AI is reshaping transformation, exposing gaps in assurance approaches developed for a different delivery environment. While traditional governance remains important, organisations also need confidence that assurance is examining the risks created by evolving technologies, data and operating models.
Key Insights:
  • Traditional assurance was designed to assess delivery against a stable plan; AI-enabled capabilities keep changing after go-live
  • AI doesn’t need an entirely new assurance model, but it does change the focus from one-off delivery to continuous engagement around model performance, data quality and vendor-induced change.
  • Confidence in a transformation programme is only as good as the assurance behind it; leaders need to review assurance capability to ensure it is capable of assuring AI-supported delivery.

Organisations invest heavily in governance to reduce the risk of transformation failure. Assurance frameworks, stage gates and independent reviews all help build confidence that programs are progressing as intended. Yet as transformation evolves through AI and automation, many organisations continue to rely on assurance approaches developed for a less complex delivery environment. The result is that organisations can feel well assured, while important sources of delivery risk remain largely unseen.  

Assurance exists to give leaders confidence that transformation is on track. When that confidence is based on assumptions that no longer reflect how change is delivered, it can create a hidden blind spot. Increasingly, the greatest risks are found not within individual projects or governance processes, but in the spaces between established structures. The gap between modern transformation and assurance capability is one such disconnect. 

AI may be changing the way organisations deliver transformation, but it should also prompt leaders to ask whether their assurance capability has evolved at the same pace.  

Why traditional assurance models fall short on AI risk 

Traditional assurance models were developed for a different generation of transformation. Programs followed a more predictable path from planning through to implementation, with relatively stable requirements and clearer boundaries around delivery. Assurance was designed to determine whether the program was progressing as expected and whether the organisation could have confidence in the decisions being made.  

Today’s transformation environment is markedly different. AI is accelerating change across industries, but it’s only one part of a broader change. Cloud platforms continue to evolve after implementation, and automation reshapes business processes over time. Organisations increasingly depend on connected technology ecosystems and data that extends across multiple systems and providers. Change is constant, and the boundaries of transformation have become far less defined. 

AI has made that change harder to ignore. Unlike traditional technology implementations, AI-enabled capabilities can continue to change after deployment as data, user behaviour and operating conditions evolve. Models may perform differently in practice than they did during testing, while AI features embedded within cloud platforms can be updated by vendors without a conventional project cycle. This creates a more fluid risk environment, where some of the most important issues may emerge after the program has passed its formal gates.   

Assurance models may have evolved alongside these changes, but rarely at the same pace. Many organisations continue to rely on assurance approaches that were designed for programs with more predictable delivery models. Those approaches still provide valuable oversight, yet they may not always shed light on the new sources of uncertainty introduced by modern transformation.  

What AI changes about assurance focus and scope 

Traditional assurance is usually very good at confirming that a project is being managed well and that governance is working as intended, by looking at whether risks are being reviewed and delivery is progressing as expected.  

AI introduces a different set of considerations. While some relate to the technology itself, many of the concerns reaching Boards and executive teams relate to the organisation’s obligations around its use. Privacy, copyright and intellectual property, consumer protection and industry regulation can all come into play, depending on how and where AI is deployed. These issues can also change as regulation develops and AI capabilities evolve. 

Performance may need to be monitored long after implementation, data quality becomes an ongoing concern rather than a one-off project activity, and accountability can become less clear when AI-enabled processes begin producing unexpected outcomes. Organisations also need greater visibility of changes introduced through third-party platforms and vendors, particularly where AI capabilities are embedded within existing services. 

This doesn’t mean organisations need an entirely new assurance model for every emerging technology. The principles of good assurance remain the same, but AI changes where assurance needs to focus. Rather than asking whether a project has been delivered successfully, assurance increasingly needs to examine whether: 

  • technology continues to perform as intended 
  • assumptions made during delivery still hold true 
  • new risks are emerging as the organisation adopts and scales AI capabilities. 

Independent assurance has an important role to play in that evolution. By bringing an objective view of emerging risks, assumptions and delivery practices, it can help leaders build confidence in transformation, without slowing innovation. 

Key questions for leaders to assess AI assurance capability 

For leaders, the priority must be asking whether existing assurance practices reflect the nature of the intended transformation. Questions worth asking include:  

  • Does our assurance approach reflect the type of transformation we’re delivering, or are we applying the same framework to every program? 
  • Are we assessing risks that emerge after implementation, particularly where AI capabilities continue to evolve over time? 
  • Do we have sufficient visibility of data quality, model performance and changes introduced by third-party technology providers? 
  • Are assurance activities focused solely on project delivery, or do they extend into operational performance and business outcomes? 
  • How regularly do we review whether our assurance approach remains fit for purpose as transformation evolves? 

These questions build on traditional assurance disciplines, recognising that AI-enabled transformation introduces different assumptions, dependencies and sources of risk.  

Building assurance capability that keeps pace with AI 

Assurance has always existed to give leaders confidence when making decisions about transformation. As AI becomes embedded across organisations, maintaining that confidence will depend on regularly testing whether assurance capability is still aligned to the way transformation is being delivered. 

Reviewing assurance capability should become part of transformation itself, not something that is revisited only when governance frameworks are redesigned. As AI continues to reshape delivery, assurance will need to evolve alongside it. 

Quay Consulting is a professional services business specialising in the project landscape, transforming strategy into fit-for-purpose delivery. Meet our team or reach out to have a discussion today.  

About Quay

Quay Consulting
Quay Consulting is a professional services business specialising in the project landscape, transforming strategy into fit-for-purpose delivery. Meet our team ...