Timothy Godlove, John Buchanan · Transactions on Engineering and Computing Sciences 2026 · 2026
DOI: 10.14738/tecs.1405.12205
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Generative and agentic artificial intelligence challenge assumptions embedded in traditional model risk management (MRM), including stable system boundaries, direct observability, controllable change, and access to model-development evidence. Yet the enduring purposes of MRM—inventory, materiality assessment, independent validation, monitoring, documentation, effective challenge, and accountable governance—remain necessary. This conceptual and applied article develops a socio-technical assurance architecture for contemporary AI systems by integrating governmental and regulatory guidance, international standards, professional assurance practices, and scholarly literature. The proposed Integrated AI Assurance Framework connects four distinct but interdependent functions: AI governance; AI risk management and MRM; independent AI/model validation; and AI auditing. The article also introduces the AI Assurance Boundary, which defines the technical and organizational components whose evidence is material to justified reliance on an AI-enabled capability, and the Assurance Sufficiency Principle, which addresses circumstances in which complete transparency, traceability, or explainability is unattainable. The resulting architecture is risk-based, with assurance intensity varying according to materiality, consequentiality, autonomy, data sensitivity, regulatory exposure, observability, topology, and third-party dependence. Lending, employment, and agentic-enterprise illustrations demonstrate how the framework supports accountable ownership, effective challenge, evidence, escalation, and independent assurance.
No comments yet — start the discussion below.