United Kingdom - AI Assurance Roadmap
Trusted Third‑Party AI Assurance Roadmap (DSIT)
United Kingdom
RAI-GB-NA-TTAARXX-2025The Department for Science, Innovation and Technology (DSIT) published the "Trusted third-party AI assurance roadmap" on 3 September 2025 to catalyse a high-quality market for independent AI assurance services in the UK. The roadmap sets out actions to professionalise third-party AI assurance, develop skills and competencies, improve information access, and establish an AI Assurance Innovation Fund (£11m) to stimulate new assurance tools and methods.
Summary
The Trusted Third‑Party AI Assurance Roadmap, published by the UK Department for Science, Innovation and Technology (DSIT) on 3 September 2025, is a strategic framework designed to accelerate the growth and credibility of the third‑party AI assurance market in the United Kingdom. It recognises third‑party assurance providers — independent companies that evaluate, audit, or test AI systems — as a critical mechanism for demonstrating the trustworthiness of AI systems and increasing adoption by both private and public sector organisations. The roadmap synthesises DSIT's market analysis, expert roundtables, engagement with the quality infrastructure (including UKAS) and existing professional bodies, and commissioned research on potential interactions with other regulatory regimes such as the EU AI Act.
Key ambitions include convening a multistakeholder consortium to build the foundations of a future AI assurance profession (including a voluntary professional code of ethics), creating a comprehensive skills and competencies framework, mapping the information access needs of assurance engagements to inform best practice guidance, and supporting innovation through an AI Assurance Innovation Fund with an initial commitment of £11 million to be administered with the aim of opening the first round of grants in Spring 2026. DSIT positions the roadmap as a market‑shaping instrument that initially relies on voluntary mechanisms — professionalisation, codes, standards alignment, and incentives — rather than imposing immediate statutory regulatory burdens. It identifies four market barriers: inconsistent quality and lack of recognised standards, skills shortages and unclear career pathways, information asymmetries between customers and assurance providers, and limited incentives to innovate in assurance methods.
The roadmap details three potential quality assurance models (people‑centred professionalisation; process or tool certification; and institution‑level accreditation) and envisages these working in sequence and in combination to increase market confidence. DSIT will convene the consortium, coordinate with UK quality infrastructure bodies (notably UKAS), engage international initiatives (for example the AIQI Consortium), and explore future levers for implementation including industry codes, accreditation pathways, and links to existing safety, security, and data protection regimes. Although the document is not a statute and does not itself create penalties, it outlines linkages to existing regulation (e.g., Data Protection Act / UK GDPR oversight by the ICO) and highlights that future mandatory measures or regulatory requirements could follow depending on market development and interactions with other UK or international instruments. The roadmap is explicitly positioned to make the UK a global hub for AI assurance, projecting significant GVA growth if uptake and quality are realised.
Full article
Read full text ↗Overview
The Trusted Third‑Party AI Assurance Roadmap published by the Department for Science, Innovation and Technology (DSIT) on 3 September 2025 sets out a market‑focused plan to grow a reliable third‑party AI assurance sector in the UK. The roadmap argues that independent assurance—conducted by specialised providers separate from developers and deployers—can play a critical role in building public and purchaser confidence, supporting adoption, and enabling safer innovation. It identifies current barriers (quality, skills, information access and innovation) and proposes near‑term government interventions to convene stakeholders, create skills frameworks, and seed market innovation through an AI Assurance Innovation Fund of £11 million. The Roadmap is non‑statutory and emphasises voluntary professionalisation, but it clearly links to the broader UK policy environment including quality infrastructure (e.g. UKAS), data protection oversight and interactions with international instruments.
Definitions
Key terms defined or used consistently in the roadmap include: "third‑party AI assurance" (independent evaluation, testing or audit services provided by organisations external to the AI developer or deployer); "assurance provider" (entity offering assurance services); "professionalisation" (activity to develop a recognised profession, with codes, competencies and potential certification or registration); and "information access requirements" (the data, models and governance artefacts assurance providers require to perform meaningful assessments). The document distinguishes third‑party assurance from internal compliance functions and indicates that assurance can target systems, processes, tools or organisational practices across the AI lifecycle.
