. The input was a text extraction covering all 41 pages, including Appendices A–D; the concept-map figure is a graphic and is not reproduced in the extracted text. No URL for this document itself is printed in it.