The laboratory evaluates whether an AI system is sufficiently governed, reliable, secure, traceable and controlled for its stated institutional use. CRG Assurance Reports communicate a scoped assurance opinion and its limitations; they are not represented as statutory approval or accredited certification.
Cybatar Riovic Group's evidence-based methodology for independently assessing whether an AI system is sufficiently governed, reliable, secure, traceable and controlled for its stated institutional use. It is an assurance methodology, not a statutory certification scheme.
5 controls covering:
5 controls covering:
5 controls covering:
5 controls covering:
5 controls covering:
5 controls covering:
5 controls covering:
5 controls covering:
5 controls covering:
5 controls covering:
Define intended use, system boundary, material risks, regulation, evidence period and independence requirements.
Execute control design and operating-effectiveness procedures, technical evaluations and evidence verification.
Record exceptions by severity, require management response and retest material remediation.
A reviewer distinct from the lead assessor challenges evidence, findings, limitations and the proposed opinion.
Conclusions range from insufficient evidence or adverse through qualified, limited assurance and reasonable assurance.
Material model, prompt, data, tool, regulation or deployment changes can trigger reassessment.