Governance and Institutional Framework
DSIT will act as the convening sponsor and coordinator for initial activities, including standing up a multistakeholder consortium composed of representatives from industry, regulators, existing professional bodies and the UK quality infrastructure. The consortium will be led by a nominated partner and tasked, in the first year, with producing a voluntary code of ethics for AI assurance, a skills and competencies framework, and a mapping of information access requirements. DSIT indicates it will maintain close relationships with the UK Accreditation Service (UKAS), sector regulators, and international efforts such as the AIQI Consortium to ensure institutional alignment. The roadmap does not create new statutory powers; it instead relies on cross‑sector governance mechanisms, voluntary standards and alignment with existing regulator remits to encourage market development.
Key Focus Areas
The roadmap concentrates on four mutually reinforcing priorities: 1) Quality and standards — bringing coherence to assurance methods and exploring accreditations and certifications to make quality visible and comparable; 2) Skills and professional pathways — developing a competencies framework that draws on adjacent disciplines (cybersecurity, data science, privacy, internal audit) and supports training and recruitment; 3) Information access and trust — mapping what evidence assurance providers need and crafting best practice guidance that balances commercial confidentiality with rigorous assessment needs; and 4) Innovation in assurance methods — creating incentives and funding for novel technical and socio‑technical assurance approaches through the dedicated AI Assurance Innovation Fund. The roadmap explores three quality models — professional certification for individuals, certification/validation of specific assurance tools or processes, and institution‑level accreditation — and suggests these models can be applied incrementally to raise confidence in the market.
Implementation Framework
Implementation is structured around near‑term, government‑supported activities and a medium‑term sequence of market interventions. Near term tasks (Year 1) include establishing the consortium, drafting voluntary professional ethics and competency materials, and mapping information flows required for different assurance engagements. Medium term actions include piloting professional certification schemes, working with the UK quality infrastructure to explore accreditation routes (for instance, accreditation approaches linked to management system standards), and deploying fund grants to develop scalable assurance tools. DSIT commits to monitoring progress and to exploring regulatory levers in future depending on market outcomes. The roadmap emphasises partnership with sector regulators and standards bodies to ensure alignment and avoid duplicated or conflicting requirements.
Monitoring and Evaluation
DSIT sets out an intention to track metrics such as market size (GVA and number of providers), quality indicators (e.g., adoption of accredited processes or professional certification), workforce metrics (number of trained assurance professionals), and outputs from funded innovation projects. Monitoring will be conducted through consortium reporting and DSIT research updates; DSIT also commits to regular engagement with the UK quality infrastructure and sectoral regulators to evaluate the effectiveness of voluntary interventions and to determine whether regulatory measures are necessary to address persistent market failures.
Penalties, Liability, and Appeals
The roadmap is not a statutory regulation and therefore does not itself establish a new penalty regime. It notes, however, that assurance activities operate within an existing legal and regulatory framework: malpractice or false claims about assurance could engage consumer protection rules and professional liability regimes; data misuse during assurance engagements is subject to the Data Protection Act/UK GDPR under ICO oversight (ICO); and sector regulators retain enforcement powers where assurance intersects regulated activities. DSIT also signals that future, more prescriptive instruments — including potential mandatory accreditation or registration in specific high‑risk contexts — could introduce statutory obligations and penalties, should voluntary approaches fail to deliver adequate market quality.
Relationship to Other Instruments
The roadmap situates third‑party AI assurance within a wider policy ecosystem. It draws links to DSIT's AI Opportunities Action Plan, the national Industrial Strategy and Compute Roadmap, and to standards development efforts (both UK and international). DSIT commissioned research on interactions with the EU AI Act and indicates its intention to align UK approaches with credible international norms while preserving market flexibility. The document also references prior DSIT grant activity such as the Fairness Innovation Challenge, which concluded in March 2025 and generated publicly available approaches to bias auditing.
International Alignment
International engagement is central to the roadmap's ambition that the UK become a global AI assurance hub. DSIT intends to work with international initiatives such as the AIQI Consortium and to coordinate quality infrastructure approaches with partners such as UKAS. The roadmap recognises that cross‑border consistency in assurance approaches, interoperability of accreditation schemes, and mutual recognition of professional credentials will all be important to enable trade and to avoid fragmentation. DSIT commits to considering international standards (e.g., ISO/IEC workstreams) and to actively engage with like‑minded countries to promote common assurance principles and practices.
