Structured professional learning

AI Assurance Academy

Twenty detailed chapters move from AI assurance foundations to evidence, human oversight, continuous operations, and inspection readiness.

A lifecycle curriculum, not a list of AI buzzwords

Each chapter defines the practitioner position, method, worked examples, failure modes, evidence expectations, inspection questions, and limits. Read in order or enter at the decision you need to make.

Browse All 20 Chapters
Part 1

Foundations and risk framing

01

Foundation · Published

From Deterministic Validation to AI Assurance

AI changes the assurance problem because correct behavior can no longer be reduced to “the same input always produces the same output.” A professional CSA strategy therefore validates the complete sociotechnical system: intended use, data, model, application logic, human decisions, operating controls, and evidence over time.

Objective-led chapter6 min
02

Foundation · Published

Classifying AI Systems and Drawing the Boundary

An AI assurance strategy fails early when the team treats “the model” as the system. This chapter provides a practical taxonomy and boundary method for predictive models, computer vision, generative AI, retrieval-augmented generation, embedded vendor features, and agents.

Objective-led chapter6 min
03

Foundation · Published

Intended Use and Context of Use

The intended-use statement is the anchor for AI requirements, risk, data, evaluation, human oversight, monitoring, and change control. This chapter shows how to write one that is precise enough to validate.

Objective-led chapter6 min
04

Foundation · Published

GxP Applicability and Risk-Based Scoping

Professional AI assurance starts by identifying the governing process and record—not by declaring that every AI tool is GxP or that every assistant is merely “productivity software.” This chapter provides a feature-level scoping method.

Objective-led chapter6 min
Part 2

Data, models, and evidence

05

Practitioner · Published

Governance, Accountability, and the AI Inventory

AI governance becomes operational only when every production use has an owner, an identifiable configuration, a risk decision, a monitoring obligation, and a controlled path to change or retirement. This chapter turns policy into lifecycle gates.

Objective-led chapter6 min
06

Practitioner · Published

Risk Analysis for AI Failure and Uncertainty

AI risk analysis must move beyond a generic statement that “the model may be wrong.” The practitioner must identify how a specific error arises, how it propagates through the process, whether it can be detected, and which controls actually interrupt the chain.

Objective-led chapter6 min
07

Practitioner · Published

Data Governance, Provenance, and ALCOA+ for AI

In AI-enabled GxP systems, data is not merely an input. It shapes model behavior, defines the evaluated population, supports the validation conclusion, and may become part of the regulated evidence. This chapter applies data-integrity thinking across the AI lifecycle.

Objective-led chapter6 min
08

Practitioner · Published

Dataset Design, Independence, and Leakage Control

An AI evaluation can look rigorous while materially overstating performance if the data split leaks related records, the challenge set resembles development data, or prevalence differs from intended use. This chapter shows how to design defensible datasets.

Objective-led chapter6 min
Part 3

Testing and human oversight

09

Practitioner · Published

Supplier and Foundation-Model Assurance

Commercial AI creates a layered supply chain: SaaS application, foundation-model provider, cloud host, retrieval service, monitoring tools, and data subprocessors. Supplier leverage is essential, but it cannot replace customer understanding of intended use and configured risk.

Objective-led chapter6 min
10

Practitioner · Published

Requirements and Acceptance Criteria for Probabilistic Systems

“The AI shall be accurate” is not a verifiable requirement. AI requirements must define the context, population, error tolerance, uncertainty response, human control, records, and operating limits that together make the use acceptable.

Objective-led chapter6 min
11

Practitioner · Published

Performance Evaluation and Metric Selection

AI assurance can fail through mathematically correct but operationally irrelevant metrics. This chapter connects the harmful process error to metrics, thresholds, uncertainty, prevalence, subgroup performance, and release decisions.

Objective-led chapter6 min
12

Practitioner · Published

Verification Strategy, Challenge Sets, and Repeatability

AI verification must test more than average model performance. A professional strategy challenges the full implemented system under normal, boundary, abnormal, adversarial, and operational conditions while preserving enough evidence to support an accountable decision.

Objective-led chapter6 min
Part 4

Operations, suppliers, and change

13

Advanced · Published

Assuring Retrieval-Augmented Generation

Retrieval-augmented generation can improve source grounding, but it creates an eight-stage assurance chain. A correct source may be excluded, split badly, retrieved incorrectly, ignored by the model, or cited inaccurately. This chapter treats RAG as a controlled knowledge system.

Objective-led chapter6 min
14

Advanced · Published

Generative AI, Hallucination, and Content Risk

Generative AI can draft, summarize, translate, compare, and search at scale, but fluent language can hide unsupported claims, harmful omission, and invented evidence. Assurance must evaluate claims, sources, workflow reliance, and user behavior—not simply whether an answer sounds good.

Objective-led chapter6 min
15

Advanced · Published

Human Oversight and Automation Bias

“A human reviews the output” is not evidence of effective control. Human oversight must be designed, tested, monitored, and resourced so the reviewer can detect error, resist automation bias, and act before impact.

Objective-led chapter6 min
16

Advanced · Published

Part 11, Electronic Records, and AI Traceability

AI introduces new questions about what constitutes the record, which metadata reconstructs a decision, how electronic signatures bind to AI-assisted content, and whether audit trails capture meaningful change. Part 11 analysis must start with predicate rules and actual intended use.

Objective-led chapter6 min
Part 5

Governance and inspection readiness

17

Advanced · Published

Change Control and Revalidation Triggers

AI behavior can change when the model, data, prompt, retrieval corpus, software, supplier routing, or operating population changes. A mature change-control system identifies these dependencies and scales revalidation to the affected risk.

Objective-led chapter6 min
18

Advanced · Published

Monitoring, Drift, Incidents, and CAPA

Release testing establishes confidence at one point in time. Operational monitoring determines whether the AI-enabled system remains inside the approved envelope and whether users, data, suppliers, or models have changed the risk.

Objective-led chapter6 min
19

Advanced · Published

Cybersecurity and Agentic AI Controls

An AI agent can select tools, plan steps, read records, create transactions, and adapt after intermediate results. That authority converts model error into system action. Assurance must therefore combine CSA, software security, identity, tool governance, human authorization, and safe recovery.

Objective-led chapter6 min
20

Advanced · Published

End-to-End Case Study and Inspection Readiness

This capstone applies the complete series to an AI-assisted deviation-triage service in a cloud eQMS. It demonstrates how to make a release decision, assemble evidence, respond to a monitoring signal, and explain the system during an inspection.