United Kingdom - AI Assurance Roadmap

Trusted Third‑Party AI Assurance Roadmap (DSIT)

United Kingdom

RAI-GB-NA-TTAARXX-2025
In Force(In Force)
PolicyGovernance and OversightConformity Assessment and RegistrationInternational Alignment
Export PDF

The Department for Science, Innovation and Technology (DSIT) published the "Trusted third-party AI assurance roadmap" on 3 September 2025 to catalyse a high-quality market for independent AI assurance services in the UK. The roadmap sets out actions to professionalise third-party AI assurance, develop skills and competencies, improve information access, and establish an AI Assurance Innovation Fund (£11m) to stimulate new assurance tools and methods.

Summary

The Trusted Third‑Party AI Assurance Roadmap, published by the UK Department for Science, Innovation and Technology (DSIT) on 3 September 2025, is a strategic framework designed to accelerate the growth and credibility of the third‑party AI assurance market in the United Kingdom. It recognises third‑party assurance providers — independent companies that evaluate, audit, or test AI systems — as a critical mechanism for demonstrating the trustworthiness of AI systems and increasing adoption by both private and public sector organisations. The roadmap synthesises DSIT's market analysis, expert roundtables, engagement with the quality infrastructure (including UKAS) and existing professional bodies, and commissioned research on potential interactions with other regulatory regimes such as the EU AI Act.

Key ambitions include convening a multistakeholder consortium to build the foundations of a future AI assurance profession (including a voluntary professional code of ethics), creating a comprehensive skills and competencies framework, mapping the information access needs of assurance engagements to inform best practice guidance, and supporting innovation through an AI Assurance Innovation Fund with an initial commitment of £11 million to be administered with the aim of opening the first round of grants in Spring 2026. DSIT positions the roadmap as a market‑shaping instrument that initially relies on voluntary mechanisms — professionalisation, codes, standards alignment, and incentives — rather than imposing immediate statutory regulatory burdens. It identifies four market barriers: inconsistent quality and lack of recognised standards, skills shortages and unclear career pathways, information asymmetries between customers and assurance providers, and limited incentives to innovate in assurance methods.

The roadmap details three potential quality assurance models (people‑centred professionalisation; process or tool certification; and institution‑level accreditation) and envisages these working in sequence and in combination to increase market confidence. DSIT will convene the consortium, coordinate with UK quality infrastructure bodies (notably UKAS), engage international initiatives (for example the AIQI Consortium), and explore future levers for implementation including industry codes, accreditation pathways, and links to existing safety, security, and data protection regimes. Although the document is not a statute and does not itself create penalties, it outlines linkages to existing regulation (e.g., Data Protection Act / UK GDPR oversight by the ICO) and highlights that future mandatory measures or regulatory requirements could follow depending on market development and interactions with other UK or international instruments. The roadmap is explicitly positioned to make the UK a global hub for AI assurance, projecting significant GVA growth if uptake and quality are realised.

Full article

Read full text ↗

Overview

The Trusted Third‑Party AI Assurance Roadmap published by the Department for Science, Innovation and Technology (DSIT) on 3 September 2025 sets out a market‑focused plan to grow a reliable third‑party AI assurance sector in the UK. The roadmap argues that independent assurance—conducted by specialised providers separate from developers and deployers—can play a critical role in building public and purchaser confidence, supporting adoption, and enabling safer innovation. It identifies current barriers (quality, skills, information access and innovation) and proposes near‑term government interventions to convene stakeholders, create skills frameworks, and seed market innovation through an AI Assurance Innovation Fund of £11 million. The Roadmap is non‑statutory and emphasises voluntary professionalisation, but it clearly links to the broader UK policy environment including quality infrastructure (e.g. UKAS), data protection oversight and interactions with international instruments.

Definitions

Key terms defined or used consistently in the roadmap include: "third‑party AI assurance" (independent evaluation, testing or audit services provided by organisations external to the AI developer or deployer); "assurance provider" (entity offering assurance services); "professionalisation" (activity to develop a recognised profession, with codes, competencies and potential certification or registration); and "information access requirements" (the data, models and governance artefacts assurance providers require to perform meaningful assessments). The document distinguishes third‑party assurance from internal compliance functions and indicates that assurance can target systems, processes, tools or organisational practices across the AI lifecycle.