Implementation Timeline
| Milestone | Date |
|---|---|
| Roadmap published | 2025-09-03 |
| Consortium convened (initial phase) | 2025-12-31 |
| Fairness Innovation Challenge conclusion (background) | 2025-03-31 |
| AI Assurance Innovation Fund — first round opens (planned) | 2026-03-31 |
| Consortium deliverables (code, competencies, info mapping) — target | 2026-09-03 |
Sources and References
| Source | Type |
|---|---|
| Trusted third-party AI assurance roadmap (DSIT) | Primary Source |
| Written statement: Roadmap to trusted third‑party AI assurance (UK Parliament) | Primary Source |
| UKAS: AI accreditation update | Primary Source |
Requirements for a company
What an organisation has to do under United Kingdom - AI Assurance Roadmap, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
0Nothing in this category.
Must not do
0Nothing in this category.
Should do
7- Engage with the DSIT-led consortium to develop voluntary codes and competencies.Representatives from industry, regulators, and professional bodies.
- Adhere to the voluntary code of ethics for AI assurance professionals once published.Third-party AI assurance professionals.
- Adopt the emerging skills and competencies framework for AI assurance professionals.Third-party AI assurance providers.
- Map existing training courses to the emerging AI assurance skills and competencies framework.Employers and training providers.
- Map information access requirements and follow best practice guidance for sharing data and models.Third-party AI assurance providers and AI deployers.
- Explore and adopt accreditations or certifications for AI assurance methods, tools, or institutional practices.Third-party AI assurance providers.
- +1 more in the table below
Should not do
0Nothing in this category.
Who must do what
The obligations under United Kingdom - AI Assurance Roadmap, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Representatives from industry, regulators, and professional bodies. | Engage with the DSIT-led consortium to develop voluntary codes and competencies. “DSIT will act as the convening sponsor and coordinator for initial activities, including standing up a multistakeholder consortium composed of representatives from industry, regulators, existing professional bodies...” | — | Governance and Institutional Framework | Recommended |
| 2 | Third-party AI assurance professionals. | Adhere to the voluntary code of ethics for AI assurance professionals once published. “The consortium will be led by a nominated partner and tasked, in the first year, with producing a voluntary code of ethics for AI assurance...” | Sep 3, 2026 | Governance and Institutional Framework | Recommended |
| 3 | Third-party AI assurance providers. | Adopt the emerging skills and competencies framework for AI assurance professionals. “Skills and professional pathways — developing a competencies framework that draws on adjacent disciplines... and supports training and recruitment” | — | Key Focus Areas | Recommended |
| 4 | Employers and training providers. | Map existing training courses to the emerging AI assurance skills and competencies framework. “developing a competencies framework that draws on adjacent disciplines (cybersecurity, data science, privacy, internal audit) and supports training and recruitment” | — | Key Focus Areas | Recommended |
| 5 | Third-party AI assurance providers and AI deployers. | Map information access requirements and follow best practice guidance for sharing data and models. “Information access and trust — mapping what evidence assurance providers need and crafting best practice guidance” | — | Key Focus Areas | Recommended |
| 6 | Third-party AI assurance providers. | Explore and adopt accreditations or certifications for AI assurance methods, tools, or institutional practices. “Quality and standards — bringing coherence to assurance methods and exploring accreditations and certifications to make quality visible and comparable” | — | Key Focus Areas | Recommended |
| 7 | Researchers and third-party AI assurance providers. | Monitor DSIT announcements and apply for grants from the AI Assurance Innovation Fund. “creating incentives and funding for novel technical and socio‑technical assurance approaches through the dedicated AI Assurance Innovation Fund.” | Mar 31, 2026 | Key Focus Areas | Recommended |
Related Regulations
AI Safety Institute (establishment following AI Safety Summit)
United Kingdom91% similar
National AI Strategy - AI Action Plan
United Kingdom90% similar
National AI Strategy
United Kingdom90% similar
A Pro‑Innovation Approach to AI Regulation (White Paper)
United Kingdom90% similar
AI Opportunities Action Plan (Matt Clifford) and Government acceptance/response
United Kingdom90% similar
© Regulations.AI · updated on 13-Jun-2026