Articles & Research

Guidance

AI assurance: a practitioner's checklist

The evidence, evaluation and monitoring practices ACS assessors expect to see in professional portfolios.

ACS Professional Standards Board

American Computer Society, Austin

July 2026 · 6 min read

The United States Capitol dome at golden hour
The United States Capitol dome at golden hour

Practical guidance for members preparing an assurance portfolio, drawn from what assessors most often find missing.

Before deployment

Assessors are not looking for exhaustive testing. They are looking for evidence that you understood what you were deciding. The strongest portfolios open with a precise statement of the deployment context — who is affected, what decision the system influences, what happens when it is wrong in each direction — and only then describe the technical work.

Weak portfolios invert this. They lead with methodology and never establish why those methods were the right ones for this context.

  • A written claim about fitness for purpose, scoped to a named deployment context.
  • Failure analysis distinguishing the cost of false positives from false negatives.
  • Evaluation covering representative, adversarial and out-of-distribution inputs.
  • Documented residual risk that the organization has explicitly accepted.

“A professional who cannot say what would make them stop the system has not finished the assurance work.”

At the point of release

Record who approved the release and on what basis. Record what was not tested and why that was reasonable. Record the rollback procedure and confirm that someone has performed it in anger, in a rehearsal, at least once. An untested rollback is an aspiration.

Where a human is expected to oversee the system, evidence that the oversight is achievable matters more than evidence that it is mandated. If your interface gives a reviewer four seconds and no context, you have designed a rubber stamp and should say so.

After release

Monitoring is where most portfolios thin out. Assessors expect to see the specific signals you watch, the thresholds that trigger action, the named owner of each signal, and at least one worked example of the monitoring producing a decision — including a decision to do nothing, if you can explain the reasoning.

Finally, state your withdrawal conditions. A professional who cannot say what would make them stop the system has not finished the assurance work.

  • Named signals, thresholds and owners, reviewed on a stated cadence.
  • Drift and population-shift checks against the deployment assumptions.
  • Incident records with root cause and the change actually made.
  • Explicit withdrawal conditions agreed with the accountable executive.
Artificial intelligenceData and privacy

Join the professional body behind this work

ACS members receive our research first, free CPD and ethics modules every year, and a route to professional registration assessed by their peers.

Become a member