Governance and Institutional Framework

DSIT will act as the convening sponsor and coordinator for initial activities, including standing up a multistakeholder consortium composed of representatives from industry, regulators, existing professional bodies and the UK quality infrastructure. The consortium will be led by a nominated partner and tasked, in the first year, with producing a voluntary code of ethics for AI assurance, a skills and competencies framework, and a mapping of information access requirements. DSIT indicates it will maintain close relationships with the UK Accreditation Service (UKAS), sector regulators, and international efforts such as the AIQI Consortium to ensure institutional alignment. The roadmap does not create new statutory powers; it instead relies on cross‑sector governance mechanisms, voluntary standards and alignment with existing regulator remits to encourage market development.

Key Focus Areas

The roadmap concentrates on four mutually reinforcing priorities: 1) Quality and standards — bringing coherence to assurance methods and exploring accreditations and certifications to make quality visible and comparable; 2) Skills and professional pathways — developing a competencies framework that draws on adjacent disciplines (cybersecurity, data science, privacy, internal audit) and supports training and recruitment; 3) Information access and trust — mapping what evidence assurance providers need and crafting best practice guidance that balances commercial confidentiality with rigorous assessment needs; and 4) Innovation in assurance methods — creating incentives and funding for novel technical and socio‑technical assurance approaches through the dedicated AI Assurance Innovation Fund. The roadmap explores three quality models — professional certification for individuals, certification/validation of specific assurance tools or processes, and institution‑level accreditation — and suggests these models can be applied incrementally to raise confidence in the market.

Implementation Framework

Implementation is structured around near‑term, government‑supported activities and a medium‑term sequence of market interventions. Near term tasks (Year 1) include establishing the consortium, drafting voluntary professional ethics and competency materials, and mapping information flows required for different assurance engagements. Medium term actions include piloting professional certification schemes, working with the UK quality infrastructure to explore accreditation routes (for instance, accreditation approaches linked to management system standards), and deploying fund grants to develop scalable assurance tools. DSIT commits to monitoring progress and to exploring regulatory levers in future depending on market outcomes. The roadmap emphasises partnership with sector regulators and standards bodies to ensure alignment and avoid duplicated or conflicting requirements.

Monitoring and Evaluation

DSIT sets out an intention to track metrics such as market size (GVA and number of providers), quality indicators (e.g., adoption of accredited processes or professional certification), workforce metrics (number of trained assurance professionals), and outputs from funded innovation projects. Monitoring will be conducted through consortium reporting and DSIT research updates; DSIT also commits to regular engagement with the UK quality infrastructure and sectoral regulators to evaluate the effectiveness of voluntary interventions and to determine whether regulatory measures are necessary to address persistent market failures.

Penalties, Liability, and Appeals

The roadmap is not a statutory regulation and therefore does not itself establish a new penalty regime. It notes, however, that assurance activities operate within an existing legal and regulatory framework: malpractice or false claims about assurance could engage consumer protection rules and professional liability regimes; data misuse during assurance engagements is subject to the Data Protection Act/UK GDPR under ICO oversight (ICO); and sector regulators retain enforcement powers where assurance intersects regulated activities. DSIT also signals that future, more prescriptive instruments — including potential mandatory accreditation or registration in specific high‑risk contexts — could introduce statutory obligations and penalties, should voluntary approaches fail to deliver adequate market quality.

Relationship to Other Instruments

The roadmap situates third‑party AI assurance within a wider policy ecosystem. It draws links to DSIT's AI Opportunities Action Plan, the national Industrial Strategy and Compute Roadmap, and to standards development efforts (both UK and international). DSIT commissioned research on interactions with the EU AI Act and indicates its intention to align UK approaches with credible international norms while preserving market flexibility. The document also references prior DSIT grant activity such as the Fairness Innovation Challenge, which concluded in March 2025 and generated publicly available approaches to bias auditing.

