Field report

Enterprise Assurance Stack: What’s New

Scope. This report reviews five primary sources on enterprise AI governance and assurance, four ISO/IEC standards and the IIA AI Auditing Framework, and reads them as a set. Dr. Fisher's research fleet of agents gathers and cross-tabulates sources; every claim below cites a primary source and is reviewed by the editor. Verification status is noted inline on each finding.

The headline

Five primary sources arrive together and, read as a set, they are not five loose standards. They are a layered AI-assurance stack that maps cleanly onto the classic three-lines-of-defense governance model. Read together, they form the board-to-certifier chain an organization needs to make a credible, third-party-verifiable claim that its AI management system works.

The stack, top to bottom:

(Finding 1, verified.)

Why it matters

The chain now closes on conformity, not self-attestation. ISO/IEC 42006:2025 sets requirements for the bodies that audit and certify AI management systems, i.e. it accredits the certifiers. That is the piece that turns "we say our AIMS is sound" into "an accredited third party certifies it." Without it the assurance chain dead-ends at self-declaration. (Finding 2, verified: https://www.iso.org/standard/42006.)

AI governance is being positioned as an extension of existing board-level IT governance, not a greenfield regime. ISO/IEC 38507:2022 sits in the ISO/IEC 385xx IT-governance (ISO 38500) numbering family, not the 420xx AI family. The numbering is the tell: boards are meant to govern AI through the IT-governance muscles they already have. (Finding 3, verified: https://www.iso.org/standard/56641.html.)

There is a visible maturation timeline. Board governance (2022) and risk guidance (2023) landed first; the operational impact-assessment and certification standards (both 2025) came later. The scaffolding matured top-down: first who governs and how you reason about risk, then how you assess a specific system and who certifies the whole thing. (Finding 4, verified: 56641 · 77304 · 42005 · 42006.)

What you can actually read today

Four of the five are paywalled ISO catalog pages. The IIA AI Auditing Framework is the only openly readable full-text source in the set: a 9.49 MB PDF (content-length 9,486,909 bytes), HTTP 200. If you want to read one thing from this set end-to-end without a standards-body purchase, it is this. (Findings 5 + 9, verified: https://www.theiia.org/globalassets/site/content/tools/professional/aiframework-sept-2024-update.pdf.)

The gap this set does not fill (agentic-RAI note)

This is entirely management-system / organizational-audit scaffolding. It contains no agentic-RAI content, no agent evaluation, no eval validity, no control, no oversight. It tells an enterprise how to govern and certify that AI is well-managed; it does not supply the technical-eval layer it is meant to assure. So the layer this brief focuses on most, agentic evaluation and control, sits underneath this stack, still without a standardized counterpart here. The stack assures a floor it does not itself define. (Finding 6, verified: 42006 · 42005 · 77304 · 56641 · IIA PDF.)

Two mappings worth carrying: flagged unverified

These are analyst hypotheses, useful for orientation, not yet verified. Treat as leads, not facts:

  • NIST AI RMF mapping (unverified): 38507→GOVERN, 42005→MAP, 23894→MEASURE/MANAGE, with IIA + 42006 acting as assurance over GOVERN. Weakest coverage falls on MEASURE: consistent with the agentic-eval gap above. (Finding 7, unverified: 56641 · 77304 · 42005.)
  • EU AI Act harmonization (unverified): ISO 42005 and ISO 42006 are plausible harmonization candidates for the Act's impact-assessment and conformity-assessment / notified-body obligations respectively. (Finding 8, unverified: 42005 · 42006.)

Bottom line

Taken together, the set is structurally complete on the governance-and-certification axis: board → risk → impact assessment → internal-audit assurance → certifier accreditation, with a maturation arc from 2022 to 2025 and one openly readable anchor (IIA). The known hole is deliberate and worth restating: this scaffolding assures a technical-eval floor it does not define, the agentic-RAI layer still needs its own standardized counterpart.


Unverified mappings are labeled inline and should be confirmed before being cited as established.