Skip content

In machines we trust?

AI has made trust cheap. Now we need to make it valuable again.

Ian Spaulding Chief Executive Officer (CEO), LRQA View profile

The debate around Artificial Intelligence has reached an extraordinary place. Between ‘AI will save humanity’ and ‘AI could end it’ sit thousands of decisions being made by organisations today. AI is already influencing how companies recruit people, allocate capital, monitor supply chains, manage data and run increasingly complex operations.

For business leaders, the immediate question is less dramatic, but considerably more useful: how do you know AI is doing what you say it is doing, and who has independently checked?

Science fiction prepared us for rogue computers, sentient machines and robots turning against their creators. It spent rather less time on the risk of perfectly ordinary people putting too much faith in a perfectly convincing machine. Yet that may be the more immediate challenge. 

The Testing, Inspection and Certification (TIC) industry cannot settle the debate about humanity’s relationship with AI. But we can contribute something currently in much shorter supply: evidence.

And, in many ways, we have been here before.

 

We have always needed someone to check

Society did not resolve every question about the steam engine before we started inspecting boilers. As railways, factories and machinery transformed economies, we learned that powerful technologies needed standards, competent inspection and, critically, someone independent of the owner to check that things were as they claimed. That principle has survived every major technological shift since.

AI is different in its capability and speed, but the underlying trust problem is remarkably familiar. Organisations will increasingly tell us their AI is responsible, controlled and well governed. The question is who verifies it.

We saw a more recent version of this with ESG. As sustainability rose up the corporate agenda, organisations became increasingly sophisticated at measuring and managing ESG risk. And entire industries, such as finance, raced to position themselves as the trusted authority (effectively providing the market’s stamp of approval). But an important distinction emerged: managing a risk, however sophisticated the approach, is not the same as independently assuring it. We should be careful not to repeat that with AI.

The resulting scrutiny of green claims should be instructive for AI. Because AI adds another complication. It can generate a convincing policy, risk assessment, supplier response or compliance document in seconds. As the cost of producing a plausible claim falls, the value of independently proving one rises.

 

AI changes both sides of the equation

There are really two AI questions for our profession. The first is assurance of AI: how do we independently verify that organisations are developing, deploying and governing AI responsibly? The second is assurance with AI: what happens when AI becomes part of the way auditors, inspectors and risk professionals themselves reach conclusions? The second may ultimately be the more important integrity question.

And assurance of AI will need to go beyond checking that the right policies exist. Just as cybersecurity has developed red teams to actively probe systems for weaknesses, credible AI assurance will increasingly need ways to challenge models, test outcomes and interrogate the security and integrity of the data behind them.

AI can interrogate volumes of information no auditor could realistically process, identify anomalies across thousands of transactions and continuously analyse risks that were previously sampled periodically. We should embrace that.

Medicine offers a useful analogy. Technology transformed what clinicians could see and understand, but an MRI scanner did not remove the need for medical judgement. AI can read the scan. Someone still has to own the diagnosis.

The same must be true in assurance. If AI drafts a finding an auditor has not independently reached, the report may look perfectly credible, but something fundamental has been lost. A ‘human in the loop’ means very little if the human simply approves what the machine has produced. AI should strengthen professional judgement, not provide somewhere for accountability to hide.

 

From annual check-up to continuous assurance

AI also challenges something more fundamental: the speed at which assurance operates. Traditional assurance often resembles an annual medical check-up. We examine evidence at a point in time, reach a conclusion and return at an agreed interval.

But AI risk does not operate on that timetable. Models change. Data changes. Applications change. New tools appear inside organisations almost overnight. And as organisations become more dependent on large language models, questions about where data sits, which models it passes through and whose rules govern it become increasingly important. Data sovereignty is part of how organisations - and governments - think about control, resilience and trust. That is so far beyond the realms of IT.

The future of assurance may therefore look less like the annual check-up and more like the heart monitor: continuous signals, intelligent analysis and expert intervention where it matters. That is a much bigger opportunity than using AI to write audit reports faster. AI should not remove judgement from risk management. It should remove the work that gets in the way of judgement.

 

From ‘trust us’ to ‘prove it’

Independent assurance cannot operate in a vacuum. AI also needs effective regulation. Governments need to establish clear expectations and boundaries, and industry should be asking for them. We need regulation that gives organisations the confidence to innovate while establishing clear accountability when things go wrong.

Let’s also be clear that regulation, standards and assurance are not alternatives. Regulation sets the rules; standards help organisations build systems to meet them; independent assurance tests whether those systems are working.

This is where ISO/IEC 42001 matters. Having an AI policy or responsible AI principles will soon be unremarkable. The differentiator will be whether an organisation can demonstrate that its governance works in practice.

ISO/IEC 42001 gives organisations an internationally recognised management system for governing AI and provides a basis for independent assessment. It moves the conversation from ‘trust us, we manage AI responsibly’ to ‘here is the evidence.

That distinction matters. Certification of an AI management system does not mean declaring that every AI system an organisation operates is universally ‘safe’. We must be precise about what has, and has not, been assured.

Nobody in our profession can tell business leaders whether AI will ultimately save or destroy humanity. But we have spent generations doing something rather more practical: making important claims checkable.

And in an age when AI makes convincing claims almost effortless, that role becomes more valuable, not less. If your organisation says it is using AI responsibly, are you ready to prove it?

 

Talk to LRQA about ISO/IEC 42001

Latest news, insights and upcoming events