International Alignment

International engagement is central to the roadmap's ambition that the UK become a global AI assurance hub. DSIT intends to work with international initiatives such as the AIQI Consortium and to coordinate quality infrastructure approaches with partners such as UKAS. The roadmap recognises that cross‑border consistency in assurance approaches, interoperability of accreditation schemes, and mutual recognition of professional credentials will all be important to enable trade and to avoid fragmentation. DSIT commits to considering international standards (e.g., ISO/IEC workstreams) and to actively engage with like‑minded countries to promote common assurance principles and practices.

Implementation Timeline

MilestoneDate
Roadmap published2025-09-03
Consortium convened (initial phase)2025-12-31
Fairness Innovation Challenge conclusion (background)2025-03-31
AI Assurance Innovation Fund — first round opens (planned)2026-03-31
Consortium deliverables (code, competencies, info mapping) — target2026-09-03

Sources and References

SourceType
Trusted third-party AI assurance roadmap (DSIT)Primary Source
Written statement: Roadmap to trusted third‑party AI assurance (UK Parliament)Primary Source
UKAS: AI accreditation updatePrimary Source

Requirements for a company

What an organisation has to do under United Kingdom - AI Assurance Roadmap, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

0

Nothing in this category.

Must not do

0

Nothing in this category.

Should do

7
  • Engage with the DSIT-led consortium to develop voluntary codes and competencies.Representatives from industry, regulators, and professional bodies.
  • Adhere to the voluntary code of ethics for AI assurance professionals once published.Third-party AI assurance professionals.
  • Adopt the emerging skills and competencies framework for AI assurance professionals.Third-party AI assurance providers.
  • Map existing training courses to the emerging AI assurance skills and competencies framework.Employers and training providers.
  • Map information access requirements and follow best practice guidance for sharing data and models.Third-party AI assurance providers and AI deployers.
  • Explore and adopt accreditations or certifications for AI assurance methods, tools, or institutional practices.Third-party AI assurance providers.
  • +1 more in the table below

Should not do

0

Nothing in this category.

Who must do what

The obligations under United Kingdom - AI Assurance Roadmap, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Representatives from industry, regulators, and professional bodies.Engage with the DSIT-led consortium to develop voluntary codes and competencies.
DSIT will act as the convening sponsor and coordinator for initial activities, including standing up a multistakeholder consortium composed of representatives from industry, regulators, existing professional bodies...
Governance and Institutional FrameworkRecommended
2Third-party AI assurance professionals.Adhere to the voluntary code of ethics for AI assurance professionals once published.
The consortium will be led by a nominated partner and tasked, in the first year, with producing a voluntary code of ethics for AI assurance...
Sep 3, 2026Governance and Institutional FrameworkRecommended
3Third-party AI assurance providers.Adopt the emerging skills and competencies framework for AI assurance professionals.
Skills and professional pathways — developing a competencies framework that draws on adjacent disciplines... and supports training and recruitment
Key Focus AreasRecommended
4Employers and training providers.Map existing training courses to the emerging AI assurance skills and competencies framework.
developing a competencies framework that draws on adjacent disciplines (cybersecurity, data science, privacy, internal audit) and supports training and recruitment
Key Focus AreasRecommended
5Third-party AI assurance providers and AI deployers.Map information access requirements and follow best practice guidance for sharing data and models.
Information access and trust — mapping what evidence assurance providers need and crafting best practice guidance
Key Focus AreasRecommended
6Third-party AI assurance providers.Explore and adopt accreditations or certifications for AI assurance methods, tools, or institutional practices.
Quality and standards — bringing coherence to assurance methods and exploring accreditations and certifications to make quality visible and comparable
Key Focus AreasRecommended
7Researchers and third-party AI assurance providers.Monitor DSIT announcements and apply for grants from the AI Assurance Innovation Fund.
creating incentives and funding for novel technical and socio‑technical assurance approaches through the dedicated AI Assurance Innovation Fund.
Mar 31, 2026Key Focus AreasRecommended

© Regulations.AI · updated on 13-Jun-2026