KiwiQA's AI assurance practice provides independent validation for AI systems deployed in regulated environments — producing documented evidence of conformity for EU AI Act, Australia's Voluntary AI Ethics Framework, and US NIST AI RMF.
The EU AI Act (February 2025) imposes binding conformity requirements on high-risk AI systems. Australia's government and ASX-listed organisations face mounting expectation of documented AI governance. The era of voluntary frameworks is ending.
From EU AI Act conformity through to bias testing and ISO 42001 gap assessment — KiwiQA provides the independent, documented assurance that regulators, boards, and auditors require.
"We're a federal agency piloting AI-assisted case management. Before going to our minister for sign-off, we needed independent assurance that the system met Australia's AI Ethics Framework principles. KiwiQA provided a structured assurance report with test evidence across all 8 principles — the format our legal team needed."
Everything you need to know — answered.
AI assurance is independent, documented validation that an AI system meets specified quality, safety, fairness, and regulatory requirements. It is needed by any organisation deploying AI in regulated sectors — government, financial services, healthcare — or supplying AI capabilities to organisations in the EU market subject to the EU AI Act's high-risk AI system requirements.
High-risk AI systems under the EU AI Act require documented risk management (Article 9), data governance evidence (Article 10), transparency and instructions for use (Article 13), and accuracy, robustness, and cybersecurity evidence (Article 15). Self-assessment is permitted for most high-risk categories, but must be supported by auditable test artefacts — not policy documents alone.
Bias testing begins by identifying protected attribute groups relevant to the AI system's decision domain. We then measure model performance (accuracy, precision, recall, false positive rate) separately across each group and compute fairness metrics: demographic parity (equal positive prediction rates), equal opportunity (equal true positive rates), and calibration (equal confidence-to-outcome alignment). Disparities above acceptable thresholds are flagged as fairness failures.
The NIST AI RMF (published January 2023) is a voluntary framework for managing AI risks across four functions: Govern (establishing accountability and culture), Map (identifying and contextualising AI risks), Measure (quantifying and assessing risk), and Manage (prioritising and implementing risk responses). It is increasingly referenced in US government procurement and aligns with ISO 42001.
Australia's Voluntary AI Ethics Framework (DISR, 2019) defines eight principles organisations should apply to AI systems: human, social and environmental wellbeing; human-centred values; fairness; privacy protection and security; reliability and safety; transparency and explainability; contestability; and accountability. While voluntary, government procurement guidance increasingly treats adherence as a vendor requirement.
A security audit evaluates controls against known vulnerability classes (authentication, authorisation, injection, cryptography). AI assurance adds dimensions a security audit cannot cover: statistical model accuracy and fairness across demographic groups, hallucination rate and groundedness, bias in training data and outputs, and conformity with AI-specific regulatory frameworks such as the EU AI Act and NIST AI RMF.
EU AI Act conformity, bias and fairness testing, NIST AI RMF alignment, AU AI Ethics Framework evidence — KiwiQA's independent assurance practice produces the documented artefacts regulators and boards require.