From Model Risk Management to AI Assurance: A Framework for Generative and Agentic AI
Artificial intelligence is changing faster than many of the governance structures designed to oversee it. Traditional Model Risk Management (MRM) remains important, but generative AI, foundation models, retrieval-augmented generation, and increasingly autonomous AI agents introduce risks that extend beyond the boundaries of a conventional model.
That challenge is the focus of our newly published peer-reviewed article, “From Model Risk Management to AI Assurance: Integrating AI Risk Management, Independent Validation, and AI Auditing for Generative and Agentic AI,” coauthored by Dr. Tim Godlove and Dr. John Buchanan and published in Transactions on Engineering and Computing Sciences (TECS), Volume 14, No. 05 (2026), pp. 19–62.
Why Traditional Model Risk Management Is Not Enough
Traditional MRM developed around systems with relatively identifiable boundaries, assumptions, inputs, outputs, and performance measures. Generative and agentic AI complicate that environment. Their behavior may be probabilistic and context dependent, they may rely on externally developed foundation models, their outputs can depend on dynamically retrieved information, and AI agents may interact with other systems or initiate actions with varying levels of human intervention.
Our central argument is not that organizations should abandon MRM. Instead, MRM must become part of a broader AI assurance architecture. No single governance, risk, validation, cybersecurity, or audit function can independently provide complete assurance over increasingly complex AI systems.
The research introduces three concepts intended to help organizations make that transition.
The AI Assurance Boundary
The AI Assurance Boundary expands the focus beyond the AI model itself. Organizations need to consider the models, data, controls, technologies, external dependencies, human actors, and organizational processes that affect whether an AI-enabled capability can reasonably be trusted.
This becomes particularly important when an organization does not control the underlying foundation model. The organization may still be responsible for the consequences of using the system even though critical components are operated by a third-party provider.
The Assurance Sufficiency Principle
Perfect transparency may not always be possible with contemporary AI.
The Assurance Sufficiency Principle addresses situations in which complete transparency, traceability, or explainability cannot be obtained. Rather than treating assurance as an all-or-nothing decision, organizations should determine whether the available evidence is sufficient for the risk and consequences associated with the proposed use. The paper therefore treats assurance as risk-based, with its intensity affected by factors including materiality, autonomy, data sensitivity, regulatory exposure, observability, system topology, and third-party dependence.
The question becomes not simply, “Do we understand everything about this AI model?” but rather:
“Do we have sufficient evidence to justify relying on this AI system for this particular purpose and level of risk?”
The Integrated AI Assurance Framework
The third contribution is the Integrated AI Assurance Framework (IAAF).
The framework connects four distinct but interdependent organizational functions:
AI governance
AI risk management and Model Risk Management
Independent AI/model validation
AI auditing
The objective is not to collapse these responsibilities into a single function. Independence and effective challenge remain important. Instead, the framework establishes a coordinated assurance architecture in which ownership, validation, evidence, escalation, monitoring, and independent assurance work together.
Moving Toward AI Assurance
Generative and agentic AI are expanding what organizations can accomplish, but greater capability also changes the nature of organizational risk. As AI systems become more interconnected, externally dependent, and capable of taking actions, organizations must think beyond whether an individual model performs as expected.
The larger question is whether the entire AI-enabled capability can be relied upon within its intended operating environment.
That is the transition from model risk management to AI assurance.
The framework presented in our research is not intended as a static compliance model. AI technologies, standards, regulations, and organizational practices will continue to evolve. Instead, the IAAF provides an adaptable architecture for bringing governance, risk management, validation, and independent audit together while preserving clear accountability and effective challenge.
Published Research
Godlove, T., & Buchanan, J. (2026). From Model Risk Management to AI Assurance: Integrating AI Risk Management, Independent Validation, and AI Auditing for Generative and Agentic AI. Transactions on Engineering and Computing Sciences, 14(05), 19–62.