Ask five organisations what their “AI audit” covers and you will get five answers. Some mean a control review. Some mean a bias test. Some mean an inventory exercise. The vocabulary collapse is not pedantry: it produces scopes that promise one thing and deliver another, and it lets a weak activity borrow the credibility of a stronger one.
Three terms do most of the work, and they are genuinely different.
The short distinction
| Question it answers | Primary output | Independence required | |
|---|---|---|---|
| Risk assessment | What could go wrong, how badly, how likely? | A prioritised risk register | None — usually first line |
| Assurance | Is the claim about this system true, on the evidence? | An opinion with an evidence base | Substantive — second or third line |
| Audit | Did we conform to a defined standard or control set? | A conformity finding | Formal — often external |
AI risk assessment
Risk assessment is forward-looking and speculative. It asks what could go wrong before you have evidence about what does. Its output is a prioritised list: harms, affected parties, likelihood, severity, and the controls proposed against each.
It is normally performed by the people building or deploying the system, and that is appropriate — they know the system best. It is also its main weakness. A team assessing the risk of its own work is subject to obvious pressures, which is why risk assessment is an input to assurance rather than a substitute for it.
ISO/IEC 23894 is the reference point here.
AI assurance
Assurance is evidential and retrospective. It takes a claim — “this model performs within tolerance for the population it serves”, “human review is meaningful” — and asks whether the evidence supports it.
Two features distinguish it:
It requires a claim. You cannot assure a system in the abstract. Where no explicit claim exists, the first job is to extract one, and this is often where the real value appears: teams discover they have never written down what they are relying on the system to do.
It requires independence proportionate to the stakes. Not necessarily external, but someone who does not own the outcome. Assurance performed by the delivery team is a self-assessment, and should be labelled as one.
The output is an opinion with a scope, a basis, and stated limitations — the structure financial audit has used for a century.
AI audit
Audit is conformity assessment. It measures a system, or the management system around it, against a defined standard and reports whether the requirements were met.
The critical property is that the criteria are external and fixed in advance. An audit against ISO/IEC 42001 asks whether the organisation’s AI management system meets that standard’s requirements. It does not ask whether the AI is a good idea, whether the model is accurate enough for its purpose, or whether the risk appetite is sensible.
This makes audit powerful and narrow at once. A clean audit report says conformity was demonstrated. It does not say the system is safe, and treating it as though it does is the single most common category error in this space.
Why the distinction has practical consequences
Scoping. “Audit our AI” is not an executable instruction. It resolves into: audit the management system against 42001, assure the claims made about three high-risk deployments, or refresh the risk assessment on the new agentic workflow. These have different costs, different skills, and different outputs.
Independence. Each activity has a different independence requirement. Assigning assurance work to the delivery team, or accepting a vendor’s own risk assessment as assurance, defeats the purpose while producing a document that looks like it did not.
What you can say afterwards. A risk assessment lets you say what you considered. An assurance opinion lets you say what you verified and within what boundary. An audit finding lets you say you conformed to a named standard. Claiming more than the activity supports is where organisations get into difficulty — with regulators and, eventually, in litigation.
A working rule
Before starting, write one sentence in this form:
We are performing [activity] of [scope], against [criteria], to support the claim that [claim], for [audience].
If you cannot complete the sentence, the engagement is not yet scoped. If completing it reveals that the criteria are internal and the assessor is the builder, you have a self-assessment — which may be exactly right for the risk, but should not be described as assurance.
Getting this vocabulary right is part of the baseline competence assessed in the Certified AI Assurance Practitioner track.